A bookkeeping practice holds genuinely sensitive data for every single client — bank details, payroll information, tax file numbers, sometimes ID documents. It's easy to think about data privacy as a box to tick rather than something that actively matters, until a client asks exactly what happens to their information and the honest answer isn't satisfying.
What actually matters, beyond a privacy policy existing
- Where the data is actually stored — which country, whose servers
- Whether it's encrypted in transit and at rest, not just "secure" in marketing copy
- Whether client data is isolated per practice, or pooled in a way that could leak across accounts
- Whether AI features train on your data, or just process it and discard it
The Australian Privacy Principles matter here specifically
As a registered BAS agent, you're handling data under the Privacy Act 1988 (Cth) and the Australian Privacy Principles — this isn't optional context, it's the actual legal framework your practice operates in. Any software holding client data on your behalf should be able to answer, specifically, how it meets that standard — not gesture at "we take privacy seriously."
A reasonable question to ask any vendor
"If my data was in this system, would I be comfortable explaining to a client exactly where it lives and who can see it?" If the honest answer requires hedging, that's worth taking seriously before committing a whole client list to the tool.
How Bookkeeper Dashboard handles this
Client data is stored on Australian servers, encrypted in transit and at rest, and isolated per practice — never sold, shared, or used to train AI models. Some processing (hosting, AI features) happens via US-based providers under the same protections, disclosed plainly rather than buried. Full detail is in the Privacy Policy.