Handling and security Current
Redacting or masking sensitive information like TFNs in client records
A practical approach to keeping high-risk identifiers out of everyday files.
A tax file number doesn't need to appear in every working file a client's matter touches. This guide sets out a practical approach to keeping it, and similar identifiers, out of normal use. It is general information, not legal or compliance advice.
Action plan
1 Understand the TFN Rule governs how TFNs are handled TFN handling is regulated separately from general privacy obligations.
The Privacy (Tax File Number) Rule 2015, issued under the Privacy Act, specifically regulates the collection, storage, use, disclosure, security, and disposal of individuals' tax file number information. It's legally binding, and a breach is treated as an interference with privacy. Treat TFN handling as its own, more specific set of obligations, not just an extension of general client-data practice.
- Recognise TFN information is governed by its own binding rule, not just general privacy practice
- Apply that stricter standard specifically to TFN fields, not client data generally
- Escalate uncertainty about TFN handling rather than guessing
Done when: TFN handling in the record is confirmed to follow the TFN Rule's stricter standard
OAIC: tax file numbers2 Mask the TFN in normal working views A masked TFN is still available when genuinely needed, without being visible by default.
Masking a TFN in the views staff normally work in, so it's only revealed when there's a role-authorised reason to see it in full, reduces how often the full number is exposed without removing it from the record entirely.
- Mask TFNs by default in accountant and client-facing views
- Require a role-authorised reason to reveal the full TFN
- Audit each time a masked TFN is revealed
Done when: TFNs are masked by default in normal working views and revealed only for an audited, authorised reason
3 Keep TFNs out of logs, exports, and everyday correspondence A TFN in a log file or email thread is much harder to control than one kept in a single restricted field.
Beyond masking in the main record, check that TFNs don't end up copied into normal logs, analytics, support correspondence, or general exports, where they're harder to track and control than in the original restricted field.
- Exclude TFNs from normal system logs, analytics, and monitoring output
- Avoid pasting TFNs into support tickets, emails, or general correspondence
- Check exports and reports don't include TFN fields by default
Done when: TFNs are confirmed absent from normal logs, exports, and everyday correspondence