Skip to main content

Caretosupport

CARE TO SUPPORT DISABILITY SERVICES | GOVERNANCE & COMPLIANCE

Privacy, Confidentiality &
Information Management Policy

Care To Support Disability Services
NDIS Provider Policy and Procedure
Legal entity
Care to Support Disability Services Pty Ltd
Trading / service name
Care To Support Disability Services
NDIS Provider No.
4050104329
ABN
74 652 737 810
Business address
1/22 Payneham Road, Stepney SA 5069
Purpose. This policy sets the rules and procedures for collecting, using, storing, accessing, correcting, sharing, retaining and securely disposing of personal and sensitive information while delivering NDIS supports and operating Care To Support Disability Services.
Document owner
Director / Privacy Officer
Approved by
Director
Version
2.0 - consolidated privacy and confidentiality policy
Effective date
24 August 2026
Next review date
24 August 2027, or earlier if legislation, NDIS requirements, systems or practices materially change
Applies to
Directors, key personnel, employees, contractors, agency workers, students, volunteers and other workers
Status
Final draft for organisational approval

1. Policy statement

Care To Support Disability Services is committed to respecting and protecting the privacy, dignity and confidentiality of NDIS participants and every person whose information we handle. Privacy is treated as a core participant right and an essential part of safe, person-centred support.

We manage personal information openly and transparently, collect only information that is reasonably necessary for legitimate functions or activities, and apply additional protections to sensitive and health information. Personal information is not to be accessed, used or shared merely because it is available.

2. Purpose and objectives

This policy is intended to:

  • Protect privacy, dignity, autonomy and confidentiality;
  • Explain what information is collected, why it is collected, how it is used and disclosed, and how consent can be changed or withdrawn;
  • Maintain accurate, current, secure and accessible information-management systems;
  • Establish clear procedures for collection, access, correction, confidentiality, audit access, retention, secure destruction, complaints and data breaches; and
  • Demonstrate compliance with applicable privacy law, the NDIS Code of Conduct and NDIS Practice Standards.

3. Scope

This policy applies to personal information and sensitive information in any format, including paper records, electronic files, photographs, video or audio recordings, emails, messages, case notes, incident reports, complaints, rosters, assessments, support plans, financial records and information held in approved cloud or practice-management systems.

It applies to all directors, key personnel, employees, contractors, labour-hire or agency workers, students, volunteers and any other person who handles information on behalf of Care To Support Disability Services. Contracted service providers must meet privacy and confidentiality requirements appropriate to the information they handle.

5. Key definitions

TermMeaning
Personal informationInformation or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not.
Sensitive informationA category of personal information that includes health information and specified information such as racial or ethnic origin, political opinions, religious beliefs, sexual orientation or practices, criminal record and certain biometric information.
Health informationInformation or an opinion about an individual's health, disability or health services, including information collected in providing a health service.
ConsentA voluntary and informed agreement by a person with capacity to consent, or by an authorised representative where applicable. Consent must be current and sufficiently specific for the relevant purpose.
Data breachUnauthorised access to, unauthorised disclosure of, or loss of personal information held by Care To Support Disability Services.
ParticipantA person receiving, seeking or referred for NDIS supports or services from Care To Support Disability Services.

6. Privacy principles we follow

Where applicable, Care To Support Disability Services applies the 13 Australian Privacy Principles. In practical terms, we:

  • Manage personal information openly and transparently;
  • Allow anonymous or pseudonymous dealings where lawful and practicable;
  • Collect only information reasonably necessary for our functions or activities and meet the higher requirements for sensitive information;
  • Deal appropriately with unsolicited information;
  • Give collection notices or explanations where required;
  • Use and disclose information only for the primary purpose, a permitted related purpose, with consent, or as otherwise required or authorised by law;
  • Apply the legal requirements for direct marketing and government-related identifiers;
  • Manage overseas disclosures with care;
  • Take reasonable steps to maintain information quality and security; and
  • Provide access and correction rights subject to lawful exceptions.

