Privacy & Policy

Purpose

Connecting Futures is committed to protecting the privacy, dignity, and rights of all participants we support. This Privacy Policy explains how we collect, use, store, disclose, and manage personal information in accordance with:

  • The Privacy Act 1988 (Cth) 

  • Australian Privacy Principles (APPs)

  • The NDIS Practice Standards and Quality Indicators

  • NDIS (Incident Management and Reportable Incidents) Rules 2018 

  • NDIS Terms of Business for Registered Providers

  • The Inclusive Employment Australia (IEA) Grant Agreement/Deed requirements

  • Other relevant Commonwealth and State legislation

This policy ensures that personal information is handled lawfully, transparently, and respectfully, while enabling safe and effective service delivery.

Scope

This policy applies to:

  • All Connecting Futures employees, contractors, students, and volunteers

  • All participants, including young people aged 15–25, and their families, carers, nominees, and guardians

  • All records, information systems, and communication channels used by Connecting Futures

Definitions

Personal Information: Information or an opinion about an identified individual or an individual who is reasonably identifiable.

Sensitive Information: A subset of personal information including health, disability, cultural background, or criminal history.

Participant: Any individual receiving services from Connecting Futures.

Duties, Responsibilities and Accountability

Management (Director and Compliance and Performance Lead):

  • Ensure Connecting Futures complies with all applicable privacy legislation, the Australian Privacy Principles, NDIS Practice Standards, and IEA requirements.

  • Implement, maintain, and review systems, policies, and procedures relating to privacy and information management.

  • Ensure all staff receive appropriate training and understand their privacy obligations

  • Monitor compliance and respond to any breaches, complaints, or risks

Staff and Representatives (Employees, Contractors, Volunteers, Students):

  • Collect, use, store, and disclose personal information in accordance with this policy.

  • Maintain confidentiality of all participant information at all times.

  • Access only the information necessary to perform their role.

  • Accurately record information in line with organisational standards.

  • Report any suspected privacy breaches, unauthorised access, or concerns immediately, and no greater than 24hrs after becoming aware.

Participants and Representatives:

  • Provide accurate and up-to-date information where possible.

  • Respect the privacy of other participants and staff.

  • Raise any concerns or complaints regarding privacy with Connecting Futures.

Types of Information Collected

We collect only information necessary to deliver safe and effective services, including:

  • Personal details (name, date of birth, contact details)

  • NDIS information (NDIS number, plan details, goals)

  • Employment and education information 

  • Health and disability-related information

  • Risk, incident, and safeguarding information

  • Support plans, progress notes, and outcomes

  • Financial and billing information (where relevant)

  • Images, recordings, or testimonials (with consent)

How Information is Collected and Recorded

Information is collected through:

  • Direct engagement with participants and families

  • Referral agencies/providers or schools, NDIA, NDIS Commission and Department of Social Services 

  • Service delivery interactions and case notes

  • Forms, agreements, and digital systems

  • Observations relevant to supports and outcomes

Documentation Requirements

  • Information is only documented where it is necessary for service delivery, compliance, duty of care or for social media purposes, with consent. 

  • Informed consent is obtained and documented using Connecting Futures Consent Forms.

  • Participants are informed what information is collected and why, typically during intake or commencement appointments. 

  • All records must be:

    • Accurate, factual, and relevant

    • Written in clear, respectful, and easy-to-understand language

    • Concise and professional (generally written in past tense for case notes)

Record Keeping Practices

Connecting Futures maintains:

  • Progress notes and outcome tracking aligned to participant goals

  • Records of supports, capacity building activities, and engagement

  • Incident reports (retained in line with legal requirements)

  • Records of communication with NDIA, DSS, and other providers

  • Documentation of any information shared, including what was shared, why, and whether consent was obtained

Records are maintained using secure digital systems, including:

  • MYP (NDIS Participants)

  • Buddy Note (IEA program)

  • Microsoft Teams

  • WAOP (IEA Program)

Connecting Futures does not keep any hard copy of Participant files and operates electronically. Any paper based evidence, is uploaded to the relevant system, and then destroyed using security bins provided at all sites by Connecting Futures. 

