Allied Health NDIS Audit Checklist
PrivacyPrivacy Act: the Australian Privacy Principles and notifiable data breachesprivacy-act--app-4-unsolicited-information
Requirement

APP 4: information the practice did not ask for

When a practice receives personal information it did not ask for (for example a family member sends another person's reports), it decides within a reasonable period whether it could have collected that information under APP 3; if not, it destroys or de-identifies it where lawful and reasonable; if it could, the other APPs apply as if it had been collected.

Clause

Privacy Act APP 4.1, 4.2, APP 4.3, 4.4

Regulator

Office of the Australian Information Commissioner

Edition held

Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches)

Checked current

6 October 2026, Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026

Who it applies to

Every allied health practice that provides a health service and holds health information, whatever its turnover (s 6D(4)(b)), every profession, speech pathology included, NDIS registered or not.

Under review, not in force

From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.

APP 4.1, 4.2Within a reasonable period after receiving unsolicited personal information, decide whether the practice could have collected it under APP 3, using it only as needed to make that decisionsource
Requirement, our statement of the clause

Within a reasonable period after receiving unsolicited personal information, decide whether the practice could have collected it under APP 3, using it only as needed to make that decision.

Evidence that typically shows this
  • A procedure for unsolicited information received by email, post or upload, with who decides
Common gap to check
  • Unsolicited records filed into the client record without a decision
APP 4.3, 4.4If it could not have been collected, destroy or de-identify it as soon as practicable where lawful and reasonable (unless it is in a Commonwealth record)source
Requirement, our statement of the clause

If it could not have been collected, destroy or de-identify it as soon as practicable where lawful and reasonable (unless it is in a Commonwealth record); otherwise APPs 5 to 13 apply as if it had been collected under APP 3.

Evidence that typically shows this
  • Destruction records for unsolicited information the practice could not have collected
Common gap to check
  • Unsolicited information kept indefinitely
Worksheet: what your practice holds, and where
RefHeld (yes, partly, no, not applicable)Where it is keptOwnerLast reviewedNext review
APP 4.1, 4.2
APP 4.3, 4.4

Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.

Related requirements

Privacy Act: the Australian Privacy Principles and notifiable data breaches

The same topic in other instruments (privacy and records)

See every requirement for your practiceSee the specimen practice