1. Policy statement
Care To Support Disability Services is committed to respecting and protecting the privacy, dignity and confidentiality of NDIS participants and every person whose information we handle. Privacy is treated as a core participant right and an essential part of safe, person-centred support.
We manage personal information openly and transparently, collect only information that is reasonably necessary for legitimate functions or activities, and apply additional protections to sensitive and health information. Personal information is not to be accessed, used or shared merely because it is available.
2. Purpose and objectives
This policy is intended to:
- Protect privacy, dignity, autonomy and confidentiality;
- Explain what information is collected, why it is collected, how it is used and disclosed, and how consent can be changed or withdrawn;
- Maintain accurate, current, secure and accessible information-management systems;
- Establish clear procedures for collection, access, correction, confidentiality, audit access, retention, secure destruction, complaints and data breaches; and
- Demonstrate compliance with applicable privacy law, the NDIS Code of Conduct and NDIS Practice Standards.
3. Scope
This policy applies to personal information and sensitive information in any format, including paper records, electronic files, photographs, video or audio recordings, emails, messages, case notes, incident reports, complaints, rosters, assessments, support plans, financial records and information held in approved cloud or practice-management systems.
It applies to all directors, key personnel, employees, contractors, labour-hire or agency workers, students, volunteers and any other person who handles information on behalf of Care To Support Disability Services. Contracted service providers must meet privacy and confidentiality requirements appropriate to the information they handle.
4. Legal and regulatory framework
Care To Support Disability Services will comply with privacy and information-handling obligations that apply to its activities, including:
- Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs);
- Part IIIC of the Privacy Act 1988 (Cth) - Notifiable Data Breaches scheme;
- National Disability Insurance Scheme Act 2013 (Cth);
- National Disability Insurance Scheme (Code of Conduct) Rules 2018;
- National Disability Insurance Scheme (Provider Registration and Practice Standards) Rules 2018;
- NDIS Practice Standards and Quality Indicators, including Privacy and Dignity and Information Management; and
- other applicable Commonwealth and South Australian laws, professional obligations, contractual requirements and record-keeping requirements.
Nothing in this policy prevents lawful information sharing where disclosure is required or authorised by law, including for safeguarding, regulatory, emergency, court or tribunal purposes.
5. Key definitions
| Term | Meaning |
|---|---|
| Personal information | Information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not. |
| Sensitive information | A category of personal information that includes health information and specified information such as racial or ethnic origin, political opinions, religious beliefs, sexual orientation or practices, criminal record and certain biometric information. |
| Health information | Information or an opinion about an individual's health, disability or health services, including information collected in providing a health service. |
| Consent | A voluntary and informed agreement by a person with capacity to consent, or by an authorised representative where applicable. Consent must be current and sufficiently specific for the relevant purpose. |
| Data breach | Unauthorised access to, unauthorised disclosure of, or loss of personal information held by Care To Support Disability Services. |
| Participant | A person receiving, seeking or referred for NDIS supports or services from Care To Support Disability Services. |
6. Privacy principles we follow
Where applicable, Care To Support Disability Services applies the 13 Australian Privacy Principles. In practical terms, we:
- Manage personal information openly and transparently;
- Allow anonymous or pseudonymous dealings where lawful and practicable;
- Collect only information reasonably necessary for our functions or activities and meet the higher requirements for sensitive information;
- Deal appropriately with unsolicited information;
- Give collection notices or explanations where required;
- Use and disclose information only for the primary purpose, a permitted related purpose, with consent, or as otherwise required or authorised by law;
- Apply the legal requirements for direct marketing and government-related identifiers;
- Manage overseas disclosures with care;
- Take reasonable steps to maintain information quality and security; and
- Provide access and correction rights subject to lawful exceptions.
7. Information we may collect
Depending on the person and services involved, we may collect:
- Identity and contact details, date of birth and communication preferences;
- NDIS participant number, plan details, funding and plan-management information;
- Health, disability, medication, allergy, behavioural support, mobility, communication and risk information relevant to safe support;
- Cultural, language, accessibility, personal preference, goal and support-network information;
- Details of guardians, nominees, authorised representatives, family members, carers and emergency contacts;
- Assessments, support plans, progress notes, case notes, incident reports, ABC logs, restrictive practice information where applicable, complaints and feedback;
- Appointment, transport, roster, attendance and service-delivery records;
- Billing, invoicing and payment-related information;
- Photographs, video or audio where genuinely required and consented to, or otherwise lawfully authorised;
- Website, enquiry, referral and correspondence information; and
- For workers and applicants: identity, contact, qualifications, employment, payroll, training, screening, compliance, performance and workplace information.
