Free for a week, then $19 for your first month
Expert Advice

How Twofold Handles Australian Privacy Law: the Privacy Act 1988 and the APPs for Clinicians (2026)

A plain-language guide to how Twofold handles the Privacy Act 1988 and the APPs — overseas disclosure, data breaches, state health records laws — and what your practice still does.

A shield with the Southern Cross joined to a clinic building and a secured document — how Twofold and an Australian practice share privacy responsibilities.

Most Australian small businesses with turnover under $3 million are exempt from the Privacy Act 1988. Health practices are not: any organisation that provides a health service and holds health information is covered, whatever its size. So every psychologist, counsellor, GP or allied health practice using an AI scribe needs to know how that tool handles the Australian Privacy Principles.

This article explains how Twofold, an AI scribe for clinicians, approaches Australian privacy law: its status under the Act, what happens when information goes overseas, how data breaches are handled, and which obligations stay with your practice. It is written for clinicians evaluating Twofold and for the practice managers and privacy officers who review it. If you are still comparing tools, see the best AI scribes for Australian psychologists.

Is Twofold covered by the Privacy Act 1988?

Yes. Where the Privacy Act applies, Twofold is an APP entity. That means the Australian Privacy Principles bind Twofold directly — it is accountable to the Office of the Australian Information Commissioner (OAIC) for how it handles personal information, not only to your practice through a contract.

The Act reaches organisations outside Australia that carry on business in Australia, and it covers health service providers regardless of turnover.

Which APPs matter most for an AI scribe, and how does Twofold meet them?

Six Australian Privacy Principles that matter for an AI scribe and how Twofold meets each. APP 1, open management: Twofold's privacy policy states what it collects and that information is disclosed to recipients in the United States. APP 3 and 6, collection and use: health information is collected by the clinician with consent and used only to provide the documentation service. APP 8, overseas disclosure: information is processed in the United States. APP 11, security: encryption, access controls and a documented security program. APP 12 and 13, access and correction: requests go to Twofold, or to the treating clinician for clinical records. Notifiable Data Breaches: Twofold notifies the OAIC of eligible data breaches.
  • APP 1 — open and transparent management. Twofold's privacy policy states what it collects, why, and that personal information, including health information, is likely to be disclosed to recipients in the United States.
  • APP 3 and APP 6 — collection, use and disclosure. Health information is sensitive information under the Act. It's collected by your clinician with the client's consent, and Twofold uses it only to provide the documentation service and directly related purposes. It is never used for marketing, and never used to train or fine-tune models.
  • APP 8 — cross-border disclosure. Twofold processes information in the United States, on Microsoft Azure and Google Cloud. See the next section for what that means for your practice.
  • APP 11 — security. Twofold protects information with administrative, technical and physical safeguards, including encryption, access controls and a documented security program.
  • APP 12 and APP 13 — access and correction. You can ask Twofold for access to, or correction of, information it holds about you. Requests about a client's clinical record go to the treating clinician.

What does overseas disclosure mean for my practice?

When your practice sends client information to Twofold, it is disclosing that information to an overseas recipient, because Twofold processes it in the United States. The Privacy Act allows this. Under APP 8, your practice must first take reasonable steps to ensure the recipient won't breach the APPs — usually by relying on the vendor's terms — and your own privacy policy should say that client information is likely to be disclosed overseas and to which countries.

Because Twofold is itself an APP entity, the APPs apply to it directly. Your practice still keeps its own APP 8 obligation to take reasonable steps before disclosing.

Twofold does not offer Australian hosting. If your practice's policy requires information to stay in Australia, Twofold is not the right fit.

Do state health records laws apply?

They can. Two states have health privacy laws that cover private health service providers and restrict transfers out of the state:

  • Victoria — Health Records Act 2001 (HPP 9). Health information may be transferred outside Victoria only on specified grounds, including that the recipient is bound by a law, scheme or contract substantially similar to the Health Privacy Principles, or that the individual consents.
  • New South Wales — Health Records and Information Privacy Act 2002 (HPP 14). A similar rule applies to transfers outside NSW.

Twofold being bound by the APPs is relevant to those grounds. Check which ground your practice relies on.

How are data breaches handled?

Under the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act), an eligible data breach is one likely to result in serious harm. The entity must assess a suspected breach within 30 days and notify the OAIC and affected individuals.

Where an eligible data breach occurs, Twofold notifies the OAIC and, where the scheme requires it of Twofold, the affected individuals.

Division of privacy responsibilities between an Australian practice and Twofold. The practice: client consent to record, a privacy policy that discloses overseas processing, reasonable steps before overseas disclosure under APP 8, client access and correction for clinical records, and reviewing every AI draft. Twofold, as an APP entity: uses health information only to provide the service, never for marketing or model training, protects it under APP 11, discloses US processing in its privacy policy, and notifies the OAIC of eligible data breaches.

What stays your practice's responsibility?

Twofold's obligations don't replace your practice's. Your practice still:

  • Obtains the client's informed consent to record the session and documents it. AHPRA notes that consent is particularly important for AI tools that record private conversations, and recording without consent can breach state surveillance device laws.
  • Keeps its own privacy policy current, including that client information is likely to be disclosed overseas.
  • Takes reasonable steps under APP 8 before disclosing information overseas.
  • Handles client requests to access or correct their clinical record.
  • Reviews every AI draft before it becomes part of the record.

This article explains how Twofold approaches Australian privacy law as of September 2026. It is general information, not legal advice. Your obligations depend on your state, profession and practice; confirm them with your professional body or a privacy adviser.

References

FAQ

Frequently asked questions

  • Is Twofold compliant with the Australian Privacy Principles?

    Yes. Where the Privacy Act 1988 applies, Twofold is an APP entity and the APPs bind it directly. It publishes a privacy policy that discloses US processing, treats health information as sensitive information, uses it only to provide the service, provides access and correction, and notifies the OAIC of eligible data breaches.

  • Where does Twofold store Australian client data?

    In the United States, on Microsoft Azure and Google Cloud. Twofold does not offer Australian hosting.

  • Is it legal for an Australian practice to use a US-hosted AI scribe?

    Yes. The Privacy Act allows overseas disclosure, provided your practice takes reasonable steps under APP 8 and says in its privacy policy that information is likely to be disclosed overseas. In Victoria and NSW, check the state health records law ground you rely on for transfers out of the state.

  • Does Twofold use client information to train AI models?

    No. Twofold states that information is never used for marketing, and never used to train or fine‑tune models.

  • Who can I complain to about Twofold's privacy practices?

    First to Twofold, at info@trytwofold.com. If you're not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC).