Privacy and Confidentiality Policy
1. Purpose
This policy outlines the commitment of Specialist Behaviour (hereinafter referred to as “the Organisation”) to protecting the privacy and confidentiality of all individuals who access our services. We recognise that service users entrust us with highly sensitive personal information, and we have a legal, ethical, and professional obligation to handle that information with the utmost care, respect, and integrity.
This policy establishes clear standards for the collection, use, storage, disclosure, and disposal of personal and sensitive information in accordance with relevant Australian legislation and disability sector standards.
2. Scope
This policy applies to:
- All employees (full-time, part-time, and casual)
- Contractors, consultants, and agency staff
This policy covers all personal and sensitive information collected, held, used, or disclosed in the course of providing Positive Behaviour Support services, including information about:
- Service users (NDIS service users and others)
- Carers, family members, and support networks
- Employees
- Referring organisations and allied health professionals
3. Legislative and Regulatory Framework
This policy is informed by and must be read in conjunction with the following legislation and standards:
3.1 Commonwealth Legislation
- Privacy Act 1988 (Cth) – including the Australian Privacy Principles (APPs)
- National Disability Insurance Scheme Act 2013 (Cth)
- NDIS (Practice Standards and Worker Screening) Rules 2018
- Disability Discrimination Act 1992 (Cth)
3.2 State and Territory Legislation
- Disability Act 2006 (Vic) [or relevant state equivalent]
- Child Wellbeing and Safety Act 2005 (Vic)
- Mandatory reporting obligations under relevant child protection legislation
4. Definitions
|
Term |
Definition |
|
Personal Information |
Information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not, and whether recorded in material form or not. |
|
Sensitive Information |
A subset of personal information that includes health information, disability information, genetic information, biometric information, sexual orientation, racial or ethnic origin, political opinion, religious beliefs, and criminal history. |
|
Service user |
An individual who receives, or is seeking to receive, Positive Behaviour Support services from Specialist Behaviour. |
|
Behaviour Support Plan (BSP) |
A documented plan developed by a behaviour support practitioner outlining strategies to address behaviours of concern and promote quality of life for the service user. |
|
Restrictive Practice |
Any practice or intervention that has the effect of restricting the rights or freedom of movement of a person, including chemical, mechanical, physical, seclusion, and environmental restraint. |
|
Disclosure |
The release, divulgence, or communication of personal or sensitive information to another person or entity. |
|
Consent |
Voluntary and informed agreement by a service user (or their authorised representative) to the collection, use, and/or disclosure of their personal information. |
|
Authorised Representative |
A person legally authorised to make decisions on behalf of a service user, including a guardian, parent (for a minor), or nominee appointed under the NDIS. |
|
Data Breach |
Any unauthorised access to, or disclosure of, personal information held by the Organisation, including accidental loss, destruction, or alteration of data. |
5. Privacy Principles
Specialist Behaviour is committed to upholding the following privacy principles in all aspects of our work:
5.1 Lawful and Transparent Collection
We collect personal and sensitive information only when it is reasonably necessary for the delivery of PBS services. We will always inform service users (and/or their authorised representatives) about what information we are collecting, why we are collecting it, how it will be used, and who it may be shared with.
5.2 Minimum Necessary Information
We collect the minimum amount of information necessary to provide high-quality, safe, and effective behaviour support services. We do not collect personal information that is excessive or irrelevant to our service delivery purpose.
5.3 Consent
We obtain informed consent from service users or their authorised representatives before collecting, using, or disclosing personal information, except where permitted or required by law. Consent may be verbal, written, or in an alternative accessible format appropriate to the service user’s communication needs. Service users have the right to withdraw consent at any time.
5.4 Accuracy and Currency
We take reasonable steps to ensure that personal information held about service users is accurate, up-to-date, and complete. We encourage service users and their support networks to notify us of any changes to their information.
5.5 Security and Protection
We implement physical, technical, and administrative safeguards to protect personal information from unauthorised access, misuse, interference, loss, modification, and disclosure.
5.6 Access and Correction
Service users have the right to access their personal information held by the Organisation and to request corrections where information is inaccurate, incomplete, or out of date. Requests will be handled in accordance with Section 9 of this policy.
5.7 Accountability
All staff and associated persons are accountable for maintaining the privacy and confidentiality of service user information. Breaches of this policy will be treated seriously and may result in disciplinary action.
