Allied Health NDIS Audit Checklist: worksheet
Privacy Act: the Australian Privacy Principles and notifiable data breaches. Edition held: Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches); checked current on 6 October 2026 (Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026).
Under review, not in force: From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.
Standards library: https://compliance.theartofservice.com/frameworks/australian-privacy-principles-apps. Page: https://allied-health-ndis-audit-checklist.theartofservice.com/rules/privacy-act/app-1-privacy-policy/
| Ref | Requirement (our statement of the clause) | Evidence an auditor or the regulator asks for | Common gap to check | Held (yes, partly, no, not applicable) | Where it is kept | Owner | Last reviewed | Next review |
|---|---|---|---|---|---|---|---|---|
| APP 1.2 | Take reasonable steps to put in place practices, procedures and systems so that the practice meets the APPs and can deal with privacy inquiries and complaints. Source: https://www.legislation.gov.au/C2004A03712/latest/text | Privacy procedures (collection, consent, disclosure, access, breach response) with an owner and a review date; Staff privacy training records | Procedures exist only in the privacy policy, with nothing staff follow day to day | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| APP 1.3 | Have a clearly expressed and up-to-date privacy policy about how the practice manages personal information. Source: https://www.legislation.gov.au/C2004A03712/latest/text | The current privacy policy with its version and last review date | Policy copied from a template and never adapted to the practice; Policy not reviewed after a new system or service was added | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| APP 1.4(a) to (c) | The policy states the kinds of personal information collected and held, how it is collected and held, and the purposes for which it is collected, held, used and disclosed. Source: https://www.legislation.gov.au/C2004A03712/latest/text | The policy sections covering kinds, methods and purposes, matched to the data inventory | Policy silent on NDIS reporting, referrals or practice software that holds records | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| APP 1.4(d), (e) | The policy states how a person can get access to and correct their information, and how they can complain about a breach of the APPs and how the practice will deal with the complaint. Source: https://www.legislation.gov.au/C2004A03712/latest/text | The access, correction and complaint sections of the policy, with a contact point | No complaint process described, or no response approach stated | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| APP 1.4(f), (g) | The policy states whether personal information is likely to be disclosed to overseas recipients and, where practicable, the countries. Source: https://www.legislation.gov.au/C2004A03712/latest/text | A list of systems and providers that store or access records overseas, matched to the policy | Cloud practice software or transcription services overseas not disclosed | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| APP 1.5, 1.6 | Make the policy available free of charge in an appropriate form (usually on the practice website) and give a copy in a particular form when someone asks. Source: https://www.legislation.gov.au/C2004A03712/latest/text | The policy published on the website and a printed copy available at reception | Policy not on the website, or only available on request | ☐ yes ☐ partly ☐ no ☐ n/a |
Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.