Compliance with new anti-money laundering (AML) laws may subject your small business to additional privacy obligations it did not face before.

.
If your business will be required to comply with the Anti-Money Laundering and Counter Terrorism Financing Act 2006 (AML Act), you also need to consider your privacy obligations when handling personal information. Even if you operate a small business that would normally be exempt from privacy regulation, the new AML laws could change this.
Specifically, businesses that are reporting entities under the AML framework must comply with the Privacy Act 1988 (Privacy Act) when collecting, using, storing or disclosing personal information for AML purposes. This includes businesses with an annual turnover of less than $3 million.
Understanding how these two frameworks interact is important if your business performs customer due diligence, identity verification or transaction monitoring. This article explains how the AML and privacy frameworks interact and what small businesses need to do to comply with both.
The Privacy Act generally regulates how organisations handle personal information through the Australian Privacy Principles (APPs). While many small businesses are normally exempt, that exemption does not apply when you handle personal information to meet AML obligations. If your business is a reporting entity under the AML Act, you must comply with the Privacy Act for activities connected with those obligations.
Activities that may trigger privacy obligations include:
To meet your AML obligations, your business will often need to collect personal information about customers, employees or other individuals. Under the APPs, you must limit the information you collect to what is reasonably necessary for your functions and activities. In the AML context, this typically means collecting information required for customer due diligence or risk assessments.
During onboarding, you will commonly collect:
However, the requirement to collect information for AML purposes does not give your business unlimited authority to gather any data you want. You should always consider whether the information you are collecting is genuinely necessary for compliance. Collecting excessive or irrelevant information may increase privacy risks and create unnecessary cybersecurity exposure.
When your business collects personal information, you must notify individuals about how their information will be handled. This is typically done through a collection notice and your privacy policy.
A collection notice should explain:
In the AML context, this may include explaining that information is collected to comply with the AML Act. However, you do not need to provide a collection notice where doing so would be inconsistent with your tipping off obligations under the AML Act.
Under the APPs, personal information should generally only be used or disclosed for the primary purpose for which it was collected. For AML activities, this may include:
In some situations, your business may also be required to disclose personal information to regulators.
For example, reporting entities must submit suspicious matter reports to AUSTRAC when certain conditions are met. Because these disclosures are authorised by law, they are permitted under the Privacy Act even if the individual has not provided consent for these disclosures.
If you disclose personal information overseas (including to a third party service provider), you must generally take reasonable steps to ensure that the overseas recipient does not breach the APPs. However, exceptions apply where the disclosure is required or authorised by the AML Act.
Businesses that handle AML data often hold large volumes of sensitive personal information. This can make them attractive targets for cybercriminals. Under the APPs, you must take reasonable steps to protect personal information from misuse, interference, loss or unauthorised access.
Practical security measures include:
Having a clear response plan ensures your business can act quickly if a data breach occurs.
Under the Privacy Act, businesses must take reasonable steps to destroy or de-identify personal information once it is no longer required. However, the AML Act requires certain records to be kept for specified periods to demonstrate compliance. This means your business must retain AML records when required by law. Once the retention period expires and there is no other reason to keep the data, you should securely delete or de-identify it.
Key Statistics
Sources
If your business is a reporting entity under the AML regime, you must comply with the Privacy Act when handling personal information for those obligations. This applies even to small businesses that would otherwise be exempt from privacy regulation.
To comply with both frameworks, your business should only collect information that is reasonably necessary, provide clear privacy notices, protect personal data with appropriate security measures, and retain information only for as long as required. Taking these steps will help you meet your AML obligations while maintaining strong privacy practices and protecting the personal information entrusted to your business.
Legal Vision
Georgia MacKay
legalvision.com.au/