Last Reviewed: July 2026
1. Introduction
GoodBlokes Psychology (‘the Practice’) is committed to protecting the privacy and confidentiality of all personal, sensitive, and health information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and all relevant professional codes, including those of the Psychology Board of Australia (PsyBA) and the Australian Psychological Society (APS).
2. Definitions
· Personal Information: Information or an opinion about an identified individual, or an individual who is reasonably identifiable.
· Sensitive Information: Information about an individual's health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, or other protected categories.
· AI Tool: Any software program using artificial intelligence to assist in clinical or administrative tasks.
3. Collection and Use of Information
Information is collected directly from clients via intake forms, consent forms, assessments, and during service provision.
Information may also be received from third parties (e.g., GPs, hospitals, other health professionals) with client consent.
Sensitive information is only collected with explicit consent unless required by law.
Information is used for the delivery of psychological services, treatment planning, communication with other health providers, and compliance with legal obligations (e.g., mandatory reporting).
4. Record Keeping and Security
All client records are maintained securely in electronic format.
Access to client records is restricted to authorised clinicians and administrative staff. Administrative staff may access files solely for the purposes of administrative support and are bound by confidentiality and privacy obligations.
Sensitive information is stored with heightened access controls.
The Practice utilises digital record-keeping applications and subscription services (e.g., BastionGPT, Zanda, Novopsych) that are bound by the Australian Privacy Act and maintain data storage within Australia. These services adhere to industry-recognised security standards such as ISO 27001 and HIPAA compliance.
Reasonable steps are taken to protect data from misuse, loss, unauthorised access, modification, or disclosure.
5. Data Security Limitations
While GoodBlokes Psychology takes all reasonable steps and utilises industry-standard security measures to protect your information, no data security system can guarantee absolute protection at all times. The transmission and exchange of information, including in-person, via phone, email or internet-based platforms, is undertaken at your own risk.
The Practice cannot guarantee the security of information transmitted to or received from us electronically. Although safeguards are in place to prevent unauthorised disclosure, there remains a residual risk that information may be accessed, disclosed, altered, or destroyed in a manner inconsistent with this policy.
Clients are responsible for maintaining the confidentiality of any passwords or account information associated with access to our platforms or services.
6. Notifiable Data Breaches
The Practice will take all reasonably necessary measures to address any unauthorised collection, use, or disclosure of Personal Information that could result in Serious Harm to an individual ("a data breach").
For the purposes of this Policy, "Serious Harm" refers to any harm or loss that has, or could have, significant adverse effects on an individual’s physical, mental or psychological, financial, or reputational wellbeing.
In the event of a data breach involving Personal Information, the Practice will assess whether serious harm has occurred or is likely to occur. When determining the likelihood of serious harm, the Practice will consider:
· Whether the compromised information includes sensitive or health-related data;
· The nature of the affected individuals (e.g., young or vulnerable persons may face higher risks);
· The number of individuals potentially impacted;
· Whether the data was encrypted, anonymised, or otherwise not easily accessible; and
· The identity of any parties who have obtained, or may obtain, access to the information.
The Practice will make reasonable efforts to notify both the Office of the Australian Information Commissioner (OAIC) and any individuals at risk of serious harm due to a data breach.
The Practice is not required to notify the OAIC if it determines that the breach has been remediated, provided corrective actions have been taken to prevent serious harm to affected individuals, and no further risk of serious harm remains.
In cases where a data breach cannot be remediated ("a notifiable data breach"), the Practice will submit a statement to the OAIC containing:
· The Practice’s identity and contact details;
· A summary of the breach;
· A description of the compromised personal, sensitive, or health information; and
· Recommended steps for affected individuals to mitigate potential harm.
Where a notifiable data breach occurs, the Practice will directly inform all individuals whose Personal Information was involved and who are at risk of Serious Harm.
If direct notification is impractical, the Practice will publish the details of the breach on its website, including the statement provided to the OAIC.
7. AI-Assisted Note-Taking
AI tools may be used to assist with clinical note-taking, session summaries, and report generation, with client consent.
Clinicians review all AI-generated notes for accuracy and completeness.
All AI tools used by the Practice store data within Australia and comply with the Australian Privacy Act.
Participation in AI note-taking is voluntary; clients may decline without affecting their access to services.
Administrative staff do not use AI tools for clinical documentation, except where their support role requires it and always under confidentiality obligations.
8. Disclosure and Communication
Information may be disclosed to other health professionals involved in a client’s care, with consent.
Disclosure without consent may occur where required by law, court order, or where there is a risk of harm to the client or others.
The Practice endeavours to ensure all client data is stored and processed within Australia. If, in exceptional circumstances, data is processed overseas, it will only be with providers bound by the Australian Privacy Act and equivalent data protection standards.
9. Child Safety and Mandatory Reporting
The Practice complies with all mandatory reporting obligations under relevant State and Commonwealth legislation.
Where concerns regarding harm or risk to children arise, appropriate action will be taken, including notification of relevant authorities and provision of ongoing support.
10. Legal Proceedings (Court Reports/Testimony)
GoodBlokes Psychology is not a forensic psychology service. Requests for court-related assessments, reports, or testimony will be considered on a case-by-case basis and must be discussed and agreed to by the treating clinician. In some circumstances, it may be appropriate to provide documentation for court purposes.
11. Client Rights
As a client of GoodBlokes Psychology, you have the right to:
· Be treated with respect at all times.
· Have your cultural background and language tradition respected.
· Receive a clear explanation of the services you will receive.
· Be asked to give your consent for any service provided prior to the service commencing and as it progresses.
· Receive an explanation about the confidentiality of the service and the exceptional situations where your confidentiality may not be protected.
· Receive a clear statement about fees for your services.
· Discuss the estimated number of sessions required to achieve your goals.
· Receive skilled and professional services, with clear goals for therapy.
· Access your personal information (subject to legal exceptions) and request correction of inaccurate or incomplete information.
· Decline the use of AI tools in your care.
· Choose your therapist and request a change if desired.
· Withdraw consent for the use of your information, except where required by law.
· Ask any questions about the service you are receiving.
12. Complaints Handling
Clients may raise privacy or service concerns with the Practice’s Privacy Officer at admin@goodblokespsychology.com.au.
Complaints will be investigated and responded to within 28 days (with a possible extension to 56 days if necessary).
If unsatisfied, clients may lodge complaints with the Office of the Australian Information Commissioner (OAIC).
13. Policy Review and Updates
This policy is reviewed periodically to ensure compliance with legislative changes and best practices.
Clients will be notified of significant updates.
This policy was last reviewed in June 2026.