A little-known side effect of changes to anti-money laundering laws is that more than 100,000 small businesses in Australia will, for the first time, be required to comply with the Privacy Act, starting 1 July 2026.
While most small businesses in Australia – defined as having a turnover of less than $3M pa – have been exempt from the Privacy Act since 2001, there are some exceptions to that rule. One such exception is for health service providers: no matter how small, and whether for-profit or non-profit, private sector health service providers in Australia must comply with obligations under the Privacy Act 1988, including to handle personal information in accordance with the Australian Privacy Principles (APPs).
A second exception relates to ‘reporting entities’ under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act). In order to address the risks of money-laundering, Parliament determined that certain industries must gather additional data about their clients and customers, in order to fulfil their ‘know your customer’ obligations. Since the customers of those industries are therefore obligated to hand over their valuable personal information including evidence of identity documents, there is a parallel obligation on the regulated entities to ensure that they collect, store, use, disclose and dispose of that personal information in a way which respects their customers’ privacy.
So what’s changing on 1 July?
The list of industries regulated under the AML-CTF Act is expanding. From 1 July 2026, the AML-CTF Act will cover not only the financial sector, but also lawyers, conveyancers, accountants, real estate professionals, and dealers in high value goods such as jewellers, amongst others.
Businesses in those industries which previously enjoyed the ‘small business’ exemption from the Privacy Act will lose the benefit of that exemption on 1 July. The OAIC estimates that this change will impact more than 100,000 small businesses.
(Larger businesses should already be complying with the Privacy Act, but guidance from the OAIC about the interplay between AML-CTF rules and the APPs will still be useful.)
What do businesses need to do now?
Businesses need to prepare. Significant uplift may be required to check data flows and develop a compliant Privacy Policy, collection notices, data retention procedure, and more. Over-collection and over-retention of data in particular can cause significant privacy risks.
Businesses also face a tooled-up privacy regulator, and a recently beefed-up civil penalty regime. With the OAIC currently conducting a compliance sweep of Privacy Policies to check their compliance with APP 1.4, now is the time to act, to get your house in order.
Businesses should prepare by:
- Drafting a Privacy Policy to meet the requirements of APP 1.4
- Drafting collection notices to meet the requirements of APP 5
- Assessing data flows for compliance with APPs 2-13
- Ensuring data retention procedures are appropriate
- Training staff in their privacy obligations, and
- Reviewing overall privacy maturity such as data breach preparedness.
Helios Salinger know-how can assist. See our:
- Small Business Privacy Pack for template policy documents and plain language, pragmatic guidance
- Privacy Act compliance training for easy online training for all staff, and
- Privacy Self-Assessment Toolkit to assess your maturity, or audit your business practices in more depth.
Or please get in touch with the Helios Salinger team for assistance with any privacy compliance needs, or our sister business Source for specialist advice on AML-CTF compliance.
Photograph © Juan Manuel Núñez Méndez on Unsplash



