Allied Health NDIS Audit Checklist

Privacy Act: the Australian Privacy Principles and notifiable data breaches: every requirement, with a worksheet for each

Privacy Act: the Australian Privacy Principles and notifiable data breaches: 9 pages and 39 requirements, each with the evidence asked for and a free worksheet. Every allied health practice that provides a health service and holds health information, whatever its turnover (s 6D(4)(b)); speech pathology included.

PrivacyOffice of the Australian Information Commissioner
Edition held

Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches)

Checked current

6 October 2026, Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026

Who it applies to

Every allied health practice that provides a health service and holds health information, whatever its turnover (s 6D(4)(b)); speech pathology included

Under review, not in force

under review, not in force From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.

The requirements

9 pages
  1. s 6D(1), (3) to s 6(1) health information, sensitive informationDoes the Privacy Act apply to an allied health practice?4 rowsCSV Print
  2. APP 1.2 to APP 1.5, 1.6APP 1: the practice privacy policy and what it must contain6 rowsCSV Print
  3. APP 3.2 to APP 3.5, 3.6APP 3: collecting health information, consent and necessity4 rowsCSV Print
  4. APP 5.1 to APP 5.2(g) to (j)APP 5: the collection notice for clients4 rowsCSV Print
  5. APP 6.1 to APP 6.5APP 6: sharing client information with other practitioners and the NDIS5 rowsCSV Print
  6. APP 11.1, APP 11.3, APP 11.2APP 11: securing client records and destroying them when no longer needed3 rowsCSV Print
  7. APP 12.1, 12.4 to APP 13.3 to 13.5APP 12 and 13: client requests to see or correct their records5 rowsCSV Print
  8. s 26WE(2) to s 26WHNotifiable data breaches: the 30-day assessment of a suspected breach4 rowsCSV Print
  9. s 26WK(2), (3) to s 26WMNotifiable data breaches: notifying the Commissioner and the people affected4 rowsCSV Print

See every requirement for your practiceSee the specimen practice