Data breach obligations for accountants handling TFNs (the NDB scheme)
Yes. Under section 26WE(1)(d) of the Privacy Act, the Notifiable Data Breaches (NDB) scheme reaches every "TFN recipient", including accountants and bookkeepers turning over less than A$3 million, for eligible breaches involving individual tax file number information. If such a breach is likely to cause serious harm, you must assess it and notify both the affected individuals and the OAIC.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
Why the NDB scheme reaches you, even under $3 million
Most small practices assume the A$3 million small-business exemption keeps them outside the Privacy Act entirely. For the tax file numbers you hold, it does not. The Privacy (Tax File Number) Rule 2015, a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth), binds every TFN recipient regardless of turnover, and the NDB scheme reaches those same recipients through s 26WE(1)(d) for eligible breaches involving TFN information. So a sub-$3m accounting or bookkeeping practice that suffers a breach of individual clients' or employees' TFNs is inside the notification regime, even with no anti-money-laundering work at all.
The NDB scheme is administered by the Office of the Australian Information Commissioner (OAIC), not the Tax Practitioners Board. It sits in Part IIIC of the Privacy Act.
What counts as an "eligible data breach"
An eligible data breach happens when three things line up:
1. There is unauthorised access to, unauthorised disclosure of, or loss of personal information your practice holds. 2. A reasonable person would conclude the breach is likely to result in serious harm to one or more of the affected individuals. 3. You have not been able to prevent that likely serious harm through remedial action.
For an accounting practice, the everyday examples are concrete: a lost or stolen laptop or phone with client files on it, a portal or email account compromised by phishing, a ransomware attack on your practice management system, a tax return or TFN emailed to the wrong client, or a misconfigured cloud folder. Tax file numbers, identity documents and bank details are exactly the kind of concentrated data that makes serious harm, including identity theft and financial fraud, a realistic outcome.
The scope line: what the NDB duty covers, and what it does not
This is where accurate scope matters, and where a lot of generic guidance overreaches.
For a practice that is only a TFN recipient (not otherwise an APP entity), the NDB duty is confined to eligible breaches involving the TFN information. A sub-$3m practice does not automatically carry an NDB duty for its other, non-TFN personal information, unless it is independently caught, for example by turning over more than A$3 million, by being a credit provider, or by another carve-in. Read: does the Privacy Act apply to accountants under $3 million?.
A separate layer applies if AML Tranche 2 makes you an AUSTRAC reporting entity from 1 July 2026. In that case Privacy Act s 6E switches the Australian Privacy Principles on for the AML/KYC identity data you collect for a designated service, so a breach of that data can also be an eligible data breach. But that is a distinct trigger for a subset of firms; it does not merge with, or replace, the TFN-based duty that already applies to most practices. Read: does becoming an AML reporting entity trigger the Privacy Act?.
In practice, because TFNs, identity documents and financial records sit together in the same client file, many firms find it simplest to run breach-response procedures across the whole file rather than trying to isolate the TFN field. That is a practical choice, not a statement that the whole practice is an APP entity.
What you must actually do when a breach happens
The scheme runs in three steps: contain, assess, notify.
- Contain. Take immediate steps to limit the breach: shut down or isolate the affected system, revoke access, recover lost devices or data where you can.
- Assess. If you only suspect an eligible breach, carry out a reasonable and expeditious assessment of whether it is one. The OAIC expects that assessment to be completed within 30 days of you becoming aware of the grounds to suspect it . If remedial action removes the likely serious harm, notification may not be required.
- Notify. If it is an eligible data breach, you must prepare a statement for the OAIC and notify the affected individuals as soon as practicable, telling them what happened, what information was involved and the steps they can take to protect themselves. Where you cannot practicably notify each individual, the scheme allows you to publish the statement instead.
Getting these steps right under time pressure is exactly why a written plan, prepared in advance, matters more than good intentions on the day.
Why a data breach response plan is not optional busywork
A breach of the TFN Rule is an "interference with the privacy of an individual", which means an affected person can complain to the OAIC. A response plan does two things at once: it helps you meet the NDB notification duty on time, and it evidences the "reasonable steps" to protect TFN information that the TFN Rule expects of you. Read: the Privacy (Tax File Number) Rule 2015, what accountants must do.
The consequences of getting it wrong are usually about exposure, not automatic fines. Penalties under the Privacy Act are ceilings, not certainties, and most matters resolve through the OAIC's complaint and conciliation process without a penalty. The realistic cost of an unhandled breach is more often the client trust you lose, the remediation you scramble to fund, and the regulator's attention, than a headline fine.
A workable plan for a small practice covers, at minimum:
1. Roles. Who leads the response, who assesses, who signs off on notification. 2. A containment checklist for the breach types accountants actually face (device loss, email misdirection, portal compromise, ransomware). 3. An assessment method for judging "likely to result in serious harm", with the 30-day clock built in. 4. Notification templates for the OAIC statement and the affected-individual notice, drafted before you need them. 5. A record of what happened and what you decided, so you can show your reasoning later.
What Privaproof is building for accountants
A data-breach response plan is one document in an accountant-specific privacy set: a privacy policy (APP 1), collection notices (APP 5), a TFN-handling policy and retention procedures, all written for accounting and bookkeeping practices and kept current as the law changes, including the 1 July 2026 AML changes and the 10 December 2026 automated-decision-making rule. Not a one-off free download, and not an AML platform bolt-on.
→ Join the founding list. Be first to know when the Accountant Kit opens, and get the plain-English updates as the 2026 changes land. No cost, no obligation.
Common questions
Do accountants under $3 million really have to report a data breach?
For breaches involving tax file numbers, yes. The NDB scheme reaches TFN recipients through s 26WE(1)(d) regardless of turnover, so an eligible breach of individual clients' or employees' TFNs must be assessed and, if it is likely to cause serious harm, notified to the affected individuals and the OAIC.
Does every breach have to be reported?
No. Only an "eligible data breach" triggers notification: unauthorised access, disclosure or loss of personal information that is likely to result in serious harm, where you have not been able to prevent that harm through remedial action. If you contain the breach and remove the likely serious harm, notification may not be required.
Who do I notify, and how fast?
You notify the affected individuals and the OAIC as soon as practicable once you have decided it is an eligible data breach. If you only suspect one, you assess it first; the OAIC expects that assessment within 30 days of becoming aware of the grounds to suspect it .
Is this the same as my TPB confidentiality duty?
No. The NDB scheme is administered by the OAIC under the Privacy Act. Your confidentiality duty under the TPB Code of Professional Conduct is separate and enforced by the Tax Practitioners Board. Meeting one does not automatically meet the other. Read: TPB Code confidentiality vs the Privacy Act.
Keep reading
- Privacy Act compliance for accountants and bookkeepers (the cornerstone)
- The Privacy (Tax File Number) Rule 2015: what accountants must do
- How must accountants store clients' tax file numbers?
- How long can an accountant keep a client's TFN?
- Does becoming an AML reporting entity trigger the Privacy Act?
General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC, or your obligations under the TPB Code, which are administered by the Tax Practitioners Board. Privaproof's accountant documents are self-authored and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner. The Privacy Act 1988 (Cth), the TFN Rule 2015 and the NDB scheme change over time, so check you are working from a current version.