Savira -- Making Compliance Easy
Be the business people trust

Privacy compliance for Australian law firms

Give your clients confidence that their information is handled properly.

Law firms hold some of the most sensitive personal information in the country. Since 1 July 2026, firms providing designated services under the AML/CTF Act have also been reporting entities, which means the Privacy Act applies regardless of turnover. Penalties for serious breaches reach $50 million.

Making Compliance easy

This guide explains what changed, why law firms are affected, and what your practice should do now to meet its privacy obligations.

Key takeaways

Privacy reform is now a real business risk

Penalties up to $50M

Serious or repeated privacy breaches can attract penalties up to AU$50 million, 30 percent of adjusted turnover, or three times the benefit gained.

Small business exemption falls away

Firms that are reporting entities under the AML/CTF Act lose the small business exemption under the Privacy Act. If you provide designated services, the Privacy Act applies to you regardless of turnover.

More identity data than ever

Customer due diligence means collecting and verifying identity information at a scale most firms have never handled. Every extra record you hold is extra exposure if something goes wrong.

Privilege is not a privacy shield

Legal professional privilege protects communications from disclosure. It does not exempt your firm from the Australian Privacy Principles or from the Notifiable Data Breaches scheme.

Individuals can sue

The statutory cause of action for serious invasions of privacy has been in force since 10 June 2025. Litigation and class action risk is real and present.

Partner-level issue

Privacy risk should sit alongside professional indemnity and AML/CTF compliance in your firm's governance and risk framework. It is not a back-office task.

Penalties up to $50M

Serious or repeated privacy breaches can attract penalties up to AU$50 million, 30 percent of adjusted turnover, or three times the benefit gained.

Small business exemption falls away

Firms that are reporting entities under the AML/CTF Act lose the small business exemption under the Privacy Act. If you provide designated services, the Privacy Act applies to you regardless of turnover.

More identity data than ever

Customer due diligence means collecting and verifying identity information at a scale most firms have never handled. Every extra record you hold is extra exposure if something goes wrong.

Privilege is not a privacy shield

Legal professional privilege protects communications from disclosure. It does not exempt your firm from the Australian Privacy Principles or from the Notifiable Data Breaches scheme.

Individuals can sue

The statutory cause of action for serious invasions of privacy has been in force since 10 June 2025. Litigation and class action risk is real and present.

Partner-level issue

Privacy risk should sit alongside professional indemnity and AML/CTF compliance in your firm's governance and risk framework. It is not a back-office task.

Does this apply to you?

Does the Privacy Act apply to your firm?

The Privacy Act 1988 (Cth) includes a small business exemption that generally excludes businesses with annual turnover of $3 million or less. Many smaller practices have historically relied on it.

That changed on 1 July 2026. Under section 6E of the Privacy Act, a small business operator that is a reporting entity under the AML/CTF Act must comply with the Privacy Act in relation to its AML/CTF-related activities. The exemption simply does not apply.

Your firm is likely affected if it provides any of the designated services set out in the AML/CTF Act, including managing client money or assets, acting in the buying, selling or transferring of real estate or a business, or creating and managing trusts, companies or similar structures.

Not every service a law firm provides is a designated service. Litigation, advice work and court advocacy are generally not captured. But if any part of your practice provides a designated service, the Privacy Act obligations follow.

What has changed under the privacy act?

Much stronger enforcement powers

The Privacy and Other Legislation Amendment Act 2024 significantly expanded the powers of the OAIC, including the ability to issue infringement notices for certain breaches, stronger investigation and information-gathering powers, and public inquiries into systemic privacy practices.

Significantly higher penalties

Maximum penalties for serious or repeated interferences with privacy have been increased to the greater of AU$50 million, three times the value of the benefit obtained, or 30 percent of adjusted turnover during the breach period.

Individuals can now sue

The statutory cause of action for serious invasions of privacy commenced on 10 June 2025. Individuals can take legal action where a privacy invasion was intentional or reckless, serious in nature, and where they had a reasonable expectation of privacy.

New Privacy Act coverage for law firms

Since 1 July 2026, law firms providing designated services under the AML/CTF Act have been reporting entities. All reporting entities are subject to the Privacy Act regardless of turnover. The OAIC has published guidance confirming that reporting entities should not retain copies of full identification documents for record-keeping, and that privacy obligations operate alongside, not in place of, other regulatory requirements.

