Allied Health NDIS Audit Checklist: worksheet
Privacy Act: the Australian Privacy Principles and notifiable data breaches. Edition held: Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches); checked current on 6 October 2026 (Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026).
Under review, not in force: From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.
Standards library: https://compliance.theartofservice.com/frameworks/notifiable-data-breaches-scheme-australia. Page: https://allied-health-ndis-audit-checklist.theartofservice.com/rules/privacy-act/notifiable-data-breach-notification/
| Ref | Requirement (our statement of the clause) | Evidence an auditor or the regulator asks for | Common gap to check | Held (yes, partly, no, not applicable) | Where it is kept | Owner | Last reviewed | Next review |
|---|---|---|---|---|---|---|---|---|
| s 26WK(2), (3) | As soon as practicable after becoming aware, prepare a statement setting out the practice's identity and contact details, a description of the breach, the kinds of information involved, and recommended steps for the people affected, and give a copy to the Commissioner. Source: https://www.legislation.gov.au/C2004A03712/latest/text | The statement to the Commissioner, with the date it was given | Statement missing the recommended steps for individuals; Delay between the decision and the statement with no reason recorded | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| s 26WL(2), (3) | As soon as practicable after preparing the statement, take reasonable steps to notify its contents to every person whose information was involved, or to every person at risk, or, if neither is practicable, publish it on the practice website and publicise it. Source: https://www.legislation.gov.au/C2004A03712/latest/text | Notification records per person, or the published statement and how it was publicised | Website publication used when individual notice was practicable | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| s 26WL(4) | A practice may notify a person by the method it normally uses to communicate with them. Source: https://www.legislation.gov.au/C2004A03712/latest/text | The method used for each person notified | Notice sent to an old address the practice no longer uses for that client | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| s 26WM | Where the same breach is an eligible data breach of more than one entity (for example the practice and its software provider), one entity's statement and notification satisfy the duty for the others. Source: https://www.legislation.gov.au/C2004A03712/latest/text | A written agreement or record of which entity notified | No one notified because each party assumed the other would | ☐ yes ☐ partly ☐ no ☐ n/a |
Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.