Allied Health NDIS Audit Checklist: worksheet
Privacy Act: the Australian Privacy Principles and notifiable data breaches. Edition held: Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches); checked current on 6 October 2026 (Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026).
Under review, not in force: From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.
Source: https://compliance.theartofservice.com/frameworks/australian-privacy-principles-apps. Page: https://allied-health-ndis-audit-checklist.theartofservice.com/rules/privacy-act/app-11-security-and-destruction/
| Ref | Requirement (our statement of the clause) | Evidence an auditor or the regulator asks for | Common gap to check | Held (yes, partly, no, not applicable) | Where it is kept | Owner | Last reviewed | Next review |
|---|---|---|---|---|---|---|---|---|
| APP 11.1 | Take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. | Access controls on practice software (individual logins, roles); Device security for laptops and phones holding client information | Shared logins on practice software; Client information on personal phones without protection | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| APP 11.3 | Those reasonable steps include technical and organisational measures (for example multi-factor sign-in, encryption, access reviews, staff training and written procedures). | A list of the technical measures in place and the organisational measures (training, procedures, access reviews) with dates | Only technical controls considered, with no training or procedures; Access never reviewed when staff leave | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| APP 11.2 | When the practice no longer needs personal information for any permitted purpose, the information is not in a Commonwealth record and no Australian law or court order requires it to be kept, take reasonable steps to destroy or de-identify it. | A retention and destruction schedule naming the law that sets each retention period; Destruction records | Records kept indefinitely with no schedule; Destruction done without the state retention period checked | ☐ yes ☐ partly ☐ no ☐ n/a |
Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.