7. Information we may collect

Depending on the person and services involved, we may collect:

  • Identity and contact details, date of birth and communication preferences;
  • NDIS participant number, plan details, funding and plan-management information;
  • Health, disability, medication, allergy, behavioural support, mobility, communication and risk information relevant to safe support;
  • Cultural, language, accessibility, personal preference, goal and support-network information;
  • Details of guardians, nominees, authorised representatives, family members, carers and emergency contacts;
  • Assessments, support plans, progress notes, case notes, incident reports, ABC logs, restrictive practice information where applicable, complaints and feedback;
  • Appointment, transport, roster, attendance and service-delivery records;
  • Billing, invoicing and payment-related information;
  • Photographs, video or audio where genuinely required and consented to, or otherwise lawfully authorised;
  • Website, enquiry, referral and correspondence information; and
  • For workers and applicants: identity, contact, qualifications, employment, payroll, training, screening, compliance, performance and workplace information.

Information must not be collected merely because it may be useful in the future. Collection must have a legitimate service, safety, legal, funding, workforce, quality, audit or organisational purpose.

8. Collection procedure and privacy notices

Information may be collected directly from the individual or, where appropriate and lawful, from an authorised representative, nominee, guardian, family member, carer, support coordinator, plan manager, allied health professional, health practitioner, hospital, government agency, NDIA, NDIS Commission, another provider or other relevant source.

At or before collection, or as soon as practicable afterwards, workers must take reasonable steps to explain:

  • Why the information is being collected and whether collection is required or optional;
  • How the information will be used and the usual types of disclosure;
  • How the information is stored and protected;
  • How the person can access or correct their information;
  • How to make a privacy complaint; and
  • Any material consequences if information is not provided.

The explanation must be provided in a form and language the person is most likely to understand, with interpreters, Easy Read information, communication aids or other reasonable adjustments where needed.

10. Use and disclosure of information

Care To Support Disability Services uses and discloses information only where lawful and reasonably necessary. Typical purposes include:

  • Assessing needs and providing safe, appropriate and person-centred supports;
  • Developing, implementing and reviewing service agreements, support plans and risk controls;
  • Coordinating services with authorised health professionals, support coordinators, plan managers, nominees, representatives and other providers;
  • Managing appointments, transport, rosters, staffing, medication supports and other service-delivery activities;
  • Invoicing, claims and NDIS-related financial administration;
  • Incident, complaint, safeguarding, behaviour support, restrictive practice and reportable incident processes where applicable;
  • Quality, audit, accreditation, registration, training, supervision, risk management and continuous improvement;
  • Worker recruitment, screening, payroll and employment administration; and
  • Complying with lawful requests, regulators, courts, tribunals and other legal obligations.

Information will not be disclosed to family members, friends, other providers or third parties simply because they know the participant. Consent, authority or another lawful basis must be confirmed first.

12. Audit, quality and regulatory access

Care To Support Disability Services may be required to provide evidence to approved quality auditors, the NDIS Quality and Safeguards Commission, the NDIA or other lawful oversight bodies. Information will be managed in accordance with applicable audit rules, participant consent arrangements and legal authority.

Participants will be informed about audit participation and privacy arrangements where required. A participant's choice about interview participation or consent to share identifiable information will be respected unless disclosure is otherwise required or authorised by law.

13. Government-related identifiers

NDIS participant numbers, Medicare numbers and other government-related identifiers will only be adopted, used or disclosed where permitted by law. They must not be used as general internal identifiers unless lawful and appropriate.

14. Information quality and case recording

Participant information must be recorded accurately, objectively, respectfully and promptly. Case notes and incident records must distinguish observed facts from professional opinions or information reported by others. Records must use person-centred language and include only information relevant to service delivery, safety, legal compliance or legitimate organisational functions.

15. Information security and confidentiality controls

Reasonable technical, physical and organisational safeguards will be used to protect information against misuse, interference, loss and unauthorised access, modification or disclosure. Controls may include:

  • Role-based or need-to-know access;
  • Unique user accounts, strong passwords and multi-factor authentication where available;
  • Secure devices, networks, approved email accounts and approved cloud or practice-management systems;
  • Locked storage for paper records and secure transport where required;
  • Clear-screen, clear-desk and secure-disposal practices;
  • Limits on downloads, screenshots, local copies and personal-device storage;
  • Confidentiality agreements, induction, privacy training and supervision;
  • Prompt access changes when roles change or workers leave;
  • Backups, system updates, malware protection and proportionate cyber-security controls; and
  • Incident reporting and data-breach response procedures.

