Internal Review Of FOI-2026-00550. The ATO Data And Intelligence Disclosure Governance Plan Referenced In The Fraud Fusion Taskforce Memorandum Of Understanding. This Document May Not Reflect The…
Show full title
Internal Review Of FOI-2026-00550. The ATO Data And Intelligence Disclosure Governance Plan Referenced In The Fraud Fusion Taskforce Memorandum Of Understanding. This Document May Not Reflect The Current Procedures, Which Are Subject To Change.
ATO
AI summary
The ATO Data and Intelligence Disclosure Governance Plan establishes procedures for sharing tax data and intelligence with the Fraud Fusion Taskforce, a multi-agency initiative led by the Australian Criminal Intelligence Commission. The document outlines governance frameworks for disclosing ATO information to partner agencies under the taskforce's Memorandum of Understanding, covering legislative authorities for data sharing, handling of sensitive identifiers like Tax File Numbers, protocols for oral disclosures, and obligations for partner agencies regarding data protection and use restrictions. It addresses Special Purpose Acquisition Data (SPAD), aggregated datasets, and security requirements for data transfer channels. The plan incorporates privacy safeguards through Privacy Impact Assessments and a Data Ethics Framework, with provisions for data destruction and stewardship responsibilities assigned to business data stewards. No specific compliance metrics, case volumes, or financial figures are disclosed in the excerpt.
Document text
Show extracted text (32,023 chars)
FOI-2026-00701
OFFICIAL:Sensitive
Australian Government
Australian Taxation Office
# ATO Data and Intelligence Disclosure Governance Plan
## For the ATO's contributions to the Fraud Fusion Taskforce
Contact: s 47E(d)
OFFICIAL:Sensitive
EXTERNAL
1
Page 1 of 16
FOI-2026-00701
OFFICIAL:Sensitive
ATO Data and Intelligence Disclosure Governance Plan
# Contents
Glossary 4
Purpose 6
ATO Data and Intelligence Disclosure Governance Plan (the Plan) 6
Disclosures and legislative provisions 8
Requesting ATO data and information 8
Prescribed taskforce 8
Disclosure for the purposes of the Taskforce 9
Oral disclosures 10
Obligations by FFT partner agencies regarding on-disclosure and use of ATO protected information 10
ACIC - Fraud Fusion Centre 11
Aggregated and unidentifiable data, information, and statistics 12
Tax File Numbers (TFNs) 12
Special Purpose Acquisition Data 13
Special Purpose Acquisition Data (SPAD) 13
Other considerations 14
Appendix 15
ATO Data Governance and Stewardship 15
SDP's data sharing process 15
OFFICIAL:Sensitive
EXTERNAL
2
Page 2 of 16
FOI-2026-00701
OFFICIAL:Sensitive
ATO Data and Intelligence Disclosure Governance Plan
Data transfer channels and security 15
Destruction of data 16
Data Ethics Framework 16
Privacy Impact Assessment (PIA) 16
OFFICIAL:Sensitive
EXTERNAL
3
Page 3 of 16
FOI-2026-00701
OFFICIAL:Sensitive
ATO Data and Intelligence Disclosure Governance Plan
## Glossary
| Key words and expressions | Meaning |
| --- | --- |
| **ACIC** | Australian Criminal Intelligence Commission |
| **ATO** | Australian Taxation Office |
| **BDS** | Business Data Steward |
| **DEA** | Data Ethics Assessment |
| **FFC** | Fraud Fusion Centre |
| **FFT, the Taskforce** | Fraud Fusion Taskforce |
| **GPP** | Government Payments Program, data sourced by ATO from third party agencies |
| **IDC** | Inter-departmental Committee |
| **Intelligence team** | ATO FFT risk and intelligence team, business function within IAC |
| **IOC** | Intelligence and Operations Committee |
| **ITAA** | *Income Tax Assessment Act 1936* |
| **LEA** | Law enforcement agency |
| **MOU** | Fraud Fusion Taskforce Memorandum of Understanding |
| **NDIA** | National Disability Insurance Agency |
| **NDIS** | National Disability Insurance Scheme |
| **PIA** | Privacy Impact Assessment |
OFFICIAL:Sensitive
EXTERNAL
4
Page 4 of 16
FOI-2026-00701
OFFICIAL:Sensitive
ATO Data and Intelligence Disclosure Governance Plan
| Key words and expressions | Meaning |
| --- | --- |
| **the Plan** | ATO Data and Intelligence Disclosure Governance Plan |
| **Privacy Act** | *Privacy Act 1988* |
| **SA** | Services Australia |
| **SDP** | Smarter Data Program, business line within ATO |
| **SES** | Senior Executive Service |
| **SPAD** | Special Purpose Acquisition Data |
| **SPC** | Strategic Prevention Committee |
| **SOC** | Serious and Organised Crime |
| **TAA** | *Taxation Administration Act 1953* |
| **Taskforce Reston** | Taskforce Reston, established by the Board of ACIC |
| **TMO** | Taskforce Management Office |
| **TFN** | Tax File Number |
OFFICIAL:Sensitive
EXTERNAL
5
Page 5 of 16
FOI-2026-00701
OFFICIAL:Sensitive
ATO Data and Intelligence Disclosure Governance Plan
# Purpose
## ATO Data and Intelligence Disclosure Governance Plan (the Plan)
1. 1. The Australian Taxation Office (ATO) Data and Intelligence Disclosure Governance Plan (the Plan) outlines the governance and legislative framework for the lawful and ethical disclosure of ATO data and intelligence to the Fraud Fusion Taskforce (FFT).
