top of page

Privacy and confidentiality

Introduction

This policy guarantees that we handle and safeguard personal information in compliance with the NDIS and applicable privacy laws. We respect individuals' privacy rights while understanding that collecting, maintaining, and managing personal information is necessary to ensure a safe working environment and uphold high-quality standards.

 

The information we gather is utilised to deliver services to participants in a secure and healthy setting that meets their specific needs. It also enables us to fulfill our duty of care responsibilities, make appropriate referrals, and conduct necessary business activities to support the services we provide.

Applicability

WHEN

WHO

  • Applies to all personal information and sensitive personal information including the personal information of employees and participants

  • Applies to all company confidential information – that is any information not publicly available.

  • Applies to all representatives including key management personnel, directors, full time workers, part time workers, casual workers, contractors and volunteers.

Regulations relevant to this policy

  • NDIS (Quality Indicators) Guidelines 2078 (Cth)

  • NDIS (Provider Registration and Practice Standards) Rules 2078 (Cth)

  • Privacy Act 1988 (Cth)

  • Privacy Amendment (Notifiable Data Breaches) Act 2077 (Cth)

Privacy and confidentiality guidelines

To support the privacy and confidentiality of individuals:

  • We are committed to complying with the privacy requirements of the Privacy Act, the Australian Privacy Principles and for Privacy Amendment (Notifiable Data Breaches) as required by organisations providing disability services

  • We are fully committed to complying with the consent requirements of the NDIS Quality and Safeguarding Framework and relevant state or territory requirements

  • We provide all individuals with access to information about the privacy of their personal information

  • Each individual has the right to opt out of consenting to and providing their personal details if they wish 

  • Individuals have the right to request access to their personal records by requesting this with their contact person 

  • Where we are required to report to government funding bodies, information provided is non-identifiable and related to services and support hours provided, age, disability, language, and nationality 

  • Personal information will only be used by us and will not be shared outside the organisation without your permission unless required by law (e.g. reporting assault, abuse, neglect, or where a court order is issued) 

  • Images or video footage of participants will not be used without their consent 

  • Participants have the option of being involved in external NDIS audits if they wish.

Privacy and confidentiality guidelines

To keep information secure:

  • We take reasonable steps to protect the personal information we hold against misuse, interference, loss, unauthorised access, modification and disclosure 

  • Personal information is accessible to the participant and is able for use only by relevant workers 

  • Security for personal information includes password protection for IT systems, locked filing cabinets and physical access restrictions with only authorised personnel permitted access 

  • Personal information no longer required is securely destroyed or de-identified.

Data Breaches

As part of information security responsibilities:

  • We will take reasonable steps to reduce the likelihood of a data breach occurring including storing personal information securely and accessible only by relevant workers 

  • If we know or suspect your personal information has been accessed by unauthorised parties, and we think this could cause you harm, we will take reasonable steps to reduce the chance of harm and advise you of the breach, and if necessary the Office of the Australian Information Commissioner.

Breach of privacy and confidentiality

A breach of privacy and confidentiality is an incident:

  • Follow the Manage incident internally process to resolve 

  • May require an investigation 

  • An intentional breach will result in disciplinary action up to and including termination of employment.

 

See our Terms and Conditions here

bottom of page