Gazette notice: Commissioner of Taxation – Notice of an Officeholder data-matching program 26 August 2024
The Australian Taxation Office (ATO) will acquire officeholder data from the Australian Securities and Investments Commission (ASIC), the Office of the Registrar of Indigenous Corporations (ORIC), the Australian Charities and Not-for-profits Commission (ACNC), and the Australian Business Registry Service (ABRS) for 2023–24 through to 2026–27.
The data items include:
- name, address, date of birth, Australian business number, email address, contact phone number, business name, organisation class, organisation type, organisation status, state of incorporation, officeholder type, role type, officeholder role start and end dates as recorded on the publicly available ASIC Companies register, the ORIC register of Aboriginal and Torres Strait Islander corporations, and the ACNC Charity Register.
We estimate that records relating to more than 11 million individuals will be obtained.
The objectives of the Officeholder data-matching program are to:
- enable Australian Business Registry Services (ABRS) to increase uptake of the director identification number (director ID) through better information on officeholders recorded by the Australian Securities and Investments Commission (ASIC), the Office of the Registrar of Indigenous Corporations (ORIC) and the Australian Charities and Not-for-profits Commission (ACNC)
- effectively link persons known to the Australian Taxation Office (ATO) to officeholders and their associated companies as recorded on the ASIC Companies register, the ORIC Register of Aboriginal and Torres Strait Islander corporations, and the ACNC Charity Register
- promote voluntary compliance and strengthen community confidence in the integrity of the tax and super systems by publicising the running of this data-matching program
- identify and educate company officeholders who may be failing to meet their registration and ongoing payment, withholding, or lodgment obligations and assist them to comply
- Identify and educate new company officeholders of their director ID obligations
- Identify and contact company office holders to confirm registration details including contact numbers, addresses or names
- help ensure company officeholders are fulfilling their tax and super reporting and compliance obligations
- identify, deter, and disrupt those promoting or engaging in illegal phoenix activity
- better utilise registry data to combat unlawful activity.
A document describing this program is available at ato.gov.au/dmprotocols
This program follows the Office of the Australian Information Commissioner’s Guidelines on data matching in Australian Government administration (2014) (the guidelines). The guidelines include standards for the use of data matching as an administrative tool in a way that:
- complies with the Australian Privacy Principles (APPs) and the Privacy Act 1988 (Privacy Act)
- is consistent with good privacy practice.
A full copy of the ATO’s privacy policy can be accessed at ato.gov.au/privacy
Overview
The Australian Taxation Office (ATO) has introduced the Officeholder data-matching program, which is set to operate from the 2023–24 financial year through to 2026–27. This initiative was enacted under the authority of the Commissioner of Taxation Notice 2024/D1, published in the Commonwealth of Australia Gazette on 26 August 2024. The primary aim of this program is to acquire officeholder data from the Australian Securities and Investments Commission (ASIC), the Office of the Registrar of Indigenous Corporations (ORIC), the Australian Charities and Not-for-profits Commission (ACNC), and the Australian Business Registry Service (ABRS) to enhance compliance and ensure the integrity of the tax and superannuation systems. The program seeks to achieve this by facilitating better information on officeholders, linking individuals to their associated companies, promoting voluntary compliance, identifying non-compliant officeholders, and combating illegal phoenix activity. This program adheres to the Office of the Australian Information Commissioner’s Guidelines on data matching in Australian Government administration (2014), ensuring compliance with the Australian Privacy Principles and the Privacy Act 1988.
Scope and Application
The Commissioner of Taxation – Notice of an Officeholder data-matching program 2024, as published in the Gazette, outlines the Australian Taxation Office's (ATO) intention to acquire officeholder data from several regulatory bodies including the Australian Securities and Investments Commission (ASIC), the Office of the Registrar of Indigenous Corporations (ORIC), the Australian Charities and Not-for-profits Commission (ACNC), and the Australian Business Registry Service (ABRS) for the financial years 2023–24 through to 2026–27. This data encompasses personal information such as name, address, date of birth, Australian business number, email address, contact phone number, business name, and organisational details such as organisation class, type, status, and state of incorporation. The data will also include officeholder information such as type, role type, and officeholder role start and end dates as recorded on publicly available registers. It is estimated that over 11 million individuals will be affected by this data acquisition.
The program aims to enhance the uptake of director identification numbers (director ID) by ensuring officeholder information is accurately linked with associated companies. It also seeks to promote voluntary compliance and community confidence in the tax and superannuation systems, identify and assist officeholders who may be non-compliant, and identify and disrupt illegal phoenix activity. This data-matching initiative adheres to the Office of the Australian Information Commissioner’s Guidelines on data matching in Australian Government administration (2014), which ensure compliance with the Australian Privacy Principles (APPs) and the Privacy Act 1988. The program's scope extends to all officeholders within the specified timeframe and across the participating regulatory bodies, with no explicit exclusions or exemptions noted in the gazette notice.
Key Provisions
The main operative sections of this legislation (C2024G00495) detail the acquisition and usage of officeholder data by the Australian Taxation Office (ATO) from various regulatory bodies. Specifically, section 1 states that the ATO will obtain data from the Australian Securities and Investments Commission (ASIC), the Office of the Registrar of Indigenous Corporations (ORIC), the Australian Charities and Not-for-profits Commission (ACNC), and the Australian Business Registry Service (ABRS) for the financial years 2023–24 through 2026–27. Section 2 outlines the specific data items that will be collected, including personal and organisational details of officeholders. These sections are fundamental as they set the parameters for the data-matching program, ensuring that the ATO has the necessary information to achieve its objectives.
The obligations imposed by this Act are primarily on the ATO and the entities from which it is acquiring data. The ATO must ensure that the data obtained is used strictly for the stated objectives, which include increasing director identification number (director ID) uptake, linking individuals with their associated companies, and promoting compliance. The regulatory bodies such as ASIC, ORIC, ACNC, and ABRS are required to provide the requested data to the ATO within the specified timeframes. Furthermore, the Act mandates that all parties comply with the Australian Privacy Principles (APPs) and the Privacy Act 1988, ensuring that privacy and data protection standards are upheld during the data-matching process.
Breaching the provisions of this Act can result in significant consequences. While the gazette does not explicitly detail the penalties for non-compliance, general Australian law provides a framework for penalties associated with breaches of privacy and data handling regulations. Under the Privacy Act 1988, unauthorised collection, use, or disclosure of personal information can lead to civil penalties, with maximum fines for serious or repeated breaches reaching up to AUD 2.1 million for corporations and AUD 420,000 for individuals. Additionally, criminal penalties may apply for more severe breaches, including imprisonment for up to two years for individuals and higher fines for corporations. These penalties underscore the importance of adhering to the Act's requirements to avoid legal repercussions.