top of page

Privacy Policy

A CPA Practice • Registered Tax Agent • ASIC Registered Agent • AUSTRAC-enrolled reporting entity

Effective date: 23 July 2026 (replaces the policy dated 7 January 2025)

Next review due: July 2027

Privacy Officer: Niki Cotter, Director
 

Our promise to you, in plain English

We're accountants. That means you trust us with some of the most sensitive information you have — your tax file number, your income, your bank details, your business finances, and even your identity documents. We take that trust seriously.

This policy explains, in plain language, what information we collect, why we collect it, where it's stored, who we share it with (and who we don't), and what your rights are. No jargon, no fine print tricks. If anything here isn't clear, ask us — explaining things clearly is what we do.

We are bound by the Privacy Act 1988 (Cth) and all 13 Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme, the confidentiality obligations in the Tax Practitioners Board (TPB) Code of Professional Conduct, the Tax Agent Services Act 2009, CPA Australia's professional and ethical standards (including APES 110, the accounting profession's Code of Ethics), the Privacy (Tax File Number) Rule 2015, and the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. As an AUSTRAC-enrolled reporting entity, we are covered by the Privacy Act in full for the information we handle — there is no "small business exemption" hiding behind this policy.

Three commitments up front:

1    We will never sell your personal information. Not to marketers, not to "business partners", not to anyone.
2    We only collect what we genuinely need to do our work for you or to meet a legal obligation.
3    Your sensitive documents live in one secure place — our encrypted Box document storage — and we will never ask you to email them to us.
 

Who this policy covers

This policy applies to personal information we collect and hold about our clients, former clients, prospective clients, and the people connected to them — for example, the directors, shareholders, beneficiaries, employees and family members of the businesses we act for. It also applies to visitors to our website and people who contact us or subscribe to our updates.

Personal information is any information or opinion about an identified individual, or an individual who is reasonably identifiable — your name, contact details, financial details, tax file number, and so on. Sensitive information is a special category given extra protection under the law, and includes things like health information and biometric information (more on that below, because identity verification involves it).

This policy doesn't cover the privacy practices of other organisations, such as the ATO, ASIC or the software providers we use — they have their own privacy policies, and we link to the important ones below.

What information we collect

Because of the work we do, we collect more than just your name and email. Depending on the services you engage us for, this typically includes:

Category

Identity and contact details

Government identifiers

Identity verification records

Financial information

Business and entity records

Engagement records

Website and email data

Examples

Name, date of birth, address, phone, email, occupation

Tax file number (TFN), ABN, director ID — handled under strict rules (see below)

The information from your driver licence or passport (such as name, date of birth and document number), verification results, and politically exposed person (PEP) and sanctions screening results collected through our identity verification provider, Annature

Income, expenses, assets, liabilities, superannuation, investments, bank account details, payroll records

Company constitutions, registers, officeholder details, trust deeds, minutes, resolutions, beneficial ownership information

Engagement letters, correspondence of substance, file notes, workpapers, signed declarations

Basic analytics about visits to our Wix website, and email correspondence

About your family and your team. If you give us personal information about someone else — your spouse, your adult children, your employees — please make sure you have their permission, and let them know this policy exists. We treat their information with the same care as yours.

Sensitive information. We don't set out to collect sensitive information, and we'll never ask for it unless it's genuinely necessary. There are two situations where it can arise in our work. First, biometric verification: when we verify your identity through Annature, the verification process may use facial biometric matching (comparing a selfie to your ID document). Biometric information is sensitive information under the Privacy Act, so we will always ask for your consent before this happens and explain the process. We keep the verification report — not your raw biometric data, which is handled under Annature's certified security arrangements. Second, occasionally sensitive information appears in the ordinary course of our work — for example, a health-related expense in your records, or a PEP screening result that touches on political association. We only use it for the purpose it was provided or as the law requires.

Your tax file number. TFNs have their own special legal protection under the Privacy (Tax File Number) Rule 2015. We only collect, use and disclose your TFN for tax-related purposes (such as preparing and lodging your returns with the ATO), we restrict access to it, we store it securely in Box, and we never include it in ordinary emails. Misusing a TFN is a criminal offence, and we treat TFN security as non-negotiable.

If you'd rather stay anonymous. You're welcome to browse our website, read our resources, or make a general enquiry without identifying yourself, or while using a pseudonym. But once we act for you as your tax agent, the law requires us to know exactly who you are — anonymity isn't an option for tax, ASIC or anti-money laundering work, and we couldn't do our job properly without it.

