Back to the 30-day assessment

Allied Health NDIS Audit Checklist: breach register

Breach register: suspected data breaches

Privacy Act: the Australian Privacy Principles and notifiable data breaches. Edition held: Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches); checked current on 6 October 2026 (Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026).

One row per suspected breach. No client names in any column.

Date became awareWhat happened (no client names)Information involved (kinds)Remedial action taken and when (s 26WF)Serious harm assessment against s 26WGAssessment finished (within 30 days, s 26WH)Eligible data breach? (yes, no, with reason)Statement to the Commissioner given on (s 26WK)People notified on, and how (s 26WL)Other entity involved (s 26WM)Owner

Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.