All articles / Security
Security

Keeping client tax data secure: what Australian firms should expect

Tax data is some of the most sensitive information a firm holds. Here are the questions worth asking of any tool that touches it.

Written by
IMG
Andrew Lovett
Founder, Tony.Online
28 July 2026 · 4 min read

Every firm handling tax returns is also handling tax file numbers, financial records and personal details. That carries real obligations under the Privacy Act and the Australian Privacy Principles, and real expectations from clients. When any new tool enters the workflow, it is fair to ask exactly how it treats that data.

Key takeaways

  • Tax data carries real Privacy Act obligations and client expectations
  • Five questions separate serious providers from the rest
  • Onshore storage, no training, and TFN redaction are the fundamentals

The questions worth asking

  • Where is the data stored? For Australian firms, data held onshore, in Australia, avoids a range of complications. It is reasonable to ask where a provider's servers actually are.
  • Is the data used to train anything? Client data should never be fed into public models or used to train a provider's systems. The answer here should be a clear no.
  • What is retained, and for how long? The less that is kept, the smaller the risk. It is worth understanding a provider's retention and deletion practices.
  • How are tax file numbers handled? TFNs carry specific obligations under the Privacy (Tax File Number) Rule. Automatic detection and redaction on upload is a strong sign a tool takes this seriously.
  • Who can access the data? Least privilege access, where only the systems that need to touch data can, plus a log of what happened, is the standard to look for.

Why it matters more than it used to

Clients are more aware of data security than they were, and a single breach can do lasting damage to a firm's reputation. Getting the fundamentals right is no longer a nice to have. It is part of the service.

This is general information, not legal advice on your obligations. As a checklist for any tool that touches client data, though, these questions separate the providers who have thought about security from the ones who have not.

IMG
Written by
Andrew Lovett
Founder, Tony.Online · Director, Lovetts · Registered Tax Agent

Two decades working across every entity type, and a computer-science background that turned into Tony.Online, the tireless second analysis he always wished he had.

This article is general information for Australian tax professionals and is not tax, financial or legal advice. It is not a substitute for your professional judgment or for advice specific to your circumstances. Tony.Online supports the analysis process and does not replace the professional responsibility of the registered tax agent; all positions should be independently verified against the current Tax Office instructions before acting. Read our full Website Disclaimer.

More reading

View all →

Enjoyed this? Get the next one.

One practical analysis note, every fortnight. No spam, unsubscribe anytime.