⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7
If your practice provides designated services under the AML/CTF Act, the Privacy Act applies to that work regardless of your turnover. The small business exemption does not cover it. Where it applies, it started on 1 July 2026, and real estate agencies, law firms, conveyancers and accounting practices are the professions most often caught by it.
Roughly half of what the regulator asks for is configuration inside your Microsoft 365 tenant. That half is what this page is about.
The AML/CTF reforms extended AUSTRAC regulation to a group of professions that had not been covered before. The OAIC lists them as real estate professionals, dealers in precious metals and stones, and professional service providers including lawyers, conveyancers, accountants, and trust and company service providers. Changes for businesses already reporting took effect on 31 March 2026.
The part that catches people is the second-order effect. A small business operator that is also an AML/CTF reporting entity has to comply with the Privacy Act in connection with those obligations, whatever its annual turnover. The $3 million threshold that kept most small practices outside the Privacy Act does not apply to that work.
So a six-person conveyancing practice that has never thought about the Australian Privacy Principles may now be handling client identity information under them. Not because the practice grew, but because of what it does.
Source: OAIC, Know your privacy obligations under the AML/CTF Act, 27 February 2026. This page describes what the guidance says. It does not tell you whether it applies to your practice, which is a question for AUSTRAC or your lawyer.
The OAIC's Privacy Essentials Checklist for AML/CTF reporting entities runs to fourteen questions. Seven of them are answered in the Microsoft 365 admin centre. Seven are answered by a lawyer. Being clear about which is which is most of the value here.
Technical controls in your Microsoft 365 tenant
“Implement cyber security controls on systems that store personal information. Controls could include role-based access controls and multi-factor authentication.”
OAIC Privacy Essentials Checklist, April 2026
MFA coverage and the accounts that slipped through it, Conditional Access, legacy authentication, privileged role sprawl in Entra ID, and shared mailboxes that can still sign in.
“Have a personal information inventory if it helps you to understand and manage your privacy risks, including keeping track of personal information with multiple purposes.”
OAIC Privacy Essentials Checklist, April 2026
Where client information actually lives across Exchange, SharePoint, OneDrive and Teams, which is rarely where anyone assumes. Purview Content Search is how you find out rather than guess.
“Does your organisation have processes in place to ensure that personal information is de-identified or destroyed once it is no longer needed, including for any AML/CTF purposes?”
OAIC Privacy Essentials Checklist, April 2026
Retention policies in Purview that actually end rather than run forever, a schedule that fires without somebody remembering, and a defined process for departed staff.
“Include staff, like IT, whose support is necessary not only to prevent a breach, but to identify affected individuals.”
OAIC Privacy Essentials Checklist, April 2026
Audit logging switched on and retained long enough to answer what was reached and whose information was in it. The default retention window is shorter than most practices expect.
“Make sure you are satisfied the third party has appropriate processes in place to protect personal information.”
OAIC Privacy Essentials Checklist, April 2026
The Enterprise Applications inventory: which third party apps someone has consented to over the years, and what they can currently read in your mail and files.
“These staff should be responsible for handling internal and external privacy enquiries, complaints, and access and correction requests in a timely manner.”
OAIC Privacy Essentials Checklist, April 2026
Being able to locate everything you hold about one individual, across every mailbox, site and chat, when they ask for it. Without Content Search this is a manual trawl.
“Organisations should monitor and address new security risks and threats.”
OAIC Privacy Essentials Checklist, April 2026
Patching, alerting, and someone actually reading what Defender and the admin centre are reporting rather than letting it accumulate unread.
Not my scope, and I will say so
Hamilton365 assesses and configures technical controls. It does not give legal advice, and I am not a lawyer. If you do not have someone for the column above, say so and I will point you at people who do this properly.
This is the question worth sitting with, because for most practices the honest answer is no.
The OAIC has been direct about identity documents. Its position is that the AML/CTF regime does not require copies of full ID documents to be kept, and that Privacy Act obligations require entities to minimise what they retain. Privacy Commissioner Carly Kind put it this way:
“One of the most significant risks to Australians' privacy is the unnecessary retention of ID documents, which are some of the most important pieces of personal information Australians possess.”
Privacy Commissioner Carly Kind, OAIC media release, 27 February 2026
In a large firm those copies sit in a document management system with a retention rule on them. In a small practice they do not. They are in email attachments, in a SharePoint folder somebody made in 2021, in the OneDrive of a staff member who left, and in a Teams chat where a client sent a photo of their licence because it was easier than scanning it.
Finding them is a Purview Content Search problem. Removing them is a retention and disposal problem. Stopping them accumulating again is a policy and DLP problem. All three are Microsoft 365 configuration, and none of them are hard once somebody has actually looked.
AML/CTF record-keeping runs for seven years. APP 11.2 requires destruction once information is no longer needed. The OAIC says full ID copies were not part of the record-keeping requirement in the first place.
Most practices have resolved this by keeping everything, which is wrong in both directions: it holds identity documents that were never required, and it usually still cannot produce a clean record of what was verified and when. Retention that satisfies both is a Purview policy design question. What the retention period should be for your practice is a question for your lawyer, and once it is decided I configure it.
Current as at August 2026. The OAIC guidance on identity document retention was published in February 2026 and updated in June 2026, and guidance this recent is the kind most likely to be revised. Read it at the source before acting on it: OAIC privacy guidance for reporting entities.
APP 11 asks for reasonable steps to protect personal information. In a tenant, reasonable steps are settings. Here is the translation.
APP 11.1, protect from unauthorised access
MFA on every account with no exceptions carved out for the principal, legacy authentication blocked, Conditional Access doing something, and privileged roles held by as few people as the practice can function with.
APP 11.1, protect from unauthorised disclosure
External sharing settings, anonymous link policy, and automatic external forwarding blocked. Most tenants are still on the defaults set the day they were created.
APP 11.2, destroy or de-identify when no longer needed
Retention and disposal policies that terminate, applied across Exchange, SharePoint and OneDrive, plus a leaver process that does not park accounts indefinitely.
APP 8, cross-border disclosure
Knowing where your tenant data is stored, and which third party applications hold standing consent to read it.
Notifiable Data Breaches, assess within 30 days
Audit logging enabled and retained past the default, so the question of what was accessed and whose information was involved is answerable inside the window rather than after it.
APP 12, respond to an access request
Purview Content Search across every mailbox, site and chat, which is the only practical way to find one person’s information in a tenant of any age.
The last one is its own discipline. If you are already facing a request or an investigation rather than preparing for one, the email investigation and eDiscovery page covers that work.
A structured review of the technical half of the OAIC checklist against your tenant, delivered as a written report you can hand to your lawyer, your insurer or your board.
Usually delivered within two weeks of tenant access being arranged. Remediation is quoted separately after the assessment, because the scope depends entirely on what turns up. Project work carries a 50% deposit.
Jamie Hamilton. 25 years in Microsoft infrastructure, currently running Identity for a 200,000-user environment. The same person scopes the assessment, does it, writes the report and takes your call about it afterwards.
Microsoft specialist rather than a general IT provider. Conditional Access, Purview retention, Content Search and Entra ID role design are the daily work, not a module somebody read up on when the AML/CTF reforms landed.
$1,850 GST inclusive, fixed fee. Tell me a little about the practice and I will confirm scope before anything starts.
Questions first? Call 0403 401 250 or email jamie@hamilton365.com.au