⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7

In force since 1 July 2026

AML/CTF brought the Privacy Act with it

If your practice provides designated services under the AML/CTF Act, the Privacy Act applies to that work regardless of your turnover. The small business exemption does not cover it. Where it applies, it started on 1 July 2026, and real estate agencies, law firms, conveyancers and accounting practices are the professions most often caught by it.

Roughly half of what the regulator asks for is configuration inside your Microsoft 365 tenant. That half is what this page is about.

What changed on 1 July 2026

The AML/CTF reforms extended AUSTRAC regulation to a group of professions that had not been covered before. The OAIC lists them as real estate professionals, dealers in precious metals and stones, and professional service providers including lawyers, conveyancers, accountants, and trust and company service providers. Changes for businesses already reporting took effect on 31 March 2026.

The part that catches people is the second-order effect. A small business operator that is also an AML/CTF reporting entity has to comply with the Privacy Act in connection with those obligations, whatever its annual turnover. The $3 million threshold that kept most small practices outside the Privacy Act does not apply to that work.

So a six-person conveyancing practice that has never thought about the Australian Privacy Principles may now be handling client identity information under them. Not because the practice grew, but because of what it does.

Source: OAIC, Know your privacy obligations under the AML/CTF Act, 27 February 2026. This page describes what the guidance says. It does not tell you whether it applies to your practice, which is a question for AUSTRAC or your lawyer.

The regulator published a checklist. Half of it is a tenant configuration job.

The OAIC's Privacy Essentials Checklist for AML/CTF reporting entities runs to fourteen questions. Seven of them are answered in the Microsoft 365 admin centre. Seven are answered by a lawyer. Being clear about which is which is most of the value here.

What I assess and configure

Technical controls in your Microsoft 365 tenant

Cyber security processes and controls

“Implement cyber security controls on systems that store personal information. Controls could include role-based access controls and multi-factor authentication.”

OAIC Privacy Essentials Checklist, April 2026

MFA coverage and the accounts that slipped through it, Conditional Access, legacy authentication, privileged role sprawl in Entra ID, and shared mailboxes that can still sign in.

An inventory of your personal information holdings

“Have a personal information inventory if it helps you to understand and manage your privacy risks, including keeping track of personal information with multiple purposes.”

OAIC Privacy Essentials Checklist, April 2026

Where client information actually lives across Exchange, SharePoint, OneDrive and Teams, which is rarely where anyone assumes. Purview Content Search is how you find out rather than guess.

Destroying information once it is no longer needed

“Does your organisation have processes in place to ensure that personal information is de-identified or destroyed once it is no longer needed, including for any AML/CTF purposes?”

OAIC Privacy Essentials Checklist, April 2026

Retention policies in Purview that actually end rather than run forever, a schedule that fires without somebody remembering, and a defined process for departed staff.

Identifying and managing a data breach

“Include staff, like IT, whose support is necessary not only to prevent a breach, but to identify affected individuals.”

OAIC Privacy Essentials Checklist, April 2026

Audit logging switched on and retained long enough to answer what was reached and whose information was in it. The default retention window is shorter than most practices expect.

Third party access to your systems

“Make sure you are satisfied the third party has appropriate processes in place to protect personal information.”

OAIC Privacy Essentials Checklist, April 2026

The Enterprise Applications inventory: which third party apps someone has consented to over the years, and what they can currently read in your mail and files.

Responding to access and correction requests

“These staff should be responsible for handling internal and external privacy enquiries, complaints, and access and correction requests in a timely manner.”

OAIC Privacy Essentials Checklist, April 2026

Being able to locate everything you hold about one individual, across every mailbox, site and chat, when they ask for it. Without Content Search this is a manual trawl.

Monitoring new security risks

“Organisations should monitor and address new security risks and threats.”

OAIC Privacy Essentials Checklist, April 2026

Patching, alerting, and someone actually reading what Defender and the admin centre are reporting rather than letting it accumulate unread.

What your lawyer handles

Not my scope, and I will say so

  • Whether the Privacy Act applies to your practice at all, and which of your work is caught
  • Your privacy policy, and whether it says what the APPs require it to say
  • Collection notices, and when a notice must not be given because of tipping-off obligations
  • Whether you are collecting more personal information than is reasonably necessary
  • Use and disclosure decisions under APP 6
  • Your privacy risk register, and whether a privacy impact assessment is warranted
  • Staff privacy training

Hamilton365 assesses and configures technical controls. It does not give legal advice, and I am not a lawyer. If you do not have someone for the column above, say so and I will point you at people who do this properly.

Where are your clients' ID document copies stored, and could you find all of them?

This is the question worth sitting with, because for most practices the honest answer is no.

