Can an accountant email a client's TFN?
There is no outright ban, but a client's tax file number is not routine email content. The Privacy (Tax File Number) Rule 2015 requires you to protect TFN information and limit how it is disclosed, and TPB guidance flags email as a channel to handle with care. Treat sending a TFN by unencrypted email as a controlled exception, and use a secure client portal or encryption wherever you can.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
Why the TFN Rule reaches your email
The Privacy (Tax File Number) Rule 2015 is a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth), and it binds every "TFN recipient", which covers a practice holding clients' TFN information. It applies regardless of your turnover, so the A$3 million small-business exemption that shelters the rest of your practice does not change how you must handle individual clients' TFNs. Read: the TFN Rule 2015, what accountants must do.
Two of the Rule's obligations bear directly on email. First, you must take reasonable steps to protect TFN information from misuse, loss and unauthorised access. Second, you must limit how you use and disclose that information. Email touches both: an unencrypted message can be intercepted or misdirected, and forwarding a TFN onward is a disclosure. (The Rule's exact internal rule numbers for the security and use/disclosure obligations are ; the effect stated here is what the Rule requires.)
A breach of the Rule is an "interference with the privacy of an individual", which means an affected client can complain to the OAIC. So a TFN that ends up in the wrong inbox is not just an operational slip: it is potential complaint exposure. Framed honestly, that is regulatory and complaint exposure, and most matters resolve without a fine, but it is a real risk you are meant to control.
What "reasonable steps" looks like in practice
The Rule sets a standard, not a script, so what is "reasonable" depends on your practice. In plain terms, most accounting and bookkeeping practices can meet it by defaulting away from plain email for TFNs:
- Prefer a secure channel. A client portal or secure document exchange keeps the TFN off open email entirely. Make it the default way clients send you their details.
- Encrypt if you must email. Where email is genuinely the only option, encrypt the file or the message, and share the password by a separate channel (a phone call or text), not in the same email.
- Do not paste a TFN into the body of a message. Avoid putting the number in a subject line or email body where it sits unencrypted in multiple mailboxes and backups.
- Minimise and mask. Ask whether you need to send the full number at all. Reference the client another way where you can.
- Check the recipient before you send. Misdirected email is one of the most common notifiable-breach causes, so confirm the address and think before you hit forward or reply-all.
- Restrict internal access. Only staff who need a client's TFN should be able to see it, in email or anywhere else.
Storage sits alongside sending: the same "reasonable steps" standard governs where the TFN lives once it arrives. Read: how must accountants store clients' tax file numbers?.
The TPB adds a separate duty
If you are a registered tax agent, you carry a second, separate obligation. Item 6 of the TPB Code of Professional Conduct requires that, absent a legal duty, you must not disclose a client's information to a third party without the client's permission. The Tax Practitioners Board has also published guidance addressing the handling of tax file numbers in email (TPB(PN) 4/2021 .
That duty is enforced by the Tax Practitioners Board and sits alongside, not instead of, the Privacy Act. Meeting one does not automatically meet the other, and the TPB does not administer the Privacy Act or the data-breach scheme; the OAIC does. Read: TPB Code confidentiality vs the Privacy Act.
If a TFN does go to the wrong person
Treat a misdirected or intercepted TFN as a possible eligible data breach. Under the Notifiable Data Breaches scheme, a breach involving TFN information reaches your practice even below A$3 million, so you need to assess whether it is likely to cause serious harm and, if so, notify the affected individuals and the OAIC. Having a plan ready before it happens is the point. Read: your data-breach obligations under the NDB scheme.
Common questions
Is it illegal to email a client's TFN?
No, there is no outright prohibition. But the TFN Rule 2015 requires you to protect TFN information and limit its disclosure, so unencrypted email of a TFN is a risk you are expected to control, not a routine default. Prefer a secure portal or encryption.
Can I put a client's TFN in the email body or subject line?
Best avoided. In the body or subject line the number sits unencrypted across multiple mailboxes and backups. If you must send it by email, put it in an encrypted attachment and share the password by a separate channel.
Does the under-$3m small-business exemption mean this does not apply to me?
No. The TFN Rule binds every TFN recipient with no turnover threshold, so how you handle individual clients' TFNs is covered even if the rest of your practice sits under the exemption. Read: does the Privacy Act apply to accountants under $3 million?.
What if I accidentally email a TFN to the wrong client?
Treat it as a potential notifiable data breach: assess the likely harm, contain it, and if a serious-harm breach involving TFN information is likely, notify the affected individual and the OAIC under the NDB scheme.
This is general information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the TPB Code, which are administered by the Tax Practitioners Board, or under the AML/CTF Act, which is administered by AUSTRAC. Privaproof's accountant documents are self-authored and are not independently reviewed by a solicitor. The Privacy Act 1988 (Cth), the TFN Rule 2015 and related guidance change over time, so check you are working from a current version. See the accountants and bookkeepers privacy hub.