Skip to content

Data breach obligations for accountants handling TFNs (the NDB scheme)

Yes. Under section 26WE(1)(d) of the Privacy Act, the Notifiable Data Breaches (NDB) scheme reaches every "TFN recipient", including accountants and bookkeepers turning over less than A$3 million, for eligible breaches involving individual tax file number information. If you suspect a breach may be an eligible one, s 26WH requires you to assess it. If you have reasonable grounds to believe it is one, s 26WK requires a statement to the OAIC and s 26WL requires you to notify the individuals or, where notifying them is not practicable, to publish that statement and publicise its contents.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

Why the NDB scheme reaches you, even under $3 million

It is easy to assume the A$3 million small-business exemption keeps you outside the Privacy Act entirely. For the individual tax file numbers you hold, it does not. The Privacy (Tax File Number) Rule 2015, a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth), binds every TFN recipient regardless of turnover, and the NDB scheme reaches those same recipients through s 26WE(1)(d), which applies where a file number recipient holds tax file number information relating to one or more individuals and is required under s 18 not to breach a s 17 rule relating to that information. So a sub-$3m accounting or bookkeeping practice that suffers a breach of individual clients' or employees' TFNs is inside the notification regime, even with no anti-money-laundering work at all. One limit is worth knowing: rule 5(2) of the TFN Rule covers the TFN information of individuals, not TFN information about companies, partnerships, trusts or superannuation funds.

The NDB scheme is administered by the Office of the Australian Information Commissioner (OAIC), not the Tax Practitioners Board. It sits in Part IIIC of the Privacy Act.

What counts as an "eligible data breach"

An eligible data breach turns on two elements, with a separate statutory exception sitting behind them (Privacy Act ss 26WE(2), 26WF):

For an accounting practice, the everyday examples are concrete: a lost or stolen laptop or phone with client files on it, a portal or email account compromised by phishing, a ransomware attack on your practice management system, a tax return or TFN emailed to the wrong client, or a misconfigured cloud folder. Tax file numbers, identity documents and bank details are exactly the kind of concentrated data that makes serious harm, including identity theft and financial fraud, a realistic outcome.

The scope line: what the NDB duty covers, and what it does not

This is where accurate scope matters, and where a lot of generic guidance overreaches.

For a practice that is only a TFN recipient (not otherwise an APP entity), the NDB duty is confined to eligible breaches involving the TFN information. A sub-$3m practice does not automatically carry an NDB duty for its other, non-TFN personal information, unless it is independently caught, for example by turning over more than A$3 million, by being a credit provider, or by another carve-in. Read: does the Privacy Act apply to accountants under $3 million?.

A separate layer applies if AML Tranche 2 makes you an AUSTRAC reporting entity. The Tranche 2 designated services commenced on 31 March 2026, which is when providing one makes you a reporting entity; the obligations that follow (enrolment, an AML/CTF program, customer due diligence, reporting and record-keeping) were deferred to 1 July 2026. Once you are a reporting entity, Privacy Act s 6E(1A) applies the Act to you as if you were an organisation, but only in relation to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, its regulations and the AML/CTF Rules. It is activity-scoped rather than practice-wide, so a breach of the personal information you handle in those activities can also be an eligible data breach. That is a distinct trigger for a subset of firms, and it does not merge with, or replace, the TFN-based duty. Read: does becoming an AML reporting entity trigger the Privacy Act?.

In practice, because TFNs, identity documents and financial records sit together in the same client file, it can be simpler to run breach-response procedures across the whole file than to isolate the TFN field. That is a practical choice, not a statement that the whole practice is an APP entity.

What you must actually do when a breach happens

The scheme runs in three steps: contain, assess, notify.

Getting these steps right under time pressure is exactly why a written plan, prepared in advance, matters more than good intentions on the day.

Why a data breach response plan is not optional busywork

A breach of a s 17 rule by a file number recipient is an "interference with the privacy of an individual" under s 13(4)(a) of the Privacy Act, which means an affected person can complain to the OAIC. Failing the NDB duties themselves is caught separately: under s 13(4A), contravening s 26WH(2), s 26WK(2) or s 26WL(3) is itself an act that is an interference with the privacy of an individual. A response plan does two things at once: it helps you meet the assessment and notification duties on time, and it evidences the reasonable steps to protect TFN information from misuse, loss and unauthorised access that rule 11(1) of the TFN Rule requires of you. Read: the Privacy (Tax File Number) Rule 2015, what accountants must do.

The consequences of getting it wrong are about exposure, not automatic fines. Penalties under the Privacy Act are ceilings rather than certainties, and the OAIC can deal with a complaint through conciliation without any penalty being imposed. Beyond any penalty, though, an unhandled breach carries its own costs: the client trust you lose, the remediation you have to fund, and the regulator's attention.

A workable plan for a small practice covers, at minimum:

What the Accountant Kit gives you

A data-breach response plan is one document in an accountant-specific privacy set: a privacy policy (APP 1), collection notices (APP 5), a TFN-handling policy and retention procedures, all written for accounting and bookkeeping practices and kept current as the law changes, including the AML obligations that commenced on 1 July 2026 and the automated-decision-making rule in APP 1.7 to 1.9 that commences on 10 December 2026 for practices that are APP entities. Not a one-off free download, and not an AML platform bolt-on.

→ Get the Accountant Kit. Editable documents you tailor to your practice, with updates as the rules change.

Common questions

Do accountants under $3 million really have to report a data breach?

For breaches involving individual tax file numbers, yes. The NDB scheme reaches TFN recipients through s 26WE(1)(d) regardless of turnover. If you suspect a breach of individual clients' or employees' TFNs may be an eligible one, s 26WH requires you to assess it. If you have reasonable grounds to believe it is one, s 26WK requires a statement to the OAIC and s 26WL requires you to notify the individuals or, where that is not practicable, to publish the statement and publicise its contents.

Does every breach have to be reported?

No. Only an "eligible data breach" triggers notification: unauthorised access to, or unauthorised disclosure of, the information, or its loss in circumstances where such access or disclosure is likely to occur, where a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals the information relates to (s 26WE(2)). A separate exception in s 26WF applies if you take action before serious harm results and, as a result, a reasonable person would conclude serious harm is not likely: the breach is then taken never to have been an eligible data breach, and notification is not required.

Who do I notify, and how fast?

You notify once you have reasonable grounds to believe there has been an eligible data breach: the statement goes to the OAIC as soon as practicable after you become so aware (s 26WK(2)), and the individuals are notified as soon as practicable after the statement is prepared (s 26WL(3)). If you only suspect a breach, you assess it first, and s 26WH(2)(b) requires you to take all reasonable steps to ensure that assessment is completed within 30 days of becoming aware of the grounds to suspect.

Is this the same as my TPB confidentiality duty?

No. The NDB scheme is administered by the OAIC under the Privacy Act. Your confidentiality duty under the TPB Code of Professional Conduct is separate and enforced by the Tax Practitioners Board. Meeting one does not automatically meet the other. Read: TPB Code confidentiality vs the Privacy Act.

Keep reading


General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC, or your obligations under the TPB Code, which are administered by the Tax Practitioners Board. For advice on your specific circumstances, consult a qualified Australian legal practitioner. The Privacy Act 1988 (Cth), the TFN Rule 2015 and the NDB scheme change over time, so check you are working from a current version.