The TFN Rule 2015: what accountants must do
The TFN Rule 2015 is a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth). Section 18 says a "file number recipient" must not breach a rule issued under s 17, and under s 11(1) anyone in possession or control of a record containing tax file number information is one, so a practice or tax agent holding individual clients' TFN information is bound, with no turnover threshold and no small-business exemption. It requires you to collect individuals' tax file numbers lawfully, secure them, restrict who can reach them, limit how you use and disclose them, securely destroy or de-identify them once they are neither required by law to be retained nor still needed for a taxation, personal assistance or superannuation law purpose, and train your staff.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
What you must tell a client when you ask for their TFN
This is the part of the Rule you can check against your own paperwork in a minute. Under r 8(2)(a), when you request an individual's tax file number you must take reasonable steps to ensure that individuals are informed of four things:
- The law that authorises you to ask. The taxation law, personal assistance law or superannuation law under which you are requesting or collecting the number.
- What you are collecting it for. The purpose, or purposes, for which the tax file number is requested or collected.
- That declining to quote a tax file number is not an offence. A person who chooses not to give you their TFN has broken no law.
- What happens if they decline. The consequences of declining to quote it.
The same rule adds two more requirements. Under r 8(2)(b) the manner of collection must not unreasonably intrude on the individual's affairs, and under r 8(2)(c) you must only request or collect information that is necessary and relevant to the purpose of collection under the applicable taxation, personal assistance or superannuation law.
In practice those four sit in a short written notice given at the point you collect the number, which is what a TFN collection notice is for. If your engagement letter or client form asks for a tax file number without saying any of the four, that is the gap.
What the Rule is, and why it reaches your practice
Most privacy obligations turn on turnover. Under s 6D(1) of the Privacy Act a business is a "small business" if its annual turnover for the previous financial year is A$3 million or less, and s 6D(3) makes an entity carrying on only small businesses a "small business operator", which sits outside the Australian Privacy Principles unless one of the exceptions in s 6D(4) applies. The TFN Rule works differently. It is made under s 17 of the Privacy Act and enforced through s 18, which binds a "file number recipient", a category that under s 11(1) covers a practice in possession or control of a record containing individual clients' TFN information.
There is no small-business exemption in the Rule and no turnover threshold. If your practice takes an individual's tax file number, the Rule applies to how you handle it, whether you turn over A$300,000 or A$30 million, and whether or not you do any anti-money-laundering work at all. The Rule has been in force since 2015, and unlike the AML changes it carries no commencement date still to come.
What the Rule actually requires
The TFN Rule sets targeted obligations across the whole lifecycle of the tax file numbers you hold. In plain terms, you are expected to:
- Collect lawfully. Under r 8(1), only request or collect TFN information for a purpose authorised by taxation, personal assistance or superannuation law, and under r 8(2)(c) only collect what is necessary and relevant to that purpose.
- Secure it, and restrict who can reach it. Under r 11(1), take reasonable steps to protect TFN information from misuse and loss, and from unauthorised access, use, modification or disclosure, and to restrict access to records containing it to the people who need to handle it for taxation, personal assistance or superannuation law purposes.
- Limit use and disclosure. Under r 10, use or disclose TFN information, including for matching personal information about individuals, only for a purpose authorised by taxation, personal assistance or superannuation law, or to give an individual their own TFN information. Under r 7(1) the TFN must not be used as part of a national identification system.
- Destroy or de-identify it. Under r 11(2), take reasonable steps to securely destroy or permanently de-identify TFN information once it is no longer required by law to be retained and no longer necessary for a purpose under taxation, personal assistance or superannuation law. Both limbs have to have ceased, so a record you are still legally required to keep is not destroyed merely because its purpose has ended.
- Train your staff. Under r 12, take reasonable steps to ensure all staff are aware of the need to protect individuals' privacy when handling TFN information, and that staff who collect or access it also know when it may be collected, the prohibitions on using and disclosing it, and the penalties or other sanctions for breaching the Rule.
The obligations sit at rr 8, 9, 10, 11(1), 11(2) and 12 of the instrument: notification at collection, tax file numbers that arrive without being collected, limits on use and disclosure, security and restricted access, secure destruction, and staff training. For the storage and destruction obligations in detail, see how must accountants store clients' tax file numbers? and how long can an accountant keep a client's TFN?.