2. 2. The Plan will refer to Commonwealth legislation, policies, protocols, and guidelines. The information in this Plan is not intended to provide your agency with legally binding advice. We encourage your agency to seek independent legal support to ensure your agency is meeting it's Commonwealth obligations when dealing with ATO information.
3. 3. The FFT is being led by the National Disability Insurance Agency (NDIA) and Services Australia (SA). Please refer to the **FFT Memorandum of Understanding (MOU)** for a list of participating agencies.
4. 4. This Plan outlines the elements of ATO data governance and data management which FFT partner agencies agree to adhere to in order to meet data governance and data management requirements when using the ATO's data. Specifically, the following paragraphs are stated in clauses 15.4 and 15.5 of the FFT MOU$^{1}$:
1. 4) To ensure adherence to the disclosure rules in the *Taxation Administration Act 1953* (Cth), the ATO has developed an ATO Data & Intelligence Disclosure Governance Plan which outlines the legislative framework, governance, data stewardship, ATO intelligence collection methodology and disclosure process, which provides the framework for disclosure of ATO protected information to the Fraud Fusion Taskforce.
2. 5) Upon becoming a party to this MOU, each respective agency also agrees to adhere to the ATO Data & Intelligence Disclosure Governance Plan to exercise good data stewardship and ensure the lawful, ethical and fit for purpose disclosure and use of ATO protected information.
5. 5. Where an FFT member agency does not agree to elements of this Plan, the ATO will work with the relevant agency to understand any concerns and identify an appropriate mechanism to resolve them, having regard to the relevant tax and privacy statutory framework.
6. 6. The overall Taskforce purpose is outlined in clauses 5.1 to 5.3 of the FFT MOU:$^{2}$
1. 1) The purpose of the Taskforce is to improve payment integrity in government programs and payments by preventing or reducing fraud and criminal activity within and against government programs (including SOC and systemic fraud), to:
1. a) protect the safety and wellbeing of participants who are at risk of harm as a result of fraud, and related service quality
2. b) protect public finances and prevent or reduce financial losses
$^{1}$ FFT MOU circulated for endorsement on 26 May 2023.
$^{2}$ FFT MOU circulated for endorsement on 26 May 2023.
OFFICIAL:Sensitive
EXTERNAL
6
Page 6 of 16
FOI-2026-00701
OFFICIAL:Sensitive
ATO Data and Intelligence Disclosure Governance Plan
c) ensure appropriate use of funds and the sustainability of the programs improve community confidence in the administration of those payments and programs
d) improve community confidence in the administration of those payments and programs.
7. The Taskforce Purpose Statements are stated in clause 5.4 of the FFT MOU³.
³ FFT MOU circulated for endorsement on 26 May 2023.
OFFICIAL:Sensitive
EXTERNAL
7
Page 7 of 16
FOI-2026-00701
OFFICIAL:Sensitive
# Disclosures and legislative provisions
## Requesting ATO data and information
8. The ATO may disclose information it holds to FFT partner agencies (taskforce officers) (including to the Australian Criminal Intelligence Commission (ACIC) as lead of the Fraud Fusion Centre (FFC)), for the purposes of the FFT. This may include oral disclosures made by authorised ATO officers. This will occur as a result of partner agencies (taskforce officers) making a formal request to the ATO, or through an ATO-initiated disclosure.
