The Accountant Kit
Fourteen editable Word documents, built around what an accounting practice actually holds and does.
Handle information properlyPolicy, TFN handling, collection and retentionView 4 documentsHide documents
- Tax File Number Handling, Storage and Destruction Procedure
- Collection Notice
- Privacy Policy
- Document Retention and Destruction Schedule
Give your team clear directionTraining, roles, and what you holdView 3 documentsHide documents
- Staff Privacy Training and Confidentiality Agreement
- Privacy Officer Role and Internal Privacy Procedure
- Data Inventory / "What We Hold" Map
Respond when something happensBreach, access and complaintsView 3 documentsHide documents
- Data Breach Response Plan
- Access and Correction Request Procedure
- Privacy Complaint Handling Procedure
As your practice changesSuppliers, offshore, payroll and marketingView 4 documentsHide documents
- Service Provider and Overseas Disclosure Clauses
- Payroll Data-Handling Arrangement
- Consent Form, Authority and Consent Clauses
- Direct Marketing and Opt-Out Procedure
A$449 / year incl GST
When the privacy rules change, the updated documents are in your account. You do not write them again.
Includes the updates we make to the kit while your membership is active. Those track the Privacy Act, the Australian Privacy Principles and the Tax File Number Rule. See what has changed
Get the Accountant Kit →Built for accounting practices, not adapted from generic small-business templates.
Fourteen documents. Not fourteen projects.
Four documents carry most of the tailoring. The rest use recurring practice details, clear prompts and the order in the Start Here sheet.
- 1
Two decisions, before you open a document
Who your Privacy Officer is, and which of three things brings your practice in: the individual TFNs you handle, whether the Privacy Act covers your practice outright, or a designated AML service. Ten of the fourteen documents name the first. The Start Here sheet settles the second in one table.
- 2
Nine details, filled in once
Your practice name, ABN, Privacy Officer and contact details are among the nine that recur across the kit. Fill them in once, then find and replace carries them through all fourteen documents in a few minutes.
What the work actually looks like
14 documents
The Start Here sheet gives you the order to work in and an indication of the time involved. You receive the complete kit.
Three privacy checks for your practice
You can check all three today.
Collect
Can you give the four things the Rule requires, on the spot? One is that declining to quote a TFN is not an offence.
Protect
Could you list every place they sit, and who can reach them, including cloud ledgers and anything backed up offshore?
Destroy
Do you know when their TFN should be securely destroyed or de-identified, and which retention rule applies?
The four, and the wording that gives them
Under r 8(2) you must take reasonable steps to make sure the person is told all four at the point you ask. Each one below is followed by the wording the kit's Collection Notice uses to satisfy it.
- The law that authorises you to ask
We are authorised to collect your tax file number under taxation, superannuation and personal assistance law, and we collect it only for those purposes.
- What you are collecting it for
To prepare and lodge your returns and statements, act as your registered agent with the ATO, report through Single Touch Payroll where we run your payroll, and administer your superannuation reporting.
- That declining is not an offence
Giving us your tax file number is not compulsory, and declining to quote one is not an offence. You do not have to provide it, and choosing not to is not an offence.
- What happens if they decline
If you choose not to, we may be unable to lodge on your behalf, and tax may be withheld from payments to you at a higher rate.
If your engagement letter, onboarding form or client portal asks for a tax file number without telling a client all four, that is the gap. The quoted wording is the Collection Notice as it ships, with your practice details left to complete. It is one document of fourteen.
A breach of the Tax File Number Rule is an interference with privacy under the Privacy Act, and an individual can complain to the Information Commissioner. No turnover test applies.
Privacy (Tax File Number) Rule 2015, rr 8(2), 11(1), 11(2), 5(3).
Privacy is part of client trust
87% of Australians are more concerned about their privacy than they were five years ago.
Your clients trust your practice with highly personal financial information. A practical privacy system helps your team handle it with the care clients increasingly expect.
A privacy policy is one document.
You may already have one. It is one of the fourteen.
Privacy policy
Says what you do
A statement for clients and your website.
Practical procedures
Tell your team how
The steps behind privacy in everyday work.
The Accountant Kit gives you the policy and the procedures behind it.
Designated services from 31 March 2026
Also relevant to some practices
AML/CTF obligations apply only if your practice provides a designated service.
Not designated services
Tax returns · Financial statements · Tax advice · BAS and GST · Bookkeeping · Audit · Payroll
Check your position if you help with
If you provide one and become a reporting entity, the Privacy Act applies to the identity data you collect for that service.
The rest of your practice can stay exempt.
Legal detail and sources
Nine professional-services designated services sit in s 6(5B) of the AML/CTF Act, with limits in s 6(5C) to (5E). Holding client money is not a designated service where the money is payment for your own fee, or the receipt or disbursement of a payment to or from a government body, so passing on an ATO refund or paying a tax debt is outside it.
