Allied Health NDIS Audit Checklist
PrivacyPrivacy Act: the Australian Privacy Principles and notifiable data breachesprivacy-act--app-11-security-and-destruction
Requirement

APP 11: securing client records and destroying them when no longer needed

A practice takes reasonable steps, including technical and organisational measures, to protect personal information from misuse, interference, loss and unauthorised access, change or disclosure, and destroys or de-identifies it once it is no longer needed and no law requires it to be kept. Health records retention periods are set mostly by state and territory law.

Clause

Privacy Act APP 11.1, APP 11.3, APP 11.2

Regulator

Office of the Australian Information Commissioner

Edition held

Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches)

Checked current

6 October 2026, Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026

Who it applies to

Every allied health practice that provides a health service and holds health information, whatever its turnover (s 6D(4)(b)), every profession, speech pathology included, NDIS registered or not.

Under review, not in force

From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.

Health records retention

Health records retention periods are set mostly by state and territory health records laws (for example in New South Wales, Victoria and the Australian Capital Territory). This list holds none of those laws and cites none of them as a clause.

APP 11.1Take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosuresource
Requirement, our statement of the clause

Take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.

Evidence that typically shows this
  • Access controls on practice software (individual logins, roles)
  • Device security for laptops and phones holding client information
Common gap to check
  • Shared logins on practice software
  • Client information on personal phones without protection
APP 11.3Those reasonable steps include technical and organisational measures (for example multi-factor sign-in, encryption, access reviews, staff training and written procedures)source
Requirement, our statement of the clause

Those reasonable steps include technical and organisational measures (for example multi-factor sign-in, encryption, access reviews, staff training and written procedures).

Evidence that typically shows this
  • A list of the technical measures in place and the organisational measures (training, procedures, access reviews) with dates
Common gap to check
  • Only technical controls considered, with no training or procedures
  • Access never reviewed when staff leave
APP 11.2When the practice no longer needs personal information for any permitted purpose, the information is not in a Commonwealth record and no Australian law or court order requires it to be kept, take reasonable steps to destroy or de-identify itsource
Requirement, our statement of the clause

When the practice no longer needs personal information for any permitted purpose, the information is not in a Commonwealth record and no Australian law or court order requires it to be kept, take reasonable steps to destroy or de-identify it.

Evidence that typically shows this
  • A retention and destruction schedule naming the law that sets each retention period
  • Destruction records
Common gap to check
  • Records kept indefinitely with no schedule
  • Destruction done without the state retention period checked
Worksheet: what your practice holds, and where
RefHeld (yes, partly, no, not applicable)Where it is keptOwnerLast reviewedNext review
APP 11.1
APP 11.3
APP 11.2

Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.

Related requirements

Privacy Act: the Australian Privacy Principles and notifiable data breaches

The same topic in other instruments (privacy and records)

See every requirement for your practiceSee the specimen practice