9. It is best practice for partner agencies (taskforce officers) to complete a form to request for written information or data from the ATO. The request must clearly articulate the nature of the request and how the request relates to the specified taskforce purpose(s). The completed form should be provided to the ATO FFT Risk and Intelligence team by emailing s 47E(d), by the agency's nominated gatekeeper (a taskforce officer).
10. The gatekeeper must be first nominated through the ATO and they must be of Executive Level or equivalent or above. To nominate or change your agency's gatekeeper, please advise the ATO FFT Liaison team by emailing s 47E(d).
11. The request for information form can be obtained from the ATO FFT Risk and Intelligence Team by emailing s 47E(d).
12. Disclosures can be made in writing, document form or orally. ATO will support partner agencies (taskforce officers) as required when making the request.
13. The ATO may initiate a protected information disclosure, including choosing to provide an oral disclosure. ATO staff will need to ensure they have obtained the necessary approvals prior to making a disclosure of ATO protected information.
14. Generally, for information or data to be disclosed by the ATO to FFT partner agencies (taskforce officers) it will go through a governance and approvals process. All disclosures of ATO protected information to the FFT require ATO SES Band 1 or above agreement. ATO SES Band 1 agreement may be provided for oral disclosures for a specified time period where the disclosures meet clearly defined parameters. These authorities must be established in advance of any disclosure and must meet all other governance requirements.
15. If information is disclosed by the ATO to a partner agency (taskforce officers), and that agency provides it to another party, this is referred to as an 'on-disclosure' of ATO information. Further information regarding 'on-disclosure' is provided in below section 'Obligations by FFT partner agencies regarding on-disclosure and use of ATO protected information'.
## Prescribed taskforce
16. The Treasury Laws Amendment (Disclosure of Information to Fraud Fusion Taskforce) Regulations 2023 commenced on 15 April 2023. The Taxation Administration Regulations 2017 made under the Taxation Administration Act 1953 (TAA) was amended effective from 15 April 2023 to enable the disclosure of protected information by the ATO to the Fraud Fusion Taskforce.⁴
⁴ Treasury Laws Amendment (Disclosure of Information to Fraud Fusion Taskforce) Regulations 2023 (legislation.gov.au)
OFFICIAL:Sensitive
EXTERNAL
8
Page 8 of 16
FOI-2026-00701
OFFICIAL:Sensitive
ATO Data and Intelligence Disclosure Governance Plan
17. Specifically, this amendment to Regulation 67 of the *Taxation Administration Regulations 2017* adds the FFT to the list of prescribed taskforces. This allows taxation officers to share protected information with taskforce officers of the FFT, where the record or disclosure is for or in connection with a purpose of the taskforce.⁵
## Disclosure for the purposes of the Taskforce
18. When disclosing for the purposes of the Taskforce⁶, the ATO will assess the following:
- whether the record is made for, or the disclosure is to, a taskforce officer of the FFT, or a court or tribunal;
- whether the record or disclosure is for, or in connection with, a purpose of the FFT;
- any time limits prescribed by the regulations; and,
- whether the relevant approvals required by s355-70 have been obtained (usually SES approval).
19. The requesting agency taskforce officer must provide appropriate assurances to the ATO that a record or disclosure is for, or in connection with, a purpose of the FFT.
20. In considering whether a record or disclosure is for, or in connection with, a purpose of the FFT, the ATO considers that the purposes of the FFT are as described in:
- the Explanatory Statement, i.e. to “better detect, address and prevent fraud against government programs”.⁷
- clause 5.1 of the MOU, i.e. “[t]he purpose of the FFT is to improve payment integrity in government programs and payments by preventing or reducing fraud and criminal activity within and against government programs...” and,
- the purpose statements at clause 5.4 of the MOU, read in conjunction with clause 5.1 above.
21. Broadly, disclosure of ATO protected information to the FFT must therefore be for the purpose of detecting, addressing, or preventing fraud against government programs.
22. The ATO cannot rely on subsection 355-70(12) to enable the ATO to disclose protected information to the Taskforce purely because it may protect public finances but where that purpose is not in relation to or connected with the purposes of the FFT.
