For solicitors & small law firms

You can read the legislation. That was never the hard part.

Since 1 July 2026, legal practitioners providing designated services under the AML/CTF Act are reporting entities. For the personal information handled in that work, the Privacy Act small business exemption no longer applies.

You don't need us to tell you what APP 11 says. You need someone to map your systems, write the operational documents, train your staff and keep the registers current — work that is slow, unbillable, and always the thing that gets pushed to next month.

No obligation. We'll tell you if you don't need us.

Where the law actually stands

Three dates matter. Only one has already passed.

Plenty of people will tell you every small business is about to fall under the Privacy Act. That isn't law yet. Here is what is in force, what is scheduled, and what is still only proposed.

Date
What changed
Status
10 Jun 2025
Statutory tort for serious invasions of privacy Individuals can sue directly. Applies regardless of your turnover.
In force
01 Jul 2026
AML/CTF Tranche 2 — legal practitioners captured as reporting entities Conveyancing, company and trust formation, managing client money and acting as a nominee are designated services. The Privacy Act now applies to personal information handled in that work, regardless of turnover.
In force
10 Dec 2026
Automated decision-making disclosure obligations If any system in your practice makes or substantially assists a decision about a person, your privacy policy must disclose it.
Scheduled
Not set
Removal of the $3m small business exemption entirely Government supports it in principle. No Bill passed, no commencement date. Treat any specific date you're quoted as commentary.
Proposed

General information, current as at the date of publication — not legal advice. We review this table monthly and date every change.

Why firms are exposed

The obligation isn't complicated. The implementation is a project nobody has time for.

A small firm's personal information lives in more places than anyone expects: the practice management system, the trust ledger, the document management system, email, a scanning folder, an external barrister's inbox, a costs consultant, an archive box in a storage unit, and a former employee's laptop that was never collected.

Legal professional privilege protects the content of a communication. It doesn't answer where the file is stored, who has read access, which offshore provider processes your backups, or what happens in the 30 days after a staff member's mailbox is compromised.

The result is firms that understand their obligations precisely and cannot demonstrate compliance with them, because nobody has done the unbillable work of writing it all down.

What it costs to get this wrong. The OAIC can issue infringement notices of up to $66,000 per contravention for lower-level failures such as not maintaining a compliant privacy policy. Serious or repeated breaches carry substantially higher penalties. Separately, since June 2025, an individual can bring a civil claim against you directly.

What we do

Four ways to work with us.

Start small if you want to see how we work. Start with the foundations if you already know where this is heading.

Privacy health check

$750 + GST, one-off

A half day of our time and a written answer to one question: how exposed are you?

  • Review of your current policy, forms and file handling
  • Written findings memo against the Australian Privacy Principles
  • Prioritised list of what to fix first
  • Credited in full against foundations if you proceed within 60 days

Privacy foundations

$4,500 – $7,500 + GST, one-off

A complete privacy program, built and handed over in four weeks.

  • Data map of every place personal information lives
  • Gap assessment against the 13 Australian Privacy Principles
  • Privacy policy and collection notices written for your practice
  • Notifiable data breach response plan
  • 60-minute staff training session

Most firms choose this

ComplyHub annual

from $10,500 + GST, per year

Foundations plus twelve months of maintenance, bundled.

  • Everything in Privacy foundations
  • Quarterly compliance review
  • Policies and registers updated as the law changes
  • Breach response line — call us first, not your lawyer
  • Annual staff training refresher

Ongoing privacy officer

$400 – $800 + GST, per month

Maintenance only, for firms whose program is already built.

  • Quarterly reviews and register upkeep
  • Regulatory change monitoring
  • Breach response line
  • If someone else built your program, we'll assess it first ($1,500)

The four weeks

What actually happens.

Week 1 — Discovery

Ninety minutes with you and your practice manager. We map the systems, the file lifecycle and the third parties — including the ones nobody thinks of as third parties, like the transcription service and the storage provider.

Week 2 — Data map and gap assessment

A documented data inventory and an assessment against the 13 Australian Privacy Principles. You get the reasoning, not just conclusions, so you can disagree with us where you want to.

Week 3 — Documents

Privacy policy, collection notices, breach response plan and retention schedule, drafted to sit alongside your existing costs agreements and file-opening procedures rather than contradict them.

Week 4 — Handover and training

An hour with your staff on what changes at the desk, plus a written summary suitable for your PI insurer and your professional indemnity renewal questionnaire.

Fair questions

What principals usually ask us.

I can read the Australian Privacy Principles myself.

You can, and better than we can argue them. That's not what this is. Interpretation is your work; implementation is ours. Mapping thirteen systems, writing collection notices for six intake forms, building a retention schedule, training six staff and maintaining a breach register is a forty-hour project at a rate you can't bill and don't want to spend. We do that part and hand it over.

Doesn't legal professional privilege cover us?

Privilege protects communications from compulsory disclosure. It doesn't govern how you store, secure, or destroy personal information, and it is no defence to a notifiable data breach or an OAIC investigation into your handling practices. They're answering different questions.

Which parts of my practice are in scope?

Designated services, not the whole firm. Property transactions, forming companies and trusts, managing client money and nominee arrangements are captured. Litigation, criminal work and general advice are generally not, in themselves. We draw the line in week one, in writing, so it's a defensible position rather than an assumption.

We're under $3 million turnover.

The exemption no longer applies to personal information handled for AML/CTF purposes. The broader removal of the $3m exemption remains a proposal — government supports it in principle, but there's no Bill and no commencement date, and we won't sell you anything on the basis of it.

Are you lawyers?

No, and we don't hold ourselves out as one. We're privacy and compliance practitioners. Where a question is genuinely one of legal interpretation, it's yours — or we refer it. Our engagement letter is explicit about the boundary.

Who you're dealing with

A small Australian firm, and you'll deal with a founder.

ComplyHub is based in Melbourne and works with Australian professional services businesses on Privacy Act obligations. Our work is delivered onshore — your data stays in Australia, and we can tell you exactly which systems it touches.

Between us we hold certifications from the International Association of Privacy Professionals in privacy program management, privacy technology and AI governance, alongside security credentials. That matters less than the fact that you'll speak to the person doing the work.

More about us and our credentials →

Hand over the part you don't have time for.

Twenty minutes on the phone. Tell us what your practice does and we'll tell you what the implementation actually involves, and what it costs. If it's a job for your practice manager, we'll say so.