Back to the requirement

Allied Health NDIS Audit Checklist: worksheet

Breach response checklist: the 30-day assessment of a suspected breach

Privacy Act: the Australian Privacy Principles and notifiable data breaches. Edition held: Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches); checked current on 6 October 2026 (Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026).

Under review, not in force: From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.

Standards library: https://compliance.theartofservice.com/frameworks/notifiable-data-breaches-scheme-australia. Page: https://allied-health-ndis-audit-checklist.theartofservice.com/rules/privacy-act/notifiable-data-breach-assessment/

RefRequirement (our statement of the clause)Evidence an auditor or the regulator asks forCommon gap to checkHeld (yes, partly, no, not applicable)Where it is keptOwnerLast reviewedNext review
s 26WE(2)An eligible data breach is unauthorised access to or disclosure of personal information, or its loss where that is likely, that a reasonable person would conclude would be likely to result in serious harm to any person it relates to.
Source: https://www.legislation.gov.au/C2004A03712/latest/text
A breach response procedure that defines an eligible data breach in the words of s 26WEA lost phone or misdirected report email not treated as a possible breach☐ yes
☐ partly
☐ no
☐ n/a
s 26WFA breach is not an eligible data breach if the practice takes action before serious harm results and, because of that action, a reasonable person would conclude serious harm is not likely (or, for a loss, no unauthorised access or disclosure occurs).
Source: https://www.legislation.gov.au/C2004A03712/latest/text
A record of remedial action taken (for example recalling a misdirected email) and why harm is no longer likelyRemedial action claimed with no record of what was done☐ yes
☐ partly
☐ no
☐ n/a
s 26WGIn judging likely serious harm, have regard to the kinds and sensitivity of the information (health information is sensitive), any security measures and the chance they are overcome, who has or could obtain it, and the nature of the harm.
Source: https://www.legislation.gov.au/C2004A03712/latest/text
A written serious-harm assessment against the s 26WG matters for each suspected breachHarm judged without writing down the s 26WG matters☐ yes
☐ partly
☐ no
☐ n/a
s 26WHWhere there are reasonable grounds to suspect an eligible data breach, carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days after becoming aware.
Source: https://www.legislation.gov.au/C2004A03712/latest/text
The breach register entry with the date the practice became aware and the date the assessment finishedThe 30-day clock started from discovery of the cause, not from awareness of the grounds☐ yes
☐ partly
☐ no
☐ n/a

Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.