Privacy Policy
A CPA Practice • Registered Tax Agent • ASIC Registered Agent • AUSTRAC-enrolled reporting entity
Effective date: 23 July 2026 (replaces the policy dated 7 January 2025)
Next review due: July 2027
Privacy Officer: Niki Cotter, Director
Index
Our promise to you, in plain English
We're accountants. That means you trust us with some of the most sensitive information you have — your tax file number, your income, your bank details, your business finances, and even your identity documents. We take that trust seriously.
This policy explains, in plain language, what information we collect, why we collect it, where it's stored, who we share it with (and who we don't), and what your rights are. No jargon, no fine print tricks. If anything here isn't clear, ask us — explaining things clearly is what we do.
We are bound by the Privacy Act 1988 (Cth) and all 13 Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme, the confidentiality obligations in the Tax Practitioners Board (TPB) Code of Professional Conduct, the Tax Agent Services Act 2009, CPA Australia's professional and ethical standards (including APES 110, the accounting profession's Code of Ethics), the Privacy (Tax File Number) Rule 2015, and the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. As an AUSTRAC-enrolled reporting entity, we are covered by the Privacy Act in full for the information we handle — there is no "small business exemption" hiding behind this policy.
Three commitments up front:
1 We will never sell your personal information. Not to marketers, not to "business partners", not to anyone.
2 We only collect what we genuinely need to do our work for you or to meet a legal obligation.
3 Your sensitive documents live in one secure place — our encrypted Box document storage — and we will never ask you to email them to us.
Who this policy covers
This policy applies to personal information we collect and hold about our clients, former clients, prospective clients, and the people connected to them — for example, the directors, shareholders, beneficiaries, employees and family members of the businesses we act for. It also applies to visitors to our website and people who contact us or subscribe to our updates.
Personal information is any information or opinion about an identified individual, or an individual who is reasonably identifiable — your name, contact details, financial details, tax file number, and so on. Sensitive information is a special category given extra protection under the law, and includes things like health information and biometric information (more on that below, because identity verification involves it).
This policy doesn't cover the privacy practices of other organisations, such as the ATO, ASIC or the software providers we use — they have their own privacy policies, and we link to the important ones below.
What information we collect
Because of the work we do, we collect more than just your name and email. Depending on the services you engage us for, this typically includes:
Category
Identity and contact details
Government identifiers
Identity verification records
Financial information
Business and entity records
Engagement records
Website and email data
Examples
Name, date of birth, address, phone, email, occupation
Tax file number (TFN), ABN, director ID — handled under strict rules (see below)
The information from your driver licence or passport (such as name, date of birth and document number), verification results, and politically exposed person (PEP) and sanctions screening results collected through our identity verification provider, Annature
Income, expenses, assets, liabilities, superannuation, investments, bank account details, payroll records
Company constitutions, registers, officeholder details, trust deeds, minutes, resolutions, beneficial ownership information
Engagement letters, correspondence of substance, file notes, workpapers, signed declarations
Basic analytics about visits to our Wix website, and email correspondence
About your family and your team. If you give us personal information about someone else — your spouse, your adult children, your employees — please make sure you have their permission, and let them know this policy exists. We treat their information with the same care as yours.
Sensitive information. We don't set out to collect sensitive information, and we'll never ask for it unless it's genuinely necessary. There are two situations where it can arise in our work. First, biometric verification: when we verify your identity through Annature, the verification process may use facial biometric matching (comparing a selfie to your ID document). Biometric information is sensitive information under the Privacy Act, so we will always ask for your consent before this happens and explain the process. We keep the verification report — not your raw biometric data, which is handled under Annature's certified security arrangements. Second, occasionally sensitive information appears in the ordinary course of our work — for example, a health-related expense in your records, or a PEP screening result that touches on political association. We only use it for the purpose it was provided or as the law requires.
Your tax file number. TFNs have their own special legal protection under the Privacy (Tax File Number) Rule 2015. We only collect, use and disclose your TFN for tax-related purposes (such as preparing and lodging your returns with the ATO), we restrict access to it, we store it securely in Box, and we never include it in ordinary emails. Misusing a TFN is a criminal offence, and we treat TFN security as non-negotiable.
If you'd rather stay anonymous. You're welcome to browse our website, read our resources, or make a general enquiry without identifying yourself, or while using a pseudonym. But once we act for you as your tax agent, the law requires us to know exactly who you are — anonymity isn't an option for tax, ASIC or anti-money laundering work, and we couldn't do our job properly without it.
