Where Your Client Data Is Stored and Handled
Last reviewed: 25th June 2026
If you're a registered tax agent, BAS agent, or accountant using SISS Data Services on behalf of your clients, this page gives you the key facts to support your own due diligence obligations under the Privacy Act 1988 and the TPB Code of Professional Conduct.
This covers all data handled by SISS, not only Consumer Data Right (CDR) data. Where data has moved outside CDR protections (for example, via the Trusted Adviser consent model), we've noted that below.
Storage location
Data is stored on Microsoft Azure, with primary storage in Australia East (Sydney) and disaster recovery in Australia South East (Melbourne).
CDR data leaving CDR protection
Data disclosed via the Trusted Adviser consent model is no longer covered by CDR Privacy Safeguards once disclosed. Where the receiving party is regulated under the Privacy Act 1988, that data is protected under the Australian Privacy Principles; please contact us for further detail on how this applies to your practice.
Who can access your (client) data
Access is limited to authorised personnel. SISS do use overseas-based employees and contractors for development work. These contractors by default only have access to DevOps project environments, not to production systems or databases, and all development work uses synthetic data.
Certifications
-
CDR Accredited Data Recipient: ADRBNK000158
-
ISO 27001:2022 certified (Compass Assurance Services, certificate 5325-2096-02, expiry October 2026)
Retention and deletion
Under our data retention policy, CDR data is deleted once the underlying consent becomes invalid, in line with CDR Rules requirements. Data outside the CDR environment is retained for a rolling two-year period. Further information on retention is available on request.
Questions
Contact our Compliance Officer at privacy@siss.com.au for anything this page doesn't cover.