top of page
Search

NDIS Privacy and Confidentiality Policy

Aug 14
9 min read

Updated: Sep 3

1. PURPOSE

DCIRS Community Care ("DCIRS") is committed to protecting the privacy, confidentiality, dignity and rights of participants, workers and other stakeholders through effective information management practices. This Policy provides for the privacy and confidentiality of participant information during and after the provision of services. It outlines the requirements for workers who work with or come into contact with participant information.

DCIRS recognises that privacy and confidentiality are fundamental safeguards that support participant safety, human rights, autonomy, choice and control, supported decision-making, and quality service delivery. Effective management of personal information promotes trust, protects people from harm, abuse, exploitation, and discrimination, and supports compliance with legislative, contractual, and regulatory obligations.

This Policy outlines how DCIRS collects, uses, stores, accesses, discloses and protects personal information in accordance with the Privacy Act 1988 (Cth), Australian Privacy Principles (APPs), NDIS requirements and other applicable legal obligations..

This Policy will commence from 17 August 2026. It replaces all other participant privacy and confidentiality policies of DCIRS (whether written or not) and interacts with DCIRS’s Data Security Policy and Cyber Security Policy.


2. APPLICATION AND SCOPE

This Policy applies to employees, agents, supports, contractors (including temporary contractors) and any other person engaged by or acting on behalf of DCIRS.

This Policy applies to all activities undertaken by DCIRS that involve the collection, creation, access, use, storage, disclosure, retention or destruction of personal, sensitive, confidential or organisational information.

The requirements of this Policy apply across all governance, operational and support functions of the organisation and extend to information held in physical, verbal, electronic, visual and recorded formats, including participant, workforce, safeguarding, quality, governance, financial and other confidential organisational information.

All persons subject to this Policy are expected to manage information responsibly and in accordance with applicable privacy, confidentiality, safeguarding, cyber security, records management, and governance requirements.

This Policy should be read in conjunction with associated governance, risk management, safeguarding, information security, records management and continual improvement documents.

This Policy does not form part of any contract of employment or engagement.


3. DEFINITIONS

Australian Privacy Principles (APPs) are the privacy principles established under the Privacy Act 1988 (Cth).

Confidential information is information that is not publicly available and is obtained through employment, engagement, or participation in services or organisational activities.

Consent is voluntary, informed, specific, and current agreement provided by an individual including a participant or authorised representative.

Health information is information or an opinion about the physical, mental or psychological health or disability of an individual.

Participant representative is a guardian, nominee, advocate, legal representative, support person or other person authorised to act on behalf of a participant.

Personal information is information or an opinion that identifies, or could reasonably identify, an individual.

Privacy Act means The Privacy Act 1988 (Cth), as amended.

Privacy breach occurs with unauthorised access, disclosure, loss, misuse, modification, destruction, or inappropriate handling of personal information.

Sensitive information is personal information afforded additional protection under privacy legislation, including health, disability, and other protected information.

Supported decision-making means the process of supporting a participant to understand information, consider options, and to make their own decisions wherever possible.


4. RISK

Risks to privacy and confidentiality arise whenever information is collected, accessed, stored, used, disclosed, or destroyed. Inappropriate information management practices may expose participants, workers and DCIRS to harm, including privacy breaches, safeguarding failures, abuse, exploitation, discrimination, reputational damage, legal liability and loss of trust.

DCIRS recognises that privacy risk extends beyond information security. Privacy failures may impact participant rights, supported decision-making, dignity, autonomy, and safety. In Supported Independent Living and shared support environments, ineffective management of information may create additional risks relating to participant choice, control, tenancy arrangements, safeguarding and community participation.

DCIRS manages privacy risks through governance oversight, staff capability, secure systems, consent processes, incident management, safeguarding practices, risk management activities, and continual improvement practices.

DCIRS recognises that effective privacy management is both a participant safeguard and a governance responsibility. Privacy risks, incidents, complaints, audit findings, and emerging information-management issues are therefore monitored through the organisation's governance, risk-management, safeguarding, and continual-improvement systems to support organisational accountability and protect participant rights.


5. PRINCIPLES

DCIRS recognises that privacy and confidentiality are not only legal obligations but critical governance safeguards that support participant rights, safety, dignity, autonomy, and quality outcomes.

The organisation is committed to maintaining information-management practices that are transparent, accountable, risk-informed and consistent with participant-centred service delivery.

In implementing this Policy, DCIRS is guided by the following principles:

  • Participants have the right to privacy, dignity, respect, confidentiality, choice and control.