⁵ Explanatory Statement, Treasury Laws Amendment (Disclosure of Information to Fraud Fusion Taskforce) Regulations 2023 (legislation.gov.au)
⁶ Pursuant to the exception in s 355-70(1) of Schedule 1 to the TAA, item 4.
⁷ Explanatory Statement, Treasury Laws Amendment (Disclosure of Information to Fraud Fusion Taskforce) Regulations 2023 (legislation.gov.au)
OFFICIAL:Sensitive
EXTERNAL
9
Page 9 of 16
FOI-2026-00701
OFFICIAL:Sensitive
ATO Data and Intelligence Disclosure Governance Plan
## Oral disclosures
23. The ATO may make oral disclosures to partner agencies (taskforce officers), and they may be permitted to do so for the purposes of the Taskforce. Oral disclosures will go through the governance and approvals process as described above.
## Obligations by FFT partner agencies regarding on-disclosure and use of ATO protected information
24. The following disclaimer is included in written ATO disclosures of protected information to partner agencies (taskforce officers): 'The information provided in ATO information disclosures to members of the Fraud Fusion Taskforce is intended for intelligence purposes only. The information in the disclosures is NOT EVIDENCE and is intended to support decision-making processes but cannot be used as a basis for administrative action.'
25. The ATO will seek to understand the purposes for which the ATO information will be used and any actions your agency intends to undertake that considers or relies on the ATO information. If ATO disclosed information is intended to be used as evidence for administrative action that will have an impact on an individual or entity, the ATO must be consulted and agree in writing to the use of the disclosure as evidence before the action is taken.
26. When the ATO discloses protected information to a FFT partner agency (taskforce officer), that agency assumes legal obligations under the TAA in relation to that information. The recipient is required to manage any ATO protected information in line with those obligations and legal or ethical requirements imposed by any relevant law or policy. Specific obligations in respect to on-disclosing information are contained within Subdivision 355-C of the TAA.
27. The on-disclosure of ATO protected information is prohibited unless an exception applies.⁸ Subdivision 355-C of Schedule 1 to the TAA contains exceptions that may allow for on-disclosure of protected information, notably that on-disclosure is permitted if it is in connection with the original purpose of disclosure or another purpose of the FFT.
28. The ATO will take all appropriate steps to ensure that the disclosure of ATO protected information to FFT partner agencies (taskforce officers) is lawful, appropriate and meets the purposes of the Taskforce. It is crucial (to remain acting lawfully) that FFT partner agencies (taskforce officers) are aware of their obligations regarding the on-disclosure of ATO protected information as described in Subdivision 355-C of Schedule 1 to the TAA.
29. Subject to the agreement of the FFT, agencies may be asked to provide the Taskforce Management Office (TMO) or ATO with assurance of their compliance with information sharing obligations in clause 15 of the MOU and those contained within this Governance Plan through an annual statement of compliance.
30. The ATO encourages FFT partner agencies to seek their own legal advice where needed.
⁸ Section 355-155 of Schedule 1 to the TAA
OFFICIAL:Sensitive
EXTERNAL
10
Page 10 of 16
FOI-2026-00701
OFFICIAL:Sensitive
ATO Data and Intelligence Disclosure Governance Plan
31. The ATO will maintain engagement with FFT partner agencies after ATO information is disclosed, to understand the use of ATO information or data (including any on-disclosure of ATO data or use of ATO data for administrative purposes in accordance with FFT purposes), ensure appropriate destruction requirements are met, and to obtain any feedback on the usefulness and quality of ATO data.
32. Partner agencies are expected to undertake their own due diligence on the appropriateness of any actions they wish to undertake that are attributed to the ATO protected information they have received.
33. At the dissolution of the Taskforce (when the MOU has ceased), the ATO will seek confirmation from all agencies who have received ATO information that all information has been appropriately destroyed. Other circumstances, such as the information being used for criminal prosecutions or ongoing compliance action (within an agency or before the courts), may permit storage and handling of information beyond the dissolution of the Taskforce. In such situations, the ATO will seek confirmation of destruction at a later date, based on guidance from ATO Records Management in line with the Archives Act.
34. If an FFT partner agency (taskforce officer) receives ATO protected information from another entity (i.e. not directly from the ATO), taskforce officers must ensure they understand the purpose/s for which they have received that information.