Information must not be collected merely because it may be useful in the future. Collection must have a legitimate service, safety, legal, funding, workforce, quality, audit or organisational purpose.
8. Collection procedure and privacy notices
Information may be collected directly from the individual or, where appropriate and lawful, from an authorised representative, nominee, guardian, family member, carer, support coordinator, plan manager, allied health professional, health practitioner, hospital, government agency, NDIA, NDIS Commission, another provider or other relevant source.
At or before collection, or as soon as practicable afterwards, workers must take reasonable steps to explain:
- Why the information is being collected and whether collection is required or optional;
- How the information will be used and the usual types of disclosure;
- How the information is stored and protected;
- How the person can access or correct their information;
- How to make a privacy complaint; and
- Any material consequences if information is not provided.
The explanation must be provided in a form and language the person is most likely to understand, with interpreters, Easy Read information, communication aids or other reasonable adjustments where needed.
9. Consent, choice and supported decision-making
9.1 Consent
Participant consent will be obtained for collection, use, retention and disclosure where consent is required. Consent must be informed, voluntary and specific enough for the relevant purpose. Workers must not pressure a participant to agree to unnecessary information sharing.
A participant may withdraw or amend consent at any time. Care To Support Disability Services will explain any practical or legal consequences. Withdrawal does not invalidate prior lawful handling and does not prevent handling that is required or authorised by law.
9.2 Representatives and decision support
Participants are supported to make and communicate their own privacy choices wherever possible. Where a legally authorised representative acts for a participant, workers must verify the representative's authority and continue to involve the participant to the greatest extent appropriate.
9.3 Photographs, video and audio
Specific consent will be obtained where required before recording or using a participant's image, voice or likeness. Consent for service delivery or record keeping does not automatically constitute consent for marketing, social media, testimonials or promotional use.
10. Use and disclosure of information
Care To Support Disability Services uses and discloses information only where lawful and reasonably necessary. Typical purposes include:
- Assessing needs and providing safe, appropriate and person-centred supports;
- Developing, implementing and reviewing service agreements, support plans and risk controls;
- Coordinating services with authorised health professionals, support coordinators, plan managers, nominees, representatives and other providers;
- Managing appointments, transport, rosters, staffing, medication supports and other service-delivery activities;
- Invoicing, claims and NDIS-related financial administration;
- Incident, complaint, safeguarding, behaviour support, restrictive practice and reportable incident processes where applicable;
- Quality, audit, accreditation, registration, training, supervision, risk management and continuous improvement;
- Worker recruitment, screening, payroll and employment administration; and
- Complying with lawful requests, regulators, courts, tribunals and other legal obligations.
Information will not be disclosed to family members, friends, other providers or third parties simply because they know the participant. Consent, authority or another lawful basis must be confirmed first.
11. Disclosure without consent
Personal information may be used or disclosed without consent where required or authorised by law. Depending on the circumstances, this may include a serious threat to life, health or safety; suspected abuse, neglect, exploitation or violence; reportable incidents; restrictive practice obligations; lawful investigations; court or tribunal orders; or other statutory requirements.
Workers should disclose only the minimum information reasonably necessary and document the basis for disclosure where appropriate. Uncertain requests must be referred to a manager or Privacy Officer unless urgent action is required to protect safety.
12. Audit, quality and regulatory access
Care To Support Disability Services may be required to provide evidence to approved quality auditors, the NDIS Quality and Safeguards Commission, the NDIA or other lawful oversight bodies. Information will be managed in accordance with applicable audit rules, participant consent arrangements and legal authority.
Participants will be informed about audit participation and privacy arrangements where required. A participant's choice about interview participation or consent to share identifiable information will be respected unless disclosure is otherwise required or authorised by law.
13. Government-related identifiers
NDIS participant numbers, Medicare numbers and other government-related identifiers will only be adopted, used or disclosed where permitted by law. They must not be used as general internal identifiers unless lawful and appropriate.