  • Participants have the right to understand how information relating to them is managed.

  • Information management practices must support participant rights, supported decision-making and meaningful participation in decisions that affect them.

  • Personal information will only be collected, accessed, used, stored and disclosed for lawful, authorised and legitimate purposes.

  • Privacy protections must operate alongside, and not unnecessarily restrict, participant autonomy, dignity of risk, and community inclusion.

  • Information access will be restricted to authorised persons with a genuine operational requirement.

  • Accountability for privacy and confidentiality is shared across all levels of the organisation.

  • Information-management risks will be identified, monitored and managed through DCIRS's governance, quality, safeguarding and risk-management systems.

  • Privacy incidents, complaints, breaches, and near misses will be utilised to strengthen organisational learning, improve controls, and enhance participant safeguards.

  • Governance oversight will support the continual evaluation of information-management practices to ensure they remain effective, relevant, and responsive to emerging risks.


6. POLICY 6.1 Participant privacy rights

DCIRS recognises privacy as a fundamental human right and an essential safeguard that supports participant safety, dignity, wellbeing, independence and self-determination.

Participants have the right to understand how information relating to them is collected, used, stored, accessed, disclosed, and protected. Participants also have the right to access their information, request corrections where information is inaccurate or incomplete, raise concerns regarding privacy practices, and participate in decisions regarding information sharing wherever possible.

DCIRS supports participants to exercise these rights through accessible information, supported decision-making practices, and reasonable adjustments tailored to individual communication requirements.

Participants also share responsibility for supporting accurate information management by providing current information, advising DCIRS of relevant changes where appropriate, and raising concerns if they believe their privacy rights have not been respected.


6.2 Collection and management of information

DCIRS collects and manages participant information for the purposes of delivering safe and effective supports, protecting participant wellbeing, meeting legal and regulatory requirements, and supporting effective business operations.

Only information that is reasonably necessary for these purposes will be collected. Information may be obtained directly from participants or from authorised representatives, healthcare professionals, government agencies, referrers and other authorised parties where appropriate.

When collecting information, DCIRS will take reasonable steps to ensure participants understand why information is being collected, how it will be used, who may have access to it, and the rights available to them regarding privacy, access, and complaints.


6.3 Consent and decision making

DCIRS is committed to obtaining informed consent wherever required and recognises that participant understanding is central to valid consent.

Consent processes should be proportionate to the participant's circumstances and support informed decision-making. Where required, reasonable adjustments and communication supports should be utilised..

Where a participant has a nominee, guardian, administrator, attorney or other authorised representative, DCIRS will take reasonable steps to verify authority prior to disclosure of information. The existence of a family relationship, friendship, or caring relationship does not automatically authorise access to participant information.

Information will only be shared where there is participant consent, lawful authority, a legitimate service-delivery purpose, a safeguarding requirement, a mandatory reporting obligation, or another lawful basis for disclosure.

Workers are responsible for ensuring that information sharing is limited to what is necessary, relevant, and proportionate to the circumstances. Workers should also consult DCIRS’s other policies on data and cyber security measures.


6.4 Supported decision-making and accessible information

DCIRS recognises that access to understandable information is an important safeguard that supports participant rights and informed decision-making.

Participants will be provided with information regarding privacy, confidentiality, consent, and information-sharing practices in ways that are appropriate to their communication needs and preferences. This may include the use of Easy Read resources, interpreters, communication supports, advocates, or other reasonable adjustments.

Workers should actively support participants to understand available options and make their own decisions wherever possible.


6.5 Confidentiality requirements

Confidentiality is a core safeguard within DCIRS's governance and participant safeguarding framework.

IWorkers, contractors, volunteers, students, and representatives are entrusted with information obtained through their engagement with DCIRS and are expected to exercise sound professional judgement when accessing, using, or disclosing that information.

Confidential information must only be accessed where necessary to fulfil authorised duties and responsibilities. Any access, use or disclosure must be lawful, proportionate, consistent with participant rights and aligned with organisational requirements.

DCIRS expects all personnel to actively protect information from inadvertent disclosure, misuse, loss, or inappropriate access. Confidentiality obligations continue beyond the cessation of employment, engagement, volunteering activities or service relationships.

Breaches of confidentiality may result in disciplinary action, contractual action, regulatory reporting, safeguarding responses, or other governance measures as appropriate.


6.6 Photographs, video, audio and media

Images, recordings, and media content may contain personal information and must therefore be managed in accordance with privacy requirements.