6. Collection of Personal and Sensitive Information
6.1 Types of Information Collected
In the course of providing PBS services, Specialist Behaviour may collect the following types of information:
6.1.1 Service user Information
- Full name, date of birth, and contact details
- NDIS number and plan details
- Disability diagnosis, medical history, and health information
- Mental health history and psychological assessments
- Communication needs, preferences, and support requirements
- Behaviours of concern, functional behaviour assessments, and behaviour data
- Behaviour Support Plans (BSPs), including any restrictive practices
- Quality of life information and personal goals
- Living arrangements, daily routines, and environment details
- Photographs or video recordings (where consent is obtained)
- Information about family members, carers, and support networks
6.1.2 Staff and Contractor Information
- Employment details, qualifications, and training records
- Worker screening and NDIS Worker Screening Check outcomes
- Performance and conduct records
- Health and safety information (where relevant)
6.2 Methods of Collection
Information is collected through a variety of means, including:
- Referral forms and service agreements
- Assessments, interviews, and observations (in-person, via telehealth, or at the service user’s environment)
- Communication with carers, family members, or authorised representatives
- Review of existing reports, plans, and records provided by other services
- Electronic client management systems
- Direct observation and behavioural data collection during service delivery
6.3 Collection from Third Parties
Where information is collected from third parties (e.g., a treating medical practitioner, school, or previous service provider), we will take reasonable steps to notify the service user or their representative that such collection has occurred and the source of that information, unless doing so would pose a risk to safety or is otherwise impracticable.
7. Use and Disclosure of Information
7.1 Authorised Uses
Personal and sensitive information will be used only for the primary purposes for which it was collected, or for directly related secondary purposes. Authorised uses include:
- Conducting functional behaviour assessments and developing Behaviour Support Plans
- Monitoring, reviewing, and updating support strategies
- Coordinating care with other service providers involved in the service user’s support
- Reporting on the use of restrictive practices to the NDIS Quality and Safeguarding Commission
- Invoicing the NDIS or other funding bodies for services provided
- Meeting mandatory reporting obligations (e.g., reportable incidents, child protection)
- Quality assurance, auditing, and accreditation activities
- Training and supervision of staff (with identifying information de-identified where possible)
7.2 Disclosure to Third Parties
Specialist Behaviour will not disclose personal or sensitive information to third parties without the service user’s consent, except in the following circumstances:
- Where disclosure is required or authorised by law (e.g., mandatory reporting, court order, NDIS Commission reporting)
- Where disclosure is necessary to prevent or lessen a serious and imminent threat to the life, health, or safety of the service user or another person
- Where the information has been de-identified and cannot be re-identified
- Where disclosure is to an authorised representative acting within the scope of their authority
7.3 Restrictive Practices Reporting
Specialist Behaviour has specific reporting obligations regarding the use of regulated restrictive practices under the NDIS Quality and Safeguarding Framework. Information about restrictive practices contained in Behaviour Support Plans will be reported to the NDIS Quality and Safeguarding Commission as required by law. Service users and their representatives will be informed of these obligations.
7.4 Mandatory Reporting
All staff are required to fulfil mandatory reporting obligations under relevant child protection legislation and NDIS incident reporting requirements. Where a mandatory report is made, service users (and/or their representatives) will be notified unless doing so would place any person at risk of harm.
8. Information Storage and Security
8.1 Physical Security
Paper-based records containing personal or sensitive information must be:
- Stored in locked filing cabinets or secure areas when not in use
- Accessible only to authorised staff
- Never left unattended in public or shared spaces
- Transported securely when required (e.g., in sealed, labelled envelopes)
8.2 Electronic Security
Electronic records are protected through the following measures:
- Password-protected access with individual user accounts
- Multi-factor authentication for systems containing sensitive information
- Encrypted storage and transmission of data
- Regular software updates and security patches
- Firewall and antivirus protection on all organisational devices
- Restricted access permissions based on role and need-to-know
- Prohibition on storing service user information on personal devices without authorisation
- Secure cloud storage solutions with Australian data residency where possible
8.3 Mobile Work and Telehealth
Staff working in the community or remotely must:
- Use only Organisation-approved devices or secure remote access solutions
- Avoid discussing or accessing service user information in public spaces
- Ensure telehealth sessions are conducted in a private, secure environment
- Not use personal email accounts to transmit service user information
- Lock devices when not in use and report lost or stolen devices immediately
8.4 Retention and Disposal
Personal information will be retained for a minimum of seven (7) years from the date of last service, or in the case of a minor, until they reach 25 years of age (whichever is later), in accordance with applicable legislation and professional standards. After the retention period, records will be disposed of securely:
- Paper records will be cross-cut shredded or professionally destroyed
- Electronic records will be permanently deleted using approved data destruction methods
9. Access to and Correction of Personal Information
9.1 Right of Access
Service users and authorised representatives have the right to request access to personal information held about them by Specialist Behaviour. Requests for access must be made in writing to the Director. The Organisation will respond to access requests within 30 days of receipt. Where access is denied or limited, the Organisation will provide written reasons and information about the right to complain.