35. Where appropriate, the ATO will work with the TMO to obtain assurance from FFT partner agencies regarding conformance to the information sharing obligations in Clause 15 of the MOU and those contained within this Governance Plan.
36. Breaches of the on-disclosure requirements within TAA are subject to heavy sanctions. The penalty for this offence is 2 years imprisonment.⁹ FFT agencies who receive ATO protected information are required to comply with the requirements within the TAA. Penalties may apply to an FFT agency if they do not comply.
37. Any breaches of the on-disclosure provisions must be reported to the ATO (s 47E(d) [redacted] within two working days of that breach being identified.
### ACIC - Fraud Fusion Centre
38. The Taskforce will have its own data governance framework (the FFT Data Governance Framework). Components of the framework outline the different mechanisms that facilitate data and intelligence sharing between taskforce agencies and into the FFC.
39. Supporting this is the FFC Data Governance Plan, which establishes key principles and governance to the collection, use, storage and disclosure of the data exchanged within the FFC.¹⁰ See the FFT MOU for description of the FFC and its purpose.
⁹ Section 355-155 of Schedule 1 to the TAA
¹⁰ ACIC Fraud Fusion Centre: Data Governance Plan
OFFICIAL:Sensitive
EXTERNAL
11
Page 11 of 16
FOI-2026-00701
OFFICIAL:Sensitive
ATO Data and Intelligence Disclosure Governance Plan
40. Disclosure and on-disclosure requirements within the TAA apply to all protected information disseminated to the ACIC, including the FFC located in ACIC. All partner agencies are bound by the on-disclosure requirements within TAA.
41. ACIC Members of Staff, including those in the FFC and Taskforce Reston, must not on-disclose ATO protected information it has seen, heard, used, or handled within ACIC unless the on-disclosure is allowable under the exceptions within the TAA.
### Aggregated and unidentifiable data, information, and statistics
42. The ATO may share aggregated and unidentifiable data, information and/or statistics to partner agencies, such information is not defined as ATO protected information, therefore the legal restrictions which apply to ATO protected information do not apply to aggregated and unidentifiable ATO information. This may be done in response to requests for information or the ATO may initiate the information sharing. The sharing of aggregated information is done for a particular purpose, use and audience. The ATO is supportive of providing such aggregated and unidentifiable information to the FFT within reasonable request parameters.
### Tax File Numbers (TFNs)
43. Information shared by the ATO for the purposes of the FFT will not include TFNs. A tax officer cannot disclose a person's TFN to a prescribed taskforce officer or to anyone else, under an exception in Division 355 of Schedule 1 to the TAA.
44. The use and application of TFNs are strictly controlled by Part VA of the *Income Tax Assessment Act 1936* (ITAA 1936) and are subject to specific offence provisions contained in Subdivision BA of Division 2 of Part III of the TAA ('Offences relating to tax file numbers').
45. Where a TFN relates to a taxpayer who is an individual, the Privacy (Tax File Number) Rule 2015 (TFN Rule)¹¹ works in tandem with Part VA of the ITAA 1936. This Rule is legally binding and must be considered if using or disclosing an individual's TFN.
46. The TAA prevents a person from recording, maintaining, divulging, or communicating a TFN.¹² Where partner agencies have received TFNs in circumstances that is not for the purpose of taxation law, personal assistance law or superannuation law, the agency must not use or disclose the TFN or record the TFN in a way that is inconsistent with the TAA or the TFN Rule.¹³
47. The penalty for unauthorised recording etc. is 100 penalty units and/or 2 years of imprisonment.¹⁴
¹¹ The Privacy (Tax File Number) Rule 2015 and the protection of tax file number information | OAIC - This resource provides a number of steps an agency or organisation should consider taking to protect the privacy of Tax File Number (TFN) information, and ensure they comply with the binding Privacy (Tax File Number) Rule 2015 (TFN Rule) issued under s 17 of the Privacy Act 1988.
¹² Section 8WB of the TAA
¹³ The Privacy (Tax File Number) Rule 2015 and the protection of tax file number information | OAIC
¹⁴ Section 8WB of the TAA
OFFICIAL:Sensitive
EXTERNAL
12
Page 12 of 16
FOI-2026-00701
OFFICIAL:Sensitive
# Special Purpose Acquisition Data
## Special Purpose Acquisition Data (SPAD)
48. SPAD consists of bulk data sets obtained by the ATO from third parties, including government agencies, who are not obliged by law to report the data to the ATO.
