The 60-second summary
The OAIC updated its AML/CTF privacy guidance again on 28 August 2026 and added a consolidated 34-page guide, an identity-document lifecycle fact sheet and decision tools. The added material sharpens the implementation message: full identity-document copies are not required for customer due diligence, personnel due diligence, ongoing monitoring or record keeping merely because those activities fall within the AML/CTF framework. A copy collected because it is convenient will not establish reasonable necessity. Organisations should consider less intrusive methods such as sighting the document, recording required fields or using a verification service that returns a token or yes/no result. Where a full copy is genuinely necessary, retention should end when the purpose is discharged unless another permitted purpose or binding duty applies.
Timeline that matters
27 February 2026
Original guidance published
The regulator published privacy guidance for reporting entities and authorised agents.
31 March 2026
Changes for existing reporting entities commenced
Reformed obligations began affecting current reporting entities.
1 July 2026
Expanded scope commenced
Specified professional and service sectors entered the expanded framework.
26 August 2026
Initial source update captured
The published PrivacyBuilt entry recorded the regulator’s minimisation and identity-copy guidance.
28 August 2026
Official guidance expanded again
The source page changed its update date and added a consolidated guide, lifecycle fact sheet and decision tools.
28 August 2026
PrivacyBuilt analysis updated
Following human review, the live entry was updated to incorporate the new operational detail while retaining the original URL.
What changed
Since the existing Pulse article was reviewed, the official source page has been updated from 26 to 28 August 2026 and now links to a consolidated 34-page guide, a dedicated identity-document lifecycle fact sheet, a personal-information decision tree and a collection flowchart. The new fact sheet states more expressly that full identity-document copies are not required for customer due diligence, personnel due diligence, ongoing monitoring or record keeping. It introduces a privacy-by-design escalation approach, gives lower-intrusion examples such as sighting a document, recording selected fields or using tokenised verification, and says convenience does not establish reasonable necessity. It also warns that section 111 alone should not support long-term retention of a full copy. The updated article preserves the existing headline analysis while adding those operational points and correcting the official update date.
Who should pay attention?
AML/CTF reporting entities and authorised agents
The expanded guidance applies privacy principles to collection, use, disclosure, security, access, correction and disposal across the compliance lifecycle.
Identity and digital-verification providers
Services should support proportionate checks, data minimisation, tokenised outcomes, clear retention and evidence of deletion.
Privacy, financial-crime and records teams
The new resources make collection necessity and retention decisions more operational and auditable.
Product, onboarding and customer-operations teams
Workflows need to collect information at the right time without using convenience as the justification for a full document copy.
Security, procurement and incident-response teams
Concentrated identity data, provider access and deletion gaps require control testing and breach readiness.
What the guidance clarifies
- Official source expanded on 28 August 2026
- The official guidance page was updated again on 28 August 2026 and added a consolidated guide plus implementation resources. This article now incorporates that operational detail.
- The core legal status has not changed
- This remains regulator guidance explaining existing Privacy Act duties alongside reforms that are already in effect.
- Full copies are not required across the compliance lifecycle
- The new fact sheet says the AML/CTF Act does not require full identity-document copies for customer due diligence, personnel due diligence, ongoing monitoring or record keeping.
- Convenience is not reasonable necessity
- A full copy collected because it is merely helpful, convenient or desirable will not establish the required necessity.
- Less intrusive verification should be considered
- The regulator gives examples such as sighting the document, recording selected fields or using digital verification that returns a token or binary result.
- Long-term retention needs more than section 111
- The fact sheet says the record-keeping provision alone should not be relied on to keep a full identity-document copy over the long term.
Global relevance — design verification around the minimum evidence needed
Why this matters for global organisations
Identity checks often create copies that outlive the verification event and spread across providers, collaboration tools and archives. The operational lesson is to design the workflow around the smallest reliable evidence of the check, escalate only when risk justifies it and give every retained copy a documented purpose, owner and expiry.