Participant information must not be stored in personal email accounts, personal cloud storage, unapproved messaging applications or other unauthorised systems. Personal information must not be discussed in public or with people who do not have a legitimate need to know.

16. Remote work, mobile devices and messaging

Workers accessing information remotely or on mobile devices must use approved systems and maintain the same level of confidentiality as at a Care To Support Disability Services workplace. Devices must be appropriately secured and must not be left accessible to family members or other unauthorised persons.

Approved messaging platforms may be used only when appropriate privacy and security controls are in place. Sensitive detail should be minimised in messages and important information transferred into the official participant record where required.

17. Overseas disclosure and cloud services

Care To Support Disability Services may use reputable third-party technology or cloud providers. Before personal information is disclosed to an overseas recipient, reasonable steps required by APP 8 will be considered, including recipient location, contractual safeguards, security arrangements and privacy risk. Likely overseas disclosures will be addressed in privacy notices or collection processes where required.

18. Retention, archiving and secure destruction

Personal information will be retained only for as long as reasonably required for service delivery, legal, NDIS, employment, insurance, taxation, safeguarding, audit, complaint, incident, contractual or other legitimate purposes.

Specific record categories will be retained for any minimum period required by applicable law or NDIS rules.

When information is no longer required and there is no lawful reason to retain it, reasonable steps will be taken to destroy it securely or de-identify it. Destruction must be irreversible and appropriate to the record format. Archived records remain subject to access controls and confidentiality obligations.

19. Access to personal information

Individuals may request access to personal information Care To Support Disability Services holds about them. Participants should be supported to access information in a form they can understand. Identity and authority must be verified before information is released.

Access will generally be provided within a reasonable period unless a lawful exception applies. If access is refused or limited, Care To Support Disability Services will provide reasons and available complaint options where required by law.

20. Correction of personal information

Individuals may request correction of information they believe is inaccurate, out of date, incomplete, irrelevant or misleading. Reasonable steps will be taken to correct information where required and, where appropriate, relevant third parties may be notified of the correction.

If a requested correction is not made, reasons will be provided where required and a statement may be attached to the record noting the individual's position.

21. Privacy in shared supports and shared living

In shared living, group activities, transport and other shared support environments, workers must protect each person's privacy. Information about one participant must not be discussed with another participant, their visitors or unrelated family members unless consent or another lawful basis exists. Shared records, noticeboards, rosters and communication books must be positioned and designed to minimise unnecessary disclosure.

22. Data breaches and cyber incidents

22.1 Immediate internal response

All actual or suspected privacy or cyber-security incidents must be reported internally as soon as possible. Examples include information sent to the wrong recipient, lost files or devices, unauthorised system access, compromised passwords, accidental publication, inappropriate discussion or deliberate disclosure.

  1. Contain the incident and stop further disclosure or access where possible.
  2. Preserve relevant evidence and identify what information, systems and individuals may be affected.
  3. Notify the Privacy Officer / Director and engage IT, legal, HR, safeguarding or communications support as required.
  4. Assess the risk of harm and take remedial action to reduce that risk.
  5. Document the event, decisions, notifications, corrective actions and lessons learned.

22.2 Notifiable Data Breaches scheme

A breach is not automatically notifiable. Care To Support Disability Services will assess whether the incident is an eligible data breach under Part IIIC of the Privacy Act. Where the legal threshold is met, affected individuals and the Office of the Australian Information Commissioner will be notified as required.

22.3 NDIS and other notifications

A privacy or cyber incident may separately trigger NDIS incident, reportable incident, safeguarding, employment, insurer, law-enforcement, contractual or other reporting obligations. Those obligations will be assessed on their own criteria. Care To Support Disability Services will not assume that every privacy breach must automatically be reported to the NDIS Commission.

23. Privacy complaints

A person who believes their information has been mishandled may make a complaint verbally or in writing. Complaints will be handled respectfully, confidentially, fairly and without retaliation or adverse treatment.

