Skip to content

Does the Privacy Act apply to accountants under $3 million?

Yes, at least for the tax file numbers you handle. The Privacy (Tax File Number) Rule 2015 binds every "TFN recipient", which the Rule defines as a file number recipient under the Privacy Act, and a practice that holds an individual's tax file number information is one, with no turnover threshold. So a practice turning over less than A$3 million is already inside the Privacy Act for its individual clients' and employees' TFN data, before any anti-money-laundering change applies.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

The small-business exemption is real, but it has a hole

Under section 6D of the Privacy Act 1988 (Cth), a business whose annual turnover for the previous financial year was A$3 million or less is a "small business" (s 6D(1)), and the person who carries it on is a "small business operator" if they carry on no business that is not a small business (s 6D(3)). A small business operator is not an "organisation" under s 6C, so it is not an APP entity and the Australian Privacy Principles (APPs) do not bind it. That is what everyone means by the small-business exemption, and it is why the common assumption runs: under $3m, the Privacy Act does not apply to us.

For a lot of your data, that is broadly right. The hole is the tax file number. The Privacy (Tax File Number) Rule 2015, a legally binding instrument made under s 17 of the Privacy Act, binds every "TFN recipient" regardless of turnover, with no small-business exemption. Because your practice handles individual clients' TFNs every day, the exemption that shelters the rest of your firm does not reach how you handle those TFNs.

Why the TFN Rule catches you no matter your size

The TFN Rule binds any "TFN recipient", and an accounting or bookkeeping practice or a registered tax agent that holds individual clients' TFN information is one. It sets obligations for how you collect, use, disclose, store, secure and destroy individuals' TFN information, and for training the staff who touch it. None of that turns on how much you turn over.

The enforcement point is what makes this concrete: under s 13(4)(a) of the Privacy Act, an act of a file number recipient that breaches a s 17 rule is an "interference with the privacy of an individual", and under s 36(1) an individual may complain to the Commissioner about it. What follows is set by statute rather than by frequency: a determination under s 52(1) can declare the conduct an interference, order steps so it is not repeated, and award compensation to the complainant, and it contains no penalty limb. A fine is a separate track, on which the Commissioner applies to the Federal Court or the Federal Circuit and Family Court for a civil penalty order (ss 13G, 80U). None of this depends on turnover: "entity" in s 13G is defined in s 6(1) to include a small business operator. Read: the TFN Rule 2015, what accountants must do.

What "inside the Privacy Act" does, and does not, mean

This is where the honest scope matters, because it is easy to overstate.

So the accurate answer is not "the whole Privacy Act now applies to you." It is "the Privacy Act already applies to the individual TFN data you handle, and you should treat that data accordingly."

The data-breach scheme reaches your TFN data too

The same logic runs through the Notifiable Data Breaches (NDB) scheme. Under s 26WE(1)(d), the NDB scheme reaches TFN recipients even below A$3 million, confined to eligible breaches involving the TFN information. In plain terms: if TFN data you hold is caught in a breach likely to cause serious harm, you have to assess it and, where the test is met, notify the affected individuals and the OAIC. A sub-$3m practice has no NDB duty for its other, non-TFN personal information unless it is independently an APP entity, but for the TFN data the duty is live now. Read: your data-breach obligations under the NDB scheme.

The separate AML question (status from 31 March 2026)

There is a second way the Privacy Act can reach a small practice, and it is narrower, so keep it distinct from the TFN Rule. From 31 March 2026, AML/CTF Tranche 2 makes a firm an AUSTRAC reporting entity only where it provides a "designated service" (the nine professional-services items are in s 6(5B) of the AML/CTF Act), for example creating or restructuring a body corporate or legal arrangement, acting on the sale or transfer of a body corporate or legal arrangement, holding client money as part of a transaction, or acting as or arranging a nominee director or trustee. The reporting-entity obligations (AML/CTF programs, customer due diligence, reporting and record-keeping) were deferred to 1 July 2026, and s 6(5C) carves several situations out of the client-money item, including money held as payment for the practice's own services. Routine tax returns, financial statements, tax advice, BAS and GST work, bookkeeping, audit and payroll are not designated services.

Where a firm is a reporting entity, Privacy Act s 6E(1A) applies the Act to the activities it carries on for the purposes of, or in connection with, activities relating to the AML/CTF Act, as if it were an organisation. The trigger is scoped to those activities, so the APPs reach the AML/KYC identity data collected for that service, not the practice's general tax, ledger or payroll records. A practice that does only the work listed above provides no designated service and is not a reporting entity at all, so its live obligation is the TFN Rule, not AML. Read: does becoming an AML reporting entity trigger the Privacy Act? and which accounting services are designated?.

One thing to note: a general removal of the A$3 million small-business exemption has been proposed as a future reform, but it is not yet law. Do not act on blog posts that describe a blanket exemption removal from 1 July 2026. What is in force is s 6D as written, with the exits Parliament already put in it (s 6D(4)(a) to (f) and s 6D(9)), alongside the TFN-Rule bind and the s 6E(1A) AML-activity carve-in described above.

So, does it apply to you?

If your practice handles individual clients' or employees' tax file numbers, which is what preparing an individual tax return or running a client's payroll produces, then yes, the Privacy Act already applies to that TFN data, under $3 million and before any AML trigger. The obligation is targeted, not total: it covers individuals' TFNs, not your whole database, and it does not make you a full APP entity. But for the TFN data at the centre of your work, it is real, and it is live today. Read the cornerstone: Privacy Act compliance for accountants and bookkeepers.

Common questions

Is my practice exempt from the Privacy Act because we turn over less than $3 million?

Not for your TFN data. The s 6D small-business exemption may cover much of your practice, but the Privacy (Tax File Number) Rule 2015 binds every TFN recipient regardless of turnover, so your handling of individual clients' and employees' tax file numbers is inside the Privacy Act now.

Does handling TFNs mean I have to comply with all 13 APPs?

No. The TFN Rule creates targeted obligations for individuals' TFN information: how you collect, secure, use, disclose and destroy it, plus staff training. It does not make a small practice a full "APP entity" bound by all 13 Australian Privacy Principles.

What about the AML changes in 2026, do they put me under the Privacy Act?

Only if you provide an AML "designated service", and the nine of those in s 6(5B) of the AML/CTF Act do not include tax returns, financial statements, tax advice, BAS and GST work, bookkeeping, audit or payroll. Those services became designated on 31 March 2026 and the AML obligations that follow started on 1 July 2026. If you are a reporting entity, s 6E(1A) applies the APPs to the activities you carry on for the purposes of, or in connection with, the AML/CTF Act, not to your general tax or payroll work. Where no designated service is provided, the live trigger is the TFN Rule, not AML.

Is the small-business exemption being removed in 2026?

A general removal has been proposed as a future reform, but it is not yet law. The s 6D exemption still stands as written, with the exits Parliament already put in it (s 6D(4)(a) to (f) and s 6D(9)), alongside the TFN-Rule bind and the s 6E(1A) AML-activity carve-in, so treat blanket "exemption removed from 1 July 2026" claims with caution.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC, or under the TPB Code, which is administered by the Tax Practitioners Board. The Privacy Act 1988 (Cth), the TFN Rule 2015 and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.