APP 4: information the practice did not ask for
When a practice receives personal information it did not ask for (for example a family member sends another person's reports), it decides within a reasonable period whether it could have collected that information under APP 3; if not, it destroys or de-identifies it where lawful and reasonable; if it could, the other APPs apply as if it had been collected.
Privacy Act APP 4.1, 4.2, APP 4.3, 4.4
Office of the Australian Information Commissioner
Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches)
6 October 2026, Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026
Every allied health practice that provides a health service and holds health information, whatever its turnover (s 6D(4)(b)), every profession, speech pathology included, NDIS registered or not.
Privacy Act: the Australian Privacy Principles and notifiable data breaches on the standards library
From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.
Within a reasonable period after receiving unsolicited personal information, decide whether the practice could have collected it under APP 3, using it only as needed to make that decision.
- A procedure for unsolicited information received by email, post or upload, with who decides
- Unsolicited records filed into the client record without a decision
If it could not have been collected, destroy or de-identify it as soon as practicable where lawful and reasonable (unless it is in a Commonwealth record); otherwise APPs 5 to 13 apply as if it had been collected under APP 3.
- Destruction records for unsolicited information the practice could not have collected
- Unsolicited information kept indefinitely
| Ref | Held (yes, partly, no, not applicable) | Where it is kept | Owner | Last reviewed | Next review |
|---|---|---|---|---|---|
| APP 4.1, 4.2 | |||||
| APP 4.3, 4.4 |
Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.
Related requirements
Privacy Act: the Australian Privacy Principles and notifiable data breaches
- APP 3.2 to APP 3.5, 3.6APP 3: collecting health information, consent and necessity
- APP 5.1 to APP 5.2(g) to (j)APP 5: the collection notice for clients
- APP 2.1, APP 2.2APP 2: letting people deal with the practice anonymously or under a pseudonym
- APP 6.1 to APP 6.5APP 6: sharing client information with other practitioners and the NDIS
- APP 1.2 to APP 1.5, 1.6APP 1: the practice privacy policy and what it must contain
- APP 7.1, 7.4 to APP 7.8APP 7: newsletters and marketing to clients
- s 6D(1), (3) to s 6(1) health information, sensitive informationDoes the Privacy Act apply to an allied health practice?
- APP 8.1, APP 8.2(a), (b), APP 8.2(c), (d)APP 8: client information that goes overseas
- Every page of this instrument
The same topic in other instruments (privacy and records)
- NDIS Practice Standards Core 5.1, Core 5.2, Core 5.3Core module: Privacy and dignity
- NDIS Practice Standards Core 12.1 to Core 12.4Core module: Information management
- NDIS Code of Conduct s 6(1)(b)Respect the privacy of people with disability
- Children guidance P-2Protect privacy and dignity, and ask before touching
- Ahpra shared Code of conduct 3.3Confidentiality and privacy
- Psychology Board Code of conduct 3.3Privacy and confidentiality
See every requirement for your practiceSee the specimen practice