49. The ATO is not the owner of SPAD and where possible, FFT partner agencies should seek to obtain the data directly from the primary source(s) in the first instance.
50. Agencies must be aware that the ATO does not control the quality of SPAD it receives. The ATO's processing of the data, including identity matching, can introduce other inaccuracies into the data.
51. SPAD is considered unconfirmed data until the personal information is confirmed with the individual/entity concerned.
52. The ATO currently holds Government Payments Program¹⁵ (GPP) data that is obtained from participating Commonwealth government agencies and programs. GPP data is SPAD. Further details regarding the collection and use of GPP data is outlined in the GPP data-matching program protocol (DMPP)¹⁶.
### *On-disclosure of SPAD by the ATO*
53. FFT partner agencies are to be aware that SPAD have additional use, on-disclosure and destruction requirements (see sections below on SPAD and Destruction).
54. In circumstances where the FFT or partner agencies seek to obtain SPAD (or related analysis) held by the ATO, the ATO is required to obtain approval from the primary/source agency before any on-disclosure of the information by the ATO to the FFT partner agency.
55. On-disclosure of SPAD by the ATO to FFT partner agencies is not to be assumed. The ATO is not the owner of SPAD.
56. The ATO will require detailed understanding of the agency's need for the SPAD, which includes (but not limited to):
- the fields of data needed
- the relevance of the data to the purpose of the request
- and intended use and outcomes.
57. The source agency and/or the ATO may place restrictions, conditions, or safeguards on the use of on-disclosed SPAD, which FFT partner agencies (as recipients of the SPAD) must adhere to.
58. **If an FFT partner agency is looking to undertake administrative or compliance action against an individual or provider resulting from SPAD they have received from the ATO, then Guideline 6 of the Office of Australian Commissioner's *Guidelines on Data Matching in Australian Government***
¹⁵ Government Payments Program | Australian Taxation Office (ato.gov.au)
¹⁶ GPP data-matching program protocol | Australian Taxation Office (ato.gov.au)
OFFICIAL:Sensitive
EXTERNAL
13
Page 13 of 16
FOI-2026-00701
OFFICIAL:Sensitive
ATO Data and Intelligence Disclosure Governance Plan
**Administration (2014) must be followed prior to any action. This will include confirming the data with the individual/entity the information is concerned with, prior to any action.**$^{17}$
59. Depending on the initial on-disclosure agreement with the source agency and any safeguards put in place, the FFT partner agency may also be required to approach the source agency and/or the ATO before it undertakes any action on an identified entity from the SPAD.
60. The ATO may need to consider relevant updates to regulatory and other obligations, such as our Data Matching Program Protocol and other necessary dependencies, before servicing SPAD disclosure requests. This is applicable to both the initial disclosure of information by the ATO to an FFT member agency, and any subsequent on-disclosure by the FFT member agency.
61. The FFT partner agency (taskforce officers) seeking SPAD will be required to be involved in scheduled formal assurance check-ins with the ATO. The ATO and any partner agencies (taskforce officers) who receive SPAD must conform with data destruction and de-identification obligations, including destruction timeframes and destroying data when it is no longer required.$^{18}$
## Other considerations
### Issue resolution and escalation points
62. To escalate any ATO-related questions, issues or concerns you or your agency may have, please reach out to s 47E(d)
$^{17}$ Guideline 6: Notify individuals of proposed administrative action of the Guidelines on data matching in Australian Government Administration (Guidelines on data matching in Australian Government administration | OAIC)
$^{18}$ Guideline 7 of the Guidelines on data matching in Australian Government Administration. We destroy data that is no longer required, in accordance with the Archives Act 1983, and the records authorities issued by the National Archives of Australia, both general and ATO-specific. We will keep each financial year of GPP data for five years when we receive the final instalment of verified data files from the data providers. Individual records that become part of the client's record will be retained for such time as required by both general and ATO specific records authorities.
As part of the Conformance to Obligations, data owners are to provide assurance that SPAD (where the Guidelines apply) has been destroyed in accordance with applicable time limits.
