Privacy policy

1.1 Purpose

This Policy and the Policies and Procedures and related documentation set out in section 1.5 below (Related Documentation) support The Angels Disability Support Services to apply the Privacy and Dignity and Information Management NDIS Practice Standards. 

1.2         Policy Aims

The Angels Disability Support Services is committed to ensuring that:

(a)            each participant supports that respect and protects their dignity and right to privacy.

(b)            management of each participant’s information ensures that it is identifiable, accurately recorded, current and confidential. Each participant’s information is easily accessible to the participant and appropriately utilised by relevant workers.

1.3           NDIS Quality Indicators

In this regard, The Angels Disability Support Services aims to demonstrate each of the following quality indicators through the application of this Policy and the relevant systems, procedures, workflows and other strategies referred to in this Policy and the Related Documentation:

Privacy and Dignity

(a)            Consistent processes and practices are in place that respects and protects the personal privacy and dignity of each participant.

(b)            Management of each participant’s information ensures that it is identifiable, accurately recorded, current and confidential. Each participant’s information is easily accessible to the participant and appropriately utilised by relevant workers.

(c)            Each participant understands and agrees to what personal information will be collected and why including recorded material in audio and/or visual format.

Information Management

(a)            Each participant’s consent is obtained to collect, use and retain their information or to disclose their information (including assessments) to other parties, including details of the purpose of collection, use and disclosure. Each participant is informed in what circumstances the information could be disclosed, including that the information could be provided without their consent if required or authorised by law.

(b)            Each participant is informed of how their information is stored and used, and when and how each participant can access or correct their information and withdraw or amend their prior consent.

(c)            An information management system is maintained that is relevant and proportionate to the size and scale of the organisation and records each participant’s information in an accurate and timely manner.

(d)            Documents are stored with appropriate use, access, transfer, storage, security, retrieval, retention, destruction and disposal processes relevant and proportionate to the scope and complexity of support delivered.

1.4        Scope

(a)            This policy applies to the provision of all services and supports at The Angels Disability Support Services.

(b)           All permanent, fixed-term and casual staff, contractors and volunteers are required to take full responsibility for ensuring a full understanding of the commitments outlined in this Policy.

1.5        Related Documentation

The application of the above NDIS Practice Standard by The Angels Disability Support Services is supported in part by and should be read alongside the Policies and Procedures and related documentation corresponding to this Policy in the Policy Register.

2.     Definitions

2.1        Definitions

In this Policy:

The Angels Disability Support Services means Angel Disability Support Services Pty Ltd ABN 64 650 546 704.

Client means a client of The Angels Disability Support Services (including an NDIS participant).

Key Management Personnel means Reena Roshiba Christina de la Ruwiere and other key management personnel involved in The Angels Disability Support Services from time to time.

Legislation Register means the register of legislation, regulations, rules and guidelines maintained by The Angels Disability Support Services.

Personal information means information or an opinion (whether true or not and whether recorded in a material form or not) about an individual who is identified or reasonably identifiable from the information. 

Policy Register means the register of policies of The Angels Disability Support Services.

Principal means Reena Roshiba Christina de la Ruwiere.

Related Documentation has the meaning given to that term in section 1.1.

Sensitive information is a subset of personal information that is generally afforded a higher level of privacy protection. Sensitive information includes health and genetic information and information about racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association or trade union, sexual preferences or practices, criminal record and some types of biometric information.

Worker means a permanent, fixed-term or casual member of staff, a contractor or volunteer employed or otherwise engaged by The Angels Disability Support Services and includes the Principal.

3.             Policy Statement

3.1           Communication of Privacy and Dignity Policy

To ensure Clients understand the subject matter of this Privacy and Dignity Policy in a manner that is responsive to their needs and in the language, mode of communication and terms that the Client is most likely to understand, The Angels Disability Support Services will:

(a)            use respectful, open, clear, and honest communication in all professional interactions (e.g., spoken, written, social media).

(b)            communicate effectively with clients to promote their understanding of the subject matter of this Privacy and Dignity Policy (e.g., active listening, use of plain language, encouraging questions).

