Allied Health NDIS Audit Checklist: worksheet
Privacy Act: the Australian Privacy Principles and notifiable data breaches. Edition held: Privacy Act 1988 (Cth), Compilation No. 104 (C2026C00227), in force 4 June 2026, registered 17 June 2026 (Schedule 1, the Australian Privacy Principles; Part IIIC, notifiable data breaches); checked current on 6 October 2026 (Federal Register of Legislation Versions API: the latest and current compilation on 6 October 2026).
Under review, not in force: From 10 December 2026, APP 1.7 to 1.9 add automated-decision content to the privacy policy (Privacy and Other Legislation Amendment Act 2024, Schedule 1 items 87 and 88). Not in force yet.
Standards library: https://compliance.theartofservice.com/frameworks/australian-privacy-principles-apps. Page: https://allied-health-ndis-audit-checklist.theartofservice.com/privacy-act-health-service-providers/
| Ref | Requirement (our statement of the clause) | Evidence an auditor or the regulator asks for | Common gap to check | Held (yes, partly, no, not applicable) | Where it is kept | Owner | Last reviewed | Next review |
|---|---|---|---|---|---|---|---|---|
| s 6D(1), (3) | A small business is one with an annual turnover of 3,000,000 dollars or less for the previous financial year; a small business operator carries on only small businesses. Source: https://www.legislation.gov.au/C2004A03712/latest/text | The practice's turnover for the previous financial year, if the practice relies on any part of the small business test for other activities | Assuming the practice is exempt because its turnover is under 3 million dollars | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| s 6D(4)(b) | An entity is not a small business operator if it provides a health service to another individual and holds any health information except in an employee record. Such an entity is an organisation bound by the Australian Privacy Principles whatever its turnover. Source: https://www.legislation.gov.au/C2004A03712/latest/text | A written note, kept with the privacy policy, that the practice provides health services and holds health information, so the Australian Privacy Principles apply | No one in the practice has recorded which privacy obligations apply; Treating client notes as exempt because the practice is small | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| s 6FB(1), (3) | A health service is an activity intended or claimed to assess, maintain, improve or manage a person's health, diagnose or treat an illness, disability or injury, or record a person's health for those purposes; health includes physical and psychological health, and such an activity in aged care, palliative care or disability care is a health service. Source: https://www.legislation.gov.au/C2004A03712/latest/text | A list of the services the practice provides (assessment, therapy, reports) mapped to the health service definition | Non-clinical services (for example NDIS support coordination or reports) assumed to fall outside the Act | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| s 6(1) health information, sensitive information | Health information, including information about a person's health or disability and personal information collected to provide a health service, is sensitive information, which the Australian Privacy Principles protect more strictly (for example APP 3.3 and APP 6.2(a)(i)). Source: https://www.legislation.gov.au/C2004A03712/latest/text | A data inventory listing where health information is held: client records, referral letters, NDIS plans and reports, email and messaging | Health information held in email, text messages or personal devices left out of the inventory | ☐ yes ☐ partly ☐ no ☐ n/a |
Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.