Why we collect your information
We collect and use your personal information for these purposes:
1
To provide our services — tax returns, BAS, financial statements, FBT, cash flow and budgeting support, business advisory, review engagements, Xero setup and support, and ASIC corporate compliance.
2
To meet our legal and professional obligations — including tax law, the Tax Agent Services Act 2009, the Corporations Act 2001, the AML/CTF Act, and the record-keeping standards set by the TPB and CPA Australia.
3
To verify your identity — which both the TPB and the AML/CTF Act require us to do before we act for you (see the dedicated section below).
4
To communicate with you — appointment reminders, lodgement due dates, questions about your work, and educational updates we think will genuinely help you.
5
To run our practice — quality reviews, professional indemnity insurance, complaint handling, and practice administration.
We won't use your information for an unrelated purpose without your consent, unless the law requires or permits it — and where that happens, we'll tell you unless the law prevents us from doing so (see the AUSTRAC section below for the one situation where we legally can't tell you).
If we receive information we didn't ask for. Sometimes people send us personal information we didn't request. If we could have lawfully collected it, we file it securely; if not, we destroy or de-identify it as soon as practicable. And if you email us something sensitive that should have gone through our secure channel, we move it to Box and delete the email — then gently remind you of the secure way to send it.
Identity verification and our anti-money laundering obligations
This section matters, so we want to explain it properly.
From 1 July 2026, accountants providing certain services became regulated under Australia's anti-money laundering and counter-terrorism financing laws (the AML/CTF Act — often called the "Tranche 2" reforms). The Ethical Accountant Pty Ltd is enrolled with AUSTRAC, the Australian Government's financial intelligence agency, as a reporting entity.
What this means for you as a client:
1
We must verify your identity before we act for you. This is a legal requirement, not us being difficult. We use Annature — an Australian, ISO 27001-certified platform that stores its identity verification data onshore in Australia — and we use it only for identity verification and AML/CTF checks, nothing else. We will never ask you to email us a photo of your driver licence or passport. If you email one anyway, we'll move it to secure storage, delete the email, and show you the proper process.
2
For companies, trusts and partnerships, we must identify the real people behind the entity — the "beneficial owners" — and in some cases ask about the source of funds for a transaction. Again, the law requires this.
3
We keep records of these checks for at least 7 years after our relationship ends, as the law requires. Consistent with current OAIC guidance, we keep the verification details and results rather than holding copies of your full identity documents any longer than needed.
4
We may be legally required to report certain matters to AUSTRAC — for example, if we form a suspicion on reasonable grounds about money laundering, terrorism financing or serious criminal activity such as tax evasion. Here is the part we want to be completely honest about: if we ever lodge a suspicious matter report, the law prohibits us from telling you. This is called the "tipping off" prohibition, and breaching it is a criminal offence. It also means that, in rare cases, the law may prevent us from giving you access to certain information or explaining why. We're telling you this now, in general terms, because transparency about the rules we operate under is exactly what this practice stands for — even the rules that limit what we can say.
The Privacy Act does not stand in the way of these legal obligations, but it does require us to collect no more than necessary, keep it secure, and be upfront with you about the process — which is what this section is for.
How we collect and store your information
How we collect it. Mostly, directly from you — in meetings, phone calls, emails, through your secure Box folder, through Annature identity verification, and through the documents you provide. We also collect information from third parties where our work requires it: the ATO (through the Tax Agent Portal), ASIC (through NowInfinity), your Xero accounting file, your previous accountant (with your authority), and publicly available registers such as the ABR and ASIC registers.
