The Privacy Act and your patients' data: a guide for psychologists
Clinical notes are among the most sensitive personal information a business can hold, and in Australia that's governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) it sets out. Here's what that actually requires of a psychology practice, in plain terms.
What the Privacy Act actually covers
The Privacy Act 1988 (Commonwealth) is Australia's principal privacy law, regulating how organisations — including most private psychology practices — collect, hold, use and disclose personal information. It sets out 13 Australian Privacy Principles (APPs) that apply across the information lifecycle, from the moment you first collect a client's details to how you eventually destroy or de-identify them.
Health information is sensitive information
Under the Privacy Act, health information — including psychological assessments, session notes and treatment records — is classified as "sensitive information," which attracts a higher standard of protection than ordinary personal information. In practice, that means clearer rules around consent, tighter restrictions on when you can use or disclose it, and a stronger expectation of security around how you store it.
Consent and lawful basis
Generally, you need a client's consent to collect and use their health information for the purpose of providing treatment, and you should be clear with them, ideally in writing at intake, about what you collect, how you'll use it, and who might see it (for example, in a supervision context, or if you need to share information with another treating practitioner with the client's consent). Consent given for one purpose doesn't automatically extend to a different, unrelated use.
Data security expectations
APP 11 requires you to take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. For a psychology practice, that translates into practical measures: encrypted storage, access limited to people who need it, secure backups, and a clear process for what happens if a client's file needs to be transferred, exported or securely destroyed.
Notifiable data breaches: under the Notifiable Data Breaches scheme, organisations covered by the Privacy Act must notify affected individuals and the OAIC if a data breach is likely to result in serious harm. Knowing this obligation exists — and having a basic plan for it — is worth doing before you ever need it, not after.
Your clients' rights over their own information
- Access. Clients generally have a right to request access to their own health information you hold.
- Correction. They can ask you to correct information that's inaccurate, out of date or incomplete.
- Complaints. If they believe their privacy has been breached, they can complain to you directly, and if unresolved, to the OAIC.
The OAIC is the regulator
The Office of the Australian Information Commissioner (OAIC) is the independent body that oversees compliance with the Privacy Act, handles complaints, and can investigate and take action over serious or repeated breaches. If you're ever unsure whether something you're planning complies, the OAIC's own guidance for health service providers is the authoritative place to check — not a general summary like this one.
Data handled the way sensitive health information deserves
Encrypted client records, hosted in the European Union, with access isolated at the database level and export or deletion available whenever you ask.
Bringing it together
The Privacy Act 1988 and the Australian Privacy Principles set a clear, if detailed, standard for how a psychology practice needs to handle client information: informed consent, real security measures, a plan for breaches, and respect for a client's right to access and correct their own records. None of this needs to be intimidating — it mostly describes what careful clinical practice already looks like, formalised into law with the OAIC as the regulator that expects you to meet it.
Frequently asked questions
What law governs patient privacy for psychologists in Australia?+
The Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) it sets out are the primary legal framework, with the Office of the Australian Information Commissioner (OAIC) as the regulator.
Is health information treated differently from other personal information?+
Yes. Health information, including psychological assessments and session notes, is classified as "sensitive information" under the Privacy Act, which attracts stricter rules around consent, use and disclosure than ordinary personal information.
What happens if there's a data breach?+
Under the Notifiable Data Breaches scheme, you're required to notify affected individuals and the OAIC if a breach is likely to result in serious harm. Having a basic response plan in place before you need one is strongly recommended.
Can clients ask to see or correct their own records?+
Yes — clients generally have a right under the Privacy Act to request access to their own health information and to ask for corrections if it's inaccurate, out of date or incomplete.
Whatever the Privacy Act requires, your data should already meet it
Encrypted client records, session notes and an export you control at any time — built for psychologists, hosted in the EU.
14 days free, no card · No lock-in · We answer directly
Nerela is practice management software built for psychologists and clinics: scheduling and online booking, patient records and session notes, invoicing and reports — in one place, with data hosted in the European Union. You start with 14 days free, no card, and you talk directly to the people building the product.
Start on Nerela — 14 days free →