APP 12 and 13: client requests to see or correct their records
A client may ask to see their information and to have it corrected. A private practice responds within a reasonable period, gives access in the manner asked where reasonable, refuses only on a listed ground with a written notice, and never charges for the request itself.
Privacy Act APP 12.1, 12.4 to APP 13.3 to 13.5
Office of the Australian Information Commissioner
Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches)
6 October 2026, Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026
Every allied health practice that provides a health service and holds health information, whatever its turnover (s 6D(4)(b)), every profession, speech pathology included, NDIS registered or not.
Privacy Act: the Australian Privacy Principles and notifiable data breaches on the standards library
From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.
On request, give the person access to their information; respond within a reasonable period and give access in the manner requested where reasonable and practicable.
- An access request procedure with a target response time
- A log of requests and responses
- Requests answered only when chased
- No log of requests
Refuse access only to the extent a ground in APP 12.3 applies (for example a serious threat to life, health or safety, or an unreasonable impact on another person's privacy); consider other means of access such as an agreed intermediary; give a written notice with the reasons and how to complain.
- Refusal notices with the APP 12.3 ground and complaint options
- Access refused with no written reasons
A practice may charge for giving access, but the charge must not be excessive and must not apply to making the request.
- The practice fee for providing copies, if any
- A fee charged for lodging the request
Take reasonable steps to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading, on request or when the practice is satisfied it needs correcting, and notify another entity it was disclosed to if the person asks.
- A correction procedure and log, including notices sent to other practitioners
- Corrections made without telling the practitioner who received the earlier report
If correction is refused, give a written notice with reasons and complaint options, associate the person's statement with the record if asked, respond within a reasonable period and charge nothing.
- Refusal notices and associated statements on file
- A client's statement not attached to the record
| Ref | Held (yes, partly, no, not applicable) | Where it is kept | Owner | Last reviewed | Next review |
|---|---|---|---|---|---|
| APP 12.1, 12.4 | |||||
| APP 12.3, 12.5, 12.9 | |||||
| APP 12.8 | |||||
| APP 13.1, 13.2 | |||||
| APP 13.3 to 13.5 |
Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.
Related requirements
Privacy Act: the Australian Privacy Principles and notifiable data breaches
- APP 11.1, APP 11.3, APP 11.2APP 11: securing client records and destroying them when no longer needed
- s 26WE(2) to s 26WHNotifiable data breaches: the 30-day assessment of a suspected breach
- APP 10.1, APP 10.2APP 10: keeping client information accurate and up to date
- s 26WK(2), (3) to s 26WMNotifiable data breaches: notifying the Commissioner and the people affected
- APP 9.1, APP 9.2APP 9: NDIS numbers, Medicare numbers and other government identifiers
- APP 8.1, APP 8.2(a), (b), APP 8.2(c), (d)APP 8: client information that goes overseas
- APP 7.1, 7.4 to APP 7.8APP 7: newsletters and marketing to clients
- APP 6.1 to APP 6.5APP 6: sharing client information with other practitioners and the NDIS
- Every page of this instrument
The same topic in other instruments (privacy and records)
- NDIS Practice Standards Core 5.1, Core 5.2, Core 5.3Core module: Privacy and dignity
- NDIS Practice Standards Core 12.1 to Core 12.4Core module: Information management
- NDIS Code of Conduct s 6(1)(b)Respect the privacy of people with disability
- Children guidance P-2Protect privacy and dignity, and ask before touching
- Ahpra shared Code of conduct 3.3Confidentiality and privacy
- Psychology Board Code of conduct 3.3Privacy and confidentiality
See every requirement for your practiceSee the specimen practice