Skip to content

Privacy compliance for Australian accountants and bookkeepers

Handle individual TFNs?

A$3msmall-business threshold
does not exemptindividual TFNs

The Tax File Number Rule sets how you collect, store, use and destroy them.

Your privacy policy is one of the fourteen. The other thirteen are what your team actually does.

14 documentsGuided tailoringKept current
13Grounded in the
Privacy Act & 13 APPs
Australian-made for
Australian accounting and bookkeeping practices

The Accountant Kit

Fourteen editable Word documents, built around what an accounting practice actually holds and does.

Handle information properlyPolicy, TFN handling, collection and retentionView 4 documentsHide documents
  • Tax File Number Handling, Storage and Destruction Procedure
  • Collection Notice
  • Privacy Policy
  • Document Retention and Destruction Schedule
Give your team clear directionTraining, roles, and what you holdView 3 documentsHide documents
  • Staff Privacy Training and Confidentiality Agreement
  • Privacy Officer Role and Internal Privacy Procedure
  • Data Inventory / "What We Hold" Map
Respond when something happensBreach, access and complaintsView 3 documentsHide documents
  • Data Breach Response Plan
  • Access and Correction Request Procedure
  • Privacy Complaint Handling Procedure
As your practice changesSuppliers, offshore, payroll and marketingView 4 documentsHide documents
  • Service Provider and Overseas Disclosure Clauses
  • Payroll Data-Handling Arrangement
  • Consent Form, Authority and Consent Clauses
  • Direct Marketing and Opt-Out Procedure

A$449 / year incl GST

No lock-in

When the privacy rules change, the updated documents are in your account. You do not write them again.

Includes the updates we make to the kit while your membership is active. Those track the Privacy Act, the Australian Privacy Principles and the Tax File Number Rule. See what has changed

Get the Accountant Kit →

Built for accounting practices, not adapted from generic small-business templates.

Fourteen documents. Not fourteen projects.

Four documents carry most of the tailoring. The rest use recurring practice details, clear prompts and the order in the Start Here sheet.

  1. 1

    Two decisions, before you open a document

    Who your Privacy Officer is, and which of three things brings your practice in: the individual TFNs you handle, whether the Privacy Act covers your practice outright, or a designated AML service. Ten of the fourteen documents name the first. The Start Here sheet settles the second in one table.

  2. 2

    Nine details, filled in once

    Your practice name, ABN, Privacy Officer and contact details are among the nine that recur across the kit. Fill them in once, then find and replace carries them through all fourteen documents in a few minutes.

What the work actually looks like

4Tailor carefully
6Fill in and read
2Adopt as they are
2Delete if they don't apply

14 documents

The Start Here sheet gives you the order to work in and an indication of the time involved. You receive the complete kit.

Three privacy checks for your practice

You can check all three today.

Collect

Can you give the four things the Rule requires, on the spot? One is that declining to quote a TFN is not an offence.

Protect

Could you list every place they sit, and who can reach them, including cloud ledgers and anything backed up offshore?

Destroy

Do you know when their TFN should be securely destroyed or de-identified, and which retention rule applies?

The four, and the wording that gives them

Under r 8(2) you must take reasonable steps to make sure the person is told all four at the point you ask. Each one below is followed by the wording the kit's Collection Notice uses to satisfy it.

  1. The law that authorises you to askWe are authorised to collect your tax file number under taxation, superannuation and personal assistance law, and we collect it only for those purposes.
  2. What you are collecting it forTo prepare and lodge your returns and statements, act as your registered agent with the ATO, report through Single Touch Payroll where we run your payroll, and administer your superannuation reporting.
  3. That declining is not an offenceGiving us your tax file number is not compulsory, and declining to quote one is not an offence. You do not have to provide it, and choosing not to is not an offence.
  4. What happens if they declineIf you choose not to, we may be unable to lodge on your behalf, and tax may be withheld from payments to you at a higher rate.

If your engagement letter, onboarding form or client portal asks for a tax file number without telling a client all four, that is the gap. The quoted wording is the Collection Notice as it ships, with your practice details left to complete. It is one document of fourteen.

A breach of the Tax File Number Rule is an interference with privacy under the Privacy Act, and an individual can complain to the Information Commissioner. No turnover test applies.

Privacy (Tax File Number) Rule 2015, rr 8(2), 11(1), 11(2), 5(3).

Privacy is part of client trust

87% of Australians are more concerned about their privacy than they were five years ago.

Your clients trust your practice with highly personal financial information. A practical privacy system helps your team handle it with the care clients increasingly expect.

Source: Office of the Australian Information Commissioner, Australian Community Attitudes to Privacy Survey 2026

A privacy policy is one document.

You may already have one. It is one of the fourteen.

Privacy policy

Says what you do

A statement for clients and your website.

vs

Practical procedures

Tell your team how

The steps behind privacy in everyday work.

The Accountant Kit gives you the policy and the procedures behind it.

