Notice of Data Matching Program - Credit and Debit Cards 2014-15

Administered by Department of the Treasury

Legislation au C2015G01369 In force Gazette

Legislation content

Commissioner of Taxation

NOTICE OF A DATA MATCHING PROGRAM

The Australian Taxation Office (ATO) will request and collect data relating to credit and debit card payments to merchants for the periods from 1 July 2014 to 30 June 2015 from the following financial institutions:

        American Express Australia Limited

        Australia and New Zealand Banking Group Limited

        Bank of Queensland Limited

        Bendigo and Adelaide Bank Limited

        BWA Merchant Services Pty Ltd

        Commonwealth Bank of Australia

        Diners Club Australia

        National Australia Bank Limited

        St George Bank

        Tyro Payments Limited

        Westpac Banking Corporation

The data requested will include information that enables the ATO match merchant accounts to a taxpayer, including name, address and contact information as well as information on the number and value of transactions processed for each merchant account. This acquired data will be electronically matched with certain sections of ATO data holdings to identify possible non-compliance with taxation law.

Records relating to approximately 900,000 merchant accounts are expected to be received. The number of affected individuals linked to those accounts is expected to be approximately 90,000.

The purpose of this data matching program is to ensure that merchants are correctly meeting their taxation obligations in relation to their business income. These obligations include registration, lodgment, reporting and payment responsibilities.

A document describing this program has been prepared in consultation with the Office of the Australian Information Commissioner. A copy of this document is available:

        at www.ato.gov.au/dmprotocols  

        by sending an email to SpecialPurposeDataSteward@ato.gov.au with reference to credit and debit card data matching program

The ATO complies with the Office of the Australian Information Commissioner’s Guidelines on data matching in Australian government administration (2014) which includes standards for data matching to protect the privacy of individuals. A full copy of the ATO’s privacy policy can be accessed at www.ato.gov.au/privacy

Overview

The Commissioner of Taxation Notice of a Data Matching Program 2015 (C2015G01369) was enacted in 2015 to address the issue of non-compliance among merchants regarding their taxation obligations. This initiative was introduced by the Australian Taxation Office (ATO) and aims to ensure that merchants accurately meet their registration, lodgment, reporting, and payment responsibilities. The ATO will collect and match data on credit and debit card payments processed by specified financial institutions with its own records to identify potential non-compliance. The data matching program is expected to cover around 900,000 merchant accounts, potentially impacting approximately 90,000 individuals. The ATO adheres to the Office of the Australian Information Commissioner’s Guidelines on data matching to safeguard individual privacy, with a full copy of the ATO’s privacy policy accessible on their website.

Scope and Application

The data matching program, as outlined in the Commissioner of Taxation Notice, pertains to a specific subset of financial institutions and their merchant accounts for the financial year 2014-2015. This program is applicable to any individual or entity operating a merchant account through the specified financial institutions, including American Express Australia Limited, Australia and New Zealand Banking Group Limited, Bank of Queensland Limited, Bendigo and Adelaide Bank Limited, BWA Merchant Services Pty Ltd, Commonwealth Bank of Australia, Diners Club Australia, National Australia Bank Limited, St George Bank, Tyro Payments Limited, and Westpac Banking Corporation. The data collected includes personal and transaction details that link these accounts to taxpayers, thereby enabling the Australian Taxation Office to match this information with its own records to identify potential non-compliance with taxation laws. This program is executed within the framework of Commonwealth legislation, extending its reach to the entirety of Australia. The program is designed to ensure that merchants are meeting their taxation obligations, including registration, lodgment, reporting, and payment duties. It does not specify any exclusions or exemptions but operates under the Office of the Australian Information Commissioner’s Guidelines on data matching, ensuring privacy and data protection standards are met. This program does not extend its application through subordinate instruments, remaining focused on the data collection and matching process as outlined in the notice. The ATO's compliance with privacy policies and guidelines is detailed and can be accessed via their website.

Key Provisions

The primary operative sections of this notice (C2015G01369) concern the data matching program (section 1) undertaken by the Australian Taxation Office (ATO). This program (section 2) involves the ATO requesting and collecting data from specified financial institutions for the specified period. The collected data (section 3) will include personal and transactional information of approximately 900,000 merchant accounts, which are expected to link to around 90,000 individuals. The data will be matched with existing ATO data holdings (section 4) to identify any potential non-compliance with taxation laws. This initiative (section 5) aims to ensure that merchants meet their tax obligations, including registration, lodgment, reporting, and payment responsibilities. The Act imposes specific obligations and requirements on both the financial institutions and the ATO. Financial institutions, listed in section 2, are required to provide the specified data to the ATO. This data must include personal information, transaction details, and account information as detailed in section 3. The ATO, on the other hand, is obligated to ensure that the data matching process complies with the Office of the Australian Information Commissioner’s Guidelines on data matching (section 5). This includes adhering to privacy standards to protect the personal information of individuals involved. Additionally, the ATO must make information about this data matching program available to the public, as outlined in section 6, to ensure transparency and accessibility. The notice (section 7) outlines potential consequences for breaches of the data matching program. While specific offences are not detailed in this notice, breaches of data handling and privacy protocols could lead to civil or criminal penalties under broader data protection and taxation laws. For example, under the Privacy Act 1988, unauthorised handling of personal information could result in civil penalties, including fines up to AU$2.1 million for corporations and AU$210,000 for individuals. Additionally, breaches of taxation laws could lead to criminal penalties, including fines and imprisonment, depending on the severity and intent of the breach. The maximum penalties for tax-related offences can vary significantly, but may include fines up to AU$525,000 for individuals and AU$2.625 million for corporations, along with potential imprisonment terms. These consequences underscore the importance of compliance with both data handling and taxation obligations.

Legal classification tags

Area of Law
Taxation Law
Instrument
Gazette Notice
Concepts
Reporting & Disclosure Obligations
Compliance Obligations
Definitions & Interpretation

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.