(c)            identify potential barriers to effective communication and make a reasonable effort to address these barriers including by providing information and materials on how to access interpreter services, and legal and advocacy services.

(d)            work with bilingual assessment staff, interpreters (linguistic and/or sign), communication specialists and relevant advocacy agencies/services that can also assist Client participation, inclusion, informed choice and control.

(e)            encourage clients to engage with their family, friends and chosen community if The Angels Disability Support Services has been directed to do so.

3.2           The personal information that The Angels Disability Support Services collects

The personal information that The Angels Disability Support Services collects from a Client includes their:

(a)            name, address, telephone and email contact details;

(b)            gender, date of birth and marital status, information about their disability and support needs;

(c)            health and medical information;

(d)            Medicare number and other identifiers used by Government Agencies or other organisations to identify individuals;

(e)            financial information and billing details including information about the services individuals are funded to receive, whether under the NDIS or otherwise;

(f)             records of interactions with individuals such as system notes and records of conversations individuals have had with The Angels Disability Support Services’s employees; and

(g)            information about the services The Angels Disability Support Services provides to individuals and the way in which The Angels Disability Support Services will deliver those to individuals.

Typically, The Angels Disability Support Services does not collect personal information in the form of recorded material in audio and/or visual format.

3.3           Sensitive information and protection of dignity

The Angels Disability Support Services only collects sensitive information where it is reasonably necessary for The Angels Disability Support Services’s functions or activities and either:

(a)            the individual has consented; or

(b)            The Angels Disability Support Services is required or authorised by or under the law (including applicable privacy legislation) to do so.

For example, in order to provide The Angels Disability Support Services’s services to a Client or to respond to a potential Client’s inquiries about services, The Angels Disability Support Services may be required to collect and hold their sensitive information including health and medical information and information relating to their disability and support requirements.

The Angels Disability Support Services will treat Clients with dignity and respect and as far as reasonably practicable protect the privacy and dignity of each Participant and, in particular, their sensitive information.

3.4           How The Angels Disability Support Services collects personal information

The Angels Disability Support Services collects personal information in a number of ways, including:

(a)            through The Angels Disability Support Services’s website;

(b)            when individuals correspond with The Angels Disability Support Services (for example by  letter, fax, email or telephone);

(c)            on hard copy forms;

(d)            in person;

(e)            from referring third parties (for example, the National Disability Insurance Scheme or a support coordinator);

(f)             at events and forums; and

(g)            from third-party funding and Government Agencies.

3.5           Why does The Angels Disability Support Services collect personal information?

The main purposes for which The Angels Disability Support Services collects, holds, uses and discloses personal information are:

(a)            providing individuals with information about The Angels Disability Support Services’ services and supports.

(b)            answering their inquiries and delivering service to Clients.

(c)            administering The Angels Disability Support Services’ services and support and process payments.

(d)            conducting quality assurance activities including conducting surveys, research and analysis and resolving complaints.

(e)            complying with laws and regulations and reporting to funding and Government Agencies.

(f)             promoting The Angels Disability Support Services and its activities, including through events and forums.

(g)            conducting research and statistical analysis relevant to The Angels Disability Support Services’ activities (including inviting individuals to participate in research projects and activities).

(h)            reporting to funding providers.

(i)              recruiting employees, contractors and volunteers.

(j)              processing payments.

(k)            answering queries and resolving complaints.

(l)              evaluating The Angels Disability Support Services’ work and reporting externally.

(m)           carrying out internal functions including administration, training, accounting, audit and information technology.

(n)            other purposes which are explained at the time of collection or which are required or authorised by or under the law (including, without limitation, privacy legislation).

(o)            purposes for which an individual has provided their consent.

(p)            for research, evaluation of services, quality assurance activities, and education in a manner that does not identify individuals. If individuals do not wish for their de-identified data to be used this way, they should contact The Angels Disability Support Services.