WHY IT MATTERS

Why law firms are in the regulatory frame

Most small and mid-sized practices have never had to comply with the Australian Privacy Principles. The AML/CTF Tranche 2 reforms changed that by bringing firms into scope as reporting entities, which brings them into scope under the Privacy Act at the same time.

The risk profile is significant. Firms routinely hold identity documents, financial records, trust account details, family and criminal matter files, and in many cases health and hardship information. Much of it is collected in person or by email, held for years, and shared with counsel, experts and other providers.

Customer due diligence adds to the pile. Firms are now collecting and verifying identity information on a scale they never have before, and keeping records for seven years. The OAIC has been explicit that AML/CTF obligations are not a licence to over-collect: you must still collect only what is reasonably necessary, and full copies of identity documents should not be retained for record-keeping purposes.

WHY IT MATTERS

What regulators have said

Person reading The Australian newspaper article about Australian privacy compliance on a tablet device

Two regulators now have an interest in how your firm handles client information, and they are looking at different things.

AUSTRAC has moved from guidance to enforcement. It has begun issuing notices to businesses that appear to be providing designated services without having enrolled, and has said it will prioritise action against those who wilfully ignore their obligations rather than those making a genuine effort.

The OAIC's concern is the flipside: firms collecting more than they need in the name of compliance. Its guidance for AML/CTF reporting entities makes clear that collection must be limited to what is reasonably necessary, that full copies of identity documents should not be retained for record-keeping, and that clients must be told what is collected and why. Doing AML badly and doing privacy badly are often the same act.

THE APPS

Key obligations under the Australian Privacy Principles

APP 1 - Privacy policy

APP 1 - Privacy policy

Your firm must have a clear, accurate and accessible privacy policy explaining what personal information you collect, why, how it is used and disclosed, and how individuals can access or correct it.

APP 3 and 5 - Collection and notification

APP 3 and 5 - Collection and notification

Only collect personal information that is reasonably necessary. Notify clients at or before collection about the purposes of collection and how their information will be handled. Costs agreements and client onboarding are the specific risk point here.

APP 6 - Use and disclosure

APP 6 - Use and disclosure

Personal information must generally only be used for the purpose it was collected for. Using client details for marketing, cross-selling or referrals without consent can breach this principle.

APP 7 - Direct marketing

APP 7 - Direct marketing

Personal information cannot be used for direct marketing without consent or a compliant opt-out. Seminar invitations, newsletters and client alerts all count. The OAIC can issue infringement notices for certain direct marketing breaches.

APP 11 - Security

APP 11 - Security

Firms must take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access. This covers practice management systems, email, document management and any remote access.

APP 12 and 13 - Access and correction

APP 12 and 13 - Access and correction

Individuals must be able to access and correct their personal information. There are limited exceptions, and privilege does not automatically remove the obligation to respond.

YOUR COMPLIANCE ROADMAP

What law firms should do now

Privacy compliance requires a structured approach across three timeframes. Immediate actions address critical gaps, medium-term work builds governance capability, and strategic initiatives embed privacy into how your practice operates.

If you provide designated services and have not enrolled with AUSTRAC, do that now. Enrolment closed on 29 July 2026 and AUSTRAC has begun issuing notices to businesses that appear to be providing designated services without enrolling. Enrolment is free and completed through AUSTRAC Online Services.

Immediate (0-3 months)

Fix critical privacy gaps now

Medium term (3-12 months)

Build governance and processes

Strategic (12-18 months)

Embed long-term privacy strategy

Immediate: 0 to 3 months

  • Confirm whether your practice provides designated services and is a reporting entity.
  • Draft or update your privacy policy so it reflects how your firm actually collects, uses and stores personal information.
  • Add a privacy collection notice to costs agreements and client onboarding documents.
  • Review what identity documents you are keeping from customer due diligence, and stop retaining full copies where they are not required.
  • Implement basic security hygiene, including multi-factor authentication and removing dormant system accounts.

Medium term: 3 to 12 months

  • Appoint a privacy lead, and consider whether this sits with your AML/CTF compliance officer.
  • Document a privacy management plan.
  • Conduct data mapping across practice management, document management, trust accounting and email.
  • Define retention periods for closed matters, deceased estate files and customer due diligence records.
  • Review terms with barristers, experts, costs consultants and outsourced providers for confidentiality and data handling coverage.
  • Deliver annual privacy training with legal-specific scenarios.