Why we collect your information

We collect and use your personal information for these purposes:

1

To provide our services — tax returns, BAS, financial statements, FBT, cash flow and budgeting support, business advisory, review engagements, Xero setup and support, and ASIC corporate compliance.

2

To meet our legal and professional obligations — including tax law, the Tax Agent Services Act 2009, the Corporations Act 2001, the AML/CTF Act, and the record-keeping standards set by the TPB and CPA Australia.

3

To verify your identity — which both the TPB and the AML/CTF Act require us to do before we act for you (see the dedicated section below).

4

To communicate with you — appointment reminders, lodgement due dates, questions about your work, and educational updates we think will genuinely help you.

5

To run our practice — quality reviews, professional indemnity insurance, complaint handling, and practice administration.

We won't use your information for an unrelated purpose without your consent, unless the law requires or permits it — and where that happens, we'll tell you unless the law prevents us from doing so (see the AUSTRAC section below for the one situation where we legally can't tell you).

If we receive information we didn't ask for. Sometimes people send us personal information we didn't request. If we could have lawfully collected it, we file it securely; if not, we destroy or de-identify it as soon as practicable. And if you email us something sensitive that should have gone through our secure channel, we move it to Box and delete the email — then gently remind you of the secure way to send it.

Identity verification and our anti-money laundering obligations

This section matters, so we want to explain it properly.

From 1 July 2026, accountants providing certain services became regulated under Australia's anti-money laundering and counter-terrorism financing laws (the AML/CTF Act — often called the "Tranche 2" reforms). The Ethical Accountant Pty Ltd is enrolled with AUSTRAC, the Australian Government's financial intelligence agency, as a reporting entity.

What this means for you as a client:

1

We must verify your identity before we act for you. This is a legal requirement, not us being difficult. We use Annature — an Australian, ISO 27001-certified platform that stores its identity verification data onshore in Australia — and we use it only for identity verification and AML/CTF checks, nothing else. We will never ask you to email us a photo of your driver licence or passport. If you email one anyway, we'll move it to secure storage, delete the email, and show you the proper process.

2

For companies, trusts and partnerships, we must identify the real people behind the entity — the "beneficial owners" — and in some cases ask about the source of funds for a transaction. Again, the law requires this.

3

We keep records of these checks for at least 7 years after our relationship ends, as the law requires. Consistent with current OAIC guidance, we keep the verification details and results rather than holding copies of your full identity documents any longer than needed.

4

We may be legally required to report certain matters to AUSTRAC — for example, if we form a suspicion on reasonable grounds about money laundering, terrorism financing or serious criminal activity such as tax evasion. Here is the part we want to be completely honest about: if we ever lodge a suspicious matter report, the law prohibits us from telling you. This is called the "tipping off" prohibition, and breaching it is a criminal offence. It also means that, in rare cases, the law may prevent us from giving you access to certain information or explaining why. We're telling you this now, in general terms, because transparency about the rules we operate under is exactly what this practice stands for — even the rules that limit what we can say.

The Privacy Act does not stand in the way of these legal obligations, but it does require us to collect no more than necessary, keep it secure, and be upfront with you about the process — which is what this section is for.

How we collect and store your information

How we collect it. Mostly, directly from you — in meetings, phone calls, emails, through your secure Box folder, through Annature identity verification, and through the documents you provide. We also collect information from third parties where our work requires it: the ATO (through the Tax Agent Portal), ASIC (through NowInfinity), your Xero accounting file, your previous accountant (with your authority), and publicly available registers such as the ABR and ASIC registers.

Where it lives. We believe you deserve to know exactly which systems hold your information. These are the only systems we use for client work, each protected by multi-factor authentication (MFA) with strong, unique passwords held in a dedicated, MFA-protected password manager:

System

Whats it used for

What its not used for

Box

Our sole document storage platform. Every client document, workpaper and record lives here, in your own secure, encrypted client folder — which is also how we exchange sensitive documents with you

----

Annature

Identity verification and AML/CTF checks only (Australian-hosted, ISO 27001 certified)

General document signing

Adobe / Adobe Sign

Engagement letters, reports, forms, and all electronic signatures (other than identity verification)

Identity verification

XPM (Xero Practice Manager)

Practice management — client records, job tracking, tax return preparation and lodgement

----

Xero

Accounting and bookkeeping data for our firm and our clients

----

NowInfinity

ASIC corporate compliance — company statements, changes and registers

----

Google Workspace

Email (Gmail) and calendar only, for general, non-sensitive communication

Document storage. We do not use Google Drive — Box is our sole document storage platform, chosen for its superior security

Wix

Our website and marketing pages

Client data of any kind

Why the "email rule" matters. Email is convenient but it is not a secure way to send financial documents or identity information. That's why we will never send your tax return, financial statements or other sensitive documents as ordinary email attachments — they're delivered through your secure Box folder or Adobe Sign — and why we ask you never to email us TFNs, bank details, identity documents or financial records. At onboarding we'll show you how to use your Box folder; it's easy, and it keeps you safe.

