Free checklist

Privacy Act & APP compliance checklist for counsellors

A practical, plain-language walk-through of what the Privacy Act 1988 and the Australian Privacy Principles actually require of a small counselling practice — not just "get a privacy policy."

The bit practices most often get wrong

"We're too small to need this" usually doesn't apply to you

The Privacy Act generally exempts small businesses (under $3 million annual turnover) from most obligations. But that exemption doesn't apply to health service providers — and providing counselling is a health service. In practice, this means a solo counsellor sees the same core obligations as a large health provider: an APP-compliant privacy policy, and full coverage under the Notifiable Data Breaches scheme, regardless of practice size.

The checklist

Working through the Australian Privacy Principles

The Privacy Act sets out 13 Australian Privacy Principles (APPs). Not all are equally relevant to a small practice day-to-day — here's what actually matters, grouped by theme.

☐ Have a written privacy policy (APP 1)

Covers what personal and health information you collect, why, how it's stored, who might see it, and how a client can access or complain. Make it available on request, not buried — a page on your website is the easiest way to satisfy this.

☐ Only collect what the service actually needs, and say why (APP 3 & 5)

Intake forms should ask for what informs care and billing, not everything you could conceivably want. Tell clients at collection time — in the intake form or verbally — what you collect and what it's used for.

☐ Treat session content as sensitive information (APP 3.3)

Health information is "sensitive information" under the Act, which sets a higher consent bar than ordinary personal information. Explicit, informed consent before collection — not just an assumed-consent clause buried in a form — is the safer standard, especially for anything AI-assisted (see our AI note-drafting compliance page).

☐ Only use or share information for the reason it was collected (APP 6)

Sharing with a GP, a funder, or a supervisor generally needs either the client's consent or a specific listed exception (like a serious threat to health or safety, or a legal requirement) — not just because it seems reasonable at the time.

☐ Keep records secure, and dispose of them properly (APP 11)

Encryption in transit and at rest, access controls so only you (and any staff who need it) can see client files, and secure deletion rather than just dragging a folder to trash when records are no longer needed.

☐ Let clients see and correct their own information (APP 12 & 13)

Clients generally have a right to access their own record and request corrections. Have a simple process ready for this rather than improvising when it's first asked.

☐ Know your data breach obligations before you need them

The Notifiable Data Breaches scheme applies to you regardless of practice size, for the same health-service-provider reason above. See our data breach response template for the step-by-step obligations.

☐ Check your state's health records retention rules too

The Privacy Act sets the floor, not the ceiling — several states have their own health records legislation (for example NSW's Health Records and Information Privacy Act, Victoria's Health Records Act) with their own minimum retention periods, plus whatever your registration body (ACA, PACFA, AHPRA) separately requires. Confirm the rules for your state and registration body directly.

General information only, not legal advice — privacy law and OAIC guidance change, and how these principles apply depends on your specific practice. Confirm your position with a lawyer or the OAIC directly before relying on this for a compliance decision.

Built into the platform

Zenvia is built around these obligations, not bolted on after

Australian hosting, encryption in transit and at rest, consent capture before any AI processing, an access and edit log on every record, and full client-data export any time. See our security page for the detail.

Get a link to this checklist by email

So you can find it again without hunting through your browser history.

Also relevant: data breach response template and how Zenvia handles security.