Data breach obligations for accountants handling TFNs (the NDB scheme)
Yes. Under section 26WE(1)(d) of the Privacy Act, the Notifiable Data Breaches (NDB) scheme reaches every "TFN recipient", including accountants and bookkeepers turning over less than A$3 million, for eligible breaches involving individual tax file number information. If you suspect a breach may be an eligible one, s 26WH requires you to assess it. If you have reasonable grounds to believe it is one, s 26WK requires a statement to the OAIC and s 26WL requires you to notify the individuals or, where notifying them is not practicable, to publish that statement and publicise its contents.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
Why the NDB scheme reaches you, even under $3 million
It is easy to assume the A$3 million small-business exemption keeps you outside the Privacy Act entirely. For the individual tax file numbers you hold, it does not. The Privacy (Tax File Number) Rule 2015, a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth), binds every TFN recipient regardless of turnover, and the NDB scheme reaches those same recipients through s 26WE(1)(d), which applies where a file number recipient holds tax file number information relating to one or more individuals and is required under s 18 not to breach a s 17 rule relating to that information. So a sub-$3m accounting or bookkeeping practice that suffers a breach of individual clients' or employees' TFNs is inside the notification regime, even with no anti-money-laundering work at all. One limit is worth knowing: rule 5(2) of the TFN Rule covers the TFN information of individuals, not TFN information about companies, partnerships, trusts or superannuation funds.
The NDB scheme is administered by the Office of the Australian Information Commissioner (OAIC), not the Tax Practitioners Board. It sits in Part IIIC of the Privacy Act.
What counts as an "eligible data breach"
An eligible data breach turns on two elements, with a separate statutory exception sitting behind them (Privacy Act ss 26WE(2), 26WF):
- There is unauthorised access to, or unauthorised disclosure of, the information your practice holds, or that information is lost in circumstances where such access or disclosure is likely to occur. For a TFN recipient the information in question is the tax file number information; for an APP entity it is personal information.
- A reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates. Section 26WG sets out the matters to weigh, including the kind and sensitivity of the information, whether it was protected by security measures and how likely those measures are to be overcome.
- The exception, which is a separate provision and not a third element: under s 26WF, if you take action before the access or disclosure results in serious harm, and as a result a reasonable person would conclude serious harm is not likely, it is taken never to have been an eligible data breach.
For an accounting practice, the everyday examples are concrete: a lost or stolen laptop or phone with client files on it, a portal or email account compromised by phishing, a ransomware attack on your practice management system, a tax return or TFN emailed to the wrong client, or a misconfigured cloud folder. Tax file numbers, identity documents and bank details are exactly the kind of concentrated data that makes serious harm, including identity theft and financial fraud, a realistic outcome.
The scope line: what the NDB duty covers, and what it does not
This is where accurate scope matters, and where a lot of generic guidance overreaches.
For a practice that is only a TFN recipient (not otherwise an APP entity), the NDB duty is confined to eligible breaches involving the TFN information. A sub-$3m practice does not automatically carry an NDB duty for its other, non-TFN personal information, unless it is independently caught, for example by turning over more than A$3 million, by being a credit provider, or by another carve-in. Read: does the Privacy Act apply to accountants under $3 million?.
A separate layer applies if AML Tranche 2 makes you an AUSTRAC reporting entity. The Tranche 2 designated services commenced on 31 March 2026, which is when providing one makes you a reporting entity; the obligations that follow (enrolment, an AML/CTF program, customer due diligence, reporting and record-keeping) were deferred to 1 July 2026. Once you are a reporting entity, Privacy Act s 6E(1A) applies the Act to you as if you were an organisation, but only in relation to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, its regulations and the AML/CTF Rules. It is activity-scoped rather than practice-wide, so a breach of the personal information you handle in those activities can also be an eligible data breach. That is a distinct trigger for a subset of firms, and it does not merge with, or replace, the TFN-based duty. Read: does becoming an AML reporting entity trigger the Privacy Act?.
In practice, because TFNs, identity documents and financial records sit together in the same client file, it can be simpler to run breach-response procedures across the whole file than to isolate the TFN field. That is a practical choice, not a statement that the whole practice is an APP entity.
What you must actually do when a breach happens
The scheme runs in three steps: contain, assess, notify.
- Contain. Take immediate steps to limit the breach: shut down or isolate the affected system, revoke access, recover lost devices or data where you can.
- Assess. Section 26WH applies when you are aware of reasonable grounds to suspect there may have been an eligible data breach but are not yet aware of reasonable grounds to believe there has been one. It puts two duties on you, not on the regulator: under s 26WH(2)(a) you must carry out a reasonable and expeditious assessment of whether there are reasonable grounds to believe the circumstances amount to an eligible data breach, and under s 26WH(2)(b) you must take all reasonable steps to ensure that assessment is completed within 30 days after you became aware of the grounds to suspect. The 30 days is a statutory outer limit on a reasonable-steps duty, not a regulator's expectation and not a target to run to. If remedial action under s 26WF removes the likely serious harm before it results, the breach is taken never to have been an eligible data breach and notification is not required.