Paper documents are the exception, not the rule. Anything on paper is scanned into Box and the paper is cross-cut shredded. Our devices are password- or biometric-protected and kept up to date, and screens are locked when unattended.

How long we keep it. We keep client records for a minimum of 7 years, which meets or exceeds the requirements of tax law, the TPB and the AML/CTF Act. When your information is no longer needed for any purpose we're allowed to keep it for, we take reasonable steps to destroy or de-identify it securely.

Who we share your information with — and who we don't

We treat your information as confidential. That's not just this policy talking: as a registered tax agent, Niki is bound by the confidentiality obligation in the TPB Code of Professional Conduct (which prohibits disclosing your information to third parties without your permission unless there's a legal duty to do so), and as a CPA, by the fundamental principle of confidentiality in APES 110, the accounting profession's Code of Ethics. That confidentiality continues even after you stop being a client.

We disclose your information only in these circumstances:

Who

Why

ATO

To prepare and lodge your returns, activity statements and other documents, and to communicate with the ATO on your behalf as your registered tax agent

ASIC

To lodge company documents and maintain your corporate compliance — strictly within the authority you give us (Form 362). Remember that officeholder and company details lodged with ASIC become part of the public record under the Corporations Act 2001

AUSTRAC

Where the AML/CTF Act requires us to report (see the section above — in the case of a suspicious matter report, the law prevents us from telling you)

TPB, CPA Australia and other regulators

Where we're legally required to — for example, TPB investigations, or breach reporting obligations under the tax agent laws

CPA Australia's Best Practice Program

If our practice is selected for a quality review, a reviewer may see client files. Reviewers are bound by strict confidentiality, and information disclosed is handled under the CPA Australia Privacy Policy

Our qualified accountant colleague

If you engage us for SMSF work, it is prepared by a qualified accountant colleague on our behalf, under the same confidentiality obligations — and we'll always tell you when this applies to your work

Our software providers

The platforms in the table above process or store your information so we can serve you. Each one is security-assessed before we rely on it, and none is permitted to use your information for its own purposes

Professional advisers

Our own legal or professional advisers, or your other advisers (such as your lawyer or finance broker) — but only with your consent

As otherwise required or permitted by law

For example, a court order or a statutory notice

Who we don't share it with. We do not sell, rent or trade your personal information. We do not share it with marketing companies, data brokers or advertisers. We do not use third-party behavioural advertising networks. We do not disclose your information to "business partners" for joint offers. If we ever sell the practice, client files would only transfer with proper safeguards and you would be notified beforehand with the ability to make choices about your information.

Overseas disclosure — where your data is hosted

Like nearly every modern Australian practice, we use cloud software, and some of those providers host data outside Australia. Under the Privacy Act (APP 8) we have to tell you about this, and we want to be specific rather than vague:

Provider

Likely hosting location

Annature (identity verification)

Australia

NowInfinity (ASIC compliance)

Australia

Box, Xero, XPM, Adobe, Google Workspace

United States, and in some cases other regions such as the European Union, on enterprise cloud infrastructure

Before we adopt any tool, we assess its security certifications, encryption and data-hosting arrangements, and we take reasonable steps to ensure overseas providers handle your information consistently with the Australian Privacy Principles. We do not send your information overseas for any other reason.

Direct marketing — our educational updates

Part of our philosophy is education: we occasionally send clients and subscribers genuinely useful updates — lodgement deadline reminders, legislative changes that affect small businesses, and practical guidance. We only send these to people who would reasonably expect them or who have opted in, and every marketing email includes a working unsubscribe link. You can also opt out at any time by emailing us at clients@ethicalaccountant.au or using the contact page — we'll action it promptly.

Opting out of marketing never affects the service messages you need as a client, such as lodgement due dates, document requests and appointment confirmations. And because we don't give your details to third parties for their marketing, there's nothing to opt out of on that front.

