Gazette notice: Commissioner of Taxation - Notice of an AFCX data-matching program 11 August 2025
The Australian Taxation Office (ATO) will acquire relevant account and transaction data from Australian Financial Crimes Exchange (AFCX) for the 2024-25 financial year through to 2026-27 financial year.
The data items include:
- Client identification details (names, addresses, phone numbers, dates of birth, identity verification document details, IP addresses etc)
- Bank account transaction details (bank account details, transaction date and amount, IP addresses etc).
We estimate that records relating to approximately 70,000 individuals will be obtained each financial year.
For this data-matching program, we will match AFCX data against ATO records and other data holdings.
The data collected under this program will be used to:
- safeguard taxpayer accounts from identity crime by implementing protective controls to enable pre-lodgment detection and application of treatments to victims of fraud
- identify, detect, monitor and treat new emerging risks and behaviour patterns which may significantly impact the integrity of the tax and superannuation systems
- compare to our records and other data holdings, as part of the methodologies by which we select taxpayers for compliance activities
- provide insights through models and analysis that support our regulatory approach, to reduce the impact of financial scam and crime.
The objectives of this program are to:
- protect taxpayer records from identity crime and unauthorised access by detecting, preventing and/or mitigating risks of unlawful registration, lodgment, and refund fraud
- build intelligence about scam, fraud and crime activities and threats in the financial ecosystem to strengthen integrity of the tax and superannuation systems and develop treatment strategies
- address new and emerging risks through enhanced intelligence capabilities to reduce the impact of financial scams and crimes on taxpayers, mitigate tax revenue risk and protect the Australian community
- detect, investigate and/or prosecute perpetrators of financial crime activity including identity takeover, money laundering or serious and organised crime.
A document describing this program is available at ato.gov.au/dmprotocols.
This program follows the Office of the Australian Information Commissioner’s (OAIC) (2014) Guidelines on data matching in Australian Government administration (the guidelines). The guidelines include standards for the use of data matching as an administrative tool in a way that:
- complies with the Australian Privacy Principles (APPs) and the Privacy Act 1988 (Privacy Act)
- is consistent with good privacy practice.
A full copy of the ATO’s privacy policy can be accessed at ato.gov.au/privacy
Overview
The Commissioner of Taxation has introduced a data-matching program in accordance with the Australian Taxation Office (ATO) Notice of an AFCX data-matching program 11 August 2025. This initiative aims to address the problem of identity crime and the integrity of the tax and superannuation systems by leveraging data from the Australian Financial Crimes Exchange (AFCX) for the 2024-25 to 2026-27 financial years. The program seeks to acquire detailed client identification and transaction data from approximately 70,000 individuals annually. The primary objective of this data-matching program is to safeguard taxpayer accounts, detect emerging risks, and enhance the ATO's regulatory approach to combat financial scams and crimes. The program adheres to the Office of the Australian Information Commissioner's Guidelines on data matching in Australian Government administration, ensuring compliance with the Australian Privacy Principles and the Privacy Act 1988.
Scope and Application
The data-matching program announced by the Commissioner of Taxation through the Australian Taxation Office (ATO) for the 2024-25 to 2026-27 financial years aims to acquire relevant account and transaction data from the Australian Financial Crimes Exchange (AFCX). This program is intended to enhance the integrity of the tax and superannuation systems by safeguarding taxpayer accounts from identity crime and unauthorised access, thereby detecting, preventing, and mitigating risks of unlawful activities such as registration, lodgment, and refund fraud. The data collected, which includes client identification details and bank account transaction details, will be matched against ATO records and other data holdings to identify new emerging risks, detect fraudulent behaviour, and support regulatory approaches to reduce financial scams and crimes. This initiative applies to approximately 70,000 individuals each financial year, and it adheres to the Australian Privacy Principles (APPs) and the Privacy Act 1988, ensuring compliance with privacy standards as outlined by the Office of the Australian Information Commissioner’s (OAIC) Guidelines on data matching. A comprehensive description of this program is available on the ATO’s website, and their privacy policy can be accessed to understand how personal information will be managed and protected.
Key Provisions
The main operative sections of this legislation detail the Australian Taxation Office's (ATO) acquisition and usage of financial transaction data from the Australian Financial Crimes Exchange (AFCX) over the 2024-25 to 2026-27 financial years. Under section 1, the ATO will obtain detailed client identification and bank transaction data from AFCX, covering approximately 70,000 individuals annually. This data, as outlined in section 2, will be used to safeguard taxpayer accounts from identity crime, identify emerging risks impacting the tax and superannuation systems, select taxpayers for compliance activities, and support regulatory approaches to reduce financial crime. The objectives, as stated in section 3, include protecting taxpayer records from identity crime, building intelligence on financial threats, addressing new risks, and prosecuting financial crime perpetrators. The program adheres to the Office of the Australian Information Commissioner’s Guidelines on data matching and complies with the Australian Privacy Principles and Privacy Act 1988.
The Act imposes specific obligations on both the ATO and AFCX. For the ATO, it mandates the acquisition and use of AFCX data for the stated objectives, ensuring compliance with privacy principles and good privacy practices. It also requires the ATO to safeguard the data obtained and use it solely for the purposes outlined in the legislation. AFCX, on the other hand, is required to provide the necessary data to the ATO in a manner consistent with the guidelines and privacy laws. Both entities must ensure that the data-matching program is conducted transparently and that any data breaches are promptly addressed.
The legislation does not explicitly state specific offences or penalties for breaches within the text provided. However, any failure to comply with the privacy principles under the Privacy Act 1988 could lead to significant civil and criminal consequences. Under the Privacy Act, unauthorised collection, use, or disclosure of personal information can result in substantial penalties. For serious and repeated contraventions, the maximum civil penalty can be up to $2.1 million for corporations and $210,000 for individuals. Additionally, criminal penalties can apply, including fines and imprisonment for officers of corporations found guilty of serious breaches. The ATO and AFCX must therefore ensure strict adherence to privacy standards to avoid these severe repercussions.