The Privacy (Tax File Number) Rule 2015: what accountants must do
The TFN Rule 2015 is a legally binding instrument made under s 17 of the Privacy Act 1988 (Cth). It binds every "TFN recipient", and a practice or tax agent holding clients' TFN information is one, with no turnover threshold and no small-business exemption. It requires you to collect individuals' tax file numbers lawfully, secure them, limit how you use and disclose them, destroy them when you no longer need them, and train your staff.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
What the Rule is, and why it reaches your practice
Most privacy obligations turn on turnover. Under s 6D of the Privacy Act a business with annual turnover of A$3 million or less is generally a "small business operator" and sits outside the Australian Privacy Principles. The TFN Rule works differently. It is made under s 17 of the Privacy Act, and it binds every "TFN recipient", a category that covers a practice holding clients' TFN information.
There is no small-business exemption in the Rule and no turnover threshold. If your practice takes an individual's tax file number, the Rule applies to how you handle it, whether you turn over A$300,000 or A$30 million, and whether or not you do any anti-money-laundering work at all. This is the obligation almost nobody sells accountants, and it is live now, with no deadline attached.
What the Rule actually requires
The TFN Rule sets targeted obligations across the whole lifecycle of the tax file numbers you hold. In plain terms, you are expected to:
- Collect lawfully. Only ask for a tax file number where you are authorised to, and do not make a person quote one where it is not required.
- Secure it. Take reasonable steps to protect TFN information from misuse, interference, loss, and unauthorised access, use or disclosure.
- Limit use and disclosure. Use and disclose tax file numbers only for the purposes the law permits, not for general identification or record-linking.
- Destroy or de-identify it. Securely destroy or de-identify TFN information once you are no longer required by law to retain it.
- Train your staff. Make sure the people in your practice who handle tax file numbers understand these obligations.
The exact rule numbers within the instrument for each of these obligations are not pinned here , so this page states the effect of the Rule rather than quoting internal clause numbers. For the storage and destruction obligations in detail, see how must accountants store clients' tax file numbers? and how long can an accountant keep a client's TFN?.
Scope, stated honestly
The Rule is real, but it is not a general privacy regime for your whole practice. Two limits matter.
It protects individuals' TFN information only. The Rule covers the tax file numbers of individuals, not the TFNs of companies, partnerships, trusts or superannuation funds, and not your general (non-TFN) client database. The caught data is the individual client and individual employee tax file numbers you hold.
It does not make you a full "APP entity". Handling tax file numbers does not sweep a small practice under all 13 Australian Privacy Principles. The Rule creates focused obligations for the TFN data itself. Whether the broader Privacy Act applies to the rest of your practice is a separate question, covered in does the Privacy Act apply to accountants under $3 million?.
What happens if you get it wrong
A breach of the TFN Rule is treated as an "interference with the privacy of an individual" under the Privacy Act. That means an affected person can complain to the Office of the Australian Information Commissioner (OAIC), which can investigate and, in serious cases, seek remedies. Penalties are ceilings, not certainties, and most matters resolve without a fine, but the exposure to a complaint is real even for a sub-A$3m practice.
There is also a separate breach-notification layer. The Notifiable Data Breaches scheme reaches TFN recipients under s 26WE(1)(d) of the Privacy Act even below the A$3 million threshold, confined to eligible breaches involving the tax file number information. So a serious breach of the TFN data you hold may need to be assessed and notified to affected individuals and the OAIC. See your data-breach obligations under the NDB scheme.
This is separate from AML Tranche 2
The TFN Rule is not the AML change. It binds you now, regardless of size, for the tax file numbers you handle. AML/CTF Tranche 2, from 1 July 2026, is a narrower and later obligation that only reaches firms providing a "designated service", and even then it pulls in the AML/KYC identity data, not your general tax files. Keep the two apart: most practices are caught by the TFN Rule and are not AML reporting entities at all. The AML side is covered separately in the accountants hub.
What accountants actually need
To meet the TFN Rule in practice, a practice generally needs a TFN-handling policy that reflects these obligations, sitting alongside a privacy policy, collection notices and a breach response plan tuned to TFN and financial-data exposure. Generic free templates usually are not written for an accounting practice and often carry the outdated "over A$3m or you are exempt" framing, which is simply wrong for TFN recipients.
Common questions
Does the A$3 million small-business exemption cover my TFN handling?
No. The TFN Rule has no turnover threshold and no small-business exemption. The s 6D exemption may still shelter the rest of your practice, but not the way you handle individual clients' or employees' tax file numbers.
Does handling TFNs mean I have to comply with all the Privacy Principles?
No. The Rule creates targeted obligations for the tax file number data itself. It does not automatically make a small practice a full "APP entity" subject to all 13 Australian Privacy Principles.
Whose TFNs does the Rule protect?
Individuals' tax file numbers, including your individual clients and the employees whose payroll you process. It does not cover the TFNs of companies, partnerships, trusts or super funds.
Is a breach of the Rule actually enforceable against a small firm?
Yes. A breach of the TFN Rule is an interference with privacy, so an affected individual can complain to the OAIC even if your practice turns over less than A$3 million.
This is general information , document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC, or your obligations under the TPB Code, which are administered by the Tax Practitioners Board. Privaproof's accountant documents are self-authored and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner. The Privacy Act 1988 (Cth) and the TFN Rule 2015 change over time, so check you are working from a current version.