Gazette notice: Commissioner of Taxation - Notice of an Offshore Merchant Data-Matching Program 20 October 2025

Administered by Department of the Treasury

Legislation au C2025G00584 In force Gazette

Legislation content

Gazette notice: Commissioner of Taxation - Notice of an Offshore Merchant Data-Matching Program 20 October 2025

The Australian Taxation Office (ATO) will acquire merchant data from the big 4 Australian banks; Australian and New Zealand Banking Group Limited, Commonwealth Bank of Australia, National Australia Bank and Westpac Banking Corporation for 2024-25 through to 2026-27.

The data items include:

  • The name of the offshore entity or other descriptors of the offshore entity and the Merchant country
  • Merchant city
  • Merchant acquirer code
  • Merchant category code
  • contact details
  • mailing addresses
  • phone numbers
  • email addresses
  • the total aggregated value of the transactions in Australian dollars (AUD) for each offshore entity for the requested period
  • the count of transactions for each offshore entity
  • all currencies used other than AUD.

We estimate that records relating to approximately 9,000 offshore merchants will be obtained each financial year.

A document describing this program is available at ato.gov.au/dmprotocols.

This program follows the Office of the Australian Information Commissioner’s Guidelines on data matching in Australian Government administration (2014) (the guidelines). The guidelines include standards for the use of data matching as an administrative tool in a way that:

  • complies with the Australian Privacy Principles (APPs) and the Privacy Act 1988 (Privacy Act)
  • is consistent with good privacy practice.

A full copy of the ATO’s privacy policy can be accessed at ato.gov.au/privacy

 

 

Overview

The Offshore Merchant Data-Matching Program Gazette, issued on 20 October 2025, is a legislative instrument under the Commissioner of Taxation, designed to address the problem of offshore tax evasion and ensure compliance with tax laws by obtaining and analysing merchant transaction data from major Australian banks. This program is enacted to bridge the gap in detecting unreported income from offshore entities by leveraging merchant data, which is critical in identifying discrepancies in tax returns and ensuring taxpayers report all income correctly. The Australian Taxation Office (ATO) will acquire merchant data from the big four Australian banks—Australian and New Zealand Banking Group Limited, Commonwealth Bank of Australia, National Australia Bank, and Westpac Banking Corporation—for the financial years 2024-25 through to 2026-27. This initiative aims to comply with the Australian Privacy Principles and the Privacy Act 1988, ensuring that data usage adheres to good privacy practice and respects individual privacy rights. The policy objective of this program is to enhance the ATO’s capacity to identify and investigate potential non-compliance by individuals and businesses with offshore transactions, thereby ensuring a fairer and more accurate tax system. The ATO will acquire detailed merchant data, including entity descriptors, transaction values, and contact details, which will be used to match against tax returns to identify discrepancies. The program is designed to be transparent and accountable, following the Office of the Australian Information Commissioner’s Guidelines on data matching in Australian Government administration (2014). By doing so, the ATO aims to uphold the integrity of the tax system and promote voluntary compliance through informed data analysis.

Scope and Application

The Offshore Merchant Data-Matching Program announced by the Commissioner of Taxation for the Australian Taxation Office (ATO) applies to offshore entities that engage in transactions with Australian merchants, specifically those represented by the four major Australian banks. This includes entities such as foreign businesses or individuals conducting transactions with Australian merchants through these banks. The geographic scope of this program extends to offshore entities, irrespective of their physical location, as long as they have transactions processed by the participating Australian banks. The program operates within the framework of Australian taxation laws, adhering to the guidelines set forth by the Office of the Australian Information Commissioner, ensuring compliance with the Australian Privacy Principles and the Privacy Act 1988. The ATO estimates that around 9,000 offshore merchants will be involved in this data-matching program annually. This initiative is designed to enhance the accuracy of tax reporting and compliance by identifying discrepancies between declared and actual offshore transactions. The ATO's privacy policy is accessible to ensure transparency and accountability in the handling of sensitive data.

Key Provisions

The main operative sections of the Gazette notice (C2025G00584) outline the Australian Taxation Office's (ATO) intention to acquire merchant data from the big four Australian banks for the financial years 2024-25 through to 2026-27. Section 1 of the notice specifies the banks involved: Australian and New Zealand Banking Group Limited, Commonwealth Bank of Australia, National Australia Bank and Westpac Banking Corporation. Section 2 details the data items to be obtained, which include various descriptors of offshore entities, merchant details, transaction values in Australian dollars, and transaction counts. Section 3 mentions that approximately 9,000 offshore merchants will be involved each financial year. The program adheres to the Office of the Australian Information Commissioner’s Guidelines on data matching in Australian Government administration (2014) and is compliant with the Australian Privacy Principles (APPs) and the Privacy Act 1988 (Privacy Act). The obligations and requirements imposed by this Act on the parties governed by it are primarily centred on the collection and processing of data in compliance with privacy laws and guidelines. The ATO must ensure that the data obtained from the banks is used solely for the purposes of tax administration and enforcement, and that it is handled in accordance with the Privacy Act and APPs. The banks, on the other hand, are required to provide the specified data to the ATO as stipulated in the Gazette notice. Both the ATO and the banks must ensure that the data is protected against unauthorised access, misuse, or disclosure. Furthermore, they are obligated to maintain records of the data transactions and to adhere to any additional guidelines or standards prescribed by the Office of the Australian Information Commissioner. The Gazette notice does not explicitly list specific offences, penalties, or consequences for breach. However, non-compliance with the Privacy Act and APPs could result in significant legal and financial repercussions. Under the Privacy Act, unauthorised collection, use, or disclosure of personal information can lead to civil penalties. The maximum civil penalty for serious or repeated breaches is up to $2.1 million for corporations and $420,000 for individuals. Additionally, breaches of privacy could result in criminal charges, with potential maximum penalties including fines of up to $210,000 for individuals and $1.05 million for corporations, along with imprisonment terms. The ATO and the banks must therefore take all necessary measures to ensure strict adherence to the privacy standards and guidelines to avoid these potential penalties and consequences.

Legal classification tags

Area of Law
Taxation Law
Instrument
Gazette Notice
Concepts
Reporting & Disclosure Obligations
Data Matching
Privacy Compliance
Catchwords
Offshore Merchant Data-Matching Program

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.