How must accountants store clients' tax file numbers?
You must take reasonable steps to protect individual clients' tax file numbers from misuse and loss, and from unauthorised access, use, modification or disclosure, and to restrict access to records containing them to staff who need to handle them (r 11(1)). You must securely destroy or permanently de-identify TFN information once it is neither required by law to be retained nor still necessary for a tax, superannuation or personal assistance purpose (r 11(2)). Those duties come from the Privacy (Tax File Number) Rule 2015 and apply even under the A$3 million small-business threshold. Specific measures such as encryption are how practices meet the standard, not requirements the Rule names.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
Where the obligation comes from
The Privacy (Tax File Number) Rule 2015 is a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth). It binds every "TFN recipient", which takes its meaning from "file number recipient" in the Privacy Act (r 6(2)): anyone in possession or control of a record containing tax file number information (s 11(1)), who must not breach a rule issued under s 17 (s 18). That test has no turnover threshold and no small-business exemption, so the security obligations below apply to how you handle individual clients' (and individual employees') TFNs regardless of your firm's size, even where the A$3 million exemption otherwise shelters the rest of your practice.
The Rule requires you to take reasonable steps to protect TFN information and restrict access to it (r 11(1)), and to securely destroy or permanently de-identify it once it is no longer required by law to be retained and no longer necessary for a purpose under taxation, superannuation or personal assistance law (r 11(2)). Both limbs have to have ceased, so a live retention obligation keeps the record even after your own purpose ends. What "reasonable" means scales with your circumstances: a two-person bookkeeping practice and a twenty-partner firm will not do identical things, but each has to be able to justify the steps it takes as reasonable in its circumstances.
Scope, stated honestly: the Rule protects the TFN information of individuals only, not the TFNs of companies, partnerships, trusts or super funds, and not your general (non-TFN) client database. Handling TFNs does not make a small practice a full "APP entity" subject to all 13 Australian Privacy Principles. It creates targeted obligations for the individual TFN data you hold.
What "reasonable steps" looks like in a practice
The Rule sets a standard, not a specification: it names no technology and no checklist. The measures below are not separate legal requirements except where a rule is cited; they are what we recommend as a practical way for a small accounting or bookkeeping practice to meet the r 11(1) reasonable-steps standard:
- Restrict access to staff who need it. Only the people who actually work on a client's file should be able to see that client's TFN. Role-based access in your practice software, rather than a shared login everyone uses, is the practical version of this.
- Secure the data at rest. Keep TFNs in access-controlled systems, not in loose spreadsheets, email folders or on unencrypted laptops and USB drives. Where your software offers encryption, use it.
- Secure the data in transit. Take care when sending TFNs anywhere. Unencrypted email of a client's TFN is a risk to control, not a routine default. See Can an accountant email a client's TFN?.
- Use a secure client portal for collecting and returning documents that contain TFNs, rather than ordinary email attachments, where you can.
- Train your staff. This one is an express requirement, not just good practice: r 12 requires reasonable steps to ensure all staff are aware of the need to protect individuals' privacy, and that staff who collect or access TFN information know the circumstances in which it may be collected, the prohibitions on use and disclosure, and the penalties for breach. A short, documented induction and refresher is the practical version.
- Control your service providers. If TFN data sits with a cloud accounting platform, a payroll bureau or an outsourced processor, we recommend treating your contract and due diligence with them as part of your own reasonable steps under r 11(1). A provider holding a record containing that TFN information is also a file number recipient in its own right (Privacy Act s 11(1)), so the duty does not simply transfer away from you.
- Keep it minimal. The Rule limits collection at both ends: TFN information may only be requested or collected for a purpose authorised by taxation, superannuation or personal assistance law (r 8(1)), and only where it is necessary and relevant to that purpose (r 8(2)(c)). Do not copy TFNs into systems that do not need them, and let them go once both limbs of r 11(2) are satisfied (see below).
None of these is exotic. The point of the Rule is that you can show you took deliberate, sensible steps rather than leaving individual TFNs lying around in whatever system was convenient.