Where it lives. We believe you deserve to know exactly which systems hold your information. These are the only systems we use for client work, each protected by multi-factor authentication (MFA) with strong, unique passwords held in a dedicated, MFA-protected password manager:
System
Whats it used for
What its not used for
Box
Our sole document storage platform. Every client document, workpaper and record lives here, in your own secure, encrypted client folder — which is also how we exchange sensitive documents with you
----
Annature
Identity verification and AML/CTF checks only (Australian-hosted, ISO 27001 certified)
General document signing
Adobe / Adobe Sign
Engagement letters, reports, forms, and all electronic signatures (other than identity verification)
Identity verification
XPM (Xero Practice Manager)
Practice management — client records, job tracking, tax return preparation and lodgement
----
Xero
Accounting and bookkeeping data for our firm and our clients
----
NowInfinity
ASIC corporate compliance — company statements, changes and registers
----
Google Workspace
Email (Gmail) and calendar only, for general, non-sensitive communication
Document storage. We do not use Google Drive — Box is our sole document storage platform, chosen for its superior security
Wix
Our website and marketing pages
Client data of any kind
Why the "email rule" matters. Email is convenient but it is not a secure way to send financial documents or identity information. That's why we will never send your tax return, financial statements or other sensitive documents as ordinary email attachments — they're delivered through your secure Box folder or Adobe Sign — and why we ask you never to email us TFNs, bank details, identity documents or financial records. At onboarding we'll show you how to use your Box folder; it's easy, and it keeps you safe.
Paper documents are the exception, not the rule. Anything on paper is scanned into Box and the paper is cross-cut shredded. Our devices are password- or biometric-protected and kept up to date, and screens are locked when unattended.
How long we keep it. We keep client records for a minimum of 7 years, which meets or exceeds the requirements of tax law, the TPB and the AML/CTF Act. When your information is no longer needed for any purpose we're allowed to keep it for, we take reasonable steps to destroy or de-identify it securely.
Who we share your information with — and who we don't
We treat your information as confidential. That's not just this policy talking: as a registered tax agent, Niki is bound by the confidentiality obligation in the TPB Code of Professional Conduct (which prohibits disclosing your information to third parties without your permission unless there's a legal duty to do so), and as a CPA, by the fundamental principle of confidentiality in APES 110, the accounting profession's Code of Ethics. That confidentiality continues even after you stop being a client.
We disclose your information only in these circumstances:
Who
Why
ATO
To prepare and lodge your returns, activity statements and other documents, and to communicate with the ATO on your behalf as your registered tax agent
ASIC
To lodge company documents and maintain your corporate compliance — strictly within the authority you give us (Form 362). Remember that officeholder and company details lodged with ASIC become part of the public record under the Corporations Act 2001
AUSTRAC
Where the AML/CTF Act requires us to report (see the section above — in the case of a suspicious matter report, the law prevents us from telling you)
TPB, CPA Australia and other regulators
Where we're legally required to — for example, TPB investigations, or breach reporting obligations under the tax agent laws
CPA Australia's Best Practice Program
If our practice is selected for a quality review, a reviewer may see client files. Reviewers are bound by strict confidentiality, and information disclosed is handled under the CPA Australia Privacy Policy
Our qualified accountant colleague
If you engage us for SMSF work, it is prepared by a qualified accountant colleague on our behalf, under the same confidentiality obligations — and we'll always tell you when this applies to your work
Our software providers
The platforms in the table above process or store your information so we can serve you. Each one is security-assessed before we rely on it, and none is permitted to use your information for its own purposes
Professional advisers
Our own legal or professional advisers, or your other advisers (such as your lawyer or finance broker) — but only with your consent
As otherwise required or permitted by law
For example, a court order or a statutory notice
Who we don't share it with. We do not sell, rent or trade your personal information. We do not share it with marketing companies, data brokers or advertisers. We do not use third-party behavioural advertising networks. We do not disclose your information to "business partners" for joint offers. If we ever sell the practice, client files would only transfer with proper safeguards and you would be notified beforehand with the ability to make choices about your information.
Overseas disclosure — where your data is hosted
Like nearly every modern Australian practice, we use cloud software, and some of those providers host data outside Australia. Under the Privacy Act (APP 8) we have to tell you about this, and we want to be specific rather than vague:
Provider
Likely hosting location
Annature (identity verification)
Australia
NowInfinity (ASIC compliance)
Australia
Box, Xero, XPM, Adobe, Google Workspace
United States, and in some cases other regions such as the European Union, on enterprise cloud infrastructure
Before we adopt any tool, we assess its security certifications, encryption and data-hosting arrangements, and we take reasonable steps to ensure overseas providers handle your information consistently with the Australian Privacy Principles. We do not send your information overseas for any other reason.
Direct marketing — our educational updates
Part of our philosophy is education: we occasionally send clients and subscribers genuinely useful updates — lodgement deadline reminders, legislative changes that affect small businesses, and practical guidance. We only send these to people who would reasonably expect them or who have opted in, and every marketing email includes a working unsubscribe link. You can also opt out at any time by emailing us at clients@ethicalaccountant.au or using the contact page — we'll action it promptly.