OFFICIAL:Sensitive
EXTERNAL
14
Page 14 of 16
FOI-2026-00701
OFFICIAL:Sensitive
# Appendix
## ATO Data Governance and Stewardship
### SDP's data sharing process
63. The data sharing process (previously known as the SDP 5-step process) ensures the ATO maintains stewardship of data throughout the sharing process, including seeking regular assurance from partner agencies of their conformance to legal use of data. The end-to-end process involves:
1. Considering what is the purpose of the request and use of the bulk ATO data?
2. Considering whether we can lawfully disclose the data in accordance with Division 355 of Schedule 1 to the TAA?
3. Undertaking due diligence activities (e.g., identify and contact business data stewards, conduct privacy and data ethics assessments).
4. Actioning of the request (data dictionary, data matching, data extraction rules, sample quality checking, adding exchange to the data exchange register, and determining secure transfer channel).
5. Maintaining engagement with recipient agency to ensure coverage over data use and storage until data is destroyed. Undertake conformance activities (including MOU annual conformance) and determine if re-assessment of data use and purpose is required.
64. The data sharing process ensures that FFT data requests and sharing regarding ATO data is aligned to the purpose of the FFT and considered from legal, ethical, privacy and security perspectives, such as through:
- Data Ethics Assessment (see Data Ethics Framework below)
- Privacy Impact Assessments (PIA) (see below)
- Data-Matching Protocol (Guidelines for the Conduct of the Data-Matching Program)¹⁹
### Data transfer channels and security
65. Data transfer from the ATO to FFT partner agencies (taskforce officers) will be through appropriate channels with respect to the nature of the data or information and in agreement with recipient agency. These channels include bulk data exchange, SIGBOX and/or secure emails.
66. ATO data or information that is disclosed will be protectively marked with appropriate security classifications.
¹⁹ Completed as required. The Office of the Australian Information Commissioner published the guidelines to assist government agencies use data matching in a way that complies with Australian Privacy Principles and the Privacy Act 1988.
OFFICIAL:Sensitive
EXTERNAL
15
Page 15 of 16
FOI-2026-00701
OFFICIAL:Sensitive
ATO Data and Intelligence Disclosure Governance Plan
## Destruction of data
67. All partner agencies who have received ATO information, data or intelligence are required to destroy such information when it is no longer required or ceases to have use for the taskforce. At the dissolution of the Taskforce (when the MOU has ceased), ATO will seek confirmation from all agencies who have received ATO information, that all information has been destroyed. Other circumstances may permit storage and handling of information beyond the dissolution of the Taskforce. In such situations, the ATO will seek confirmation of destruction at a later date.
68. Agencies are required to destroy data securely and to provide ATO assurance of the destruction.
69. Specific timeframes may apply to SPAD and how long it can be held. Partner agencies who have received SPAD from the ATO will need to ensure they destroy and de-identify SPAD that is no longer required, or within the specified timeframes.20
70. This aligns with the Privacy Act, Archives Act 1983 and Guidelines on Data Matching in Australian Government Administration 2014.
71. Additionally, the ATO will also consider the ATO Record Authorities timeframes for storing and destruction of records in the course of administering tax, super and other laws.
## Data Ethics Framework
72. The Data Ethics Framework will guide ATO's considerations and actions to ensure data is used and managed ethically throughout the data lifecycle. This includes the use of data in analytics, AI, Machine Learning, and automated decision-making processes. These are important data use considerations when assessing whether a data request is in line with ATO Data Ethics principles. The Data Ethics Framework provides assurance that the ATO takes measures to manage data related risks and that we consider, monitor and document potential ethical risks associated with data activities.
73. A Data Ethics Assessment (DEA) is required for data sharing activities. All DEAs will be registered in the Data Ethics Assessment Register (DEAR). Assessments will be reviewed annually or if a significant change in the data share occurs.
## Privacy Impact Assessment (PIA)
74. The Privacy (Australian Government Agencies — Governance) APP Code 2017 requires that the ATO undertakes PIAs for any project that is a high privacy risk project, which is a project that:
- involves any new or changed ways of handling personal information, and
- is likely to have a significant impact on the privacy of individuals.
75. PIAs will be completed for all bulk data shares as part of the data sharing process, in the same instance as DEAs. PIAs will be updated as changes or new risks are identified for each exchange.
20 Guideline 7: Destroy information that is no longer required Guidelines on data matching in Australian Government administration | OAIC
OFFICIAL:Sensitive
EXTERNAL
16
Page 16 of 16