Your business may have privacy duties now, and the ID scans are the first job

A rule change most small offices have not been told about

Australia's Privacy Act has always let most small businesses off. If your annual turnover is $3 million or less you were generally exempt, and a lot of good businesses have run for years without a privacy policy or a retention rule.

That exemption stopped helping a large group of small businesses on 1 July 2026.

The reason is not a privacy law change. It is the money laundering rules. From 1 July 2026 the anti-money laundering and counter-terrorism financing laws began applying to services commonly provided by legal professionals, accountants, conveyancers, real estate professionals and dealers in precious stones and metals (AUSTRAC, 26 March 2026). Businesses in those sectors are usually called tranche 2 entities.

Once you are a reporting entity, the privacy exemption no longer covers the customer information you handle for those obligations. The regulator puts it plainly.

So a two person conveyancing practice that verifies a client's identity is now handling that information under the Australian Privacy Principles, in the same way a large firm does.

This page is about the information technology side of that: where the customer identity records actually sit in a small office, and what to do with them. It is not legal advice, and it does not tell you whether you are a reporting entity. That question belongs to AUSTRAC and to your own adviser.

The surprise in the rules: you were never asked to keep the scans

Most offices verify identity the same way. The client emails a photo of a passport or a licence, someone saves it into the matter folder, and it stays there forever because nobody wants to be the person who deleted proof.

The record keeping rules do not ask for that.

The regulator's guidance says to keep the details you relied on instead, such as the name, date of birth, residential address, document number and expiry date. That applies from when the new laws commence, which is 31 March 2026 for tranche 1 reporting entities and 1 July 2026 for tranche 2.

That single distinction changes the risk in a small office more than any product you could buy. Keeping the verification record instead of the picture reduces how much you hold, and the details you do keep still need protecting. A folder holding nine hundred licence and passport images is a different problem again. That is an identity theft kit, and it is sitting on a machine in a suburban office.

Where those images actually are

Almost nobody has them in one place. Before you can reduce anything, find every copy. In a typical small office the images are in at least five of these:

The last two are the ones that catch people out. Deleting a file from the shared drive does not remove it from six months of backups, and it does nothing at all about the copy in the mailbox.

What to do, in order

This is the sequence that works in a small office. Each step is finishable in an afternoon, and each one reduces the damage of a break in before the next step starts.

  1. Stop the inflow first. Change how you ask for identity so new scans stop arriving by email. Verify in person or through a verification service, record the details, and tell staff not to save the image.
  2. Write down what you are allowed to keep. The details, not the picture. Put it in one short internal note so the answer does not depend on who is at the desk.
  3. Find every copy, including mailboxes, backups and phones. Search by file type and by keyword across each system rather than browsing folders.
  4. Extract the details you need into the client record, then destroy the images. Check before you destroy anything: the rule requires reasonable steps to destroy or de-identify personal information once it is no longer needed for any purpose for which it may be used or disclosed, but it does not apply where an Australian law or a court or tribunal order requires you to retain it. In these professions that exception is not theoretical, so confirm your own record keeping duties first.
  5. Secure what remains. The information you keep still needs protecting from misuse, interference, loss and unauthorised access. In practice that means access limited to the people who need it, multi factor authentication on the systems holding it, and a device that is encrypted and patched.
  6. Tell people what you collect and why. Before you collect the information, or as soon as practicable afterwards, you have to take reasonable steps to notify the customer. The regulator publishes a template collection notice for reporting entities, which is a far better starting point than writing your own.
  7. Fix retention in the backups. Decide how long copies survive, and confirm the schedule matches. This is the step most often skipped, and it is the one that makes the other six true.

What this does not mean

It does not mean deleting your records. The obligation to keep records is real and separate. What changed is the form the record takes.

It does not mean the small business exemption is gone in general. Removing it across the board has been discussed for years and is not settled law. What is settled is that being a reporting entity puts you outside the exemption for that work, and that the health, credit reporting, personal information trading and government contractor categories were already outside it.

It does not mean you need new hardware. Most of this work is finding, extracting, destroying and restricting, on systems you already own.

How we help with it

The part of this we do is the technical part. We map where personal information has accumulated across mail, file storage, line of business systems, devices and backups, reduce what is held, set access and retention so it stays reduced, and document what was done. The legal question of what your obligations are stays with your adviser, and the AML/CTF question stays with AUSTRAC.

If you would rather see the ideas before you talk to anyone, the private business infrastructure page covers how we approach data flow and custody, and private storage and backup covers the retention and restore side that step seven depends on.

Ask about a data and retention review

Frequently asked questions

Does this apply to my business?

That depends on whether you provide a designated service under the anti-money laundering laws, which is a question for AUSTRAC and your own adviser rather than for us. The sectors newly covered from 1 July 2026 are legal professionals, accountants, conveyancers, real estate professionals and dealers in precious stones and metals. If you are one of those and you verify customer identity, it is worth checking rather than assuming.

We are well under $3 million in turnover. Does the exemption still protect us?

Not for this work. The regulator's guidance states that reporting entities must comply with the Privacy Act when handling personal information in connection with their AML/CTF obligations, including businesses with an annual turnover of less than $3 million.

Do we have to delete the identity documents we already hold?

The Australian Privacy Principles require reasonable steps to destroy or de-identify personal information once it is no longer needed for any purpose for which it may be used or disclosed. That obligation does not apply where an Australian law or a court or tribunal order requires you to keep the information, so check your own record keeping duties before destroying anything. Since the AML/CTF record keeping rules do not require the images themselves, a large archive of them is hard to justify once you have confirmed nothing else requires it. Extract the details you relied on into the record first.

What should we keep instead of the scan?

The regulator's guidance points to keeping the personal information from the document that relates directly to your record keeping obligations, giving names, date of birth, residential address, date of expiry and passport or licence number as examples.

Is a password on the folder enough?

No. Protecting the information is one obligation and holding less of it is another. A password does nothing about the copy in the mailbox, the copy in the backup, or a staff member who already has access. Reduce first, then restrict access to the people who need it and put multi factor authentication on the systems that hold what is left.

Our backups still have the old scans. Is that a problem?

It is the normal situation, and it is worth fixing deliberately rather than in a panic. Decide a retention period, confirm the backup schedule actually matches it, and let the old copies age out. Do not start deleting individual files inside backups, because that tends to break the restore you are keeping them for.

Does this mean we need a privacy policy?

Handling personal information under the Australian Privacy Principles brings obligations about notifying people what you collect and why. The regulator publishes a template collection notice for reporting entities, which is the practical place to start. What your full policy needs to say is a question for your adviser.