X
  • About
  • Advertise
  • Contact
Get the latest news! Subscribe to the SMSF Adviser bulletin
  • News
    • Money
    • Education
    • Strategy
  • Webcasts
  • Features
  • Events
  • Podcasts
  • Promoted Content
No Results
View All Results
  • News
    • Money
    • Education
    • Strategy
  • Webcasts
  • Features
  • Events
  • Podcasts
  • Promoted Content
No Results
View All Results
Home News

ATO releases data breach guidance for professionals

With the notifiable data breaches scheme to commence from 22 February, the ATO has released updated guidance for tax professionals for dealing with data breaches and protecting against refund and superannuation fraud.

by Miranda Brownlee
January 8, 2018
in News
Reading Time: 3 mins read
Share on FacebookShare on Twitter

In a public communication on its website, the ATO said tax professionals hold a large amount of client, staff and business information, and have therefore become a target for identity thieves.

“Tax professionals who experience a data breach may discover their clients’ identities have been stolen, and refund fraud committed in the client’s name,” said the ATO.

X

A data breach occurs, the ATO explained, when confidential taxpayer information has been accessed by an unauthorised third party.

Examples can include unauthorised removal of computers, data or records in both paper and digital formats; criminals exploiting vulnerabilities in IT security controls, hacking or phishing for information; or people with legitimate access to the data using it for fraudulent means, said the ATO.

It could also include accidental disclosure of information, for example, records emailed to an unauthorised third party or hard copies left in a public place, the ATO said.

“Tax professionals are encouraged to report data breaches to us to ensure protective measures can be placed on client accounts, protecting them and government revenue from further harm,” the ATO recommended.

The ATO said that were a firm has experienced a breach it recommends that the practitioner contacts the ATO as soon as practicable and contacts the Office of the Australian Information Commissioner (OAIC) to ensure that they comply with any obligations under the Notifiable Data Breach Scheme (NDBS).

“Data breaches are often a precursor for refund fraud. The ATO has sophisticated mechanisms in place for identifying and protecting against potential refund and superannuation fraud that assist in meeting our obligation to protect government revenue,” it stated.

The tax professional should also inform impacted clients and staff of the data breach and contact their software supplier if they suspect the breach may have originated in one of their service offerings.

“Consider what information was accessed during the breach and take steps to safeguard this where necessary – for example, you may need to cancel your AUSkey,” the ATO advised.

“Take steps to secure the information in your business by ensuring all security software and controls are up-to-date [and] review systems access and remove it for people who no longer require it.”

The ATO said that if a data breach occurs within a practice, it may implement a range of additional safeguards to protect clients and government revenue.

“We may issue an alert to our staff requiring them to seek additional proof of record ownership from your client,” said the ATO.

“The requirement will apply when your client interacts with us. The alert prompts our staff to ask additional questions when validating your client’s identity. This alert does not prevent you from dealing with us on behalf of your client or change how we will identify you.”

The tax office said it will also continue to monitor the client’s ATO records where a breach has occurred.

“If we identify any irregular activity, we may contact you or your client to ensure the activity is legitimate. This may delay our processing of income tax returns and other forms,” it explained.

“Depending on your client’s circumstances, we may also apply additional security measures within our systems. These measures prevent particular activity where we perceive increased risk to clients, government revenue or both.”

In some cases, the ATO said it may assign a data breach manager who will assist professionals in the management of data breaches within their practice.

“The data breach manager may provide support to lessen the impact of the data breach on your practice and your client,” said the ATO.

“Information security is an important aspect of your business. It’s important you keep all your business, staff and client information secure. If your data is lost or compromised, it can be very difficult and costly to recover.”

Tags: News

Related Posts

Plan overseas travel so fund stays compliant

by Keeli Cambourne
December 15, 2025

Michael Hallinan, special counsel for SUPERCentral said to ensure that any overseas travel doesn’t impact the status of the fund,...

Unused cap space available to new Australian residents

by Keeli Cambourne
December 15, 2025

Matthew Richardson, SMSF manager for Accurium, said on a recent webinar that it is possible to take into account unused...

Under-18s super carve-out widens the gender gap

by Keeli Cambourne
December 15, 2025

The Super Members Council is urging the government to  scrap the law after new analysis shows it widens the gender...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Join our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.
SMSF Adviser is the authoritative source of news, opinions and market intelligence for Australia’s SMSF sector. The SMSF sector now represents more than one million members and approximately one third of Australia's superannuation savings. Over the past five years the number of SMSF members has increased by close to 30 per cent, highlighting the opportunity for engaged, informed and driven professionals to build successful SMSF advice business.

Subscribe to our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

About Us

  • About
  • Advertise
  • Contact
  • Terms & Conditions
  • Privacy Collection Notice
  • Privacy Policy

Popular Topics

  • News
  • Strategy
  • Money
  • Podcasts
  • Promoted Content
  • Feature Articles
  • Education
  • Video

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited

No Results
View All Results
NEWSLETTER
  • News
  • Money
  • Education
  • Strategy
  • Webcasts
  • Features
  • Events
  • Podcasts
  • Promoted Content
  • About
  • Advertise
  • Contact Us

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited