Do bookkeepers need a privacy policy in Australia?
If your bookkeeping practice handles individual clients' or employees' tax file numbers, then in substance yes. The Privacy (Tax File Number) Rule 2015 binds every "TFN recipient" regardless of turnover, so even a small BAS-only or payroll-only practice under A$3 million has real obligations to secure and document how it handles that TFN data. Pure bookkeeping is not, by itself, an AML designated service.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
The short answer, and the reason for it
Most bookkeepers assume the A$3 million small-business exemption in the Privacy Act covers them. For the general run of their records, it often does. For tax file numbers, it does not.
The Privacy (Tax File Number) Rule 2015 is a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth). It binds every "TFN recipient", a category that covers a bookkeeper, accountant or registered tax agent holding clients' TFN information. The Rule carries no turnover threshold and no small-business exemption. So the moment you hold a client's or an employee's TFN, you are inside the Privacy Act for that data, whatever your revenue and whether or not you touch any anti-money-laundering work.
A breach of the Rule is treated as an "interference with the privacy of an individual", which means an affected person can complain to the OAIC. That is the exposure a privacy policy and sound TFN-handling practices are there to manage.
What the obligation actually covers (and what it does not)
Being bound by the TFN Rule is narrower than "the whole Privacy Act now applies to everything you do". Keeping the scope honest matters:
- It reaches individuals' TFN information only. The Rule protects the TFNs of individual people, your individual clients and the employees whose payroll you process. It does not reach the TFNs of companies, partnerships, trusts or super funds, and it does not automatically pull your general (non-TFN) client database under the Act.
- It does not make you a full "APP entity". Handling TFNs does not, on its own, subject a small practice to all 13 Australian Privacy Principles. The TFN Rule creates targeted obligations for the TFN data you hold: collecting it lawfully, limiting its use and disclosure, securing it, destroying it when you are no longer required to keep it, and training your staff.
So the accurate framing is not "bookkeepers are now fully regulated by the Privacy Act". It is: for the TFN data you handle, real and current obligations apply, and a privacy policy plus a TFN-handling policy is how you meet and evidence them. Read: does the Privacy Act apply to accountants under $3 million?
Why payroll makes this sharper for bookkeepers
Bookkeepers sit on an unusually concentrated pile of TFN data, because payroll runs through them. When you process a business client's payroll, you hold names, TFNs, super details and bank accounts for that client's employees, people who are not your own clients at all. That is third-party TFN data, in volume, in one small practice.
There is a genuine open question here, and it is worth stating plainly rather than glossing. The Privacy Act's employee-records exemption is designed to exempt an employer's handling of its own employees' records. Whether it also shields a bookkeeper who processes a client's employees' payroll as a third-party processor is unsettled. Because the position is unresolved, the safe course is to handle client-employee payroll data as if it needs care, not to assume an exemption removes the risk. Read: bookkeepers and client-employee payroll data
Pure bookkeeping is not an AML designated service
You may have seen a lot of noise about AML/CTF Tranche 2 arriving on 1 July 2026. It is real, but for most bookkeepers it is beside the point, so here is the accurate version.
From 1 July 2026, a firm becomes an AUSTRAC reporting entity only where it provides a "designated service", for example forming or restructuring companies and trusts, holding or disbursing client money, arranging finance, or acting as or arranging a nominee director or trustee. Routine bookkeeping, BAS and GST work, and payroll are not designated services. Preparing tax returns, financial statements and tax advice are not either.
So the ordinary work of a bookkeeping practice does not, on its own, make you an AML reporting entity. Even for a firm that does provide a designated service, AML only reaches the AML/KYC identity data: Privacy Act s 6E switches the Privacy Act on for the information collected for that service, not for your general ledgers, BAS files or payroll records. The line is advice-out, execution-in. Read: which accounting services are designated?
The takeaway: your privacy obligation as a bookkeeper flows from the TFN Rule, not from AML. It applies now, it has no deadline, and it does not depend on any designated service.
What a bookkeeping practice actually needs
A privacy policy is the headline document, but it rarely stands alone. For a practice that handles TFNs, the practical set is:
1. A privacy policy written for a bookkeeping practice, not a generic fill-in-the-blanks template. 2. A TFN-handling policy that meets the specific collection, use, disclosure, security and destruction obligations of the TFN Rule 2015. 3. Collection notices for the points where you take client and employee details. 4. A data-breach response plan, because the Notifiable Data Breaches scheme reaches TFN recipients even below A$3 million for eligible breaches involving TFN information. Read: data-breach obligations for accountants handling TFNs 5. Retention and destruction procedures that reconcile record-keeping requirements with the "destroy when no longer needed" principle.
Free generic policy generators usually are not written for a bookkeeping practice, and many still carry the outdated "over A$3m or you are exempt" framing, which is wrong for TFN recipients. AML software does not give you these either, because it addresses a different obligation entirely.
Common questions
I only do BAS and bookkeeping under $3 million. Am I really caught?
For the TFNs you handle, yes. The TFN Rule 2015 binds every TFN recipient regardless of turnover, so the small-business exemption does not switch it off. It does not make your whole practice a full APP entity, but it does mean a privacy policy and TFN-handling practices are expected for the TFN data you hold.
Does AML Tranche 2 mean bookkeepers now need a privacy policy?
No, not on that basis. Pure bookkeeping, BAS and payroll are not designated services, so ordinary bookkeeping does not make you an AML reporting entity. Your privacy obligation comes from the TFN Rule, which already applies and has no deadline.
Is a privacy policy the only document I need?
No. It is the headline, but you generally also need a TFN-handling policy, collection notices and a data-breach response plan for the concentrated TFN and financial data a bookkeeping practice holds.
What about my payroll clients' employees?
You hold their TFNs, super and bank details as a third-party processor. Whether the employee-records exemption shields that arrangement is unsettled , so the prudent approach is to treat client-employee payroll data as requiring the same care as your own clients' TFN data.
Keep reading
- Privacy Act compliance for accountants and bookkeepers
- Does the Privacy Act apply to accountants under $3 million?
- The Privacy (Tax File Number) Rule 2015: what accountants must do
- Bookkeepers and client-employee payroll data
- AML Tranche 2 for accountants: which services are designated?
General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice, and it does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC. Privaproof's accountant and bookkeeper documents are self-authored and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner. The Privacy Act 1988 (Cth), the TFN Rule 2015 and related guidance change over time, so check you are working from a current version.