For accountants & bookkeepers

You hold more financial data than the banks your clients complain about.

Since 1 July 2026, accountants providing designated services under the AML/CTF Act are reporting entities. For the personal information handled in that work, the Privacy Act small business exemption no longer applies — regardless of turnover.

Your clients will ask you what this means for them. It's worth having your own house in order first.

No obligation. We'll tell you if you don't need us.

Where the law actually stands

Three dates matter. Only one has already passed.

Plenty of people will tell you every small business is about to fall under the Privacy Act. That isn't law yet. Here is what is in force, what is scheduled, and what is still only proposed.

Date
What changed
Status
10 Jun 2025
Statutory tort for serious invasions of privacy Individuals can sue directly. Applies regardless of your turnover.
In force
01 Jul 2026
AML/CTF Tranche 2 — accountants captured as reporting entities Company and trust formation, managing client money, and assisting with property transactions are designated services. The Privacy Act now applies to the personal information you handle in that work, even under the $3m threshold.
In force
10 Dec 2026
Automated decision-making disclosure obligations If your software scores, screens or flags clients automatically, your privacy policy must disclose it.
Scheduled
Not set
Removal of the $3m small business exemption entirely Government supports it in principle. No Bill passed, no commencement date. Treat any specific date you're quoted as commentary.
Proposed

General information, current as at the date of publication — not legal advice. We review this table monthly and date every change.

Why practices are exposed

Tax file numbers, bank feeds, payroll, and every director's identity document.

Tax file numbers alone carry their own rules on top of the Privacy Act. Add bank feeds, payroll files with employee TFNs and super details, ATO portal access, director identity documents, trust deeds and beneficial ownership records, and your practice holds a denser financial picture of a household than any other business it deals with.

Most of it moves through email. Client sends a photo of a passport; a staff member forwards it to the person doing the work; it lands in three mailboxes, a document management system and someone's downloads folder. Nobody deletes it.

The exposure isn't theoretical. Accounting practices are actively targeted for business email compromise precisely because of what they hold, and a breach of TFNs is a notifiable data breach with a very short clock on it.

What it costs to get this wrong. The OAIC can issue infringement notices of up to $66,000 per contravention for lower-level failures such as not maintaining a compliant privacy policy. Serious or repeated breaches carry substantially higher penalties. Separately, since June 2025, an individual can bring a civil claim against you directly.

What we do

Four ways to work with us.

Start small if you want to see how we work. Start with the foundations if you already know where this is heading.

Privacy health check

$750 + GST, one-off

A half day of our time and a written answer to one question: how exposed are you?

  • Review of your current policy, forms and file handling
  • Written findings memo against the Australian Privacy Principles
  • Prioritised list of what to fix first
  • Credited in full against foundations if you proceed within 60 days

Privacy foundations

$4,500 – $7,500 + GST, one-off

A complete privacy program, built and handed over in four weeks.

  • Data map of every place personal information lives
  • Gap assessment against the 13 Australian Privacy Principles
  • Privacy policy and collection notices written for your practice
  • Notifiable data breach response plan
  • 60-minute staff training session

Most practices choose this

ComplyHub annual

from $10,500 + GST, per year

Foundations plus twelve months of maintenance, bundled.

  • Everything in Privacy foundations
  • Quarterly compliance review
  • Policies and registers updated as the law changes
  • Breach response line — call us first, not your lawyer
  • Annual staff training refresher

Ongoing privacy officer

$400 – $800 + GST, per month

Maintenance only, for practices whose program is already built.

  • Quarterly reviews and register upkeep
  • Regulatory change monitoring
  • Breach response line
  • If someone else built your program, we'll assess it first ($1,500)

The four weeks

What actually happens.

Week 1 — Discovery

Ninety minutes with you and whoever administers your ledger, payroll and document management systems. We follow the data: client onboarding, engagement, the work itself, and the archive.

Week 2 — Data map and gap assessment

We document what you hold, where, who has access and how long you keep it, then assess against the 13 Australian Privacy Principles — with particular attention to TFN handling, offshore processing and third-party software.

Week 3 — Documents

Privacy policy, collection notices for engagement and onboarding, breach response plan, retention schedule, and a short data-handling standard your staff can actually follow.

Week 4 — Handover and training

An hour with your team, plus a written summary you can hand to your professional body, your PI insurer, or a client who asks how you look after their information.

Fair questions

What partners usually ask us.

My software vendor says they handle compliance for me.

They handle their own. A cloud ledger provider is a service provider to you; under APP 8 you remain accountable for personal information you disclose to them, including where it's processed overseas. Their certification covers their infrastructure, not your collection notices, your staff practices, your retention decisions or your breach response. Ask them for the specific clause that says otherwise — we'll read it with you.

Doesn't my AML/CTF program already cover this?

No. Separate Acts, separate regulators. AUSTRAC governs what you must collect and keep. The OAIC governs how you handle, secure, disclose and destroy it. Enrolling is what brought you into scope, not what satisfies it.

We're under $3 million turnover.

The exemption no longer applies to personal information handled for AML/CTF purposes. Note also that TFN handling and employee records have always had their own rules that sit outside the turnover test.

Which parts of my practice are actually captured?

Not all of it. Designated services include things like forming companies and trusts, acting as a nominee, managing client money and assisting with property transactions — not straightforward tax return preparation on its own. Week one is where we draw the line, because it determines how much program you need.

Can we refer clients to you?

Yes, and a good number of our conversations start that way. We have a referral arrangement for practices whose clients are in the same position — details below.

Referral partners

Your clients are about to ask you this question.

Every real estate agency, buyer's agent and property developer on your client list came into scope on the same day you did — and most of them don't know it yet. When they ask you what to do about privacy, you have three options: take it on, ignore it, or introduce someone.

We run a straightforward referral arrangement for accounting and bookkeeping practices. You make a warm introduction; we scope, quote and deliver; you stay in the loop with a copy of the handover summary so nothing lands on your client's desk that you haven't seen. Fee-share or client discount, whichever your professional obligations and your preference allow. No lock-in, no exclusivity, no obligation to refer.

Ask us about the referral programme →

Who you're dealing with

A small Australian firm, and you'll deal with a founder.

ComplyHub is based in Melbourne and works with Australian professional services businesses on Privacy Act obligations. Our work is delivered onshore — your data stays in Australia, and we can tell you exactly which systems it touches.

Between us we hold certifications from the International Association of Privacy Professionals in privacy program management, privacy technology and AI governance, alongside security credentials. That matters less than the fact that you'll speak to the person doing the work.

More about us and our credentials →

Get your own house in order first.

Twenty minutes on the phone. We'll walk through what your practice holds and where it goes, and tell you plainly whether you have a problem. Then we can talk about your clients.