APP 1: the practice privacy policy and what it must contain
Every practice covered by the Act needs practices, procedures and systems to comply with the APPs and handle privacy complaints, and a clearly expressed, up-to-date privacy policy that says what it collects, why, how people can get access and complain, and whether information goes overseas.
Privacy Act APP 1.2 to APP 1.5, 1.6
Office of the Australian Information Commissioner
Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches)
6 October 2026, Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026
Every allied health practice that provides a health service and holds health information, whatever its turnover (s 6D(4)(b)), every profession, speech pathology included, NDIS registered or not.
Privacy Act: the Australian Privacy Principles and notifiable data breaches on the standards library
From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.
Take reasonable steps to put in place practices, procedures and systems that will ensure the practice complies with the APPs and can deal with privacy inquiries and complaints.
- Privacy procedures (collection, consent, disclosure, access, breach response) with an owner and a review date
- Staff privacy training records
- Procedures exist only in the privacy policy, with nothing staff follow day to day
Have a clearly expressed and up-to-date privacy policy about how the practice manages personal information.
- The current privacy policy with its version and last review date
- Policy copied from a template and never adapted to the practice
- Policy not reviewed after a new system or service was added
The policy states the kinds of personal information collected and held, how it is collected and held, and the purposes for which it is collected, held, used and disclosed.
- The policy sections covering kinds, methods and purposes, matched to the data inventory
- Policy silent on NDIS reporting, referrals or practice software that holds records
The policy states how a person can get access to and correct their information, and how they can complain about a breach of the APPs and how the practice will deal with the complaint.
- The access, correction and complaint sections of the policy, with a contact point
- No complaint process described, or no response approach stated
The policy states whether personal information is likely to be disclosed to overseas recipients and, where practicable, the countries.
- A list of systems and providers that store or access records overseas, matched to the policy
- Cloud practice software or transcription services overseas not disclosed
Make the policy available free of charge in an appropriate form (usually on the practice website) and give a copy in a particular form when someone asks.
- The policy published on the website and a printed copy available at reception
- Policy not on the website, or only available on request
| Ref | Held (yes, partly, no, not applicable) | Where it is kept | Owner | Last reviewed | Next review |
|---|---|---|---|---|---|
| APP 1.2 | |||||
| APP 1.3 | |||||
| APP 1.4(a) to (c) | |||||
| APP 1.4(d), (e) | |||||
| APP 1.4(f), (g) | |||||
| APP 1.5, 1.6 |
Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.
Related requirements
Privacy Act: the Australian Privacy Principles and notifiable data breaches
- s 6D(1), (3) to s 6(1) health information, sensitive informationDoes the Privacy Act apply to an allied health practice?
- APP 2.1, APP 2.2APP 2: letting people deal with the practice anonymously or under a pseudonym
- APP 3.2 to APP 3.5, 3.6APP 3: collecting health information, consent and necessity
- APP 4.1, 4.2, APP 4.3, 4.4APP 4: information the practice did not ask for
- APP 5.1 to APP 5.2(g) to (j)APP 5: the collection notice for clients
- APP 6.1 to APP 6.5APP 6: sharing client information with other practitioners and the NDIS
- APP 7.1, 7.4 to APP 7.8APP 7: newsletters and marketing to clients
- APP 8.1, APP 8.2(a), (b), APP 8.2(c), (d)APP 8: client information that goes overseas
- Every page of this instrument
The same topic in other instruments (privacy and records)
- NDIS Practice Standards Core 5.1, Core 5.2, Core 5.3Core module: Privacy and dignity
- NDIS Practice Standards Core 12.1 to Core 12.4Core module: Information management
- NDIS Code of Conduct s 6(1)(b)Respect the privacy of people with disability
- Children guidance P-2Protect privacy and dignity, and ask before touching
- Ahpra shared Code of conduct 3.3Confidentiality and privacy
- Psychology Board Code of conduct 3.3Privacy and confidentiality
See every requirement for your practiceSee the specimen practice