This guide explains what changed, why law firms are affected, and what your practice should do now to meet its privacy obligations.
Privacy reform is now a real business risk
Does the Privacy Act apply to your firm?
The Privacy Act 1988 (Cth) includes a small business exemption that generally excludes businesses with annual turnover of $3 million or less. Many smaller practices have historically relied on it.
That changed on 1 July 2026. Under section 6E of the Privacy Act, a small business operator that is a reporting entity under the AML/CTF Act must comply with the Privacy Act in relation to its AML/CTF-related activities. The exemption simply does not apply.
Your firm is likely affected if it provides any of the designated services set out in the AML/CTF Act, including managing client money or assets, acting in the buying, selling or transferring of real estate or a business, or creating and managing trusts, companies or similar structures.
Not every service a law firm provides is a designated service. Litigation, advice work and court advocacy are generally not captured. But if any part of your practice provides a designated service, the Privacy Act obligations follow.
What has changed under the privacy act?
Much stronger enforcement powers
The Privacy and Other Legislation Amendment Act 2024 significantly expanded the powers of the OAIC, including the ability to issue infringement notices for certain breaches, stronger investigation and information-gathering powers, and public inquiries into systemic privacy practices.
Significantly higher penalties
Maximum penalties for serious or repeated interferences with privacy have been increased to the greater of AU$50 million, three times the value of the benefit obtained, or 30 percent of adjusted turnover during the breach period.
Individuals can now sue
The statutory cause of action for serious invasions of privacy commenced on 10 June 2025. Individuals can take legal action where a privacy invasion was intentional or reckless, serious in nature, and where they had a reasonable expectation of privacy.
New Privacy Act coverage for law firms
Since 1 July 2026, law firms providing designated services under the AML/CTF Act have been reporting entities. All reporting entities are subject to the Privacy Act regardless of turnover. The OAIC has published guidance confirming that reporting entities should not retain copies of full identification documents for record-keeping, and that privacy obligations operate alongside, not in place of, other regulatory requirements.
WHY IT MATTERS
Why law firms are in the regulatory frame
Most small and mid-sized practices have never had to comply with the Australian Privacy Principles. The AML/CTF Tranche 2 reforms changed that by bringing firms into scope as reporting entities, which brings them into scope under the Privacy Act at the same time.
The risk profile is significant. Firms routinely hold identity documents, financial records, trust account details, family and criminal matter files, and in many cases health and hardship information. Much of it is collected in person or by email, held for years, and shared with counsel, experts and other providers.
Customer due diligence adds to the pile. Firms are now collecting and verifying identity information on a scale they never have before, and keeping records for seven years. The OAIC has been explicit that AML/CTF obligations are not a licence to over-collect: you must still collect only what is reasonably necessary, and full copies of identity documents should not be retained for record-keeping purposes.
WHY IT MATTERS
What regulators have said
Two regulators now have an interest in how your firm handles client information, and they are looking at different things.
AUSTRAC has moved from guidance to enforcement. It has begun issuing notices to businesses that appear to be providing designated services without having enrolled, and has said it will prioritise action against those who wilfully ignore their obligations rather than those making a genuine effort.
The OAIC's concern is the flipside: firms collecting more than they need in the name of compliance. Its guidance for AML/CTF reporting entities makes clear that collection must be limited to what is reasonably necessary, that full copies of identity documents should not be retained for record-keeping, and that clients must be told what is collected and why. Doing AML badly and doing privacy badly are often the same act.
Key obligations under the Australian Privacy Principles
APP 1 - Privacy policy
Your firm must have a clear, accurate and accessible privacy policy explaining what personal information you collect, why, how it is used and disclosed, and how individuals can access or correct it.
APP 3 and 5 - Collection and notification
Only collect personal information that is reasonably necessary. Notify clients at or before collection about the purposes of collection and how their information will be handled. Costs agreements and client onboarding are the specific risk point here.
APP 6 - Use and disclosure
Personal information must generally only be used for the purpose it was collected for. Using client details for marketing, cross-selling or referrals without consent can breach this principle.
APP 7 - Direct marketing
Personal information cannot be used for direct marketing without consent or a compliant opt-out. Seminar invitations, newsletters and client alerts all count. The OAIC can issue infringement notices for certain direct marketing breaches.
APP 11 - Security
Firms must take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access. This covers practice management systems, email, document management and any remote access.
APP 12 and 13 - Access and correction
Individuals must be able to access and correct their personal information. There are limited exceptions, and privilege does not automatically remove the obligation to respond.
What law firms should do now
Privacy compliance requires a structured approach across three timeframes. Immediate actions address critical gaps, medium-term work builds governance capability, and strategic initiatives embed privacy into how your practice operates.
If you provide designated services and have not enrolled with AUSTRAC, do that now. Enrolment closed on 29 July 2026 and AUSTRAC has begun issuing notices to businesses that appear to be providing designated services without enrolling. Enrolment is free and completed through AUSTRAC Online Services.
Immediate (0-3 months)
Fix critical privacy gaps now
Medium term (3-12 months)
Build governance and processes
Strategic (12-18 months)
Embed long-term privacy strategy
Immediate: 0 to 3 months
- Confirm whether your practice provides designated services and is a reporting entity.
- Draft or update your privacy policy so it reflects how your firm actually collects, uses and stores personal information.
- Add a privacy collection notice to costs agreements and client onboarding documents.
- Review what identity documents you are keeping from customer due diligence, and stop retaining full copies where they are not required.
- Implement basic security hygiene, including multi-factor authentication and removing dormant system accounts.
Medium term: 3 to 12 months
- Appoint a privacy lead, and consider whether this sits with your AML/CTF compliance officer.
- Document a privacy management plan.
- Conduct data mapping across practice management, document management, trust accounting and email.
- Define retention periods for closed matters, deceased estate files and customer due diligence records.
- Review terms with barristers, experts, costs consultants and outsourced providers for confidentiality and data handling coverage.
- Deliver annual privacy training with legal-specific scenarios.
Strategic: 12 to 18 months
- Integrate privacy processes with your AML/CTF program rather than running them as separate workstreams.
- Conduct privacy impact assessments for higher-risk activities, particularly client onboarding and any AI-assisted document review or drafting tools.
- Integrate privacy risk into partner meeting reporting and the firm's risk register.
- Review professional indemnity and cyber insurance coverage.
- Treat privacy capability as a differentiator when pitching to clients in regulated sectors.
Practical checklist
Use this as an accountability tool. Assign an owner in your team to each item and track progress against it.
What businesses like yours ask
How Savira can help
Savira helps Australian law firms handle the parts of privacy compliance that are ongoing rather than one-off. Generate and maintain a privacy policy that reflects what your firm actually does, collect and record consent through your website, and keep an auditable record of who agreed to what and when, so you can answer a client or a regulator without digging through inboxes.
Whether you are a sole practitioner or a national network, Savira gives you the compliance foundations without needing a consultant or a developer.
Staying current with privacy reform
This guide was last updated 29 August 2026 to reflect the commencement of AML/CTF Tranche 2 on 1 July 2026 and the OAIC's privacy guidance for reporting entities. Australian privacy law continues to evolve. Register to stay across regulatory changes affecting law firms.