Participants should be informed of the purpose, intended use and retention of photographs, video or audio recordings prior to consent being sought. Material collected for service-delivery purposes must not be repurposed for promotional, marketing or public use without express approval from the participant and the Operations Manager or Managing Director.


6.7 Information security and protection

DCIRS maintains administrative, physical, and technical controls to protect information from misuse, interference, loss, unauthorised access, modification, and disclosure.

Information security forms part of the organisation's broader risk management and governance framework and operates in conjunction with the Data Security Policy, Cyber Security Policy, and other governance controls. Workers must promptly report security weaknesses, vulnerabilities, and concerns through appropriate organisational processes.


6.8 Privacy breaches and incident management

Privacy breaches represent significant governance, safeguarding, and risk-management events and therefore require prompt reporting, assessment, and response.

All workers are responsible for promptly reporting actual, suspected or potential privacy breaches by reporting promptly to the Operations Manager, or the Managing Director if they are not available..

DCIRS will assess privacy incidents proportionate to the nature, severity, and potential impact of the event. Where required, incidents may be managed in conjunction with safeguarding investigations, cyber-security responses, complaints processes, reportable incident obligations, insurance notifications, or legislative reporting requirements.

The organisation is committed not only to responding to individual incidents but also to understanding underlying causes, identifying systemic weaknesses, and implementing corrective actions designed to reduce the likelihood of recurrence.

Information obtained through incident investigations, audits, complaints, participant feedback, and quality reviews will contribute to organisational learning and continual improvement.


6.9 Access and correction of information

DCIRS supports participant access to information held about them, subject to legislative requirements and reasonable verification processes.

Where information is identified as inaccurate, incomplete or outdated, reasonable steps will be taken to correct the information. Where access cannot be granted, reasons will be provided where lawful and appropriate.


6.10 Supported Independent Living (SIL) privacy requirements

DCIRS recognises that SIL environments create unique privacy and confidentiality considerations due to the interaction of supports, housing arrangements and shared living environments.

Privacy practices within SIL environments must support participant voice, rights, freedoms, autonomy, and supported decision-making.

Information relating to one participant must not be disclosed to another participant without appropriate authority. Workers are expected to actively consider privacy within shared environments and support participants to understand how information relating to their supports, tenancy and living arrangements is managed.


6.11 Governance, monitoring, and oversight

Privacy and confidentiality management form part of DCIRS's integrated governance framework and are supported through safeguarding, quality-management, risk-management, incident-management and continual-improvement systems.

Directors, Responsible Persons and senior leaders are responsible for ensuring appropriate oversight of privacy obligations, information-management risks, and compliance requirements.

The organisation will monitor and review privacy-related information, including:

  • Privacy breaches and security incidents.

  • Safeguarding concerns involving information management.

  • Complaints and participant feedback.

  • Audit and compliance outcomes.

  • Corrective actions and improvement initiatives.

  • Emerging legislative, technological, and operational risks.

Information derived from these activities will be considered through governance reporting pathways and used to support risk-informed decision-making, organisational learning, and service improvement.

DCIRS recognises that effective privacy management requires ongoing review and adaptation. Accordingly, privacy-related trends, emerging risks, systemic issues, and participant feedback will be incorporated into continual-improvement activities to strengthen organisational capability, participant protections, and overall service quality.


7. ASSOCIATED DOCUMENTS

  • Code of Conduct Policy

  • Continual Improvement Policy

  • Cyber Security Policy

  • Data Security Policy

  • Incident and Risk Reporting Policy

  • NDIS Feedback and Complaints Policy

  • NDIS Safeguarding Policy

  • Risk Management Policy


8. LEGISLATION AND STANDARDS

  • Privacy Act 1988 (Cth)

  • Australian Privacy Principles

  • Notifiable Data Breaches Scheme

  • National Disability Insurance Scheme Act 2013

  • NDIS Practice Standards and Quality Indicators

  • NDIS Code of Conduct

  • Supported Independent Living Practice Standards

  • Disability Discrimination Act 1992

  • Human Rights Principles and Conventions applicable to service delivery


6. VERSION AND REVIEW INFORMATION

DCIRS reserves the right to amend and vary this policy from time to time.

Version 1.0: 17 August 2026 | Reviewed 17 August 2028


© 2026 DCIRS Community Care Pty. Ltd. All rights reserved. This policy is the intellectual property of DCIRS Community Care. No part of this document may be reproduced, distributed, copied, or transmitted in any form or by any means, including photocopying, digital scraping, or other electronic methods, without the prior written permission of the copyright owner.


 
 
 

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page