Only keep TFNs as long as you must, then destroy them
The TFN Rule requires you to securely destroy or permanently de-identify TFN information once it is neither required by law to be retained nor still necessary for a purpose under taxation, superannuation or personal assistance law (r 11(2)). That is the tension worth planning for: your firm has various record-keeping obligations, and where you provide AML designated services the AML/CTF Act sets a seven-year record-keeping floor for the AML/KYC data caught by that regime. Those retention duties are a lawful basis to keep the relevant records, but they are not a licence to keep every copy of every TFN forever.
The workable answer is a written retention and destruction schedule: identify what you must keep and for how long, then securely destroy or de-identify the rest, including stray copies in email and downloads. See How long can an accountant keep a client's TFN?.
What happens if TFN data is breached
Good TFN security is also what reduces the chance of ever having to run the breach-notification process. Under s 26WE(1)(d) the Notifiable Data Breaches scheme reaches a file number recipient, the statutory term for a TFN recipient, even below A$3 million turnover, and s 26WB puts a file number recipient inside the definition of "entity" for that Part. It is confined to eligible breaches involving the TFN information. So if TFN information you hold is accessed, disclosed or lost in a way likely to result in serious harm, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days (s 26WH), then, where it is an eligible data breach, prepare a statement for the Commissioner and notify affected individuals (ss 26WK and 26WL).
Separately, a breach of the TFN Rule by a file number recipient is an "interference with the privacy of an individual" (s 13(4)(a)), so an affected person can complain to the OAIC. A determination under s 52(1) carries no fine: the Commissioner can declare that the conduct interfered with privacy, require steps so it is not repeated, and award compensation to the complainant. A pecuniary penalty for a serious interference is a separate track the Commissioner has to take to the Federal Court or the Federal Circuit and Family Court (Division 2) (ss 13G and 80U). A short, ready-to-run breach plan is what turns a bad day into a managed one. See Data breach obligations for accountants handling TFNs.
Common questions
Do I have to encrypt tax file numbers?
The Rule does not name specific technologies; it requires reasonable steps to protect TFN information from misuse, loss and unauthorised access. Encryption of data at rest and in transit is one of the clearest ways to show you took those steps, so where your systems offer it, using it is sensible. What is "reasonable" scales with the size and nature of your practice.
Can I keep clients' TFNs in a spreadsheet?
You can hold TFNs in whatever system lets you meet the Rule, but a loose, widely-shared spreadsheet is hard to defend: access is not restricted to who needs it, it is easy to copy and email, and it is easy to forget when destruction time comes. Access-controlled practice software is a much safer home for individual TFNs.
Does this apply to my practice if we turn over under $3 million?
Yes, for the individual TFNs you handle. A file number recipient is anyone in possession or control of a record containing TFN information (Privacy Act s 11(1)), with no turnover threshold, so the A$3 million small-business exemption does not switch off your TFN-security obligations even though it may shelter other parts of your practice. The Rule covers individuals' TFNs only, not those of company, trust, partnership or SMSF clients (r 5(2)). See Does the Privacy Act apply to accountants under $3 million?.
What about tax file numbers in payroll I run for a client's staff?
When you process a business client's payroll you hold TFNs for that client's employees, who are not your own clients. The same standard applies, and it does not depend on any grey area: holding a record containing their TFN information makes you a file number recipient (Privacy Act s 11(1)), they are individuals, and s 18 requires you to comply with the TFN Rule. The employee-records exemption does not change that, because s 7B(3) exempts acts of an organisation "that is or was an employer of an individual" from the Australian Privacy Principles, and it does not reach the separate s 18 duty. See Bookkeepers and client-employee payroll data.
Keep reading
- The TFN Rule 2015: what accountants must do
- Can an accountant email a client's TFN?
- How long can an accountant keep a client's TFN?
- Data breach obligations for accountants handling TFNs
- Privacy Act compliance for accountants and bookkeepers
General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC, or under the TPB Code, which is administered by the Tax Practitioners Board. The Privacy Act 1988 (Cth), the TFN Rule 2015 and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.