Does the Privacy Act apply to an allied health practice?
A business with an annual turnover of 3 million dollars or less is usually a small business operator outside the Act, but not if it provides a health service and holds health information other than in an employee record. Assessing, treating, managing or recording a person's physical or psychological health is a health service, and so is that activity in disability care. An allied health practice of any size is therefore covered.
Privacy Act s 6D(1), (3) to s 6(1) health information, sensitive information
Office of the Australian Information Commissioner
Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches)
6 October 2026, Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026
Every allied health practice that provides a health service and holds health information, whatever its turnover (s 6D(4)(b)), every profession, speech pathology included, NDIS registered or not.
Privacy Act: the Australian Privacy Principles and notifiable data breaches on the standards library
From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.
A small business is one with an annual turnover of 3,000,000 dollars or less for the previous financial year; a small business operator carries on only small businesses.
- The practice's turnover for the previous financial year, if the practice relies on any part of the small business test for other activities
- Assuming the practice is exempt because its turnover is under 3 million dollars
An entity is not a small business operator if it provides a health service to another individual and holds any health information except in an employee record. Such an entity is an organisation bound by the Australian Privacy Principles whatever its turnover.
- A written note, kept with the privacy policy, that the practice provides health services and holds health information, so the Australian Privacy Principles apply
- No one in the practice has recorded which privacy obligations apply
- Treating client notes as exempt because the practice is small
A health service is an activity intended or claimed to assess, maintain, improve or manage a person's health, diagnose or treat an illness, disability or injury, or record a person's health for those purposes; health includes physical and psychological health, and such an activity in aged care, palliative care or disability care is a health service.
- A list of the services the practice provides (assessment, therapy, reports) mapped to the health service definition
- Non-clinical services (for example NDIS support coordination or reports) assumed to fall outside the Act
Health information, including information about a person's health or disability and personal information collected to provide a health service, is sensitive information, which the Australian Privacy Principles protect more strictly (for example APP 3.3 and APP 6.2(a)(i)).
- A data inventory listing where health information is held: client records, referral letters, NDIS plans and reports, email and messaging
- Health information held in email, text messages or personal devices left out of the inventory
| Ref | Held (yes, partly, no, not applicable) | Where it is kept | Owner | Last reviewed | Next review |
|---|---|---|---|---|---|
| s 6D(1), (3) | |||||
| s 6D(4)(b) | |||||
| s 6FB(1), (3) | |||||
| s 6(1) health information, sensitive information |
Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.
Related requirements
Privacy Act: the Australian Privacy Principles and notifiable data breaches
- APP 1.2 to APP 1.5, 1.6APP 1: the practice privacy policy and what it must contain
- APP 3.2 to APP 3.5, 3.6APP 3: collecting health information, consent and necessity
- APP 5.1 to APP 5.2(g) to (j)APP 5: the collection notice for clients
- APP 6.1 to APP 6.5APP 6: sharing client information with other practitioners and the NDIS
- APP 11.1, APP 11.3, APP 11.2APP 11: securing client records and destroying them when no longer needed
- APP 12.1, 12.4 to APP 13.3 to 13.5APP 12 and 13: client requests to see or correct their records
- s 26WE(2) to s 26WHNotifiable data breaches: the 30-day assessment of a suspected breach
- s 26WK(2), (3) to s 26WMNotifiable data breaches: notifying the Commissioner and the people affected
- Every page of this instrument
The same topic in other instruments (privacy and records)
- NDIS Practice Standards Core 5.1, Core 5.2, Core 5.3Core module: Privacy and dignity
- NDIS Practice Standards Core 12.1 to Core 12.4Core module: Information management
- NDIS Code of Conduct s 6(1)(b)Respect the privacy of people with disability
- Children guidance P-2Protect privacy and dignity, and ask before touching
- Ahpra shared Code of conduct 3.3Confidentiality and privacy
- Psychology Board Code of conduct 3.3Privacy and confidentiality
See every requirement for your practiceSee the specimen practice