Scope, stated honestly
The Rule is real, but it is not a general privacy regime for your whole practice. Two limits matter.
It protects individuals' TFN information only. The Rule covers the tax file numbers of individuals, not the TFNs of companies, partnerships, trusts or superannuation funds, and not your general (non-TFN) client database. The caught data is the individual client and individual employee tax file numbers you hold.
It does not make you a full "APP entity". Handling tax file numbers does not sweep a small practice under all 13 Australian Privacy Principles. The Rule creates focused obligations for the TFN data itself. Whether the broader Privacy Act applies to the rest of your practice is a separate question, covered in does the Privacy Act apply to accountants under $3 million?.
What happens if you get it wrong
A breach of the TFN Rule is an "interference with the privacy of an individual" under s 13(4)(a) of the Privacy Act, and r 5(3) of the Rule says the same. That means an affected person can complain to the Office of the Australian Information Commissioner (OAIC). A determination under s 52(1) carries no fine: the Commissioner can declare that the conduct was an interference, order steps so it is not repeated, and award the complainant compensation for loss or damage. A civil penalty is a separate track, and under ss 13G and 80U the Commissioner has to apply to the Federal Court, or the Federal Circuit and Family Court, to obtain one. The exposure to a complaint is real even for a sub-A$3m practice.
There is also a separate breach-notification layer. The Notifiable Data Breaches scheme reaches a "file number recipient", which is the term s 26WE(1)(d) of the Privacy Act uses, even below the A$3 million threshold, and that limb is confined to the tax file number information you hold. So a serious breach of the TFN data you hold may need to be assessed and notified to affected individuals and the OAIC. It reaches the rest of your client records only where some other trigger makes your practice an APP entity. See your data-breach obligations under the NDB scheme.
This is separate from AML Tranche 2
The TFN Rule is not the AML change. It binds you now, regardless of size, for the tax file numbers you handle. AML/CTF Tranche 2 is narrower and later: since 31 March 2026 a firm is a reporting entity only where it provides a "designated service", and the AML/CTF obligations themselves, including enrolment, programs, customer due diligence and reporting, apply from 1 July 2026. Even then it pulls in the AML/KYC identity data, not your general tax files. Keep the two apart: the TFN Rule turns on holding an individual's tax file number, while the AML regime turns on the service you provide. The AML side is covered separately in the accountants hub.
What accountants actually need
To meet the TFN Rule in practice, a practice needs a TFN collection notice carrying the four things r 8(2)(a) requires, a TFN-handling procedure covering rr 8, 9 and 10, a security and access-restriction control for r 11(1), a secure destruction rule for r 11(2), and staff training for r 12, plus a breach response plan for the s 26WE(1)(d) route into the NDB scheme. A privacy policy is a separate question: that obligation is APP 1.3, so it arises only where some other trigger makes your practice an APP entity. Privaproof provides these as templates you tailor, written for an accounting practice.
Common questions
Does the A$3 million small-business exemption cover my TFN handling?
No. The TFN Rule has no turnover threshold and no small-business exemption. The s 6D exemption may still shelter the rest of your practice, but not the way you handle individual clients' or employees' tax file numbers.
Does handling TFNs mean I have to comply with all the Privacy Principles?
No. The Rule creates targeted obligations for the tax file number data itself. It does not automatically make a small practice a full "APP entity" subject to all 13 Australian Privacy Principles.
Whose TFNs does the Rule protect?
Individuals' tax file numbers, including your individual clients and the employees whose payroll you process. It does not cover the TFNs of companies, partnerships, trusts or super funds.
Is a breach of the Rule actually enforceable against a small firm?
Yes. A breach of the TFN Rule is an interference with privacy, so an affected individual can complain to the OAIC even if your practice turns over less than A$3 million.
This is general information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC, or your obligations under the TPB Code, which are administered by the Tax Practitioners Board. For advice on your specific circumstances, consult a qualified Australian legal practitioner. The Privacy Act 1988 (Cth) and the TFN Rule 2015 change over time, so check you are working from a current version.