Privacy Act 2026 — by industry
Privacy Policy for Accounting Firms: The 2026 Australian Compliance Guide
What an Australian accounting or bookkeeping firm's privacy policy needs in 2026 under the Privacy Act 1988 — including AML Tranche 2 KYC from 1 July 2026 and the 10 December 2026 automated decision-making disclosure. Plain English, source-checked.
Accounting and bookkeeping firms hold deeply sensitive financial and identity data — and from 1 July 2026, AML/CTF Tranche 2 adds formal KYC collection on top. That makes a Privacy Act compliant privacy policy a 2026 priority. Here is what your firm's policy needs.
Why 2026 changes things for accountants
If you provide a designated service, AML/CTF Tranche 2 makes you a reporting entity from 1 July 2026. Capture is service-based, not occupation-based — so not every accountant is caught — but if you are, the Privacy Act applies to the personal information you collect for AML/CTF regardless of turnover. See AML Tranche 2 and the Privacy Act. (Source: AUSTRAC.)
What your policy must cover (APP 1)
- What you collect: identity and contact details, TFNs and financial records,
KYC and beneficial-ownership information, business records.
- Why: providing accounting services, meeting legal/tax obligations, and AML/CTF
due diligence.
- Who you disclose to: the ATO and regulators where required, software providers,
AUSTRAC where required, and any overseas recipients (e.g. offshore processing).
- Access, correction and complaints, with the path to the OAIC.
- Security and retention, keeping only what you need.
The general step-by-step is in how to write a privacy policy that complies in 2026.
Automated decision-making in accounting tech
If you use software that makes or substantially supports decisions significantly affecting clients (for example, automated risk or eligibility scoring), the 10 December 2026 ADM disclosure obligation likely applies. See the ADM guide.
Breach response
Financial and identity records are high-value breach targets. Build your 30-day assessment process under the Notifiable Data Breaches scheme — see the data-breach response plan.
Run the free checker, then use the free checklist's self-audit on your policy.
General information only, not legal or compliance advice. Current to June 2026; confirm your obligations at oaic.gov.au and austrac.gov.au or with a qualified adviser. Last verified: 8 June 2026.
Run the free ML/TF risk assessment →