Skip to content

How long can an accountant keep a client's TFN?

There is no fixed number of years. The Privacy (Tax File Number) Rule 2015 requires you to securely destroy or de-identify a client's tax file number once you are no longer required by law to retain it and no longer need it for a permitted purpose. Where a record-keeping law applies, that law sets the floor for how long you must keep it; the TFN Rule sets the ceiling on keeping it any longer.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

The rule: destroy when you no longer need it, not "keep it forever"

The Privacy (Tax File Number) Rule 2015 is a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth), and it binds every "TFN recipient", and a practice or registered tax agent holding clients' TFN information is one. It applies regardless of your turnover, so the A$3 million small-business exemption does not change how long you may hold individual TFN information.

One of the Rule's obligations is retention and destruction: you must take reasonable steps to securely destroy or permanently de-identify TFN information once you are no longer required by law to retain it, and it is no longer needed for a purpose under the Rule. There is no set period in the Rule itself. The trigger is need plus any legal retention requirement, not the calendar.

So the answer to "how long can I keep a client's TFN" is really two questions stacked together: how long does another law require you to keep the record, and when does the last permitted purpose fall away.

"Required by law to retain it": the floor

Several laws can require you to keep records that happen to contain a TFN, and those requirements set the minimum you must hold. Two that commonly apply to an accounting practice:

While a law like these requires you to keep a record, you are "required by law to retain it", so the TFN Rule's destruction obligation does not bite yet. The floor wins for as long as it runs.

The AML seven-year floor is narrow, so do not over-apply it

It is easy to assume the seven-year AML figure governs everything. It does not. AML/CTF Tranche 2 makes a firm a reporting entity only where it provides a designated service (for example forming or restructuring companies and trusts, holding or disbursing client money, or acting as a nominee), and even then Privacy Act s 6E applies the Privacy Act only to the AML/KYC identity data you collect for that service, not to your general tax files, ledgers or payroll.

Routine tax returns, financial statements, tax advice, BAS and GST work, bookkeeping, audit and payroll are not designated services. So the AML seven-year floor is the retention driver for your AML/KYC records, not a blanket rule for every TFN in your practice. For a practice that does no designated service at all, the AML floor does not apply, and retention is governed by the TFN Rule read together with tax and other record-keeping law. Read: which accounting services are designated? and does becoming a reporting entity trigger the Privacy Act?.

When the floor ends: the ceiling takes over

Once every retention law has run and you no longer need the TFN for a permitted purpose, the Rule's destruction obligation applies. At that point you should securely destroy or de-identify the TFN information rather than let it sit in old files, mailboxes and backups. "We might need it one day" is not a permitted purpose once the legal retention period has passed.

Practical points that follow from this:

Scope, stated honestly

The TFN Rule protects the TFN information of individuals only, not the TFNs of companies, partnerships, trusts or super funds, and not your general (non-TFN) client database. Handling TFNs does not make a small practice a full "APP entity" subject to all 13 Australian Privacy Principles; it creates targeted obligations, including this retention and destruction duty, for the individual TFN data you hold. A breach of the Rule is an "interference with the privacy of an individual", so keeping TFNs indefinitely with no basis is a real exposure to an OAIC complaint, not a technicality. Read: the TFN Rule 2015, what accountants must do.

Penalties here are ceilings, not certainties; most matters resolve without a fine. The point of a retention schedule is not fear of a penalty, it is that holding sensitive TFN data you no longer need is avoidable risk.

Common questions

Is there a set number of years to keep a client's TFN?

No. The TFN Rule does not name a period. You keep TFN information for as long as a law requires you to retain the record and for as long as you still need it for a permitted purpose, then you securely destroy or de-identify it. Any specific number, such as a tax or AML record-keeping period, comes from that other law, not from the TFN Rule.

Does the seven-year AML period apply to every client TFN?

No. The seven-year AML record-keeping floor applies to the AML/KYC data you collect where you provide a designated service and are an AUSTRAC reporting entity. Via Privacy Act s 6E it reaches that AML data only, not your general tax files. If your practice provides no designated service, the AML floor does not apply at all.

Can I just archive old TFNs instead of destroying them?

Once every legal retention period has ended and you no longer need the TFN for a permitted purpose, the Rule expects secure destruction or de-identification, not indefinite archiving. Archiving a TFN "just in case" is not a permitted purpose once the retention floor has passed.

Do I have to delete the TFN from email and backups too?

Reasonable steps to destroy TFN information extends to the copies you hold, which can include email, client portals and backups, not only the primary file. A retention and destruction procedure that accounts for those locations is the practical way to meet the obligation. Read: your data-breach obligations under the NDB scheme.

Keep reading


General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC, or your record-keeping obligations under tax law, which are administered by the ATO. Privaproof's accountant documents are self-authored and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner. The Privacy Act 1988 (Cth), the TFN Rule 2015 and related record-keeping laws change over time, so check you are working from a current version.