- Notify. If you are aware of reasonable grounds to believe there has been an eligible data breach, s 26WK(2) requires you to prepare a statement and give a copy of it to the OAIC as soon as practicable after becoming so aware. Under s 26WK(3) the statement must set out your identity and contact details, a description of the breach, the particular kinds of information concerned, and recommendations about the steps individuals should take. Section 26WL(2) then requires you to notify the contents of that statement to each individual the information relates to or, if that is not practicable, to each individual at risk from the breach; and if neither is practicable, to publish a copy of the statement on your website and take reasonable steps to publicise its contents. Section 26WL(3) requires you to do that as soon as practicable after the statement is prepared.
Getting these steps right under time pressure is exactly why a written plan, prepared in advance, matters more than good intentions on the day.
Why a data breach response plan is not optional busywork
A breach of a s 17 rule by a file number recipient is an "interference with the privacy of an individual" under s 13(4)(a) of the Privacy Act, which means an affected person can complain to the OAIC. Failing the NDB duties themselves is caught separately: under s 13(4A), contravening s 26WH(2), s 26WK(2) or s 26WL(3) is itself an act that is an interference with the privacy of an individual. A response plan does two things at once: it helps you meet the assessment and notification duties on time, and it evidences the reasonable steps to protect TFN information from misuse, loss and unauthorised access that rule 11(1) of the TFN Rule requires of you. Read: the Privacy (Tax File Number) Rule 2015, what accountants must do.
The consequences of getting it wrong are about exposure, not automatic fines. Penalties under the Privacy Act are ceilings rather than certainties, and the OAIC can deal with a complaint through conciliation without any penalty being imposed. Beyond any penalty, though, an unhandled breach carries its own costs: the client trust you lose, the remediation you have to fund, and the regulator's attention.
A workable plan for a small practice covers, at minimum:
- Roles. Who leads the response, who assesses, who signs off on notification.
- A containment checklist for the breach types accountants actually face (device loss, email misdirection, portal compromise, ransomware).
- An assessment method for judging "likely to result in serious harm", worked against the factors in s 26WG, with the s 26WH(2)(b) 30-day outer limit built in.
- Notification templates for the s 26WK statement to the OAIC and the affected-individual notice, drafted before you need them.
- A record of what happened and what you decided, so you can show your reasoning later.
What the Accountant Kit gives you
A data-breach response plan is one document in an accountant-specific privacy set: a privacy policy (APP 1), collection notices (APP 5), a TFN-handling policy and retention procedures, all written for accounting and bookkeeping practices and kept current as the law changes, including the AML obligations that commenced on 1 July 2026 and the automated-decision-making rule in APP 1.7 to 1.9 that commences on 10 December 2026 for practices that are APP entities. Not a one-off free download, and not an AML platform bolt-on.
→ Get the Accountant Kit. Editable documents you tailor to your practice, with updates as the rules change.
Common questions
Do accountants under $3 million really have to report a data breach?
For breaches involving individual tax file numbers, yes. The NDB scheme reaches TFN recipients through s 26WE(1)(d) regardless of turnover. If you suspect a breach of individual clients' or employees' TFNs may be an eligible one, s 26WH requires you to assess it. If you have reasonable grounds to believe it is one, s 26WK requires a statement to the OAIC and s 26WL requires you to notify the individuals or, where that is not practicable, to publish the statement and publicise its contents.
Does every breach have to be reported?
No. Only an "eligible data breach" triggers notification: unauthorised access to, or unauthorised disclosure of, the information, or its loss in circumstances where such access or disclosure is likely to occur, where a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals the information relates to (s 26WE(2)). A separate exception in s 26WF applies if you take action before serious harm results and, as a result, a reasonable person would conclude serious harm is not likely: the breach is then taken never to have been an eligible data breach, and notification is not required.
Who do I notify, and how fast?
You notify once you have reasonable grounds to believe there has been an eligible data breach: the statement goes to the OAIC as soon as practicable after you become so aware (s 26WK(2)), and the individuals are notified as soon as practicable after the statement is prepared (s 26WL(3)). If you only suspect a breach, you assess it first, and s 26WH(2)(b) requires you to take all reasonable steps to ensure that assessment is completed within 30 days of becoming aware of the grounds to suspect.
Is this the same as my TPB confidentiality duty?
No. The NDB scheme is administered by the OAIC under the Privacy Act. Your confidentiality duty under the TPB Code of Professional Conduct is separate and enforced by the Tax Practitioners Board. Meeting one does not automatically meet the other. Read: TPB Code confidentiality vs the Privacy Act.
Keep reading
- Privacy Act compliance for accountants and bookkeepers (the cornerstone)
- The TFN Rule 2015: what accountants must do
- How must accountants store clients' tax file numbers?
- How long can an accountant keep a client's TFN?
- Does becoming an AML reporting entity trigger the Privacy Act?
General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC, or your obligations under the TPB Code, which are administered by the Tax Practitioners Board. For advice on your specific circumstances, consult a qualified Australian legal practitioner. The Privacy Act 1988 (Cth), the TFN Rule 2015 and the NDB scheme change over time, so check you are working from a current version.