9.2 Grounds for Refusing Access
Access to personal information may be refused in limited circumstances, including where:
- Providing access would pose a serious threat to the life, health, or safety of any person
- Providing access would unreasonably impact the privacy of another individual
- Access is unlawful or would prejudice enforcement of a law
- Legal proceedings are active and the information is subject to legal privilege
9.3 Right to Correction
If a service user believes that their personal information is inaccurate, incomplete, or out of date, they may request a correction. The Organisation will correct information within 30 days of a valid request. Where a correction is refused, the Organisation will provide written reasons and the service user may request that a statement of the claimed correction be associated with their record.
10. Data Breach Management
10.1 Identifying a Data Breach
A data breach occurs when personal information held by the Organisation is accessed by, or disclosed to, an unauthorised party, or is lost, destroyed, or altered without authority. Staff must immediately report any suspected or actual data breach to their supervisor and the Director.
10.2 Response Procedure
Upon identifying or suspecting a data breach, the Organisation will:
- Contain the breach and prevent further compromise of information
- Assess the nature and scope of the breach
- Determine whether the breach is likely to result in serious harm to any individuals
- Notify affected individuals as soon as practicable where required
- Notify the Office of the Australian Information Commissioner (OAIC) of eligible data breaches under the Notifiable Data Breaches scheme
- Document the breach, the response taken, and any remedial actions
- Review and improve systems and procedures to prevent recurrence
10.3 Notifiable Data Breaches
Under the Privacy Act 1988 (Cth), Specialist Behaviour is required to notify the OAIC and affected individuals of eligible data breaches likely to result in serious harm to one or more individuals. The OAIC must be notified as soon as practicable, and no later than 30 days after becoming aware of an eligible breach.
11. Roles and Responsibilities
|
Role |
Key Responsibilities |
|
Director / Executive Leadership |
Overall accountability for privacy compliance; approving this policy; ensuring adequate resources for implementation. |
|
Clinical Operations Coordinator |
Day-to-day oversight of privacy compliance; managing access and correction requests; coordinating data breach response; maintaining the policy; delivering staff training. |
|
Behaviour Support Practitioners |
Collecting, storing, and using service user information in accordance with this policy; obtaining informed consent; reporting breaches; maintaining confidentiality of BSPs and assessment data. |
|
All Staff & Contractors |
Understanding and complying with this policy; completing mandatory privacy training; reporting suspected breaches; maintaining confidentiality of all service user information. |
|
IT / Systems Administrator |
Implementing and maintaining technical security controls; managing user access permissions; ensuring secure storage and transmission of data; managing data backups and disposal. |
12. Staff Awareness
All staff and contractors must read and acknowledge their understanding of this privacy and confidentiality training as part of their induction, and upon recontracting thereafter (at minimum annually).
13. Privacy Complaints
13.1 Internal Complaints
Service users, their representatives, or any person who believes their privacy has been breached may make a complaint to the Privacy Officer. Complaints should be submitted in writing (or in an accessible format if required) and will be acknowledged within five (5) business days. The Organisation will investigate and respond to complaints within 30 days.
13.2 External Complaints
If a complainant is not satisfied with Specialist Behaviour’s response, they may escalate their complaint to:
- Office of the Australian Information Commissioner (OAIC) – for complaints about handling of personal information under the Privacy Act 1988 (Cth). Website: www.oaic.gov.au | Phone: 1300 363 992
- NDIS Quality and Safeguarding Commission – for complaints related to the provision of NDIS supports and services. Website: www.ndiscommission.gov.au | Phone: 1800 035 544
- State-based health complaints authority (e.g., Health Complaints Commissioner in Victoria) for health information complaints
14. Policy Review and Monitoring
This policy will be reviewed at least annually, or earlier in the event of:
- Changes to relevant legislation, regulations, or NDIS Practice Standards
- A significant privacy breach or systemic issue identified through complaint or audit
- Significant changes to organisational operations, technology, or service model
- Recommendations from an external audit or regulatory body
The Operations Coordinator is responsible for coordinating the review process. All updates must be approved by the Director prior to implementation. Staff will be notified of any material changes.