AML/CTF Act 2006 s 6(5B), s 6(5C) to (5E); Privacy Act 1988 (Cth) s 6E(1A).
Put a practical privacy baseline in place
One complete 14-document privacy kit for Australian accounting and bookkeeping practices. Guided tailoring for your practice, kept current as the privacy rules change.
A$449/year incl GST
General information and document templates you tailor, not legal advice. Written by Privaproof.
The detail, if you want it
The practical answer is above. The legal detail is here when you need it.
The TFN Rule already binds you, with no threshold and no deadlineIt binds every practice holding individual TFN information, whatever your turnover.Read detailHide detail
The Privacy (Tax File Number) Rule 2015, a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth), binds every "TFN recipient". That covers a practice or registered tax agent holding individual clients' TFN information. It applies regardless of your turnover, so the A$3 million small-business exemption does not apply to how you handle individual tax file numbers.
The Rule sets obligations for collecting, using, disclosing, storing, securing and destroying individuals' TFN information, and for training your staff. Under s 13(4)(a) of the Privacy Act, an act or practice of a file number recipient that breaches a rule issued under s 17 is "an interference with the privacy of an individual", and r 5(3) of the Rule says the same in its own words: a breach is an interference with privacy under the Privacy Act, and the individual may complain to the Information Commissioner. That route is open without your practice being an APP entity at all. Read: the TFN Rule 2015, what accountants must do.
Scope, stated honestly: under r 5(2) the TFN Rule protects the TFN information of individuals only, not the general (non-TFN) client database, and not the TFNs of companies, partnerships, trusts or super funds. Handling TFNs does not make a small practice a full "APP entity" subject to all 13 Australian Privacy Principles. It creates targeted obligations for the TFN data you hold. Read: does the Privacy Act apply to accountants under $3 million?.
Why an accounting practice concentrates the riskTFNs, tax returns, bank details and client-employee payroll data, in one place.Read detailHide detail
A small accounting or bookkeeping practice holds a concentrated set of personal and financial information in one place:
- Individual client TFNs and identity documents.
- Full tax returns and financial position.
- Bank and BSB details for refunds and payments.
- Client-employee payroll data you process on behalf of business clients: names, TFNs, super and bank details for people who are not even your own clients. (The employee-records exemption in s 7B(3) of the Privacy Act is written for an act of an organisation "that is or was an employer of an individual", and a practice running payroll for a business client is not that employer. Whether the exemption reaches a third-party processor is unresolved, so do not assume it switches off your handling of this data.)
- SMSF member data where you administer self-managed super funds.
That concentration is why the paragraph below sets out precisely which of these the data-breach scheme reaches, and which it does not.
Where the notifiable data breaches scheme reaches, and where it does not. Under s 26WE(1)(d) of the Privacy Act the NDB scheme reaches a file number recipient in relation to tax file number information. It reaches the rest of that list only where some other trigger makes your practice an APP entity. Read: your data-breach obligations under the NDB scheme.
Your professional confidentiality duty is not the same thingThe TPB Code and the Privacy Act are different regimes with different regulators.Read detailHide detail
Registered tax agents and registered BAS agents already carry a confidentiality obligation under item 6 of the Code of Professional Conduct in s 30-10 of the Tax Agent Services Act 2009: information relating to a client's affairs must not be disclosed to a third party without the client's permission or a legal duty to disclose. The Tax Agent Services (Code of Professional Conduct) Determination 2024 adds further obligations on top of the existing Code. That regime is enforced by the Tax Practitioners Board and sits alongside, not instead of, the Privacy Act. The TPB does not administer the Privacy Act or the data-breach scheme; the OAIC does. Meeting one does not automatically meet the other. Read: TPB Code confidentiality vs the Privacy Act.
Keep up with the changes
Not buying today? Get the plain-English updates as the privacy rules change, and the notes on what they mean in practice. No cost, no obligation.
✓ You’re on the list. We’ll email you as the changes land.
We never sell your data. See our Privacy Policy.
Keep reading
- Does the Privacy Act apply to accountants under $3 million?
- Do bookkeepers need a privacy policy?
- The TFN Rule 2015: what accountants must do
- How must accountants store clients' tax file numbers?
- Can an accountant email a client's TFN?
- The accountant privacy policy: what it must cover
- AML Tranche 2 for accountants: which services are designated?
- Does becoming an AML reporting entity trigger the Privacy Act?
- Data-breach obligations for accountants handling TFNs
- How long can an accountant keep a client's TFN?
- TPB Code confidentiality vs the Privacy Act
- Bookkeepers and client-employee payroll data
- AML kit vs privacy kit: what your AML software leaves out
General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC, or your obligations under the TPB Code, which are administered by the Tax Practitioners Board. The Privacy Act 1988 (Cth), the TFN Rule 2015 and related guidance change over time, so check you are working from a current version.