Privacy and Confidentiality Policy

1. Purpose

This policy outlines the commitment of Specialist Behaviour (hereinafter referred to as “the Organisation”) to protecting the privacy and confidentiality of all individuals who access our services. We recognise that service users entrust us with highly sensitive personal information, and we have a legal, ethical, and professional obligation to handle that information with the utmost care, respect, and integrity.

This policy establishes clear standards for the collection, use, storage, disclosure, and disposal of personal and sensitive information in accordance with relevant Australian legislation and disability sector standards.

2. Scope

This policy applies to:

  • All employees (full-time, part-time, and casual)
  • Contractors, consultants, and agency staff

This policy covers all personal and sensitive information collected, held, used, or disclosed in the course of providing Positive Behaviour Support services, including information about:

  • Service users (NDIS service users and others)
  • Carers, family members, and support networks
  • Employees
  • Referring organisations and allied health professionals

3. Legislative and Regulatory Framework

This policy is informed by and must be read in conjunction with the following legislation and standards:

3.1 Commonwealth Legislation

  • Privacy Act 1988 (Cth) – including the Australian Privacy Principles (APPs)
  • National Disability Insurance Scheme Act 2013 (Cth)
  • NDIS (Practice Standards and Worker Screening) Rules 2018
  • Disability Discrimination Act 1992 (Cth)

3.2 State and Territory Legislation

  • Disability Act 2006 (Vic) [or relevant state equivalent]
  • Child Wellbeing and Safety Act 2005 (Vic)
  • Mandatory reporting obligations under relevant child protection legislation

4. Definitions

Term

Definition

Personal Information

Information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not, and whether recorded in material form or not.

Sensitive Information

A subset of personal information that includes health information, disability information, genetic information, biometric information, sexual orientation, racial or ethnic origin, political opinion, religious beliefs, and criminal history.

Service user

An individual who receives, or is seeking to receive, Positive Behaviour Support services from Specialist Behaviour.

Behaviour Support Plan (BSP)

A documented plan developed by a behaviour support practitioner outlining strategies to address behaviours of concern and promote quality of life for the service user.

Restrictive Practice

Any practice or intervention that has the effect of restricting the rights or freedom of movement of a person, including chemical, mechanical, physical, seclusion, and environmental restraint.

Disclosure

The release, divulgence, or communication of personal or sensitive information to another person or entity.

Consent

Voluntary and informed agreement by a service user (or their authorised representative) to the collection, use, and/or disclosure of their personal information.

Authorised Representative

A person legally authorised to make decisions on behalf of a service user, including a guardian, parent (for a minor), or nominee appointed under the NDIS.

Data Breach

Any unauthorised access to, or disclosure of, personal information held by the Organisation, including accidental loss, destruction, or alteration of data.

5. Privacy Principles

Specialist Behaviour is committed to upholding the following privacy principles in all aspects of our work:

5.1 Lawful and Transparent Collection

We collect personal and sensitive information only when it is reasonably necessary for the delivery of PBS services. We will always inform service users (and/or their authorised representatives) about what information we are collecting, why we are collecting it, how it will be used, and who it may be shared with.

5.2 Minimum Necessary Information

We collect the minimum amount of information necessary to provide high-quality, safe, and effective behaviour support services. We do not collect personal information that is excessive or irrelevant to our service delivery purpose.

5.3 Consent

We obtain informed consent from service users or their authorised representatives before collecting, using, or disclosing personal information, except where permitted or required by law. Consent may be verbal, written, or in an alternative accessible format appropriate to the service user’s communication needs. Service users have the right to withdraw consent at any time.

5.4 Accuracy and Currency

We take reasonable steps to ensure that personal information held about service users is accurate, up-to-date, and complete. We encourage service users and their support networks to notify us of any changes to their information.

5.5 Security and Protection

We implement physical, technical, and administrative safeguards to protect personal information from unauthorised access, misuse, interference, loss, modification, and disclosure.

5.6 Access and Correction

Service users have the right to access their personal information held by the Organisation and to request corrections where information is inaccurate, incomplete, or out of date. Requests will be handled in accordance with Section 9 of this policy.

5.7 Accountability

All staff and associated persons are accountable for maintaining the privacy and confidentiality of service user information. Breaches of this policy will be treated seriously and may result in disciplinary action.