14. Information quality and case recording
Participant information must be recorded accurately, objectively, respectfully and promptly. Case notes and incident records must distinguish observed facts from professional opinions or information reported by others. Records must use person-centred language and include only information relevant to service delivery, safety, legal compliance or legitimate organisational functions.
15. Information security and confidentiality controls
Reasonable technical, physical and organisational safeguards will be used to protect information against misuse, interference, loss and unauthorised access, modification or disclosure. Controls may include:
- Role-based or need-to-know access;
- Unique user accounts, strong passwords and multi-factor authentication where available;
- Secure devices, networks, approved email accounts and approved cloud or practice-management systems;
- Locked storage for paper records and secure transport where required;
- Clear-screen, clear-desk and secure-disposal practices;
- Limits on downloads, screenshots, local copies and personal-device storage;
- Confidentiality agreements, induction, privacy training and supervision;
- Prompt access changes when roles change or workers leave;
- Backups, system updates, malware protection and proportionate cyber-security controls; and
- Incident reporting and data-breach response procedures.
Participant information must not be stored in personal email accounts, personal cloud storage, unapproved messaging applications or other unauthorised systems. Personal information must not be discussed in public or with people who do not have a legitimate need to know.
16. Remote work, mobile devices and messaging
Workers accessing information remotely or on mobile devices must use approved systems and maintain the same level of confidentiality as at a Care To Support Disability Services workplace. Devices must be appropriately secured and must not be left accessible to family members or other unauthorised persons.
Approved messaging platforms may be used only when appropriate privacy and security controls are in place. Sensitive detail should be minimised in messages and important information transferred into the official participant record where required.
17. Overseas disclosure and cloud services
Care To Support Disability Services may use reputable third-party technology or cloud providers. Before personal information is disclosed to an overseas recipient, reasonable steps required by APP 8 will be considered, including recipient location, contractual safeguards, security arrangements and privacy risk. Likely overseas disclosures will be addressed in privacy notices or collection processes where required.
18. Retention, archiving and secure destruction
Personal information will be retained only for as long as reasonably required for service delivery, legal, NDIS, employment, insurance, taxation, safeguarding, audit, complaint, incident, contractual or other legitimate purposes.
Specific record categories will be retained for any minimum period required by applicable law or NDIS rules.
When information is no longer required and there is no lawful reason to retain it, reasonable steps will be taken to destroy it securely or de-identify it. Destruction must be irreversible and appropriate to the record format. Archived records remain subject to access controls and confidentiality obligations.
19. Access to personal information
Individuals may request access to personal information Care To Support Disability Services holds about them. Participants should be supported to access information in a form they can understand. Identity and authority must be verified before information is released.
Access will generally be provided within a reasonable period unless a lawful exception applies. If access is refused or limited, Care To Support Disability Services will provide reasons and available complaint options where required by law.
20. Correction of personal information
Individuals may request correction of information they believe is inaccurate, out of date, incomplete, irrelevant or misleading. Reasonable steps will be taken to correct information where required and, where appropriate, relevant third parties may be notified of the correction.
If a requested correction is not made, reasons will be provided where required and a statement may be attached to the record noting the individual's position.
22. Data breaches and cyber incidents
22.1 Immediate internal response
All actual or suspected privacy or cyber-security incidents must be reported internally as soon as possible. Examples include information sent to the wrong recipient, lost files or devices, unauthorised system access, compromised passwords, accidental publication, inappropriate discussion or deliberate disclosure.
- Contain the incident and stop further disclosure or access where possible.
- Preserve relevant evidence and identify what information, systems and individuals may be affected.
- Notify the Privacy Officer / Director and engage IT, legal, HR, safeguarding or communications support as required.
- Assess the risk of harm and take remedial action to reduce that risk.
- Document the event, decisions, notifications, corrective actions and lessons learned.
22.2 Notifiable Data Breaches scheme
A breach is not automatically notifiable. Care To Support Disability Services will assess whether the incident is an eligible data breach under Part IIIC of the Privacy Act. Where the legal threshold is met, affected individuals and the Office of the Australian Information Commissioner will be notified as required.
22.3 NDIS and other notifications
A privacy or cyber incident may separately trigger NDIS incident, reportable incident, safeguarding, employment, insurer, law-enforcement, contractual or other reporting obligations. Those obligations will be assessed on their own criteria. Care To Support Disability Services will not assume that every privacy breach must automatically be reported to the NDIS Commission.
