Skip to content

Regulatory Pulse

OAIC expands AML/CTF privacy guidance: ID-document lifecycle tools and minimisation

Draft revision: OAIC’s 28 August update adds lifecycle tools and sharper guidance on necessity, less intrusive verification and time-limited retention of identity-document copies.

Australia
Privacy operations, identity data and retention
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Privacy regulator guidance update · Reviewed 28 August 2026 · 9 min read

The 60-second summary

The OAIC updated its AML/CTF privacy guidance again on 28 August 2026 and added a consolidated 34-page guide, an identity-document lifecycle fact sheet and decision tools. The added material sharpens the implementation message: full identity-document copies are not required for customer due diligence, personnel due diligence, ongoing monitoring or record keeping merely because those activities fall within the AML/CTF framework. A copy collected because it is convenient will not establish reasonable necessity. Organisations should consider less intrusive methods such as sighting the document, recording required fields or using a verification service that returns a token or yes/no result. Where a full copy is genuinely necessary, retention should end when the purpose is discharged unless another permitted purpose or binding duty applies.

Timeline that matters

  1. 27 February 2026

    Original guidance published

    The regulator published privacy guidance for reporting entities and authorised agents.

  2. 31 March 2026

    Changes for existing reporting entities commenced

    Reformed obligations began affecting current reporting entities.

  3. 1 July 2026

    Expanded scope commenced

    Specified professional and service sectors entered the expanded framework.

  4. 26 August 2026

    Initial source update captured

    The published PrivacyBuilt entry recorded the regulator’s minimisation and identity-copy guidance.

  5. 28 August 2026

    Official guidance expanded again

    The source page changed its update date and added a consolidated guide, lifecycle fact sheet and decision tools.

  6. 28 August 2026

    PrivacyBuilt analysis updated

    Following human review, the live entry was updated to incorporate the new operational detail while retaining the original URL.

What changed

Since the existing Pulse article was reviewed, the official source page has been updated from 26 to 28 August 2026 and now links to a consolidated 34-page guide, a dedicated identity-document lifecycle fact sheet, a personal-information decision tree and a collection flowchart. The new fact sheet states more expressly that full identity-document copies are not required for customer due diligence, personnel due diligence, ongoing monitoring or record keeping. It introduces a privacy-by-design escalation approach, gives lower-intrusion examples such as sighting a document, recording selected fields or using tokenised verification, and says convenience does not establish reasonable necessity. It also warns that section 111 alone should not support long-term retention of a full copy. The updated article preserves the existing headline analysis while adding those operational points and correcting the official update date.

Who should pay attention?

AML/CTF reporting entities and authorised agents

The expanded guidance applies privacy principles to collection, use, disclosure, security, access, correction and disposal across the compliance lifecycle.

Identity and digital-verification providers

Services should support proportionate checks, data minimisation, tokenised outcomes, clear retention and evidence of deletion.

Privacy, financial-crime and records teams

The new resources make collection necessity and retention decisions more operational and auditable.

Product, onboarding and customer-operations teams

Workflows need to collect information at the right time without using convenience as the justification for a full document copy.

Security, procurement and incident-response teams

Concentrated identity data, provider access and deletion gaps require control testing and breach readiness.

What the guidance clarifies

Official source expanded on 28 August 2026
The official guidance page was updated again on 28 August 2026 and added a consolidated guide plus implementation resources. This article now incorporates that operational detail.
The core legal status has not changed
This remains regulator guidance explaining existing Privacy Act duties alongside reforms that are already in effect.
Full copies are not required across the compliance lifecycle
The new fact sheet says the AML/CTF Act does not require full identity-document copies for customer due diligence, personnel due diligence, ongoing monitoring or record keeping.
Convenience is not reasonable necessity
A full copy collected because it is merely helpful, convenient or desirable will not establish the required necessity.
Less intrusive verification should be considered
The regulator gives examples such as sighting the document, recording selected fields or using digital verification that returns a token or binary result.
Long-term retention needs more than section 111
The fact sheet says the record-keeping provision alone should not be relied on to keep a full identity-document copy over the long term.

