Skip to content

Can an accountant email a client's TFN?

There is no outright ban, but a client's tax file number is not routine email content. The Privacy (Tax File Number) Rule 2015 requires you to protect TFN information and limit how it is disclosed, and the Tax Practitioners Board states in TPB(GS) 36/2021 that email is, in itself, not considered to be a secure form of communication. Treat sending a TFN by unencrypted email as a controlled exception, and use a secure client portal or encryption wherever you can.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

Why the TFN Rule reaches your email

The Privacy (Tax File Number) Rule 2015 is a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth), and it binds every "TFN recipient", which covers a practice holding individual clients' TFN information. It applies regardless of your turnover, so even where the A$3 million small-business exemption covers the rest of your practice, it does not change how you must handle individual clients' TFNs. Read: the TFN Rule 2015, what accountants must do.

Two of the Rule's obligations bear directly on email. First, r 11(1) requires reasonable steps to protect TFN information from misuse, loss and unauthorised access, and to restrict access to those who need it. Second, r 10 limits how you may use and disclose it. Email touches both: an unencrypted message can be intercepted or misdirected, and forwarding a TFN onward is a disclosure.

A breach of the Rule is an "interference with the privacy of an individual" under s 13(4)(a) of the Privacy Act, which means an affected client can complain to the OAIC. So a TFN that ends up in the wrong inbox is not just an operational slip: it is potential complaint exposure. Framed honestly, that is regulatory and complaint exposure rather than an automatic penalty, because under s 52(1) a Commissioner determination can declare the conduct an interference, order steps to stop it recurring and award compensation for loss or damage, but it cannot impose a fine; a pecuniary penalty has to be sought from the Federal Court. It is still a real risk you are meant to control.

What "reasonable steps" looks like in practice

The Rule sets a standard, not a script, so what is "reasonable" depends on your practice. In plain terms, most accounting and bookkeeping practices can meet it by defaulting away from plain email for TFNs:

Storage sits alongside sending: the same "reasonable steps" standard governs where the TFN lives once it arrives. Read: how must accountants store clients' tax file numbers?.

The TPB adds a separate duty

If you are a registered tax agent, you carry a second, separate obligation. Item 6 of the TPB Code of Professional Conduct requires that, absent a legal duty, you must not disclose a client's information to a third party without the client's permission. That duty sits in s 30-10(6) of the Tax Agent Services Act 2009 (Cth), and it is enforced by the Tax Practitioners Board.

That duty is enforced by the Tax Practitioners Board and sits alongside, not instead of, the Privacy Act. Meeting one does not automatically meet the other, and the TPB does not administer the Privacy Act or the data-breach scheme; the OAIC does. Read: TPB Code confidentiality vs the Privacy Act.

If a TFN does go to the wrong person

Treat a misdirected or intercepted TFN as a possible eligible data breach. Under s 26WE(1)(d) of the Notifiable Data Breaches scheme, a breach involving TFN information reaches your practice even below A$3 million, so you need to assess whether it is likely to cause serious harm and, if so, notify the affected individuals and the OAIC. That limb is TFN-specific: the scheme reaches the rest of your client data only where some other trigger makes your practice an APP entity. Having a plan ready before it happens is the point. Read: your data-breach obligations under the NDB scheme.

Common questions

Is it illegal to email a client's TFN?

No, no provision bans email as a channel, and the TPB says so directly in TPB(GS) 36/2021: including a client's TFN in an email "does not, on its own and without further information, necessarily give rise to a breach of a law regulating the use and disclosure of TFNs". Two limits still apply. The TFN Rule 2015 requires you to protect TFN information (r 11(1)) and limits its use and disclosure (r 10), so unencrypted email of a TFN is a risk you are expected to control, not a routine default. Separately, s 8WB of the Taxation Administration Act 1953 makes it an offence to divulge or communicate another person's TFN to a third person, carrying 100 penalty units or imprisonment for 2 years, or both, but s 8WB(1A)(c) excepts a person acting on the other person's behalf in the conduct of their affairs, which is the ordinary position when you act for your client. Prefer a secure portal or encryption.

Can I put a client's TFN in the email body or subject line?

Best avoided. In the body or subject line the number sits unencrypted across multiple mailboxes and backups. If you must send it by email, put it in an encrypted attachment and share the password by a separate channel.

Does the under-$3m small-business exemption mean this does not apply to me?

No. The TFN Rule binds every TFN recipient with no turnover threshold, so how you handle individual clients' TFNs is covered even if the rest of your practice sits under the exemption. Read: does the Privacy Act apply to accountants under $3 million?.

What if I accidentally email a TFN to the wrong client?

Treat it as a potential notifiable data breach: assess the likely harm, contain it, and if a serious-harm breach involving TFN information is likely, notify the affected individual and the OAIC under the NDB scheme.


This is general information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the TPB Code, which are administered by the Tax Practitioners Board, or under the AML/CTF Act, which is administered by AUSTRAC. The Privacy Act 1988 (Cth), the TFN Rule 2015 and related guidance change over time, so check you are working from a current version. See the accountants and bookkeepers privacy hub.