Privacy compliance for Australian accountants and bookkeepers: you handle TFNs, so the Privacy Act already applies to you.
If your practice handles clients' or employees' tax file numbers, you have privacy obligations under the Privacy Act right now, even if you turn over less than A$3 million and do no anti-money-laundering work at all. The Privacy (Tax File Number) Rule 2015 binds every practice that handles individual TFNs, with no small-business exemption. Most accountants and bookkeepers assume the under-$3m exemption covers them. For their clients' TFNs, it does not. This page explains the obligation almost nobody has told you about, and the separate AML change arriving on 1 July 2026.
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
Hook 1: the TFN Rule already binds you (no threshold, no deadline)
The Privacy (Tax File Number) Rule 2015, a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth), binds every "TFN recipient". That covers a practice or registered tax agent holding clients' TFN information. It applies regardless of your turnover, so the A$3 million small-business exemption that shelters the rest of your practice does not apply to how you handle individual tax file numbers.
The Rule sets obligations for collecting, using, disclosing, storing, securing and destroying individuals' TFN information, and for training your staff. A breach of the Rule is an "interference with the privacy of an individual", which means an affected person can complain to the OAIC. Read: the TFN Rule 2015, what accountants must do.
Scope, stated honestly: the TFN Rule protects the TFN information of individuals only, not the general (non-TFN) client database, and not the TFNs of companies, partnerships, trusts or super funds. Handling TFNs does not make a small practice a full "APP entity" subject to all 13 Australian Privacy Principles. It creates targeted obligations for the TFN data you hold. Read: does the Privacy Act apply to accountants under $3 million?.
Why an accounting practice is a high-value target
A small accounting or bookkeeping practice concentrates an unusual amount of sensitive data in one place:
- Individual client TFNs and identity documents.
- Full tax returns and financial position.
- Bank and BSB details for refunds and payments.
- Client-employee payroll data you process on behalf of business clients: names, TFNs, super and bank details for people who are not even your own clients. (Whether the employee-records exemption reaches a third-party processor is unsettled, so handle this data carefully.
- SMSF member data where you administer self-managed super funds.
That is exactly the kind of concentrated identity and financial data that makes a breach serious and a complaint concrete. Read: your data-breach obligations under the NDB scheme.
Hook 2: AML Tranche 2 from 1 July 2026 (only for some services)
This one is narrower, and it is easy to overstate, so here is the accurate version. From 1 July 2026, AML/CTF Tranche 2 makes a firm an AUSTRAC reporting entity only where it provides a "designated service", for example forming or restructuring companies and trusts, holding or disbursing client money, arranging finance, or acting as or arranging a nominee director or trustee. Where you are a reporting entity, Privacy Act s 6E switches the Privacy Act on for the AML/KYC identity data you collect for that service, regardless of turnover.
Routine tax returns, financial statements, tax advice, BAS and GST work, bookkeeping, audit and payroll are not designated services. So most practices are not AML reporting entities at all, and even a firm that is caught is caught for the AML/KYC data only, not its general tax files, ledgers or payroll. The line is advice-out, execution-in: advising on a restructure is not a designated service; actually forming the entity or holding the funds is. Read: which accounting services are designated?.
Enrolment for newly regulated firms opened 31 March 2026; existing providers of a designated service enrol by around 29 July 2026. Confirm your firm's exact position with AUSTRAC.
Your professional confidentiality duty is not the same thing
Registered tax agents already carry a confidentiality obligation under item 6 of the TPB Code of Professional Conduct, reinforced by the Tax Agent Services (Code of Professional Conduct) Determination 2024. That duty is enforced by the Tax Practitioners Board and sits alongside, not instead of, the Privacy Act. The TPB does not administer the Privacy Act or the data-breach scheme; the OAIC does. Meeting one does not automatically meet the other. Read: TPB Code confidentiality vs the Privacy Act.
What an accounting practice actually needs
1. A privacy policy (APP 1) written for an accounting practice, not a generic fill-in. 2. Collection notices (APP 5) for the points where you take client and employee details. 3. A TFN-handling policy that meets the specific obligations of the TFN Rule 2015. 4. A data-breach response plan for the NDB scheme, tuned to TFN and financial-data exposure. 5. Retention and destruction procedures that reconcile record-keeping floors with the "destroy when no longer needed" principle.
The AML platforms do not give you these. Free generic templates usually are not written for an accounting practice, carry the outdated "over $3m or you are exempt" framing (wrong for TFN recipients), and do not keep pace as the law changes.
What Privaproof is building for accountants
A dedicated, accountant-specific privacy document set, written for accounting and bookkeeping practices, and kept current as the law changes. Not a one-off free download, and not an AML platform bolt-on: the privacy-focused answer to the obligations you already carry.
- Written for accountants and bookkeepers: TFNs, client-employee payroll, SMSF, financial data.
- Practical, plain-English documents you tailor to your firm, with guidance built in.
- Kept current: while your subscription is active, we monitor the law and aim to provide updated versions as it changes, including the 1 July 2026 AML changes and the 10 December 2026 automated-decision-making rule. This is not a guarantee of compliance, and does not replace your own legal advice.
These are compliance tools and templates you tailor to your own business. They are general information, not legal advice, and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner.
Join the founding list
Be first to know when the Accountant Kit opens, and get the plain-English updates as the 2026 changes land. No cost, no obligation.
✓ You’re on the founding list. We’ll email you as the changes land.
We never sell your data. See our Privacy Policy.
Keep reading
- Does the Privacy Act apply to accountants under $3 million?
- Do bookkeepers need a privacy policy?
- The Privacy (Tax File Number) Rule 2015: what accountants must do
- How must accountants store clients' tax file numbers?
- Can an accountant email a client's TFN?
- The accountant privacy policy: what it must cover
- AML Tranche 2 for accountants: which services are designated?
- Does becoming an AML reporting entity trigger the Privacy Act?
- Data-breach obligations for accountants handling TFNs
- How long can an accountant keep a client's TFN?
- TPB Code confidentiality vs the Privacy Act
- Bookkeepers and client-employee payroll data
- AML kit vs privacy kit: what your AML software leaves out
General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC, or your obligations under the TPB Code, which are administered by the Tax Practitioners Board. Privaproof's accountant documents are self-authored and are not independently reviewed by a solicitor. The Privacy Act 1988 (Cth), the TFN Rule 2015 and related guidance change over time, so check you are working from a current version.