6. Collection of Personal and Sensitive Information

6.1 Types of Information Collected

In the course of providing PBS services, Specialist Behaviour may collect the following types of information:

6.1.1 Service user Information

  • Full name, date of birth, and contact details
  • NDIS number and plan details
  • Disability diagnosis, medical history, and health information
  • Mental health history and psychological assessments
  • Communication needs, preferences, and support requirements
  • Behaviours of concern, functional behaviour assessments, and behaviour data
  • Behaviour Support Plans (BSPs), including any restrictive practices
  • Quality of life information and personal goals
  • Living arrangements, daily routines, and environment details
  • Photographs or video recordings (where consent is obtained)
  • Information about family members, carers, and support networks

6.1.2 Staff and Contractor Information

  • Employment details, qualifications, and training records
  • Worker screening and NDIS Worker Screening Check outcomes
  • Performance and conduct records
  • Health and safety information (where relevant)

6.2 Methods of Collection

Information is collected through a variety of means, including:

  • Referral forms and service agreements
  • Assessments, interviews, and observations (in-person, via telehealth, or at the service user’s environment)
  • Communication with carers, family members, or authorised representatives
  • Review of existing reports, plans, and records provided by other services
  • Electronic client management systems
  • Direct observation and behavioural data collection during service delivery

6.3 Collection from Third Parties

Where information is collected from third parties (e.g., a treating medical practitioner, school, or previous service provider), we will take reasonable steps to notify the service user or their representative that such collection has occurred and the source of that information, unless doing so would pose a risk to safety or is otherwise impracticable.

7. Use and Disclosure of Information

7.1 Authorised Uses

Personal and sensitive information will be used only for the primary purposes for which it was collected, or for directly related secondary purposes. Authorised uses include:

  • Conducting functional behaviour assessments and developing Behaviour Support Plans
  • Monitoring, reviewing, and updating support strategies
  • Coordinating care with other service providers involved in the service user’s support
  • Reporting on the use of restrictive practices to the NDIS Quality and Safeguarding Commission
  • Invoicing the NDIS or other funding bodies for services provided
  • Meeting mandatory reporting obligations (e.g., reportable incidents, child protection)
  • Quality assurance, auditing, and accreditation activities
  • Training and supervision of staff (with identifying information de-identified where possible)

7.2 Disclosure to Third Parties

Specialist Behaviour will not disclose personal or sensitive information to third parties without the service user’s consent, except in the following circumstances:

  • Where disclosure is required or authorised by law (e.g., mandatory reporting, court order, NDIS Commission reporting)
  • Where disclosure is necessary to prevent or lessen a serious and imminent threat to the life, health, or safety of the service user or another person
  • Where the information has been de-identified and cannot be re-identified
  • Where disclosure is to an authorised representative acting within the scope of their authority

7.3 Restrictive Practices Reporting

Specialist Behaviour has specific reporting obligations regarding the use of regulated restrictive practices under the NDIS Quality and Safeguarding Framework. Information about restrictive practices contained in Behaviour Support Plans will be reported to the NDIS Quality and Safeguarding Commission as required by law. Service users and their representatives will be informed of these obligations.

7.4 Mandatory Reporting

All staff are required to fulfil mandatory reporting obligations under relevant child protection legislation and NDIS incident reporting requirements. Where a mandatory report is made, service users (and/or their representatives) will be notified unless doing so would place any person at risk of harm.

8. Information Storage and Security

8.1 Physical Security

Paper-based records containing personal or sensitive information must be:

  • Stored in locked filing cabinets or secure areas when not in use
  • Accessible only to authorised staff
  • Never left unattended in public or shared spaces
  • Transported securely when required (e.g., in sealed, labelled envelopes)

8.2 Electronic Security

Electronic records are protected through the following measures:

  • Password-protected access with individual user accounts
  • Multi-factor authentication for systems containing sensitive information
  • Encrypted storage and transmission of data
  • Regular software updates and security patches
  • Firewall and antivirus protection on all organisational devices
  • Restricted access permissions based on role and need-to-know
  • Prohibition on storing service user information on personal devices without authorisation
  • Secure cloud storage solutions with Australian data residency where possible

8.3 Mobile Work and Telehealth

Staff working in the community or remotely must:

  • Use only Organisation-approved devices or secure remote access solutions
  • Avoid discussing or accessing service user information in public spaces
  • Ensure telehealth sessions are conducted in a private, secure environment
  • Not use personal email accounts to transmit service user information
  • Lock devices when not in use and report lost or stolen devices immediately

8.4 Retention and Disposal

Personal information will be retained for a minimum of seven (7) years from the date of last service, or in the case of a minor, until they reach 25 years of age (whichever is later), in accordance with applicable legislation and professional standards. After the retention period, records will be disposed of securely:

  • Paper records will be cross-cut shredded or professionally destroyed
  • Electronic records will be permanently deleted using approved data destruction methods

9. Access to and Correction of Personal Information

9.1 Right of Access

Service users and authorised representatives have the right to request access to personal information held about them by Specialist Behaviour. Requests for access must be made in writing to the Director. The Organisation will respond to access requests within 30 days of receipt. Where access is denied or limited, the Organisation will provide written reasons and information about the right to complain.

