The accountant privacy policy: what it must cover
An accountant's privacy policy should describe the real data your practice holds: individual client and employee tax file numbers, identity and VOI documents, tax returns, BAS, bank details, client-employee payroll, SMSF member records and any AML/KYC data, and how you collect, use, secure, disclose and destroy it. A generic fill-in-the-blanks template rarely reflects an accounting practice, and one written for a general business can carry the wrong "under $3 million, so exempt" assumption.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
Do you legally need a privacy policy at all?
It depends on how the Privacy Act reaches your practice, and there are two different ways.
If you handle individual tax file numbers, the TFN Rule already binds you. The Privacy (Tax File Number) Rule 2015, a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth), binds every "TFN recipient", and a practice or registered tax agent holding individual clients' TFN information is one, with no turnover threshold and no small-business exemption. It sets obligations for collecting, using, disclosing, securing, retaining and destroying individuals' TFN information, and for training your staff on it. A written privacy policy and a TFN-handling policy are the practical way you meet and evidence those obligations. Note the scope, stated honestly: handling TFNs does not make a small practice a full "APP entity" subject to all 13 Australian Privacy Principles, and the TFN Rule protects the TFN information of individuals only, not the general (non-TFN) client database. Read: the TFN Rule 2015, what accountants must do.
If you are a full APP entity, APP 1 makes a privacy policy a strict requirement. The usual trigger for a practice is turnover: a business is a small business if its annual turnover for the previous financial year was A$3 million or less (s 6D(1)), and s 6D(4)(a) works as a one-way ratchet, so a practice that has had any completed financial year above A$3 million since it started is outside the exemption even if turnover later falls. Turnover is not the only trigger. Section 6D(4)(b) to (f) also reach a health service provider holding health information, a business that discloses personal information about someone for a benefit, service or advantage, a business that provides a benefit, service or advantage in order to collect it, a contracted service provider for a Commonwealth contract and a credit reporting body, and s 6D(9) reaches a body corporate related to a body corporate that is not a small business. Separately, if a designated service makes you an AUSTRAC reporting entity, Privacy Act s 6E(1A) applies the Act to you as if you were an organisation, but only in relation to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, so it reaches that AML work and not your general tax files, and it does not make the whole practice an APP entity. For an APP entity, Australian Privacy Principle 1 requires a clearly expressed and up-to-date privacy policy as the baseline public document.
So a privacy policy is either strictly required (as an APP entity) or the sensible, expected way to meet the TFN Rule obligations you already carry. Either way, a document written for an accounting practice does more real work than a horizontal template. A general removal of the A$3 million small-business exemption has been proposed but is not yet law, so we do not treat it as in force.
What an accountant's privacy policy must cover
A policy that fits an accounting or bookkeeping practice should address, at a minimum:
- What personal information you collect. Be specific to the practice: individual client and employee tax file numbers, identity and verification-of-identity documents, tax returns and financial position, BAS and GST records, bank and BSB details, client-employee payroll data, SMSF member records, and any customer due diligence or KYC records where you provide an AML designated service.
- How and why you collect it. The purposes you collect for (preparing and lodging returns, BAS and financial statements, running payroll, meeting your own legal obligations), and the fact that you often collect information about third parties, such as a business client's employees, not just the client in front of you.
- How you use and disclose it. The routine disclosures an accounting practice makes: to the ATO and ASIC, to superannuation funds, to your accounting and lodgement software providers, and, for reporting entities, to AUSTRAC. If any of that data is stored or processed overseas (for example in cloud software), the policy should say so.
- How you secure it. The reasonable steps you take to protect the data from misuse, loss and unauthorised access, reflecting APP 11 for APP entities and the security obligation the TFN Rule imposes for TFN information. Read: how must accountants store clients' tax file numbers?.
- How long you keep it, and how you destroy it. The retention and destruction approach, reconciling the "destroy or de-identify when no longer needed" principle with the record-keeping periods that tax law and, where it applies, the AML seven-year floor impose on you. Read: how long can an accountant keep a client's TFN?.
- How people can access, correct or complain. Access and correction of the information you hold, and how someone raises a privacy concern, including that they can complain to the OAIC. A breach of the TFN Rule is an "interference with the privacy of an individual", so this is a real avenue for an affected person.
- How to contact you about privacy. A named contact point and the practical steps a person takes to make an enquiry or request.
A collection notice (APP 5) is a separate, shorter document you give people at the point you take their details. The privacy policy is the standing public document; the collection notice is the point-of-collection heads-up. An accounting practice generally needs both, plus a data-breach response plan for the notifiable-breach duty that reaches TFN information even under A$3 million. Read: your data-breach obligations under the NDB scheme.
Where a generic template falls short
A free or off-the-shelf privacy policy is written for "a business", not an accounting practice. In practice that means it usually:
- Names none of your real data flows. It will not mention TFNs, VOI, BAS, SMSF member data or client-employee payroll, so it describes a practice that is not yours.
- Carries the wrong exemption framing. A general template can say, or imply, that a business under A$3 million has no obligations. That is wrong for a TFN recipient: the TFN Rule binds you regardless of turnover. It also skips the other s 6D(4) triggers and the related-body-corporate rule in s 6D(9), any of which can put a practice inside the Act whatever its turnover.
