Skip to content

Do bookkeepers need a privacy policy in Australia?

Not automatically. The duty to have a privacy policy is APP 1.3, and it binds APP entities, so a bookkeeping practice under the A$3 million small-business threshold with no other trigger does not owe one. But if you handle individual clients' or employees' tax file numbers you are a "TFN recipient", and the Privacy (Tax File Number) Rule 2015 binds you regardless of turnover: how you collect a TFN, what you must tell the person when you ask for it, who can see it, when you destroy it, training your staff, and notifying an eligible breach of it. Pure bookkeeping is not, by itself, an AML designated service.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

The short answer, and the reason for it

A bookkeeping practice with an annual turnover of A$3 million or less is a small business under s 6D(1) of the Privacy Act 1988 (Cth) and is generally not an APP entity, so the 13 Australian Privacy Principles do not bind it. Turnover is not the only test. Section 6D(4) also takes a practice outside the exemption if it holds health information, discloses personal information about someone for a benefit or advantage, provides a benefit or advantage to collect it, is a Commonwealth contracted service provider or is a credit reporting body, and s 6EA lets a small business operator opt in. Once turnover has exceeded A$3 million for a completed financial year, s 6D(4)(a) does not switch back off if turnover later falls. For tax file numbers, none of that is the point.

The Privacy (Tax File Number) Rule 2015 is a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth). It binds every "TFN recipient", a category that covers a bookkeeper, accountant or registered tax agent holding individual clients' TFN information. The Rule carries no turnover threshold and no small-business exemption. So the moment you hold a client's or an employee's TFN, you are inside the Privacy Act for that data, whatever your revenue and whether or not you touch any anti-money-laundering work.

Under s 13(4)(a) of the Privacy Act, an act or practice of a file number recipient that breaches a rule issued under s 17 is an "interference with the privacy of an individual", so an affected person can complain to the Information Commissioner without your practice being an APP entity at all. Sound TFN-handling practices are what manage that exposure. A privacy policy answers a separate duty, APP 1.3, which is dealt with below.

What the obligation actually covers (and what it does not)

Being bound by the TFN Rule is narrower than "the whole Privacy Act now applies to everything you do". Keeping the scope honest matters:

So the accurate framing is not "bookkeepers are now fully regulated by the Privacy Act". It is: for the TFN data you handle, real and current obligations apply, and a TFN collection notice plus a TFN-handling procedure is how you meet and evidence them. A published privacy policy is required by APP 1.3, which binds APP entities, so it becomes compulsory only if some other trigger makes your practice one. Read: does the Privacy Act apply to accountants under $3 million?

Why payroll makes this sharper for bookkeepers

Bookkeepers sit on an unusually concentrated pile of TFN data, because payroll runs through them. When you process a business client's payroll, you hold names, TFNs, super details and bank accounts for that client's employees, people who are not your own clients at all. That is third-party TFN data, in volume, in one small practice.

The employee-records exemption does not help you here, and it is worth being precise about why. Section 7B(3) of the Privacy Act exempts an act or practice by "an organisation that is or was an employer of an individual" where it is directly related to that employment relationship and to an employee record the organisation holds. On its terms it protects the employer, not a bookkeeper processing someone else's employees. It is also an exemption from the Australian Privacy Principles, and the TFN Rule binds you by a different route, s 18, which the exemption does not touch. So the individual TFNs in a client's payroll sit inside the TFN Rule for you in the ordinary way, and should be handled with the same care as your own clients' TFN data. Read: bookkeepers and client-employee payroll data

Pure bookkeeping is not an AML designated service

You may have seen a lot of noise about AML/CTF Tranche 2. Two dates are merged in that noise and they are not the same. The professional-services designated services in table 6 commenced on 31 March 2026. Only the obligations, being AML/CTF programs, customer due diligence, reporting and record-keeping, were deferred to 1 July 2026. For a practice doing only bookkeeping, BAS and payroll work both dates are beside the point, and here is why.

From 31 March 2026, a firm becomes an AUSTRAC reporting entity only where it provides a "designated service" (the nine professional-services items are in s 6(5B) of the AML/CTF Act), for example creating or restructuring a body corporate or legal arrangement, acting on a transaction to sell, buy or otherwise transfer a body corporate or legal arrangement, receiving or holding a client's money as part of assisting them with a transaction, or acting as or arranging a nominee director or trustee. The client-money item is cut back further by s 6(5C)(a): money a client pays you for your own services is expressly outside it. Routine bookkeeping, BAS and GST work, and payroll are not designated services. Preparing tax returns, financial statements and tax advice are not either.

So the ordinary work of a bookkeeping practice does not, on its own, make you an AML reporting entity. Even for a firm that does provide a designated service, the reach is limited. Under s 6E of the Privacy Act, where a small business operator is a reporting entity the Act applies "in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to" the AML/CTF Act, as if it were an organisation. That is the AML and customer-due-diligence side of the practice, not your general ledgers, BAS files or payroll records. What decides it is the service you provide, not the profession you are in. Read: which accounting services are designated?

The takeaway: your privacy obligation as a bookkeeper flows from the TFN Rule, not from AML. It applies now, it has no deadline, and it does not depend on any designated service.

What a bookkeeping practice actually needs

For a practice that handles individual clients' or employees' tax file numbers, the working set is driven by the TFN Rule rather than by the Australian Privacy Principles:

A generic policy generator is built around the Australian Privacy Principles, so it will not produce the TFN collection notice, handling procedure, training record or destruction rule the TFN Rule actually asks for, and an "over A$3m or you are exempt" framing does not describe a file number recipient's position. AML software does not give you these either, because it addresses a different obligation entirely.

Common questions

I only do BAS and bookkeeping under $3 million. Am I really caught?

For the individual TFNs you handle, yes. The TFN Rule 2015 binds every TFN recipient regardless of turnover, so the small-business exemption does not switch it off. It does not make your practice an APP entity, so on its own it does not require a published privacy policy. What it does require is a collection notice when you ask for a TFN, controlled use and disclosure, security and restricted access, secure destruction, staff training, and notification of an eligible breach of TFN information.

Does AML Tranche 2 mean bookkeepers now need a privacy policy?

No, not on that basis. Pure bookkeeping, BAS and payroll are not designated services, so ordinary bookkeeping does not make you an AML reporting entity and s 6E of the Privacy Act is not switched on. Your live privacy obligation comes from the TFN Rule, which already applies, has no deadline, and calls for TFN-handling documents rather than an APP privacy policy.

Is a privacy policy the only document I need?

A privacy policy is usually not the first one. For a practice bound by the TFN Rule the working set is a TFN collection notice, a TFN-handling procedure, a staff training record, secure destruction rules and a data-breach response plan, with a published privacy policy on top of those only if a trigger makes you an APP entity.

What about my payroll clients' employees?

You hold their TFNs, super and bank details as a third-party processor. The employee-records exemption in s 7B(3) is written for an organisation "that is or was an employer of an individual", and it operates on the Australian Privacy Principles rather than on the TFN Rule, so it does not shield you. Treat client-employee payroll data as carrying the same TFN Rule obligations as your own clients' TFN data.

Keep reading


General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice, and it does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC. For advice on your specific circumstances, consult a qualified Australian legal practitioner. The Privacy Act 1988 (Cth), the TFN Rule 2015 and related guidance change over time, so check you are working from a current version.