Back to the requirement

Allied Health NDIS Audit Checklist: worksheet

APP 1: the practice privacy policy and what it must contain

Privacy Act: the Australian Privacy Principles and notifiable data breaches. Edition held: Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches); checked current on 6 October 2026 (Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026).

Under review, not in force: From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.

Standards library: https://compliance.theartofservice.com/frameworks/australian-privacy-principles-apps. Page: https://allied-health-ndis-audit-checklist.theartofservice.com/rules/privacy-act/app-1-privacy-policy/

RefRequirement (our statement of the clause)Evidence an auditor or the regulator asks forCommon gap to checkHeld (yes, partly, no, not applicable)Where it is keptOwnerLast reviewedNext review
APP 1.2Take reasonable steps to put in place practices, procedures and systems so that the practice meets the APPs and can deal with privacy inquiries and complaints.
Source: https://www.legislation.gov.au/C2004A03712/latest/text
Privacy procedures (collection, consent, disclosure, access, breach response) with an owner and a review date; Staff privacy training recordsProcedures exist only in the privacy policy, with nothing staff follow day to day☐ yes
☐ partly
☐ no
☐ n/a
APP 1.3Have a clearly expressed and up-to-date privacy policy about how the practice manages personal information.
Source: https://www.legislation.gov.au/C2004A03712/latest/text
The current privacy policy with its version and last review datePolicy copied from a template and never adapted to the practice; Policy not reviewed after a new system or service was added☐ yes
☐ partly
☐ no
☐ n/a
APP 1.4(a) to (c)The policy states the kinds of personal information collected and held, how it is collected and held, and the purposes for which it is collected, held, used and disclosed.
Source: https://www.legislation.gov.au/C2004A03712/latest/text
The policy sections covering kinds, methods and purposes, matched to the data inventoryPolicy silent on NDIS reporting, referrals or practice software that holds records☐ yes
☐ partly
☐ no
☐ n/a
APP 1.4(d), (e)The policy states how a person can get access to and correct their information, and how they can complain about a breach of the APPs and how the practice will deal with the complaint.
Source: https://www.legislation.gov.au/C2004A03712/latest/text
The access, correction and complaint sections of the policy, with a contact pointNo complaint process described, or no response approach stated☐ yes
☐ partly
☐ no
☐ n/a
APP 1.4(f), (g)The policy states whether personal information is likely to be disclosed to overseas recipients and, where practicable, the countries.
Source: https://www.legislation.gov.au/C2004A03712/latest/text
A list of systems and providers that store or access records overseas, matched to the policyCloud practice software or transcription services overseas not disclosed☐ yes
☐ partly
☐ no
☐ n/a
APP 1.5, 1.6Make the policy available free of charge in an appropriate form (usually on the practice website) and give a copy in a particular form when someone asks.
Source: https://www.legislation.gov.au/C2004A03712/latest/text
The policy published on the website and a printed copy available at receptionPolicy not on the website, or only available on request☐ yes
☐ partly
☐ no
☐ n/a

Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.