The OAIC has been direct about identity documents. Its position is that the AML/CTF regime does not require copies of full ID documents to be kept, and that Privacy Act obligations require entities to minimise what they retain. Privacy Commissioner Carly Kind put it this way:

“One of the most significant risks to Australians' privacy is the unnecessary retention of ID documents, which are some of the most important pieces of personal information Australians possess.”

Privacy Commissioner Carly Kind, OAIC media release, 27 February 2026

In a large firm those copies sit in a document management system with a retention rule on them. In a small practice they do not. They are in email attachments, in a SharePoint folder somebody made in 2021, in the OneDrive of a staff member who left, and in a Teams chat where a client sent a photo of their licence because it was easier than scanning it.

Finding them is a Purview Content Search problem. Removing them is a retention and disposal problem. Stopping them accumulating again is a policy and DLP problem. All three are Microsoft 365 configuration, and none of them are hard once somebody has actually looked.

The tension nobody resolves

AML/CTF record-keeping runs for seven years. APP 11.2 requires destruction once information is no longer needed. The OAIC says full ID copies were not part of the record-keeping requirement in the first place.

Most practices have resolved this by keeping everything, which is wrong in both directions: it holds identity documents that were never required, and it usually still cannot produce a clean record of what was verified and when. Retention that satisfies both is a Purview policy design question. What the retention period should be for your practice is a question for your lawyer, and once it is decided I configure it.

Current as at August 2026. The OAIC guidance on identity document retention was published in February 2026 and updated in June 2026, and guidance this recent is the kind most likely to be revised. Read it at the source before acting on it: OAIC privacy guidance for reporting entities.

What APP 11 looks like in a Microsoft 365 tenant

APP 11 asks for reasonable steps to protect personal information. In a tenant, reasonable steps are settings. Here is the translation.

APP 11.1, protect from unauthorised access

MFA on every account with no exceptions carved out for the principal, legacy authentication blocked, Conditional Access doing something, and privileged roles held by as few people as the practice can function with.

APP 11.1, protect from unauthorised disclosure

External sharing settings, anonymous link policy, and automatic external forwarding blocked. Most tenants are still on the defaults set the day they were created.

APP 11.2, destroy or de-identify when no longer needed

Retention and disposal policies that terminate, applied across Exchange, SharePoint and OneDrive, plus a leaver process that does not park accounts indefinitely.

APP 8, cross-border disclosure

Knowing where your tenant data is stored, and which third party applications hold standing consent to read it.

Notifiable Data Breaches, assess within 30 days

Audit logging enabled and retained past the default, so the question of what was accessed and whose information was involved is answerable inside the window rather than after it.

APP 12, respond to an access request

Purview Content Search across every mailbox, site and chat, which is the only practical way to find one person’s information in a tenant of any age.

The last one is its own discipline. If you are already facing a request or an investigation rather than preparing for one, the email investigation and eDiscovery page covers that work.

$1,850 GST inclusive · fixed fee

Privacy Act Readiness Assessment for Microsoft 365

A structured review of the technical half of the OAIC checklist against your tenant, delivered as a written report you can hand to your lawyer, your insurer or your board.

What is assessed

  • MFA coverage, Conditional Access and legacy authentication
  • Privileged roles and least privilege in Entra ID
  • Where personal information actually lives, across mail, files and chat
  • Identity document copies: a Content Search sweep to find what you are holding
  • Retention and disposal policy, and whether anything actually ends
  • External sharing, anonymous links and external forwarding
  • Audit logging and whether the retention window answers a breach question
  • Third party application consents against your tenant

What you get

  • A written report with findings rated by severity
  • A remediation roadmap, tiered by what to do first
  • The identity document finding stated plainly, with locations and counts
  • A clear split of what is technical and what belongs with your lawyer
  • A walkthrough call to go through it

Usually delivered within two weeks of tenant access being arranged. Remediation is quoted separately after the assessment, because the scope depends entirely on what turns up. Project work carries a 50% deposit.

Not a reporting entity, or not sure yet, and just want to know where your tenant stands? The Microsoft 365 Health Check covers the same security and Identity ground at $599 GST inclusive, without the AML/CTF framing.

Who does the work

Jamie Hamilton. 25 years in Microsoft infrastructure, currently running Identity for a 200,000-user environment. The same person scopes the assessment, does it, writes the report and takes your call about it afterwards.

Microsoft specialist rather than a general IT provider. Conditional Access, Purview retention, Content Search and Entra ID role design are the daily work, not a module somebody read up on when the AML/CTF reforms landed.

Questions practices ask

Book a readiness assessment

$1,850 GST inclusive, fixed fee. Tell me a little about the practice and I will confirm scope before anything starts.

This enquiry is about technical controls in your Microsoft 365 tenant. It is not a request for legal advice, and nothing on this page is legal advice.

Questions first? Call 0403 401 250 or email jamie@hamilton365.com.au