Strategic: 12 to 18 months

  • Integrate privacy processes with your AML/CTF program rather than running them as separate workstreams.
  • Conduct privacy impact assessments for higher-risk activities, particularly client onboarding and any AI-assisted document review or drafting tools.
  • Integrate privacy risk into partner meeting reporting and the firm's risk register.
  • Review professional indemnity and cyber insurance coverage.
  • Treat privacy capability as a differentiator when pitching to clients in regulated sectors.
Free tool

Practical checklist

Use this as an accountability tool. Assign an owner in your team to each item and track progress against it.

AreaImmediate PriorityNext Phase
Privacy PolicyDraft or update and publishSchedule annual review
Collection noticesAdd privacy disclosures to costs agreements and onboardingStandardise templates across all practice areas
Identity documentsAudit what you hold from customer due diligenceSet and enforce retention and destruction periods
Matter filesAudit what is stored and whereDefine retention for closed matters and estate files
MarketingConfirm consent and opt-out on all client communicationsConduct full CRM and mailing list governance review
SecurityEnforce multi-factor authentication; remove dormant accountsCommission periodic risk assessment
SecurityTighten access controls; remove dormant accounts; enforce MFACommission periodic risk assessments; establish breach response plan
TrainingInitial all-staff sessionBuild annual refresh into calendar
GovernanceAppoint a privacy leadIntegrate into partner reporting cycle
Privacy Policy
Immediate PriorityDraft or update and publish
Next PhaseSchedule annual review
Collection notices
Immediate PriorityAdd privacy disclosures to costs agreements and onboarding
Next PhaseStandardise templates across all practice areas
Identity documents
Immediate PriorityAudit what you hold from customer due diligence
Next PhaseSet and enforce retention and destruction periods
Matter files
Immediate PriorityAudit what is stored and where
Next PhaseDefine retention for closed matters and estate files
Marketing
Immediate PriorityConfirm consent and opt-out on all client communications
Next PhaseConduct full CRM and mailing list governance review
Security
Immediate PriorityEnforce multi-factor authentication; remove dormant accounts
Next PhaseCommission periodic risk assessment
Security
Immediate PriorityTighten access controls; remove dormant accounts; enforce MFA
Next PhaseCommission periodic risk assessments; establish breach response plan
Training
Immediate PriorityInitial all-staff session
Next PhaseBuild annual refresh into calendar
Governance
Immediate PriorityAppoint a privacy lead
Next PhaseIntegrate into partner reporting cycle
Common questions

What businesses like yours ask

If your firm provides designated services under the AML/CTF Act, yes. Section 6E of the Privacy Act removes the small business exemption for reporting entities. Litigation, advice work and court advocacy are generally not designated services, but if any part of the practice provides one, the obligations follow.
No. Privilege protects communications from compelled disclosure. It does not exempt your firm from the Australian Privacy Principles, the Notifiable Data Breaches scheme, or an individual's right to seek access to their personal information.
Enrol as soon as you can. Enrolment closed on 29 July 2026 and AUSTRAC has begun issuing notices to businesses that appear to be providing designated services without enrolling. It has indicated it will focus on those wilfully ignoring their obligations rather than firms making a genuine effort. Enrolment is free through AUSTRAC Online Services.
Probably. Most firm websites run analytics and often advertising scripts, and those collect personal information before anyone has agreed to it. Your enquiry form also needs a collection notice, because a prospective client filling it in is handing over information about a legal problem before they are even a client.
Almost certainly. Customer due diligence means you are collecting identity information you were not collecting before, from people you may never act for, and keeping it for seven years. If the policy does not say that, it does not reflect your practice.

How Savira can help

Savira helps Australian law firms handle the parts of privacy compliance that are ongoing rather than one-off. Generate and maintain a privacy policy that reflects what your firm actually does, collect and record consent through your website, and keep an auditable record of who agreed to what and when, so you can answer a client or a regulator without digging through inboxes.

Whether you are a sole practitioner or a national network, Savira gives you the compliance foundations without needing a consultant or a developer.

Staying current with privacy reform

This guide was last updated 29 August 2026 to reflect the commencement of AML/CTF Tranche 2 on 1 July 2026 and the OAIC's privacy guidance for reporting entities. Australian privacy law continues to evolve. Register to stay across regulatory changes affecting law firms.