Global relevance — design verification around the minimum evidence needed

Why this matters for global organisations

Identity checks often create copies that outlive the verification event and spread across providers, collaboration tools and archives. The operational lesson is to design the workflow around the smallest reliable evidence of the check, escalate only when risk justifies it and give every retained copy a documented purpose, owner and expiry.

  • Use lower-intrusion verification methods where they can meet the defined objective.
  • Treat convenience as an insufficient reason to retain a high-risk source document.
  • Separate the verification result from the full document and limit access to each.
  • Require providers to support purpose-based retention, deletion and exportable audit evidence.
  • Test actual disposal across systems and backups rather than relying on policy statements.

12 actions to start now

  1. Replace any blanket identity-document collection rule with a decision tied to the specific compliance activity and assessed financial-crime risk.
  2. Test whether identity can be verified by sighting a document, recording only required fields or using a service that returns a token or yes/no result.
  3. Require a written reasonable-necessity decision before a full identity-document copy is collected.
  4. Map identity documents and extracted fields across onboarding, personnel checks, monitoring, case management, email, support tools, vendors, archives and backups.
  5. Assign a separate purpose and retention period to every use of an identity-document copy.
  6. Do not rely on the revised record-keeping provision alone as a basis for long-term retention of full copies.
  7. Record the verification method, relevant identifying details, result and risk assessment while minimising the retained source document.
  8. Create an exception route for another binding retention duty or a genuinely necessary compliance purpose, with specialist approval and expiry.
  9. Update privacy notices, operating procedures and staff training to reflect collection timing, proportionate verification and deletion.
  10. Review provider configurations so full images are not retained by default after verification and deletion can be demonstrated.
  11. Run a privacy impact assessment where the scale, sensitivity, verification method or vendor model creates elevated risk.
  12. Test deletion and de-identification across live systems, archives and provider environments, then retain results and unresolved exceptions.

Evidence worth retaining

  • Documented comparison between the 26 August article basis and the source materials available on 28 August 2026.
  • Scope register identifying reporting entities, authorised agents, designated services, compliance activities and accountable owners.
  • Identity-document lifecycle map covering collection, verification, extraction, use, disclosure, storage, access and disposal.
  • Reasonable-necessity assessments for each identity-document collection point, including less intrusive alternatives considered.
  • Risk-based verification standard showing when controls may escalate and why the chosen method is proportionate.
  • Register of full identity-document copies, purposes, legal grounds, collection dates, systems, vendors, expiry dates and owners.
  • Records of required identity details, verification method, outcome, analysis and assessed financial-crime risk.
  • Separate assessments for legacy copies and for retention required under another law or binding order.
  • Privacy impact assessments, notices, procedures, training and control approvals.
  • Provider contracts, configurations, subprocessor lists, security evidence and deletion commitments.
  • Deletion and de-identification logs covering production, collaboration tools, archives, support environments and backups.
  • Periodic test results, exception reports, remediation owners and management review evidence.

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Which activities genuinely require a full identity-document copy rather than selected fields or a verification result?
  • Can each collection be justified objectively as reasonably necessary and proportionate?
  • Are full copies requested before there is a reasonable basis to expect a regulated service?
  • Could sighting, tokenisation or a yes/no verification result achieve the same purpose with less risk?
  • What exact record is needed to demonstrate the check without retaining the source image?
  • Is any team relying on the record-keeping provision alone for long-term retention of a full copy?
  • Which other laws or binding requirements apply, and what are their precise time limits?
  • Do providers retain images after verification, and can they prove deletion across subprocessors and backups?
  • Have secondary uses of identity information been separated from the original compliance purpose?
  • Can the organisation reproduce its decision, system configuration and deletion evidence during an audit or incident?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.