- Use lower-intrusion verification methods where they can meet the defined objective.
- Treat convenience as an insufficient reason to retain a high-risk source document.
- Separate the verification result from the full document and limit access to each.
- Require providers to support purpose-based retention, deletion and exportable audit evidence.
- Test actual disposal across systems and backups rather than relying on policy statements.
12 actions to start now
- Replace any blanket identity-document collection rule with a decision tied to the specific compliance activity and assessed financial-crime risk.
- Test whether identity can be verified by sighting a document, recording only required fields or using a service that returns a token or yes/no result.
- Require a written reasonable-necessity decision before a full identity-document copy is collected.
- Map identity documents and extracted fields across onboarding, personnel checks, monitoring, case management, email, support tools, vendors, archives and backups.
- Assign a separate purpose and retention period to every use of an identity-document copy.
- Do not rely on the revised record-keeping provision alone as a basis for long-term retention of full copies.
- Record the verification method, relevant identifying details, result and risk assessment while minimising the retained source document.
- Create an exception route for another binding retention duty or a genuinely necessary compliance purpose, with specialist approval and expiry.
- Update privacy notices, operating procedures and staff training to reflect collection timing, proportionate verification and deletion.
- Review provider configurations so full images are not retained by default after verification and deletion can be demonstrated.
- Run a privacy impact assessment where the scale, sensitivity, verification method or vendor model creates elevated risk.
- Test deletion and de-identification across live systems, archives and provider environments, then retain results and unresolved exceptions.
Evidence worth retaining
- Documented comparison between the 26 August article basis and the source materials available on 28 August 2026.
- Scope register identifying reporting entities, authorised agents, designated services, compliance activities and accountable owners.
- Identity-document lifecycle map covering collection, verification, extraction, use, disclosure, storage, access and disposal.
- Reasonable-necessity assessments for each identity-document collection point, including less intrusive alternatives considered.
- Risk-based verification standard showing when controls may escalate and why the chosen method is proportionate.
- Register of full identity-document copies, purposes, legal grounds, collection dates, systems, vendors, expiry dates and owners.
- Records of required identity details, verification method, outcome, analysis and assessed financial-crime risk.
- Separate assessments for legacy copies and for retention required under another law or binding order.
- Privacy impact assessments, notices, procedures, training and control approvals.
- Provider contracts, configurations, subprocessor lists, security evidence and deletion commitments.
- Deletion and de-identification logs covering production, collaboration tools, archives, support environments and backups.
- Periodic test results, exception reports, remediation owners and management review evidence.
Questions to take to counsel or your conformity team
These are discussion prompts, not legal advice or conclusions.
- Which activities genuinely require a full identity-document copy rather than selected fields or a verification result?
- Can each collection be justified objectively as reasonably necessary and proportionate?
- Are full copies requested before there is a reasonable basis to expect a regulated service?
- Could sighting, tokenisation or a yes/no verification result achieve the same purpose with less risk?
- What exact record is needed to demonstrate the check without retaining the source image?
- Is any team relying on the record-keeping provision alone for long-term retention of a full copy?
- Which other laws or binding requirements apply, and what are their precise time limits?
- Do providers retain images after verification, and can they prove deletion across subprocessors and backups?
- Have secondary uses of identity information been separated from the original compliance purpose?
- Can the organisation reproduce its decision, system configuration and deletion evidence during an audit or incident?
Official sources
- OAIC — AML/CTF privacy guidance, updated 28 August 2026
- OAIC — consolidated guide to privacy for reporting entities, August 2026
- OAIC — identity-document lifecycle fact sheet, updated August 2026
- OAIC — personal-information decision tree
- OAIC — collection flowchart for AML/CTF compliance
- OAIC — Privacy Essentials Checklist for AML/CTF reporting entities
- OAIC — template privacy collection notice for AML/CTF reporting entities
PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.
PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.