How must accountants store clients' tax file numbers?
You must take reasonable steps to protect clients' tax file numbers from misuse, loss and unauthorised access. That means restricting TFN access to staff who need it, keeping the data secure in transit and at rest, and securely destroying or de-identifying it once you are no longer required by law to retain it. This duty comes from the Privacy (Tax File Number) Rule 2015 and applies even under the A$3 million small-business threshold.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
Where the obligation comes from
The Privacy (Tax File Number) Rule 2015 is a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth). It binds every "TFN recipient", a category that covers a practice holding clients' TFN information, with no turnover threshold and no small-business exemption. So the security obligations below apply to how you handle individual clients' (and individual employees') TFNs regardless of your firm's size, even where the A$3 million exemption otherwise shelters the rest of your practice.
The Rule requires you to take reasonable steps to protect TFN information and to securely dispose of it when it is no longer needed. (The exact rule numbers within the instrument for the security and disposal obligations are not pinned here. .) What "reasonable" means scales with your circumstances: a two-person bookkeeping practice and a twenty-partner firm will not do identical things, but both must be able to show they thought it through.
Scope, stated honestly: the Rule protects the TFN information of individuals only, not the TFNs of companies, partnerships, trusts or super funds, and not your general (non-TFN) client database. Handling TFNs does not make a small practice a full "APP entity" subject to all 13 Australian Privacy Principles. It creates targeted obligations for the individual TFN data you hold.
What "reasonable steps" looks like in a practice
There is no official checklist you can tick and be done, but the following measures are the sort of thing a small accounting or bookkeeping practice can reasonably be expected to have in place:
- Restrict access to staff who need it. Only the people who actually work on a client's file should be able to see that client's TFN. Role-based access in your practice software, rather than a shared login everyone uses, is the practical version of this.
- Secure the data at rest. Keep TFNs in access-controlled systems, not in loose spreadsheets, email folders or on unencrypted laptops and USB drives. Where your software offers encryption, use it.
- Secure the data in transit. Take care when sending TFNs anywhere. Unencrypted email of a client's TFN is a risk to control, not a routine default. See Can an accountant email a client's TFN?.
- Use a secure client portal for collecting and returning documents that contain TFNs, rather than ordinary email attachments, where you can.
- Train your staff. The TFN Rule expects the people who handle TFNs to understand their obligations. A short, documented induction and refresher is reasonable and cheap.
- Control your service providers. If TFN data sits with a cloud accounting platform, a payroll bureau or an outsourced processor, your reasonable steps extend to how they hold it.
- Keep it minimal. Do not collect or copy TFNs you do not need, and do not keep them after you are lawfully allowed to let them go (see below).
None of these is exotic. The point of the Rule is that you can show you took deliberate, sensible steps rather than leaving individual TFNs lying around in whatever system was convenient.
Only keep TFNs as long as you must, then destroy them
The TFN Rule requires you to securely destroy or de-identify TFN information once you are no longer required by law to retain it. That is the tension worth planning for: your firm has various record-keeping obligations, and where you provide AML designated services the AML/CTF Act sets a seven-year record-keeping floor for the AML/KYC data caught by that regime. Those retention duties are a lawful basis to keep the relevant records, but they are not a licence to keep every copy of every TFN forever.
The workable answer is a written retention and destruction schedule: identify what you must keep and for how long, then securely destroy or de-identify the rest, including stray copies in email and downloads. See How long can an accountant keep a client's TFN?.
What happens if TFN data is breached
Storing TFNs securely is also how you stay clear of the breach-notification duty. Under s 26WE(1)(d) the Notifiable Data Breaches scheme reaches TFN recipients even below A$3 million turnover, confined to eligible breaches involving the TFN information. So if TFNs you hold are lost or exposed in a way likely to cause serious harm, you may have to assess the breach and notify affected individuals and the OAIC.
Separately, a breach of the TFN Rule itself is an "interference with the privacy of an individual", which means an affected person can complain to the OAIC. Enforcement here is best understood as complaint and regulatory exposure; most matters resolve without a fine. A short, ready-to-run breach plan is what turns a bad day into a managed one. See Data breach obligations for accountants handling TFNs.
Common questions
Do I have to encrypt tax file numbers?
The Rule does not name specific technologies; it requires reasonable steps to protect TFN information from misuse, loss and unauthorised access. Encryption of data at rest and in transit is one of the clearest ways to show you took those steps, so where your systems offer it, using it is sensible. What is "reasonable" scales with the size and nature of your practice.
Can I keep clients' TFNs in a spreadsheet?
You can hold TFNs in whatever system lets you meet the Rule, but a loose, widely-shared spreadsheet is hard to defend: access is not restricted to who needs it, it is easy to copy and email, and it is easy to forget when destruction time comes. Access-controlled practice software is a much safer home for individual TFNs.
Does this apply to my practice if we turn over under $3 million?
Yes, for the TFNs you handle. The TFN Rule binds every TFN recipient with no turnover threshold, so the A$3 million small-business exemption does not switch off your TFN-security obligations even though it may shelter other parts of your practice. See Does the Privacy Act apply to accountants under $3 million?.
What about tax file numbers in payroll I run for a client's staff?
When you process a business client's payroll you hold TFNs for that client's employees, who are not your own clients. Handle those TFNs to the same standard. Whether the Privacy Act employee-records exemption reaches a third-party processor in this situation is unsettled, so do not rely on it either way. See Bookkeepers and client-employee payroll data.
Keep reading
- The Privacy (Tax File Number) Rule 2015: what accountants must do
- Can an accountant email a client's TFN?
- How long can an accountant keep a client's TFN?
- Data breach obligations for accountants handling TFNs
- Privacy Act compliance for accountants and bookkeepers
General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. Privaproof's accountant documents are self-authored and are not independently reviewed by a solicitor. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC, or under the TPB Code, which is administered by the Tax Practitioners Board. The Privacy Act 1988 (Cth), the TFN Rule 2015 and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.