Bookkeepers and client-employee payroll data: your privacy exposure
When you run a business client's payroll, you hold tax file numbers, superannuation and bank details for that client's employees, people who are not your own clients. The Privacy (Tax File Number) Rule 2015 binds you for those employees' TFN information regardless of your turnover, which makes payroll one of a bookkeeper's sharpest privacy exposures. This is a Privacy Act question, not an anti-money-laundering one: pure payroll and bookkeeping are not AML designated services.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
Why payroll is different from the rest of your work
Most of the personal information a small bookkeeping practice holds relates to its own clients: the business owners you are engaged by. Payroll breaks that pattern. To run a client's payroll you collect and hold a full set of sensitive details for that client's employees, third parties you may never deal with directly:
- Tax file numbers for each employee.
- Bank and BSB details for wage payments.
- Superannuation fund and member details.
- Names, addresses, dates of birth, and often salary and leave records.
You are handling the identity and financial data of a whole workforce, concentrated in one small practice, for people who never chose you and often do not know you hold it. That concentration is exactly what makes a payroll breach serious, and a complaint concrete.
The TFN Rule binds you for those employees' TFNs
The Privacy (Tax File Number) Rule 2015, a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth), binds every "TFN recipient", which covers a bookkeeper holding clients' TFN information. It applies with no turnover threshold, so the A$3 million small-business exemption that shelters most of your practice does not switch off your obligations for the TFN information you handle. The Rule does not distinguish between a client's TFN and a client-employee's TFN: an individual TFN is an individual TFN, and once you hold it, the Rule's obligations apply.
Those obligations cover how you collect, use, disclose, store, secure and destroy individuals' TFN information, and how you train staff who touch it. A breach of the Rule is an "interference with the privacy of an individual", which means an affected person, including an employee whose payroll you process, can complain to the OAIC. Read: the TFN Rule 2015, what accountants must do.
Scope, stated honestly. The TFN Rule creates targeted obligations for the individual TFN information you hold. It does not make a small bookkeeping practice a full "APP entity" subject to all 13 Australian Privacy Principles, and it protects the TFNs of individuals only, not of companies, partnerships, trusts or super funds. Payroll simply happens to be a place where you hold a large volume of the individual TFN data the Rule does cover.
The employee-records exemption: a trap, not a shield
There is a common assumption that employee payroll is covered by the Privacy Act's employee-records exemption, so you can relax. Be careful here.
The employee-records exemption is written for an employer's handling of its own current or former employees' records. When you run payroll for a business client, you are not that employer: you are a third party processing another organisation's employee records under contract. **Whether the exemption reaches a bookkeeper or accountant acting as a third-party processor of a client's employee records is unresolved. * Australian guidance on the point is thin, so do not build your handling of payroll data on the assumption that the exemption shields you.
Two things do not depend on that unresolved question, and they are the safer ground to stand on:
- The TFN Rule binds you for the employees' TFN information whatever the answer on the exemption, because it turns on you being a TFN recipient, not on whose employees they are.
- Treating this concentrated identity and financial dataset carefully, as though it is in scope, is the low-regret position: it costs little and removes the risk of guessing wrong on an unsettled point.
This is a privacy question, not an AML one
It is worth being precise, because AML software vendors are loud in this space and it is easy to think payroll pulls you into anti-money-laundering territory. It does not. Preparing tax returns, financial statements, tax advice, BAS and GST work, bookkeeping, audit and payroll are not "designated services" under AML/CTF Tranche 2. Running a client's payroll does not make you an AUSTRAC reporting entity, and it does not trigger the Privacy Act s 6E bridge that applies to firms providing designated services. Read: which accounting services are designated?.
So your payroll exposure is not an AML gap you can close by buying an AML kit. It is a Privacy Act obligation, driven by the TFN Rule and the data breach scheme, that sits with you regardless of whether you ever touch a designated service.
What a payroll bookkeeper actually needs
- A privacy policy (APP 1) written for a bookkeeping practice, that reflects the client-employee payroll data you actually hold, not a generic fill-in-the-blanks template.
- A collection notice (APP 5) for the points where employee details enter your systems, so people are told what you collect and why.
- A TFN-handling policy that meets the specific obligations of the TFN Rule for the employee TFNs you process.
- A data breach response plan for the Notifiable Data Breaches scheme. Under s 26WE(1)(d) the NDB scheme reaches TFN recipients even below A$3 million, confined to eligible breaches involving TFN information, so a payroll breach that exposes employee TFNs is squarely the kind of event you must be ready to assess and, where required, notify to affected people and the OAIC. Read: your data-breach obligations under the NDB scheme.
- Secure storage and transfer practices for the payroll files themselves, including how you send payslips and payroll data. Read: how must accountants store clients' tax file numbers?.
The AML platforms do not give you any of this, because payroll is not their patch. Generic free templates rarely mention client-employee payroll at all, and often carry the outdated "over A$3m or you are exempt" framing that is wrong for TFN recipients.
Common questions
Does the $3 million small-business exemption cover my payroll clients' data?
Not for the TFN information. The Privacy (Tax File Number) Rule 2015 binds every TFN recipient with no turnover threshold, so your obligations for the employee TFNs you process apply even if your practice turns over well under A$3 million.
Are client-employee payroll records covered by the employee-records exemption?
Whether that exemption reaches a bookkeeper processing another business's employee records as a third party is unresolved. The exemption is written for an employer handling its own employee records, and you are not that employer. Do not rely on it to switch off your handling of that data.
Does running payroll make me an AML reporting entity?
No. Payroll, bookkeeping, BAS work and tax preparation are not designated services under AML/CTF Tranche 2, so payroll alone does not make you an AUSTRAC reporting entity or trigger the Privacy Act s 6E bridge.
What if a payroll file is breached?
An eligible data breach involving employee TFN information falls within the Notifiable Data Breaches scheme, which reaches TFN recipients under s 26WE(1)(d) even below A$3 million. You would need to assess it and, where the threshold is met, notify affected individuals and the OAIC.
Keep reading
- Do bookkeepers need a privacy policy in Australia?
- The Privacy (Tax File Number) Rule 2015: what accountants must do
- How must accountants store clients' tax file numbers?
- Data-breach obligations for accountants handling TFNs
- Back to: Privacy Act compliance for accountants and bookkeepers
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Privaproof's accountant documents are self-authored and are not independently reviewed by a solicitor. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC, or under the TPB Code of Professional Conduct, which is administered by the Tax Practitioners Board. The Privacy Act 1988 (Cth), the TFN Rule 2015 and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.