Skip to content

Does the Privacy Act apply to accountants under $3 million?

Yes, at least for the tax file numbers you handle. The Privacy (Tax File Number) Rule 2015 binds every TFN recipient, including accountants, bookkeepers and registered tax agents, with no turnover threshold. So a practice turning over less than A$3 million is already inside the Privacy Act for its individual clients' and employees' TFN data, before any anti-money-laundering change applies.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

The small-business exemption is real, but it has a hole

Under section 6D of the Privacy Act 1988 (Cth), a business with annual turnover of A$3 million or less is generally a "small business operator" and is exempt from the Act and the Australian Privacy Principles (APPs). Most accounting and bookkeeping practices sit under that threshold, so the common assumption is: under $3m, the Privacy Act does not apply to us.

For a lot of your data, that is broadly right. The hole is the tax file number. The Privacy (Tax File Number) Rule 2015, a legally binding instrument made under s 17 of the Privacy Act, binds every "TFN recipient" regardless of turnover, with no small-business exemption. Because your practice handles individual clients' TFNs every day, the exemption that shelters the rest of your firm does not reach how you handle those TFNs.

Why the TFN Rule catches you no matter your size

The TFN Rule binds any "TFN recipient", and an accounting or bookkeeping practice or a registered tax agent that holds clients' TFN information is one. It sets obligations for how you collect, use, disclose, store, secure and destroy individuals' TFN information, and for training the staff who touch it. None of that turns on how much you turn over.

The enforcement point is what makes this concrete: a breach of the TFN Rule is an "interference with the privacy of an individual" under the Privacy Act, so an affected person can lodge a complaint with the OAIC. Penalties are ceilings, not certainties, and most matters resolve without a fine, but the exposure to a complaint is real and it applies to a sub-$3m practice. Read: the TFN Rule 2015, what accountants must do.

What "inside the Privacy Act" does, and does not, mean

This is where the honest scope matters, because it is easy to overstate.

So the accurate answer is not "the whole Privacy Act now applies to you." It is "the Privacy Act already applies to the individual TFN data you handle, and you should treat that data accordingly."

The data-breach scheme reaches your TFN data too

The same logic runs through the Notifiable Data Breaches (NDB) scheme. Under s 26WE(1)(d), the NDB scheme reaches TFN recipients even below A$3 million, confined to eligible breaches involving the TFN information. In plain terms: if TFN data you hold is caught in a breach likely to cause serious harm, you have to assess it and, where the test is met, notify the affected individuals and the OAIC. A sub-$3m practice has no NDB duty for its other, non-TFN personal information unless it is independently an APP entity, but for the TFN data the duty is live now. Read: your data-breach obligations under the NDB scheme.

The separate AML question (from 1 July 2026)

There is a second way the Privacy Act can reach a small practice, and it is narrower, so keep it distinct from the TFN Rule. From 1 July 2026, AML/CTF Tranche 2 makes a firm an AUSTRAC reporting entity only where it provides a "designated service", for example forming or restructuring companies and trusts, holding or disbursing client money, arranging finance, or acting as or arranging a nominee director or trustee. Routine tax returns, financial statements, tax advice, BAS and GST work, bookkeeping, audit and payroll are not designated services.

Where a firm is a reporting entity, Privacy Act s 6E treats it as an organisation for its AML activities, so the APPs reach the AML/KYC identity data it collects for that service, not its general tax, ledger or payroll records. Most practices provide no designated service and are not reporting entities at all, so for most accountants the live obligation is the TFN Rule, not AML. Read: does becoming an AML reporting entity trigger the Privacy Act? and which accounting services are designated?.

One thing to note: a general removal of the A$3 million small-business exemption has been proposed as a future reform, but it is not yet law. Do not act on blog posts that describe a blanket exemption removal from 1 July 2026. Only the current TFN-Rule bind and the s 6E AML-data carve-in are in force.

So, does it apply to you?

If your practice handles individual clients' or employees' tax file numbers, and almost every accounting and bookkeeping practice does, then yes, the Privacy Act already applies to that TFN data, under $3 million and before any AML trigger. The obligation is targeted, not total: it covers individuals' TFNs, not your whole database, and it does not make you a full APP entity. But for the TFN data at the centre of your work, it is real, and it is live today. Read the cornerstone: Privacy Act compliance for accountants and bookkeepers.

Common questions

Is my practice exempt from the Privacy Act because we turn over less than $3 million?

Not for your TFN data. The s 6D small-business exemption may cover much of your practice, but the Privacy (Tax File Number) Rule 2015 binds every TFN recipient regardless of turnover, so your handling of individual clients' and employees' tax file numbers is inside the Privacy Act now.

Does handling TFNs mean I have to comply with all 13 APPs?

No. The TFN Rule creates targeted obligations for individuals' TFN information: how you collect, secure, use, disclose and destroy it, plus staff training. It does not make a small practice a full "APP entity" bound by all 13 Australian Privacy Principles.

What about the AML changes from 1 July 2026, do they put me under the Privacy Act?

Only if you provide an AML "designated service", which most routine accounting and bookkeeping work is not. If you are a reporting entity, s 6E applies the APPs to the AML/KYC data you collect for that service, not to your general tax or payroll files. For most practices, the live trigger is the TFN Rule, not AML.

Is the small-business exemption being removed in 2026?

A general removal has been proposed as a future reform, but it is not yet law. Only the TFN-Rule bind and the s 6E AML-data carve-in are currently in force, so treat blanket "exemption removed from 1 July 2026" claims with caution.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Privaproof's accountant documents are self-authored and are not independently reviewed by a solicitor. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC, or under the TPB Code, which is administered by the Tax Practitioners Board. The Privacy Act 1988 (Cth), the TFN Rule 2015 and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.