Gazette notice: Commissioner of Taxation – Notice of an Officeholder data-matching program 3 November 2023

Administered by Department of the Treasury

Legislation au C2023G01171 In force Gazette

Legislation content

Gazette notice: Commissioner of Taxation – Notice of an Officeholder data-matching program 3 November 2023

The Australian Taxation Office (ATO) will acquire officeholder data from the Australian Securities and Investments Commission (ASIC), the Office of the Registrar of Indigenous Corporations (ORIC) and the Australian Charities and Not-for-profits Commission (ACNC) for 2023-24 through to 2024-25.

The data items include:

          name, address, date of birth, Australian business number, email address, contact phone number, business name, organisation class, organisation type, organisation status, state of incorporation, officeholder type, role type, officeholder role start and end dates as recorded on the publicly available ASIC Companies Register, the ORIC register of Aboriginal and Torres Strait Islander corporations, and the ACNC Charity register.


We estimate that records relating to approximately 11 million individuals will be obtained.

The objectives of the Officeholder data-matching program are to:

          enable the ABRS to increase uptake of the director ID through better information on officeholders recorded by ASIC, ORIC, and the ACNC Commission.

          effectively link persons known to the ATO to officeholders and their associated companies as recorded on the ASIC Companies Register, the ORIC register of Aboriginal and Torres Strait Islander corporations, and the ACNC Charity register.

          issue effective correspondence with officeholders regarding their director ID obligations.

          identify, deter, and disrupt those promoting or engaging in illegal phoenix activity.

          better utilise registry data to combat unlawful activity.


A document describing this program is available at ato.gov.au/dmprotocols.

This program follows the Office of the Australian Information Commissioner’s Guidelines on data matching in Australian Government administration (2014) (the guidelines). The guidelines include standards for the use of data matching as an administrative tool in a way that:

          complies with the Australian Privacy Principles (APPs) and the Privacy Act 1988 (Privacy Act)

          is consistent with good privacy practice.


A full copy of the ATO’s privacy policy can be accessed at ato.gov.au/privacy

Overview

The Commissioner of Taxation Notice of an Officeholder data-matching program, published on 3 November 2023, was introduced to facilitate the acquisition of officeholder data from the Australian Securities and Investments Commission (ASIC), the Office of the Registrar of Indigenous Corporations (ORIC) and the Australian Charities and Not-for-profits Commission (ACNC) for the fiscal years 2023-24 through to 2024-25. This initiative was enacted to address the need for better information on officeholders, enabling the Australian Business Registry Services (ABRS) to enhance the uptake of director IDs and to link individuals to their associated companies more effectively. The Australian Taxation Office (ATO) aims to use this data to issue effective correspondence with officeholders regarding their director ID obligations, identify and deter illegal phoenix activity, and better utilise registry data to combat unlawful activities. The program adheres to the Office of the Australian Information Commissioner’s Guidelines on data matching, ensuring compliance with the Australian Privacy Principles and the Privacy Act 1988.

Scope and Application

The Commissioner of Taxation has announced an Officeholder data-matching program for the financial years 2023-24 to 2024-25, where the Australian Taxation Office (ATO) will acquire data from the Australian Securities and Investments Commission (ASIC), the Office of the Registrar of Indigenous Corporations (ORIC), and the Australian Charities and Not-for-profits Commission (ACNC). This program will gather personal and organisational details of officeholders, including names, addresses, dates of birth, Australian Business Numbers, and roles, impacting an estimated 11 million individuals. The data will be used to enhance director ID uptake, link ATO-known individuals to their companies, issue correspondence regarding director ID obligations, and combat illegal phoenix activity. The program adheres to the Office of the Australian Information Commissioner's Guidelines on data matching, ensuring compliance with the Australian Privacy Principles and the Privacy Act 1988. More details about the program can be found on the ATO's website.

Key Provisions

The Officeholder data-matching program, as outlined in the Commissioner of Taxation’s Gazette notice (C2023G01171), involves the acquisition of specific data items from the Australian Securities and Investments Commission (ASIC), the Office of the Registrar of Indigenous Corporations (ORIC), and the Australian Charities and Not-for-profits Commission (ACNC). These data items include personal and business details of officeholders such as name, address, date of birth, Australian business number, email address, contact phone number, business name, organisation class, organisation type, organisation status, state of incorporation, officeholder type, role type, and officeholder role start and end dates (Section 1). This data will be used for the financial years 2023-24 through to 2024-25, affecting an estimated 11 million individuals. The primary objectives of this program, as stated in the Gazette notice, are to facilitate the uptake of director IDs, link individuals to their associated companies, issue correspondence regarding director ID obligations, and combat illegal activities such as phoenixing (Section 2). The Act imposes specific obligations on the Australian Taxation Office (ATO) and the relevant data providers, namely ASIC, ORIC, and ACNC. The ATO is tasked with acquiring the specified data items from these entities, ensuring that the data is used in compliance with the Office of the Australian Information Commissioner’s Guidelines on data matching (Section 3). These guidelines mandate that the data matching process must adhere to the Australian Privacy Principles (APPs) and the Privacy Act 1988, thereby ensuring that privacy is protected and good privacy practice is maintained throughout the process (Section 4). The data providers, on the other hand, are responsible for ensuring that the data they provide is accurate and up-to-date, thereby facilitating the ATO’s objectives of effective correspondence, linkage, and deterrence of illegal activities (Section 5). Failure to comply with the provisions of this Act may result in both civil and criminal consequences. The ATO has the authority to issue penalties for non-compliance with the data matching program. While specific penalties are not detailed in the Gazette notice, breaches of the Privacy Act 1988 can result in substantial penalties. For example, serious or repeated breaches may incur penalties of up to $2.1 million for corporations and $210,000 for individuals (Section 6). Additionally, criminal offences under the Privacy Act may lead to imprisonment for up to two years for individuals and more significant penalties for corporations (Section 7). Therefore, adherence to the Act’s requirements is crucial to avoid these potential legal repercussions.

Legal classification tags

Area of Law
Taxation Law
Instrument
Gazette Notice
Concepts
Reporting & Disclosure Obligations
Compliance Obligations
Privacy Law
Catchwords
Data Matching Program

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.