Back to the requirement

Allied Health NDIS Audit Checklist: worksheet

APP 11: securing client records and destroying them when no longer needed

Privacy Act: the Australian Privacy Principles and notifiable data breaches. Edition held: Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches); checked current on 6 October 2026 (Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026).

Under review, not in force: From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.

Source: https://compliance.theartofservice.com/frameworks/australian-privacy-principles-apps. Page: https://allied-health-ndis-audit-checklist.theartofservice.com/rules/privacy-act/app-11-security-and-destruction/

RefRequirement (our statement of the clause)Evidence an auditor or the regulator asks forCommon gap to checkHeld (yes, partly, no, not applicable)Where it is keptOwnerLast reviewedNext review
APP 11.1Take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.Access controls on practice software (individual logins, roles); Device security for laptops and phones holding client informationShared logins on practice software; Client information on personal phones without protection☐ yes
☐ partly
☐ no
☐ n/a
APP 11.3Those reasonable steps include technical and organisational measures (for example multi-factor sign-in, encryption, access reviews, staff training and written procedures).A list of the technical measures in place and the organisational measures (training, procedures, access reviews) with datesOnly technical controls considered, with no training or procedures; Access never reviewed when staff leave☐ yes
☐ partly
☐ no
☐ n/a
APP 11.2When the practice no longer needs personal information for any permitted purpose, the information is not in a Commonwealth record and no Australian law or court order requires it to be kept, take reasonable steps to destroy or de-identify it.A retention and destruction schedule naming the law that sets each retention period; Destruction recordsRecords kept indefinitely with no schedule; Destruction done without the state retention period checked☐ yes
☐ partly
☐ no
☐ n/a

Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.