Opting out of marketing never affects the service messages you need as a client, such as lodgement due dates, document requests and appointment confirmations. And because we don't give your details to third parties for their marketing, there's nothing to opt out of on that front.
Our website
Our website runs on Wix and holds no client data. Like most websites, it collects basic technical information (browser type, pages visited, and similar analytics data) through cookies to keep the site working and help us understand what visitors find useful. You can block or delete cookies in your browser settings; the site will still work. We don't use tracking for third-party advertising. Anything you submit through the contact form comes to us by email — please don't include sensitive financial details in it; just tell us how to reach you and we'll set up a secure channel.
If something goes wrong: data breaches and the NDB scheme
No system on earth is breach-proof, so we'd rather tell you honestly what we've done to prepare than pretend it could never happen.
Prevention: multi-factor authentication on every system, unique passwords in a dedicated MFA-protected password manager, a single encrypted document platform (Box) instead of scattered copies, no sensitive data in email, security-assessed vendors, and prompt software updates.
Response: we are subject to the Notifiable Data Breaches (NDB) scheme under the Privacy Act, and if a breach ever occurs we will follow it:
1
Contain — immediately secure the affected system (password rotation, vendor notification, access revocation).
2
Assess — investigate whether the breach is likely to result in serious harm to any individual. The law allows up to 30 days for this assessment; we aim to move much faster.
3
Notify — if serious harm is likely and can't be prevented by remedial action, we will notify the Office of the Australian Information Commissioner (OAIC) and each affected person as soon as practicable, telling you what happened, what information was involved, and what steps you should take to protect yourself.
4
Learn — conduct a root-cause review and fix whatever allowed it to happen.
(In the unusual event that a legal secrecy provision — such as the AML/CTF tipping off prohibition — prevents part of a notification, we notify to the fullest extent the law allows.)
Your rights: access, correction and control
You can ask to see your information (APP 12). Just ask — by email or through your Box folder. We'll need to confirm your identity (usually easy, since we've verified it already), and we'll respond within 30 days, normally much sooner. For most requests there is no charge; if a request is unusually large we may charge a reasonable cost-recovery fee for our time, and we'll tell you before doing any work. Access can only be refused in limited situations set out in the Privacy Act — for example, where it would unreasonably affect someone else's privacy or where the law prohibits it. If we refuse, we'll give you written reasons and your complaint options, except in the rare case where the law itself prevents us from explaining.
You can ask us to correct your information (APP 13). Accurate information matters enormously in tax work, so please tell us whenever your details change. If you believe something we hold is inaccurate, out of date, incomplete or misleading, we'll take reasonable steps to correct it — free of charge, within 30 days. If we don't agree that it's wrong, you can ask us to attach a statement of your view to the record, and we will.
Also worth knowing: many of your source records live in your systems too — your Xero file is yours, and your Box client folder gives you year-round access to the documents we hold for you. Transparency isn't a request process here; it's built into how we work.
Questions, concerns and complaints
If you have any question or concern about how we've handled your personal information, please tell us — directly, and first. We genuinely want to know.
Step 1 — Contact our Privacy Officer:
Niki Cotter, Director & Privacy Officer
The Ethical Accountant Pty Ltd
Email:clients@ethicalaccountant.au
Post: PO Box 600, Redbank Plains QLD 4301
Or via the contact page
We will acknowledge your complaint promptly, investigate it properly, and respond within 30 days. Because you deal directly with Niki — there are no junior hand-offs — your complaint goes straight to the person who can fix it.
Step 2 — If you're not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC), the national privacy regulator. The OAIC generally expects you to have complained to us first and given us 30 days to respond.
Office of the Australian Information Commissioner
Online: www.oaic.gov.au
Phone: 1300 363 992
Post: GPO Box 5288, Sydney NSW 2001
Complaints about our tax agent services (rather than privacy) can also be made to the Tax Practitioners Board, and complaints about professional conduct to CPA Australia. We'll never treat a complaint as a mark against you — it's information that helps us improve.
Changes to this policy
We review this policy at least annually, and whenever the law or our practices change. The current version is always at ethicalaccountant.au/privacy. If we make a material change — especially to how we use your information — we'll post a notice on our website and email our clients at least 30 days before it takes effect.


