Skip to content

The accountant privacy policy: what it must cover

An accountant's privacy policy should describe the real data your practice holds: individual client and employee tax file numbers, identity and VOI documents, tax returns, BAS, bank details, client-employee payroll, SMSF member records and any AML/KYC data, and how you collect, use, secure, disclose and destroy it. A generic fill-in-the-blanks template rarely reflects an accounting practice, and many still carry the wrong "under $3 million, so exempt" assumption.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

Do you legally need a privacy policy at all?

It depends on how the Privacy Act reaches your practice, and there are two different ways.

If you handle individual tax file numbers, the TFN Rule already binds you. The Privacy (Tax File Number) Rule 2015, a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth), binds every "TFN recipient", and a practice or registered tax agent holding clients' TFN information is one, with no turnover threshold and no small-business exemption. It sets obligations for collecting, using, disclosing, securing, retaining and destroying individuals' TFN information, and for training your staff on it. A written privacy policy and a TFN-handling policy are the practical way you meet and evidence those obligations. Note the scope, stated honestly: handling TFNs does not make a small practice a full "APP entity" subject to all 13 Australian Privacy Principles, and the TFN Rule protects the TFN information of individuals only, not the general (non-TFN) client database. Read: the TFN Rule 2015, what accountants must do.

If you are a full APP entity, APP 1 makes a privacy policy a strict requirement. That is the case if your practice turns over more than A$3 million, or if a designated service makes you an AUSTRAC reporting entity, in which case Privacy Act s 6E applies the APPs to the AML/KYC identity data you collect for that service (only that data, not your general tax files). For an APP entity, Australian Privacy Principle 1 requires a clearly expressed and up-to-date privacy policy as the baseline public document.

So a privacy policy is either strictly required (as an APP entity) or the sensible, expected way to meet the TFN Rule obligations you already carry. Either way, a document written for an accounting practice does more real work than a horizontal template. A general removal of the A$3 million small-business exemption has been proposed but is not yet law, so we do not treat it as in force.

What an accountant's privacy policy must cover

A policy that fits an accounting or bookkeeping practice should address, at a minimum:

A collection notice (APP 5) is a separate, shorter document you give people at the point you take their details. The privacy policy is the standing public document; the collection notice is the point-of-collection heads-up. An accounting practice generally needs both, plus a data-breach response plan for the notifiable-breach duty that reaches TFN information even under A$3 million. Read: your data-breach obligations under the NDB scheme.

Where a generic template falls short

A free or off-the-shelf privacy policy is written for "a business", not an accounting practice. In practice that means it usually:

The AML and forward-looking layers, if they apply to you

Two further points affect the policy only for some firms, so keep them scoped.

AML/KYC data, for designated-service firms only. From 1 July 2026, AML/CTF Tranche 2 makes a firm an AUSTRAC reporting entity only where it provides a designated service, such as forming or restructuring companies and trusts, holding or disbursing client money, or acting as or arranging a nominee. Routine tax returns, financial statements, tax advice, BAS, bookkeeping, audit and payroll are not designated services. Where you are a reporting entity, s 6E applies the Privacy Act to the AML/KYC identity data you collect for that service, so your policy should cover that data. It does not pull your general tax files, ledgers or payroll under the Act by that route. Enrolment for newly regulated firms opened 31 March 2026; existing providers of a designated service enrol by around 29 July 2026. Read: which accounting services are designated?.

Automated decision-making disclosure, conditional, from 10 December 2026. If your practice uses software that makes, or substantially helps make, a decision that could significantly affect a person, and your practice is an APP entity, then from 10 December 2026 the new privacy-policy transparency requirement will expect that automated decision-making to be disclosed in the policy. Whether a given tool crosses that threshold is fact-specific, so treat it as a "check this", not an automatic obligation.

Your professional confidentiality duty under item 6 of the TPB Code of Professional Conduct sits alongside the Privacy Act, not instead of it, and is enforced by the Tax Practitioners Board rather than the OAIC. A privacy policy does not discharge the TPB Code, and the TPB does not administer the Privacy Act. Read: TPB Code confidentiality vs the Privacy Act.

Common questions

Does a small accounting practice under $3 million need a privacy policy?

For your practice generally, the A$3 million small-business exemption may still apply, but not for your clients' tax file numbers. The TFN Rule binds you for individual TFN information regardless of turnover, so a privacy policy and a TFN-handling policy are the sensible way to meet those obligations even for a small practice. If you are an APP entity (over A$3 million, or a reporting entity for your AML data), APP 1 makes a privacy policy a strict requirement.

Can I just use a free privacy policy template?

You can start from one, but a generic template rarely names an accounting practice's real data (TFNs, VOI, BAS, payroll, SMSF), and many still carry the outdated "under $3m, so exempt" framing that is wrong for TFN recipients. Tailor it to the data you actually hold, or start from a document written for accountants.

Is a privacy policy the only document I need?

No. The policy is the standing public document. Most accounting practices also need collection notices (APP 5) for the points where you take client and employee details, and a data-breach response plan for the notifiable-breach duty that reaches TFN information even under A$3 million.

Does my policy need to mention AML?

Only if you provide an AML designated service and are therefore a reporting entity. In that case s 6E brings the AML/KYC identity data under the Privacy Act, so your policy should cover it. Firms doing only tax returns, BAS, bookkeeping, audit and payroll provide no designated service and are not reporting entities.

Where Privaproof fits

Privaproof is building a dedicated, accountant-specific privacy document set: a privacy policy, collection notices, a TFN-handling policy and a data-breach response plan, written for accounting and bookkeeping practices and kept current as the law changes, including the 1 July 2026 AML changes and the 10 December 2026 automated-decision-making rule. Not a one-off free download, and not an AML platform bolt-on.

→ Join the founding list. Be first to know when the Accountant Kit opens, and get the plain-English updates as the 2026 changes land. No cost, no obligation.

Keep reading


General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. Privaproof's accountant documents are self-authored and are not independently reviewed by a solicitor. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC, or your obligations under the TPB Code, which are administered by the Tax Practitioners Board. The Privacy Act 1988 (Cth), the TFN Rule 2015 and related guidance change over time, so check you are working from a current version.