Allied Health NDIS Audit Checklist
PrivacyPrivacy Act: the Australian Privacy Principles and notifiable data breachesprivacy-act--notifiable-data-breach-notification
Requirement

Notifiable data breaches: notifying the Commissioner and the people affected

Once a practice has reasonable grounds to believe there has been an eligible data breach, it prepares a statement, gives it to the Australian Information Commissioner as soon as practicable, and as soon as practicable after that notifies the affected people, or those at risk, or publishes the statement where neither is practicable.

Clause

Privacy Act s 26WK(2), (3) to s 26WM

Regulator

Office of the Australian Information Commissioner

Edition held

Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches)

Checked current

6 October 2026, Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026

Who it applies to

Every allied health practice that provides a health service and holds health information, whatever its turnover (s 6D(4)(b)), every profession, speech pathology included, NDIS registered or not.

Under review, not in force

From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.

s 26WK(2), (3)As soon as practicable after becoming aware, prepare a statement setting out thesource
Requirement, our statement of the clause

As soon as practicable after becoming aware, prepare a statement setting out the practice's identity and contact details, a description of the breach, the kinds of information involved, and recommended steps for the people affected, and give a copy to the Commissioner.

Evidence that typically shows this
  • The statement to the Commissioner, with the date it was given
Common gap to check
  • Statement missing the recommended steps for individuals
  • Delay between the decision and the statement with no reason recorded
s 26WL(2), (3)As soon as practicable after preparing the statement, take reasonable steps to notifysource
Requirement, our statement of the clause

As soon as practicable after preparing the statement, take reasonable steps to notify its contents to every person whose information was involved, or to every person at risk, or, if neither is practicable, publish it on the practice website and publicise it.

Evidence that typically shows this
  • Notification records per person, or the published statement and how it was publicised
Common gap to check
  • Website publication used when individual notice was practicable
s 26WL(4)A practice may notify a person by the method it normally uses to communicate with themsource
Requirement, our statement of the clause

A practice may notify a person by the method it normally uses to communicate with them.

Evidence that typically shows this
  • The method used for each person notified
Common gap to check
  • Notice sent to an old address the practice no longer uses for that client
s 26WMWhere the same breach is an eligible data breach of more than one entity (for examplesource
Requirement, our statement of the clause

Where the same breach is an eligible data breach of more than one entity (for example the practice and its software provider), one entity's statement and notification satisfy the duty for the others.

Evidence that typically shows this
  • A written agreement or record of which entity notified
Common gap to check
  • No one notified because each party assumed the other would
Worksheet: what your practice holds, and where
RefHeld (yes, partly, no, not applicable)Where it is keptOwnerLast reviewedNext review
s 26WK(2), (3)
s 26WL(2), (3)
s 26WL(4)
s 26WM

Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.

Related requirements

Privacy Act: the Australian Privacy Principles and notifiable data breaches

The same topic in other instruments (privacy and records)

See every requirement for your practiceSee the specimen practice