Our website

Our website runs on Wix and holds no client data. Like most websites, it collects basic technical information (browser type, pages visited, and similar analytics data) through cookies to keep the site working and help us understand what visitors find useful. You can block or delete cookies in your browser settings; the site will still work. We don't use tracking for third-party advertising. Anything you submit through the contact form comes to us by email — please don't include sensitive financial details in it; just tell us how to reach you and we'll set up a secure channel.

If something goes wrong: data breaches and the NDB scheme

No system on earth is breach-proof, so we'd rather tell you honestly what we've done to prepare than pretend it could never happen.

Prevention: multi-factor authentication on every system, unique passwords in a dedicated MFA-protected password manager, a single encrypted document platform (Box) instead of scattered copies, no sensitive data in email, security-assessed vendors, and prompt software updates.

Response: we are subject to the Notifiable Data Breaches (NDB) scheme under the Privacy Act, and if a breach ever occurs we will follow it:

1

Contain — immediately secure the affected system (password rotation, vendor notification, access revocation).

2

Assess — investigate whether the breach is likely to result in serious harm to any individual. The law allows up to 30 days for this assessment; we aim to move much faster.

3

Notify — if serious harm is likely and can't be prevented by remedial action, we will notify the Office of the Australian Information Commissioner (OAIC) and each affected person as soon as practicable, telling you what happened, what information was involved, and what steps you should take to protect yourself.

4

Learn — conduct a root-cause review and fix whatever allowed it to happen.

(In the unusual event that a legal secrecy provision — such as the AML/CTF tipping off prohibition — prevents part of a notification, we notify to the fullest extent the law allows.)

Your rights: access, correction and control

You can ask to see your information (APP 12). Just ask — by email or through your Box folder. We'll need to confirm your identity (usually easy, since we've verified it already), and we'll respond within 30 days, normally much sooner. For most requests there is no charge; if a request is unusually large we may charge a reasonable cost-recovery fee for our time, and we'll tell you before doing any work. Access can only be refused in limited situations set out in the Privacy Act — for example, where it would unreasonably affect someone else's privacy or where the law prohibits it. If we refuse, we'll give you written reasons and your complaint options, except in the rare case where the law itself prevents us from explaining.

You can ask us to correct your information (APP 13). Accurate information matters enormously in tax work, so please tell us whenever your details change. If you believe something we hold is inaccurate, out of date, incomplete or misleading, we'll take reasonable steps to correct it — free of charge, within 30 days. If we don't agree that it's wrong, you can ask us to attach a statement of your view to the record, and we will.

Also worth knowing: many of your source records live in your systems too — your Xero file is yours, and your Box client folder gives you year-round access to the documents we hold for you. Transparency isn't a request process here; it's built into how we work.

Questions, concerns and complaints

If you have any question or concern about how we've handled your personal information, please tell us — directly, and first. We genuinely want to know.

Step 1 — Contact our Privacy Officer:

Niki Cotter, Director & Privacy Officer
The Ethical Accountant Pty Ltd
Email:clients@ethicalaccountant.au

Post: PO Box 600, Redbank Plains QLD 4301
Or via the contact page

 

We will acknowledge your complaint promptly, investigate it properly, and respond within 30 days. Because you deal directly with Niki — there are no junior hand-offs — your complaint goes straight to the person who can fix it.

 

Step 2 — If you're not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC), the national privacy regulator. The OAIC generally expects you to have complained to us first and given us 30 days to respond.

Office of the Australian Information Commissioner

Online: www.oaic.gov.au

Phone: 1300 363 992
Post: GPO Box 5288, Sydney NSW 2001

Complaints about our tax agent services (rather than privacy) can also be made to the Tax Practitioners Board, and complaints about professional conduct to CPA Australia. We'll never treat a complaint as a mark against you — it's information that helps us improve.

Changes to this policy

We review this policy at least annually, and whenever the law or our practices change. The current version is always at ethicalaccountant.au/privacy. If we make a material change — especially to how we use your information — we'll post a notice on our website and email our clients at least 30 days before it takes effect.

Niki Cotter

22 years supporting small to medium businesses • Xero specialist • Direct access to your accountant​

Turn your Xero numbers into clear, confident decisions.

The Ethical Accountant partners with small business owners to build honest numbers, strong cash flow, and decisions you can stand behind.

The Ethical Accountant provides ethical small business accounting and advisory services for Xero-based businesses, supporting cash flow clarity, compliance, and sustainable growth.

bottom of page