As of 31 August 2026, the tax authority issued a directive requiring certified bookkeepers, bookkeeping firms, and tax return agents to strengthen personal data protection measures in accordance with the Personal Data Protection Act. The guidance mandates encryption, access controls, regular audits, and breach notification procedures to safeguard taxpayer information held by tax professionals.
Key Takeaways
- Mandatory Security Framework: Firms must implement a documented data security policy covering storage, transmission, and disposal.
- Staff Training: Regular privacy awareness training for all personnel handling taxpayer data is required.
- Incident Reporting: Any data breach must be reported to the competent authority within 72 hours.
Disclaimer: This article is compiled and summarized by the AI based on publicly available information and is for general information purposes only. It does not constitute any form of formal tax advice, legal opinion, or basis for performance. Please consult a qualified professional tax advisor or legal counsel for tax advice.
Source: Read Official Announcement
