Skip to content

Bookkeepers and client-employee payroll data: your privacy exposure

When you run a business client's payroll, you hold tax file numbers, superannuation and bank details for that client's employees, people who are not your own clients. The Privacy (Tax File Number) Rule 2015 binds you for those employees' TFN information regardless of your turnover, which makes payroll one of a bookkeeper's sharpest privacy exposures. This is a Privacy Act question, not an anti-money-laundering one: pure payroll and bookkeeping are not AML designated services.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

Why payroll is different from the rest of your work

Most of the personal information a small bookkeeping practice holds relates to its own clients: the business owners you are engaged by. Payroll breaks that pattern. To run a client's payroll you collect and hold a full set of sensitive details for that client's employees, third parties you may never deal with directly:

You are handling the identity and financial data of a whole workforce, concentrated in one small practice, for people who never chose you and often do not know you hold it. That concentration is exactly what makes a payroll breach serious, and a complaint concrete.

The TFN Rule binds you for those employees' TFNs

The Privacy (Tax File Number) Rule 2015, a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth), binds every "TFN recipient", which covers a bookkeeper holding clients' TFN information. It applies with no turnover threshold, so the A$3 million small-business exemption that shelters most of your practice does not switch off your obligations for the TFN information you handle. The Rule does not distinguish between a client's TFN and a client-employee's TFN: an individual TFN is an individual TFN, and once you hold it, the Rule's obligations apply.

Those obligations cover how you collect, use, disclose, store, secure and destroy individuals' TFN information, and how you train staff who touch it. A breach of the Rule is an "interference with the privacy of an individual", which means an affected person, including an employee whose payroll you process, can complain to the OAIC. Read: the TFN Rule 2015, what accountants must do.

Scope, stated honestly. The TFN Rule creates targeted obligations for the individual TFN information you hold. It does not make a small bookkeeping practice a full "APP entity" subject to all 13 Australian Privacy Principles, and it protects the TFNs of individuals only, not of companies, partnerships, trusts or super funds. Payroll simply happens to be a place where you hold a large volume of the individual TFN data the Rule does cover.

The employee-records exemption: a trap, not a shield

There is a common assumption that employee payroll is covered by the Privacy Act's employee-records exemption, so you can relax. Be careful here.

The employee-records exemption is written for an employer's handling of its own current or former employees' records. When you run payroll for a business client, you are not that employer: you are a third party processing another organisation's employee records under contract. **Whether the exemption reaches a bookkeeper or accountant acting as a third-party processor of a client's employee records is unresolved. * Australian guidance on the point is thin, so do not build your handling of payroll data on the assumption that the exemption shields you.

Two things do not depend on that unresolved question, and they are the safer ground to stand on:

This is a privacy question, not an AML one

It is worth being precise, because AML software vendors are loud in this space and it is easy to think payroll pulls you into anti-money-laundering territory. It does not. Preparing tax returns, financial statements, tax advice, BAS and GST work, bookkeeping, audit and payroll are not "designated services" under AML/CTF Tranche 2. Running a client's payroll does not make you an AUSTRAC reporting entity, and it does not trigger the Privacy Act s 6E bridge that applies to firms providing designated services. Read: which accounting services are designated?.

So your payroll exposure is not an AML gap you can close by buying an AML kit. It is a Privacy Act obligation, driven by the TFN Rule and the data breach scheme, that sits with you regardless of whether you ever touch a designated service.

What a payroll bookkeeper actually needs

The AML platforms do not give you any of this, because payroll is not their patch. Generic free templates rarely mention client-employee payroll at all, and often carry the outdated "over A$3m or you are exempt" framing that is wrong for TFN recipients.

Common questions

Does the $3 million small-business exemption cover my payroll clients' data?

Not for the TFN information. The Privacy (Tax File Number) Rule 2015 binds every TFN recipient with no turnover threshold, so your obligations for the employee TFNs you process apply even if your practice turns over well under A$3 million.

Are client-employee payroll records covered by the employee-records exemption?

Whether that exemption reaches a bookkeeper processing another business's employee records as a third party is unresolved. The exemption is written for an employer handling its own employee records, and you are not that employer. Do not rely on it to switch off your handling of that data.

Does running payroll make me an AML reporting entity?

No. Payroll, bookkeeping, BAS work and tax preparation are not designated services under AML/CTF Tranche 2, so payroll alone does not make you an AUSTRAC reporting entity or trigger the Privacy Act s 6E bridge.

What if a payroll file is breached?

An eligible data breach involving employee TFN information falls within the Notifiable Data Breaches scheme, which reaches TFN recipients under s 26WE(1)(d) even below A$3 million. You would need to assess it and, where the threshold is met, notify affected individuals and the OAIC.

Keep reading


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Privaproof's accountant documents are self-authored and are not independently reviewed by a solicitor. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC, or under the TPB Code of Professional Conduct, which is administered by the Tax Practitioners Board. The Privacy Act 1988 (Cth), the TFN Rule 2015 and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.