- Misses the third-party payroll angle. When you process a business client's payroll you hold TFNs, super and bank details for people who are not your own clients. The employee-records exemption in Privacy Act s 7B(3) is written for "an organisation that is or was an employer of an individual" and covers acts directly related to "a current or former employment relationship between the employer and the individual", so on the face of the section it does not reach a practice handling someone else's employees. Those employees' TFN information is caught by the TFN Rule while it is in your hands, so this data should be described and handled, not assumed away.
- Does not stay current. A one-off download does not update as the law moves, and 2026 brings changes worth reflecting.
The AML and forward-looking layers, if they apply to you
Two further points affect the policy only for some firms, so keep them scoped.
AML/KYC data, for designated-service firms only. From 31 March 2026, AML/CTF Tranche 2 makes a firm an AUSTRAC reporting entity only where it provides a designated service in table 6 of s 6 of the AML/CTF Act 2006, such as creating or restructuring a body corporate or legal arrangement (item 6), receiving, holding, controlling or disbursing a person's money as part of a transaction (item 3), or acting as, or arranging for another person to act as, a nominee director, trustee or nominee shareholder (items 7 and 8). Routine tax returns, financial statements, tax advice, BAS, bookkeeping, audit and payroll are not designated services in that table. Where you are a reporting entity, s 6E(1A) applies the Privacy Act to you as if you were an organisation in relation to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, so your policy should cover that AML work and the identity data it involves. It does not pull your general tax files, ledgers or payroll under the Act by that route. Enrolment for newly regulated firms opened 31 March 2026, and for anyone already providing a designated service before 1 July 2026 the enrolment date is fixed at 29 July 2026 by Sch 3 Part 4 item 12 of the amending Act rather than counted from a start date. The AML/CTF obligations themselves, the program, customer due diligence, reporting and record-keeping, start 1 July 2026. Read: which accounting services are designated?.
Automated decision-making disclosure, conditional, from 10 December 2026. From 10 December 2026, APP 1.7 requires an APP entity's privacy policy to contain the information listed in APP 1.8 where the entity has arranged for a computer program to make, or to do a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect the rights or interests of an individual, and personal information about that individual is used in the operation of the program. APP 1.9 confirms that a beneficial effect counts as much as an adverse one, and APP 1.8 asks for the kinds of personal information used and the kinds of decisions made solely by, or partly with the help of, those programs. It binds APP entities only, so a practice outside the Act on the s 6D tests is not caught, and whether a given tool crosses the threshold is fact-specific, so treat it as a "check this", not an automatic obligation.
Your professional confidentiality duty under item 6 of the TPB Code of Professional Conduct sits alongside the Privacy Act, not instead of it, and is enforced by the Tax Practitioners Board rather than the OAIC. A privacy policy does not discharge the TPB Code, and the TPB does not administer the Privacy Act. Read: TPB Code confidentiality vs the Privacy Act.
Common questions
Does a small accounting practice under $3 million need a privacy policy?
For your practice generally, the A$3 million small-business exemption may still apply, but not for your clients' tax file numbers. The TFN Rule binds you for individual TFN information regardless of turnover, so a privacy policy and a TFN-handling policy are the sensible way to meet those obligations even for a small practice. Check the exemption rather than assume it: s 6D(4)(a) works one way only, so a practice that has already had a completed financial year over A$3 million is outside the exemption even if turnover has since fallen, and s 6D(4)(b) to (f) and s 6D(9) carry further triggers. If you are an APP entity, APP 1 makes a privacy policy a strict requirement, and if a designated service makes you a reporting entity, s 6E(1A) applies the Act to your AML/CTF activities whatever your turnover.
Can I just use a free privacy policy template?
You can start from one, but a generic template rarely names an accounting practice's real data (TFNs, VOI, BAS, payroll, SMSF), and a template written for a general business can carry the outdated "under $3m, so exempt" framing that is wrong for TFN recipients. Tailor it to the data you actually hold, or start from a document written for accountants.
Is a privacy policy the only document I need?
No. The policy is the standing public document. Most accounting practices also need collection notices (APP 5) for the points where you take client and employee details, and a data-breach response plan for the notifiable-breach duty that reaches TFN information even under A$3 million.
Does my policy need to mention AML?
Only if you provide an AML designated service and are therefore a reporting entity. In that case s 6E(1A) applies the Privacy Act to the activities you carry on in connection with the AML/CTF Act, including the identity data those activities involve, so your policy should cover it. Firms doing only tax returns, BAS, bookkeeping, audit and payroll provide no designated service in table 6 and are not reporting entities on that basis.
Where Privaproof fits
Privaproof provides a dedicated, accountant-specific privacy document set: a privacy policy, collection notices, a TFN-handling policy and a data-breach response plan, written for accounting and bookkeeping practices and kept current as the law changes, including the 2026 AML/CTF changes (designated services from 31 March 2026, obligations from 1 July 2026) and the 10 December 2026 automated-decision-making rule. Not a one-off free download, and not an AML platform bolt-on.
→ Get the Accountant Kit. Editable documents you tailor to your practice, with updates as the rules change.
Keep reading
- Privacy Act compliance for accountants and bookkeepers
- Does the Privacy Act apply to accountants under $3 million?
- The TFN Rule 2015: what accountants must do
- How must accountants store clients' tax file numbers?
- Data-breach obligations for accountants handling TFNs
General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC, or your obligations under the TPB Code, which are administered by the Tax Practitioners Board. The Privacy Act 1988 (Cth), the TFN Rule 2015 and related guidance change over time, so check you are working from a current version.