Designated services from 31 March 2026

Also relevant to some practices

AML/CTF obligations apply only if your practice provides a designated service.

Not designated services

Tax returns · Financial statements · Tax advice · BAS and GST · Bookkeeping · Audit · Payroll

Check your position if you help with

Creating or restructuring companies or trusts
Selling or transferring a company or trust
Equity or debt finance for a company or trust
Client money held in a transaction

If you provide one and become a reporting entity, the Privacy Act applies to the identity data you collect for that service.

The rest of your practice can stay exempt.

Is my practice caught? →

Legal detail and sources

Nine professional-services designated services sit in s 6(5B) of the AML/CTF Act, with limits in s 6(5C) to (5E). Holding client money is not a designated service where the money is payment for your own fee, or the receipt or disbursement of a payment to or from a government body, so passing on an ATO refund or paying a tax debt is outside it.

AML/CTF Act 2006 s 6(5B), s 6(5C) to (5E); Privacy Act 1988 (Cth) s 6E(1A).

Put a practical privacy baseline in place

One complete 14-document privacy kit for Australian accounting and bookkeeping practices. Guided tailoring for your practice, kept current as the privacy rules change.

A$449/year incl GST

General information and document templates you tailor, not legal advice. Written by Privaproof.

The detail, if you want it

The practical answer is above. The legal detail is here when you need it.

The TFN Rule already binds you, with no threshold and no deadlineIt binds every practice holding individual TFN information, whatever your turnover.Read detailHide detail

The Privacy (Tax File Number) Rule 2015, a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth), binds every "TFN recipient". That covers a practice or registered tax agent holding individual clients' TFN information. It applies regardless of your turnover, so the A$3 million small-business exemption does not apply to how you handle individual tax file numbers.

The Rule sets obligations for collecting, using, disclosing, storing, securing and destroying individuals' TFN information, and for training your staff. Under s 13(4)(a) of the Privacy Act, an act or practice of a file number recipient that breaches a rule issued under s 17 is "an interference with the privacy of an individual", and r 5(3) of the Rule says the same in its own words: a breach is an interference with privacy under the Privacy Act, and the individual may complain to the Information Commissioner. That route is open without your practice being an APP entity at all. Read: the TFN Rule 2015, what accountants must do.

Scope, stated honestly: under r 5(2) the TFN Rule protects the TFN information of individuals only, not the general (non-TFN) client database, and not the TFNs of companies, partnerships, trusts or super funds. Handling TFNs does not make a small practice a full "APP entity" subject to all 13 Australian Privacy Principles. It creates targeted obligations for the TFN data you hold. Read: does the Privacy Act apply to accountants under $3 million?.

Why an accounting practice concentrates the riskTFNs, tax returns, bank details and client-employee payroll data, in one place.Read detailHide detail

A small accounting or bookkeeping practice holds a concentrated set of personal and financial information in one place:

  • Individual client TFNs and identity documents.
  • Full tax returns and financial position.
  • Bank and BSB details for refunds and payments.
  • Client-employee payroll data you process on behalf of business clients: names, TFNs, super and bank details for people who are not even your own clients. (The employee-records exemption in s 7B(3) of the Privacy Act is written for an act of an organisation "that is or was an employer of an individual", and a practice running payroll for a business client is not that employer. Whether the exemption reaches a third-party processor is unresolved, so do not assume it switches off your handling of this data.)
  • SMSF member data where you administer self-managed super funds.

That concentration is why the paragraph below sets out precisely which of these the data-breach scheme reaches, and which it does not.

Where the notifiable data breaches scheme reaches, and where it does not. Under s 26WE(1)(d) of the Privacy Act the NDB scheme reaches a file number recipient in relation to tax file number information. It reaches the rest of that list only where some other trigger makes your practice an APP entity. Read: your data-breach obligations under the NDB scheme.

Your professional confidentiality duty is not the same thingThe TPB Code and the Privacy Act are different regimes with different regulators.Read detailHide detail

Registered tax agents and registered BAS agents already carry a confidentiality obligation under item 6 of the Code of Professional Conduct in s 30-10 of the Tax Agent Services Act 2009: information relating to a client's affairs must not be disclosed to a third party without the client's permission or a legal duty to disclose. The Tax Agent Services (Code of Professional Conduct) Determination 2024 adds further obligations on top of the existing Code. That regime is enforced by the Tax Practitioners Board and sits alongside, not instead of, the Privacy Act. The TPB does not administer the Privacy Act or the data-breach scheme; the OAIC does. Meeting one does not automatically meet the other. Read: TPB Code confidentiality vs the Privacy Act.

Keep up with the changes

Not buying today? Get the plain-English updates as the privacy rules change, and the notes on what they mean in practice. No cost, no obligation.

We never sell your data. See our Privacy Policy.

Keep reading


General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC, or your obligations under the TPB Code, which are administered by the Tax Practitioners Board. The Privacy Act 1988 (Cth), the TFN Rule 2015 and related guidance change over time, so check you are working from a current version.