Skip to content

Privacy compliance for Australian accountants and bookkeepers: you handle TFNs, so the Privacy Act already applies to you.

If your practice handles clients' or employees' tax file numbers, you have privacy obligations under the Privacy Act right now, even if you turn over less than A$3 million and do no anti-money-laundering work at all. The Privacy (Tax File Number) Rule 2015 binds every practice that handles individual TFNs, with no small-business exemption. Most accountants and bookkeepers assume the under-$3m exemption covers them. For their clients' TFNs, it does not. This page explains the obligation almost nobody has told you about, and the separate AML change arriving on 1 July 2026.

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

Hook 1: the TFN Rule already binds you (no threshold, no deadline)

The Privacy (Tax File Number) Rule 2015, a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth), binds every "TFN recipient". That covers a practice or registered tax agent holding clients' TFN information. It applies regardless of your turnover, so the A$3 million small-business exemption that shelters the rest of your practice does not apply to how you handle individual tax file numbers.

The Rule sets obligations for collecting, using, disclosing, storing, securing and destroying individuals' TFN information, and for training your staff. A breach of the Rule is an "interference with the privacy of an individual", which means an affected person can complain to the OAIC. Read: the TFN Rule 2015, what accountants must do.

Scope, stated honestly: the TFN Rule protects the TFN information of individuals only, not the general (non-TFN) client database, and not the TFNs of companies, partnerships, trusts or super funds. Handling TFNs does not make a small practice a full "APP entity" subject to all 13 Australian Privacy Principles. It creates targeted obligations for the TFN data you hold. Read: does the Privacy Act apply to accountants under $3 million?.

Why an accounting practice is a high-value target

A small accounting or bookkeeping practice concentrates an unusual amount of sensitive data in one place:

That is exactly the kind of concentrated identity and financial data that makes a breach serious and a complaint concrete. Read: your data-breach obligations under the NDB scheme.

Hook 2: AML Tranche 2 from 1 July 2026 (only for some services)

This one is narrower, and it is easy to overstate, so here is the accurate version. From 1 July 2026, AML/CTF Tranche 2 makes a firm an AUSTRAC reporting entity only where it provides a "designated service", for example forming or restructuring companies and trusts, holding or disbursing client money, arranging finance, or acting as or arranging a nominee director or trustee. Where you are a reporting entity, Privacy Act s 6E switches the Privacy Act on for the AML/KYC identity data you collect for that service, regardless of turnover.

Routine tax returns, financial statements, tax advice, BAS and GST work, bookkeeping, audit and payroll are not designated services. So most practices are not AML reporting entities at all, and even a firm that is caught is caught for the AML/KYC data only, not its general tax files, ledgers or payroll. The line is advice-out, execution-in: advising on a restructure is not a designated service; actually forming the entity or holding the funds is. Read: which accounting services are designated?.

Enrolment for newly regulated firms opened 31 March 2026; existing providers of a designated service enrol by around 29 July 2026. Confirm your firm's exact position with AUSTRAC.

Your professional confidentiality duty is not the same thing

Registered tax agents already carry a confidentiality obligation under item 6 of the TPB Code of Professional Conduct, reinforced by the Tax Agent Services (Code of Professional Conduct) Determination 2024. That duty is enforced by the Tax Practitioners Board and sits alongside, not instead of, the Privacy Act. The TPB does not administer the Privacy Act or the data-breach scheme; the OAIC does. Meeting one does not automatically meet the other. Read: TPB Code confidentiality vs the Privacy Act.

What an accounting practice actually needs

1. A privacy policy (APP 1) written for an accounting practice, not a generic fill-in. 2. Collection notices (APP 5) for the points where you take client and employee details. 3. A TFN-handling policy that meets the specific obligations of the TFN Rule 2015. 4. A data-breach response plan for the NDB scheme, tuned to TFN and financial-data exposure. 5. Retention and destruction procedures that reconcile record-keeping floors with the "destroy when no longer needed" principle.

The AML platforms do not give you these. Free generic templates usually are not written for an accounting practice, carry the outdated "over $3m or you are exempt" framing (wrong for TFN recipients), and do not keep pace as the law changes.

What Privaproof is building for accountants

A dedicated, accountant-specific privacy document set, written for accounting and bookkeeping practices, and kept current as the law changes. Not a one-off free download, and not an AML platform bolt-on: the privacy-focused answer to the obligations you already carry.

These are compliance tools and templates you tailor to your own business. They are general information, not legal advice, and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner.

Join the founding list

Be first to know when the Accountant Kit opens, and get the plain-English updates as the 2026 changes land. No cost, no obligation.

We never sell your data. See our Privacy Policy.

Keep reading


General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC, or your obligations under the TPB Code, which are administered by the Tax Practitioners Board. Privaproof's accountant documents are self-authored and are not independently reviewed by a solicitor. The Privacy Act 1988 (Cth), the TFN Rule 2015 and related guidance change over time, so check you are working from a current version.