(q)            to keep individuals informed and up to date about The Angels Disability Support Services’s work, for example, changes to the National Disability Insurance Scheme or information about disability supports, either where The Angels Disability Support Services has their express or implied consent, or where The Angels Disability Support Services is otherwise permitted by law to do so. The Angels Disability Support Services may send this information in a variety of ways, including by mail, email, SMS, telephone, or social media.

(r)             where an individual has consented to receive marketing communications from The Angels Disability Support Services, that consent will remain current until they advise The Angels Disability Support Services otherwise. However, individuals can opt-out at any time.

(s)            to manage and improve users’ experience on the The Angels Disability Support Services website using “cookies”. A cookie is a small text file that The Angels Disability Support Services’ site may place on their computer as a tool to remember their preferences. Individuals may refuse the use of cookies by selecting the appropriate settings on their browser.

(t)             to tailor advertising, both on The Angels Disability Support Services’ website and through advertising networks on other websites, based on their visits or behaviour through cookies on their device. Individuals can control how cookies are used and for what through the settings on their chosen browser.

(u)            to track visits to the The Angels Disability Support Services website, using this information to track the effectiveness of the website. While this data is mostly anonymous, sometimes The Angels Disability Support Services will connect it to individuals, for instance in personalising a webpage, or pre-filling a form with their details. For more information on The Angels Disability Support Services’ analytics tools, read Google’s privacy policy.

3.6           Can I withdraw or amend my consent to the use of my personal information?

A Client may withdraw or amend their consent to The Angels Disability Support Services using their personal information at any time by written notice to The Angels Disability Support Services. The nature of the business carried on by The Angels Disability Support Services means that, generally, it is not possible for The Angels Disability Support Services to provide services or support to Clients or otherwise deal with individuals if a Client withdraws or amends their consent.

3.7           What third parties does The Angels Disability Support Services disclose personal information to?

The Angels Disability Support Services may disclose personal information to third parties where appropriate for the purposes set out above, including disclosure to:

(a)            The Angels Disability Support Services’s funding providers;

(b)            government and regulatory bodies, including the National Disability Insurance Agency, Medicare, the Department of Social Services, the Department of Health & Human Services, and the Australian Taxation Office;

(c)            people acting on their behalf including their nominated representatives, legal guardians, executors, trustees and legal representatives;

(d)            the police, or to the Disability Services Commissioner, or to comply with compulsory notices from courts of law, tribunals or Government Agencies;

(e)            financial institutions for payment processing;

(f)             referees whose details are provided to The Angels Disability Support Services by job applicants; and

(g)            The Angels Disability Support Services’s contracted service providers, including:

(1)            information technology service providers

(2)            invoice processing service providers

(3)            marketing and communications service providers including call centres

(4)            freight and courier services

(5)            external business advisers (such as recruitment advisors, auditors and lawyers).

In the case of these contracted service providers, The Angels Disability Support Services may disclose personal information to the service provider and the service provider may, in turn, provide The Angels Disability Support Services with personal information collected from individuals in the course of providing the relevant products or services. 

3.8           How is personal information stored and used?

(a)            The Angels Disability Support Services holds personal information in a number of ways, including in hard copy documents, electronic databases, email contact lists, and paper files held in drawers and cabinets. Paper files may also be archived in boxes and stored offsite in secure facilities. 

(b)            The Angels Disability Support Services must take reasonable steps to:

(1)            make sure that the personal information that The Angels Disability Support Services collects, uses and discloses is accurate, up to date and complete and (in the case of use and disclosure) relevant;

(2)            protect the personal information that The Angels Disability Support Services holds from misuse, interference and loss and from unauthorised access, modification or disclosure; and

(3)            destroy or permanently de-identify personal information that is no longer needed for any purpose that is permitted by the Australian Privacy Principles, subject to other legal obligations and retention requirements applicable to The Angels Disability Support Services.

(c)            The Angels Disability Support Services employees must only access and use personal information for a valid work purpose. When handling personal information, employees should:

(1)            confirm recipient details before sending faxes or emails;

(2)            always store any hard copies of confidential information that is not being used in a secure cabinet or room;

(3)            be aware of the surroundings and people nearby;

(4)            limit taking hard copy information away from secure sites;

(5)            secure information when travelling e.g. in a briefcase, folder etc.;

(6)            dispose of unneeded copies of information securely; and

(7)            ensure the information is available to people who need to access it.