  1. Contact the Privacy Officer and provide enough information for the concern to be understood.
  2. Care To Support Disability Services will acknowledge and assess the complaint, seek further information if required and investigate proportionately.
  3. The outcome and any corrective actions will be communicated within a reasonable period.
  4. If the person remains dissatisfied, they may request internal review or contact an appropriate external regulator.

24. Workforce confidentiality and conduct

Every worker is responsible for protecting personal information. Access to information is a privilege attached to the worker's role, not a personal entitlement. Workers must:

  • Access only information required to perform authorised duties;
  • Follow participant consent and communication preferences;
  • Confirm recipient details before sending information;
  • Not photograph, record, copy or share participant information for personal purposes;
  • Not discuss participant information on personal social media or with unauthorised people;
  • Keep passwords and authentication methods confidential;
  • Complete required privacy, confidentiality and cyber-security training;
  • Report suspected breaches, lost information or inappropriate access immediately; and
  • Continue to protect confidential information after employment or engagement ends.

Breaches of confidentiality or privacy requirements may result in corrective or disciplinary action, termination of engagement, notification to regulators or law enforcement, and other action permitted by law and organisational procedure.

25. Training, declarations and governance

The Director has overall accountability for privacy governance. The Privacy Officer coordinates privacy enquiries, complaints, breach assessment, policy review and privacy improvement. Managers and team leaders are responsible for implementing this policy in daily operations and ensuring workers understand their responsibilities.

Privacy and confidentiality training will be provided at induction and refreshed as appropriate. Workers may be required to sign confidentiality or privacy acknowledgements and complete further training where audits, incidents, supervision or performance reviews identify a knowledge gap.

Compliance may be monitored through supervision, file reviews, access reviews, incident analysis, audits, training records, risk assessments and continuous improvement processes.

26. Automated decision transparency

From 10 December 2026, where applicable to the organisation's practices, Care To Support Disability Services will ensure its privacy policy and related notices meet new APP 1 transparency requirements concerning computer programs used to make decisions that could reasonably be expected to significantly affect an individual's rights or interests. Systems and workflows will be reviewed before this requirement commences.

27. Contact details

Privacy Officer
Care To Support Disability Services
Address
1/22 Payneham Road, Stepney SA 5069
Email
admin@caretosupport.com.au
General enquiries
info@caretosupport.com.au
Phone
0414 933 555
Website
www.caretosupport.com.au
ABN
74 652 737 810

28. External complaints and oversight

28.1 Office of the Australian Information Commissioner (OAIC)

For unresolved concerns about the handling of personal information or privacy rights. A person should generally raise the complaint with Care To Support Disability Services first so the organisation has an opportunity to respond.

Phone: 1300 363 992 | Post: GPO Box 5288, Sydney NSW 2001 | Website: www.oaic.gov.au/privacy/privacy-complaints

28.2 NDIS Quality and Safeguards Commission

For concerns or complaints about the quality or safety of NDIS supports and services, including concerns that an NDIS provider or worker has breached a participant's privacy or dignity.

Phone: 1800 035 544 | TTY: 133 677 | Email: contactcentre@ndiscommission.gov.au | Post: PO Box 210, Penrith NSW 2751 | Website: www.ndiscommission.gov.au/complaints/report

National Relay Service users can ask for 1800 035 544. Interpreters can be arranged. A person will not be disadvantaged for making a complaint or contacting an external regulator.

30. References

  • Privacy Act 1988 (Cth), including Schedule 1 - Australian Privacy Principles and Part IIIC - Notifiable Data Breaches.
  • Office of the Australian Information Commissioner, Australian Privacy Principles Guidelines and Privacy complaints guidance.
  • National Disability Insurance Scheme Act 2013 (Cth).
  • National Disability Insurance Scheme (Code of Conduct) Rules 2018.
  • National Disability Insurance Scheme (Provider Registration and Practice Standards) Rules 2018.
  • NDIS Quality and Safeguards Commission, NDIS Practice Standards and Quality Indicators - Core Module: Rights and Responsibilities (Privacy and Dignity).
  • NDIS Quality and Safeguards Commission, NDIS Practice Standards and Quality Indicators - Core Module: Provider Governance and Operational Management (Information Management).
  • NDIS Quality and Safeguards Commission, NDIS Code of Conduct and complaints guidance.