APP 11: securing client records and destroying them when no longer needed
A practice takes reasonable steps, including technical and organisational measures, to protect personal information from misuse, interference, loss and unauthorised access, change or disclosure, and destroys or de-identifies it once it is no longer needed and no law requires it to be kept. Health records retention periods are set mostly by state and territory law.
Privacy Act APP 11.1, APP 11.3, APP 11.2
Office of the Australian Information Commissioner
Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches)
6 October 2026, Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026
Every allied health practice that provides a health service and holds health information, whatever its turnover (s 6D(4)(b)), every profession, speech pathology included, NDIS registered or not.
Privacy Act: the Australian Privacy Principles and notifiable data breaches on the standards library
From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.
Health records retention periods are set mostly by state and territory health records laws (for example in New South Wales, Victoria and the Australian Capital Territory). This list holds none of those laws and cites none of them as a clause.
Take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.
- Access controls on practice software (individual logins, roles)
- Device security for laptops and phones holding client information
- Shared logins on practice software
- Client information on personal phones without protection
Those reasonable steps include technical and organisational measures (for example multi-factor sign-in, encryption, access reviews, staff training and written procedures).
- A list of the technical measures in place and the organisational measures (training, procedures, access reviews) with dates
- Only technical controls considered, with no training or procedures
- Access never reviewed when staff leave
When the practice no longer needs personal information for any permitted purpose, the information is not in a Commonwealth record and no Australian law or court order requires it to be kept, take reasonable steps to destroy or de-identify it.
- A retention and destruction schedule naming the law that sets each retention period
- Destruction records
- Records kept indefinitely with no schedule
- Destruction done without the state retention period checked
| Ref | Held (yes, partly, no, not applicable) | Where it is kept | Owner | Last reviewed | Next review |
|---|---|---|---|---|---|
| APP 11.1 | |||||
| APP 11.3 | |||||
| APP 11.2 |
Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.
Related requirements
Privacy Act: the Australian Privacy Principles and notifiable data breaches
- APP 10.1, APP 10.2APP 10: keeping client information accurate and up to date
- APP 12.1, 12.4 to APP 13.3 to 13.5APP 12 and 13: client requests to see or correct their records
- APP 9.1, APP 9.2APP 9: NDIS numbers, Medicare numbers and other government identifiers
- s 26WE(2) to s 26WHNotifiable data breaches: the 30-day assessment of a suspected breach
- APP 8.1, APP 8.2(a), (b), APP 8.2(c), (d)APP 8: client information that goes overseas
- s 26WK(2), (3) to s 26WMNotifiable data breaches: notifying the Commissioner and the people affected
- APP 7.1, 7.4 to APP 7.8APP 7: newsletters and marketing to clients
- APP 6.1 to APP 6.5APP 6: sharing client information with other practitioners and the NDIS
- Every page of this instrument
The same topic in other instruments (privacy and records)
- NDIS Practice Standards Core 5.1, Core 5.2, Core 5.3Core module: Privacy and dignity
- NDIS Practice Standards Core 12.1 to Core 12.4Core module: Information management
- NDIS Code of Conduct s 6(1)(b)Respect the privacy of people with disability
- Children guidance P-2Protect privacy and dignity, and ask before touching
- Ahpra shared Code of conduct 3.3Confidentiality and privacy
- Psychology Board Code of conduct 3.3Privacy and confidentiality
See every requirement for your practiceSee the specimen practice