| Company Name: | Careify Support Services |
| Policy Name | Privacy and Confidentiality Policy |
| Policy Number | GV-F-11 Version: V1 |
| Effective Date | 1/5/2025 |
| Review Date | 1/5/2027 |
| Approved By | Careify Directors |
Introduction
Careify Support Services is committed to protecting the privacy, dignity, and confidentiality of participants, employees, contractors, volunteers, and other stakeholders. We comply with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the confidentiality requirements under the NDIS Practice Standards.
This policy is designed for an organisation governed by directors without a board of management.
Scope
This policy applies to:
– Participants
– Families and carers
– Employees
– Contractors
– Volunteers
– Other stakeholders
Purpose
The purpose of this policy is to:
– Ensure the lawful collection, use, storage, and disclosure of personal and sensitive information
– Maintain participants’ trust and confidence in our service delivery
– Protect the rights of individuals to privacy and confidentiality
Principles
Careify Support Services upholds the following principles:
– Transparency: Individuals are informed about why their information is collected and how it will be used.
– Consent: Personal information is collected with the individual’s informed consent wherever possible.
– Security: Information is stored securely to prevent unauthorized access, loss, or misuse.
– Access and Correction: Individuals can access and request correction of their personal information.
– Use and Disclosure: Information is used and disclosed only for the purpose for which it was collected, unless otherwise permitted or required by law.
Definitions
– Personal Information: Information or opinion about an identified individual or an individual who is reasonably identifiable.
– Sensitive Information: Information about an individual’s health, disability, racial or ethnic origin, or other information of a sensitive nature.
Collection of Information
Careify Support Services collects personal and sensitive information that is necessary to:
– Deliver services
– Manage participant support plans
– Meet funding and regulatory requirements
We collect information:
– Directly from participants, families, and advocates
– From other service providers or healthcare professionals (with consent)
Use and Disclosure of Information
Information may be used or disclosed:
– To deliver appropriate services and supports
– To communicate with participants and stakeholders
– To meet legal, regulatory, and contractual obligations
– To respond to emergencies or serious threats to health or safety
Information will not be disclosed to third parties without the individual’s consent unless required or authorised by law.
Data Security and Storage
Careify Support Services ensures:
– Information is stored securely in physical and electronic formats
– Access is restricted to authorised personnel
– Secure disposal of information when no longer required
Access and Correction
Participants and stakeholders have the right to:
– Request access to their personal information
– Request corrections to inaccurate, incomplete, or outdated information
Requests are managed promptly and respectfully, subject to any applicable legal restrictions.
Confidentiality Obligations
All employees, contractors, and volunteers must:
– Sign confidentiality agreements
– Maintain confidentiality during and after their employment or engagement
– Report any actual or suspected breaches of confidentiality immediately
Breach of Privacy or Confidentiality
Any breach must be reported immediately to a Director. Breaches will be investigated, and remedial action will be taken, including notifying affected individuals and reporting to the Office of the Australian Information Commissioner (OAIC) where necessary.
Training
All personnel are trained on:
– Privacy rights and responsibilities
– Confidentiality requirements
– Secure information handling practices
Monitoring and Review
This Privacy and Confidentiality Policy is reviewed:
– Every 2 years
– After any significant breach or change in legislation
References
– Privacy Act 1988 (Cth)
Privacy Act 1988 – Federal Register of Legislation
– Australian Privacy Principles (APPs)
Australian Privacy Principles | OAIC
– National Disability Insurance Scheme Act 2013 (Cth)
National Disability Insurance Scheme (NDIS)
– NDIS Practice Standards and Quality Indicators
NDIS Practice Standards | NDIS Quality and Safeguards Commission