(d)            The Angels Disability Support Services employees may only share personal information as set out under this policy and in circumstances permitted under law.

3.9           How is personal information kept secure?

The steps The Angels Disability Support Services takes to secure the personal information The Angels Disability Support Services holds include:

(a)            website protection measures (such as encryption, firewalls and anti-virus software);

(b)            security restrictions on access to The Angels Disability Support Services’s computer systems (such as login and password protection) and cloud-based storage (using Google Drive and OneDrive),

(c)            controlled access to The Angels Disability Support Services’s premises

(d)            personnel security (including restricting the use of personal information by The Angels Disability Support Services employees to those who have a legitimate need to know the information for the purposes set out above); and

(e)            training and workplace policies.

3.10        Information retention

Unless otherwise required by law, all Client records and personal information will be retained for at least seven years after a Client ceases to be a client.

3.11        Information disposal

(a)            Employees should ensure record retention requirements have been met prior to the disposal of any personal information.

(b)            When disposing of personal information, employees should:

(1)            Place unneeded working documents or copies of information in secure bins or adequate shredders.

(2)            Ensure any electronic media including computers, hard drives, USB keys etc. are sanitised when no longer required.

3.12        Privacy incidents

Privacy incidents may result from unauthorised people accessing, changing or destroying personal information. Examples of situations from which incidents may arise include:

(a)            the accidental download of a virus onto an agency computer;

(b)            discussing or sharing of personal information on a social networking website such as Facebook;

(c)            loss or theft of a portable storage device containing personal information;

(d)            non-secure disposal of hard copies of personal information (i.e. placing readable paper in recycle bin or hard waste bin);

(e)            documents sent to the wrong fax number or email address; and

(f)             documents sent to a free web-based email account such as Yahoo!, Gmail or Hotmail.

Privacy incidents can:

(g)            occur due to accidental or deliberate actions;

(h)            result from human error or technical failures; and

(I)           apply to information in any form, whether electronic or hard copy.

3.13        Incident reporting

It is vital all privacy incidents are reported as soon as possible so that their impact may be minimised. Employees should be aware of:

(a)            how to identify potential privacy incidents

(b)            the reason for reporting incidents is so their impact can be minimised – not to punish individuals

(c)            the need to report all incidents to their manager as soon as they become aware of them.

The Angels Disability Support Services must report all Client related privacy incidents to the:

(a)            NDIS Commission

(b)            Office of the Australian Information Commissioner,

  • SA Department of Health

as applicable, within one business day of becoming aware of, or being notified of a possible privacy incident, or within one business day of an allegation being made of a potential breach.

A breach of Client privacy may have a major impact, a non-major impact, or be a near miss or an incident with no apparent impact on a Client. In each case, the incident has to be reported and managed in accordance with the Incident Management and Reporting Policy.

3.14        Access and Correction

Clients have a legal right to request access or correction of their personal information held by The Angels Disability Support Services.

Clients may ask individuals to verify their identity before processing any access or correction requests, to ensure that the personal information The Angels Disability Support Services holds is properly protected.

3.15        Complaints

If a Client has a complaint about how The Angels Disability Support Services has collected or handled their personal information, it will be managed in accordance with the The Angels Disability Support Services Feedback and Complaints Management System.

4.             General

4.1           Relevant Legislation, Regulations, Rules and Guidelines

Legislation, Rules, Guidelines and Policies apply to this policy and supporting documentation as set out in the Legislation Register.

4.2           Inconsistency

If and to the extent that the terms of this Policy are or would be inconsistent with the requirements of any applicable law, this Policy is deemed to be amended but only to the extent required to comply with the applicable law.

4.3           Policy Details

Approved By:                          The Board of Angel Disability Support Services Pty Ltd

Approval Date:                         February 2022

Next Scheduled Review:          June 2023

Version:                                   1