From 1 July, the Privacy Act applies to accounting, legal and property firms. Here's what to do.
Riverstone Labs
Riverstone Labs

Riverstone Labs
Riverstone Labs

From 1 July 2026, a large group of professional-services firms come under the Privacy Act for the first time. If you run an accounting practice, a law firm, a conveyancer, a real-estate agency, or you deal in high-value goods, that includes you, and your turnover doesn't change it.
The change rides in on the second tranche of the AML/CTF reforms, which bring these professions into the anti-money-laundering regime as "reporting entities". Coming under AML/CTF also brings you under the Privacy Act. Somewhere north of 100,000 small businesses are covered for the first time, by profession rather than by size.
The privacy obligations here are the ones larger firms have carried for years. In practice, four things:
A privacy policy that accurately describes what personal information you collect and why. A record of the personal information you hold and where it actually lives. Reasonable security over it, which mostly means the unglamorous basics: access control, not emailing client IDs around, a plan for the day something leaks. And a nominated person who is accountable for it.
For most small practices that's a few weeks of dull work, not a transformation project. It does have to be done, though, and it isn't done by default.
These professions run automated client checks: identity verification, risk scoring on a new matter or listing, conflict checks. The AML reforms push you to do more of that, not less.
A conveyancer running automated identity verification on every new client is the clearest case. That tool holds personal information, and in practice it screens people: pass, refer, reject. From 1 July, that handling is under the Privacy Act. And from 10 December, a second Privacy Act change requires you to disclose, in your privacy policy, where software makes decisions that significantly affect people. Automated client screening sits squarely inside that.
So two obligations arrive within six months: privacy compliance from July, automated-decision disclosure from December.
The OAIC won't publish its final guidance on the automated-decision rules until around September, so the precise line for what "significantly affects" a person is still firming up. If you're in one of these professions, the safe assumption is that you're in scope from 1 July, with the automated-decision detail to confirm once the guidance lands. The specifics are worth checking for your own practice.
List the tools that touch a client decision. Mark which ones hold personal information, and which ones screen or score people. Get a privacy policy in place that describes them honestly. Put a name against who is accountable. That covers most of it, and it turns a December scramble into a July afternoon.
If you want a fast read on which of your tools are caught, we built a free AI Exposure Check. A few plain questions, and you get back a map of where you're likely exposed across both the July and December changes. About three minutes.
Run the free AI Exposure Check →
This is general information about a moving regulatory picture, not legal advice. The AML/CTF and privacy interaction is worth confirming with a lawyer for your specific practice.
Book a free 15-minute assessment. We'll look at your operations and identify the highest-ROI automation opportunities.
Book your free assessment