Allied Health NDIS Audit Checklist: worksheet
Privacy Act: the Australian Privacy Principles and notifiable data breaches. Edition held: Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches); checked current on 6 October 2026 (Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026).
Under review, not in force: From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.
Standards library: https://compliance.theartofservice.com/frameworks/australian-privacy-principles-apps. Page: https://allied-health-ndis-audit-checklist.theartofservice.com/rules/privacy-act/app-3-collecting-health-information/
| Ref | Requirement (our statement of the clause) | Evidence an auditor or the regulator asks for | Common gap to check | Held (yes, partly, no, not applicable) | Where it is kept | Owner | Last reviewed | Next review |
|---|---|---|---|---|---|---|---|---|
| APP 3.2 | Collect personal information that is not sensitive only where it is reasonably necessary for one or more of the practice's functions or activities. Source: https://www.legislation.gov.au/C2004A03712/latest/text | Intake and referral forms reviewed field by field for necessity | Intake forms asking for information no service uses | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| APP 3.3(a) | Collect sensitive information, including health information, only with the person's consent and where it is reasonably necessary for the practice's functions or activities. Source: https://www.legislation.gov.au/C2004A03712/latest/text | Consent recorded at intake for the health information collected, with how consent was given; Consent arrangements for children and people with a substitute decision-maker | Consent assumed rather than recorded; No process where a parent, guardian or nominee consents | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| APP 3.4(a), (c), s 16B | Sensitive information may be collected without consent only where an exception applies, such as collection required or authorised by an Australian law, or a permitted health situation under s 16B (for example where the information is necessary to provide a health service and is collected as required by law or in line with binding professional confidentiality rules). Source: https://www.legislation.gov.au/C2004A03712/latest/text | A note of each situation where the practice collects health information without consent and the exception relied on | Collecting a client's family history about other people without checking s 16B(1A) | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| APP 3.5, 3.6 | Collect personal information only by lawful and fair means, and from the person unless it is unreasonable or impracticable to do so (for example a referral from a treating doctor). Source: https://www.legislation.gov.au/C2004A03712/latest/text | Referral intake procedure noting when information comes from someone other than the client | No record of the source when information comes from a third party | ☐ yes ☐ partly ☐ no ☐ n/a |
Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.