23. Privacy complaints
A person who believes their information has been mishandled may make a complaint verbally or in writing. Complaints will be handled respectfully, confidentially, fairly and without retaliation or adverse treatment.
- Contact the Privacy Officer and provide enough information for the concern to be understood.
- Care To Support Disability Services will acknowledge and assess the complaint, seek further information if required and investigate proportionately.
- The outcome and any corrective actions will be communicated within a reasonable period.
- If the person remains dissatisfied, they may request internal review or contact an appropriate external regulator.
24. Workforce confidentiality and conduct
Every worker is responsible for protecting personal information. Access to information is a privilege attached to the worker's role, not a personal entitlement. Workers must:
- Access only information required to perform authorised duties;
- Follow participant consent and communication preferences;
- Confirm recipient details before sending information;
- Not photograph, record, copy or share participant information for personal purposes;
- Not discuss participant information on personal social media or with unauthorised people;
- Keep passwords and authentication methods confidential;
- Complete required privacy, confidentiality and cyber-security training;
- Report suspected breaches, lost information or inappropriate access immediately; and
- Continue to protect confidential information after employment or engagement ends.
Breaches of confidentiality or privacy requirements may result in corrective or disciplinary action, termination of engagement, notification to regulators or law enforcement, and other action permitted by law and organisational procedure.
25. Training, declarations and governance
The Director has overall accountability for privacy governance. The Privacy Officer coordinates privacy enquiries, complaints, breach assessment, policy review and privacy improvement. Managers and team leaders are responsible for implementing this policy in daily operations and ensuring workers understand their responsibilities.
Privacy and confidentiality training will be provided at induction and refreshed as appropriate. Workers may be required to sign confidentiality or privacy acknowledgements and complete further training where audits, incidents, supervision or performance reviews identify a knowledge gap.
Compliance may be monitored through supervision, file reviews, access reviews, incident analysis, audits, training records, risk assessments and continuous improvement processes.
26. Automated decision transparency
From 10 December 2026, where applicable to the organisation's practices, Care To Support Disability Services will ensure its privacy policy and related notices meet new APP 1 transparency requirements concerning computer programs used to make decisions that could reasonably be expected to significantly affect an individual's rights or interests. Systems and workflows will be reviewed before this requirement commences.
27. Contact details
28. External complaints and oversight
28.1 Office of the Australian Information Commissioner (OAIC)
For unresolved concerns about the handling of personal information or privacy rights. A person should generally raise the complaint with Care To Support Disability Services first so the organisation has an opportunity to respond.
Phone: 1300 363 992 | Post: GPO Box 5288, Sydney NSW 2001 | Website: www.oaic.gov.au/privacy/privacy-complaints
28.2 NDIS Quality and Safeguards Commission
For concerns or complaints about the quality or safety of NDIS supports and services, including concerns that an NDIS provider or worker has breached a participant's privacy or dignity.
Phone: 1800 035 544 | TTY: 133 677 | Email: contactcentre@ndiscommission.gov.au | Post: PO Box 210, Penrith NSW 2751 | Website: www.ndiscommission.gov.au/complaints/report
National Relay Service users can ask for 1800 035 544. Interpreters can be arranged. A person will not be disadvantaged for making a complaint or contacting an external regulator.
30. References
- Privacy Act 1988 (Cth), including Schedule 1 - Australian Privacy Principles and Part IIIC - Notifiable Data Breaches.
- Office of the Australian Information Commissioner, Australian Privacy Principles Guidelines and Privacy complaints guidance.
- National Disability Insurance Scheme Act 2013 (Cth).
- National Disability Insurance Scheme (Code of Conduct) Rules 2018.
- National Disability Insurance Scheme (Provider Registration and Practice Standards) Rules 2018.
- NDIS Quality and Safeguards Commission, NDIS Practice Standards and Quality Indicators - Core Module: Rights and Responsibilities (Privacy and Dignity).
- NDIS Quality and Safeguards Commission, NDIS Practice Standards and Quality Indicators - Core Module: Provider Governance and Operational Management (Information Management).
- NDIS Quality and Safeguards Commission, NDIS Code of Conduct and complaints guidance.