9.2 Grounds for Refusing Access

Access to personal information may be refused in limited circumstances, including where:

  • Providing access would pose a serious threat to the life, health, or safety of any person
  • Providing access would unreasonably impact the privacy of another individual
  • Access is unlawful or would prejudice enforcement of a law
  • Legal proceedings are active and the information is subject to legal privilege

9.3 Right to Correction

If a service user believes that their personal information is inaccurate, incomplete, or out of date, they may request a correction. The Organisation will correct information within 30 days of a valid request. Where a correction is refused, the Organisation will provide written reasons and the service user may request that a statement of the claimed correction be associated with their record.

10. Data Breach Management

10.1 Identifying a Data Breach

A data breach occurs when personal information held by the Organisation is accessed by, or disclosed to, an unauthorised party, or is lost, destroyed, or altered without authority. Staff must immediately report any suspected or actual data breach to their supervisor and the Director.

10.2 Response Procedure

Upon identifying or suspecting a data breach, the Organisation will:

  • Contain the breach and prevent further compromise of information
  • Assess the nature and scope of the breach
  • Determine whether the breach is likely to result in serious harm to any individuals
  • Notify affected individuals as soon as practicable where required
  • Notify the Office of the Australian Information Commissioner (OAIC) of eligible data breaches under the Notifiable Data Breaches scheme
  • Document the breach, the response taken, and any remedial actions
  • Review and improve systems and procedures to prevent recurrence

10.3 Notifiable Data Breaches

Under the Privacy Act 1988 (Cth), Specialist Behaviour is required to notify the OAIC and affected individuals of eligible data breaches likely to result in serious harm to one or more individuals. The OAIC must be notified as soon as practicable, and no later than 30 days after becoming aware of an eligible breach.

11. Roles and Responsibilities

Role

Key Responsibilities

Director / Executive Leadership

Overall accountability for privacy compliance; approving this policy; ensuring adequate resources for implementation.

Clinical Operations Coordinator

Day-to-day oversight of privacy compliance; managing access and correction requests; coordinating data breach response; maintaining the policy; delivering staff training.

Behaviour Support Practitioners

Collecting, storing, and using service user information in accordance with this policy; obtaining informed consent; reporting breaches; maintaining confidentiality of BSPs and assessment data.

All Staff & Contractors

Understanding and complying with this policy; completing mandatory privacy training; reporting suspected breaches; maintaining confidentiality of all service user information.

IT / Systems Administrator

Implementing and maintaining technical security controls; managing user access permissions; ensuring secure storage and transmission of data; managing data backups and disposal.

12. Staff Awareness

All staff and contractors must read and acknowledge their understanding of this privacy and confidentiality training as part of their induction, and upon recontracting thereafter (at minimum annually).

13. Privacy Complaints

13.1 Internal Complaints

Service users, their representatives, or any person who believes their privacy has been breached may make a complaint to the Privacy Officer. Complaints should be submitted in writing (or in an accessible format if required) and will be acknowledged within five (5) business days. The Organisation will investigate and respond to complaints within 30 days.

13.2 External Complaints

If a complainant is not satisfied with Specialist Behaviour’s response, they may escalate their complaint to:

  • Office of the Australian Information Commissioner (OAIC) – for complaints about handling of personal information under the Privacy Act 1988 (Cth). Website: www.oaic.gov.au | Phone: 1300 363 992
  • NDIS Quality and Safeguarding Commission – for complaints related to the provision of NDIS supports and services. Website: www.ndiscommission.gov.au | Phone: 1800 035 544
  • State-based health complaints authority (e.g., Health Complaints Commissioner in Victoria) for health information complaints

14. Policy Review and Monitoring

This policy will be reviewed at least annually, or earlier in the event of:

  • Changes to relevant legislation, regulations, or NDIS Practice Standards
  • A significant privacy breach or systemic issue identified through complaint or audit
  • Significant changes to organisational operations, technology, or service model
  • Recommendations from an external audit or regulatory body

The Operations Coordinator is responsible for coordinating the review process. All updates must be approved by the Director prior to implementation. Staff will be notified of any material changes.

 

 

Organisations we work with