Privacy and Confidentiality
Description
Context
This policy ensures we protect and handle personal information in accordance with the NDIS and relevant privacy legislation. We acknowledge an individual’s right to privacy while recognising that personal information is required to be collected, maintained and administered in order to provide a safe working environment and a high standard of quality.
The information we collect is used to provide services to participants in a safe and healthy environment with individual requirements, to meet duty of care obligations, to initiate appropriate referrals, and to conduct business activities to support those services.
This policy applies to all personal information, including sensitive personal information, used and held by the organisation for participants and employees.
Applicability
When
applies to all personal information and sensitive personal information including the personal information of employees and participants
applies to all company confidential information – that is any information not publicly available
Who
applies to everyone in the organisation including key management personnel, full time workers, casual workers, contractors and volunteers
What is personal information?
Personal information includes (regardless of its accuracy):
name
address
phone number
email address
date of birth
recorded opinions or notes about someone
any other information that could be used to identify someone
What is sensitive personal information?
Sensitive personal information can include personal information that is normally private such as:
health information
ethnicity
political opinions
membership of a political association, professional or trade association or trade union
religious beliefs or affiliations
philosophical beliefs
sexuality
criminal record
biometric information (such as finger prints)
What is a data breach?
A data breach is type of security incident where personal, sensitive or confidential information normally protected, is deliberately or mistakenly copied, sent, viewed, stolen or used by an unauthorised person or parties. A data breach where people affected by the data breach are at risk of serious harm as a result, is reportable to the Office of the Australian Information Commissioner.
Source Document: NDIS (Provider Registration and Practice Standards) Rules 2018
https://www.legislation.gov.au/Details/F2018L00631
NDIS (Quality Indicators) Guidelines 2018
https://www.legislation.gov.au/Details/F2018N00041
Policy
Privacy and confidentiality commitment
we are fully committed to complying with the privacy requirements of the Privacy Act, the Australian Privacy Principles and for Privacy Amendment (Notifiable Data Breaches) as required by organisations providing disability services.
we are fully committed to complying with the consent requirements of the NDIS Quality and Safeguarding Framework
we provide all individuals with access to information about the privacy of their personal information
individuals have the right to request access to their personal records by requesting this with their treating clinician
where we are required to report to government funding bodies, information provided is non-identifiable and related to services and support hours provided, age, disability, language, and nationality
personal information will only be used by us and will not be shared outside the organisation without your permission unless required by law (e.g. reporting assault, abuse, neglect, or where a court order is issued)
Security of information
we take reasonable steps to protect the personal information we hold against misuse, interference, loss, unauthorised access, modification and disclosure
personal information is accessible to the participant and is able for use by relevant workers
security for personal information includes password protection for IT systems, locked filing cabinets and physical access restrictions with only authorised personnel permitted access
personal information no longer required is securely destroyed or de-identified
Data breaches
we will take reasonable steps to reduce the likelihood of a data breach occurring including storing personal information securely and accessible only by relevant workers
if we know or suspect your personal information has been accessed by unauthorised parties, and we think this could cause you harm, we will take reasonable steps to reduce the chance of harm and advise you of the breach, and if necessary contact the Office of the Australian Information Commissioner