Record Retention and Disposal

Connecting Futures retains Participant records only for as long as necessary to meet legal, regulatory, and operational requirements.

  • Participant records are retained for a minimum of 7 years after exit from service, unless a longer period is required by law.

  • Records relating to incidents, complaints, or reportable incidents are retained in accordance with relevant legislative requirements and may be kept longer where required.

  • Records associated with Inclusive Employment Australia (IEA) services are retained in line with Department of Social Services requirements.

After the retention period has expired:

  • Records are securely destroyed or de-identified.

  • Electronic records are permanently deleted in accordance with system processes.

  • Physical records (if any) are securely destroyed.

Where records are held in external systems (e.g., WAOP), retention and access may be subject to external system controls and government data management policies.

Participant Rights and Access to Information

Connecting Futures recognises the right of participants to access and control their personal information.

Participants, or their authorised representatives (e.g., guardian or nominee), have the right to:

  • Request access to their personal records.

  • Be informed about where and how their information is stored.

  • Request corrections where information is inaccurate, incomplete, or unclear.

  • Receive support to understand the information contained in their file.

Access Process

  • Requests for access should be made to Connecting Futures in writing. Requests should be escalated to Management if the request is for confidential records requested by a Partipcant who’s services have ceased, or by a person requesting information about another Participant. 

  • Access will be provided within a reasonable timeframe, unless restricted by law to the authorised person. 

  • Connecting Futures will provide assistance to ensure participants can understand the information provided.

  • If access cannot be granted, this will be clearly communicated with a rationale provided. 

Amendments and Corrections

  • Participants may request changes to their records if information is incorrect, incomplete, or unclear.

  • Corrections will be made promptly where appropriate.

  • If a correction is not made, a note of the requested amendment will be recorded in the file.

Privacy and Third-Party Access

  • No third party will be granted access to a participant’s personal information without the participant’s consent, unless required or authorised by law.

  • Any access by third parties must be approved by the Director or their nominee.

  • Connecting Futures Management will request appropriate evidence to verify the identity of the person requesting access to records, to ensure they are authorised to access those records. If reliable and sufficient evidence cannot be provided, records cannot be released.  

Transfer of Information

  • Participant files remain the property of Connecting Futures and are maintained on behalf of the participant.

  • Where a participant transitions to another provider, relevant information may be shared only with consent and approval from management.

  • Full files will not be transferred; instead, appropriate summaries or extracts will be provided as needed for continuity of support.

Use of Information for Research and Reporting

  • Information may be used for internal reporting, program evaluation, or research purposes only with participant consent.

  • Any data used will be de-identified to ensure individuals cannot be recognised.

Limits on Access to Information

While Connecting Futures supports participant access to personal information, there are limited circumstances where access may be restricted or not granted, in line with the Australian Privacy Principles.

Access may be refused or limited where:

  • Providing access would pose a serious threat to the life, health, or safety of the participant or another person.

  • Information relates to other individuals and cannot be reasonably separated or de-identified.

  • The request is frivolous, vexatious, or repeated in a way that is unreasonable.

  • Connecting Futures is no longer in possession of the information, for example:

    • Where records were held in external systems such as the Workforce Australia Online Portal (WAOP) and access has ceased following program exit.

  • The information has been lawfully destroyed or archived in line with retention requirements (e.g., records older than 7 years)

  • Access would prejudice legal proceedings or regulatory investigations.

Where access is refused or limited:

  • Participants will be provided with a clear explanation of the reasons (unless unlawful to do so).

  • Alternative options may be offered, such as access to a summary of information where appropriate.

  • Participants will be informed of their right to make a complaint.

Connecting Futures will always aim to provide the greatest level of access possible, while balancing legal, safety, and privacy obligations. 

Staff Training and Awareness

Connecting Futures is committed to ensuring all staff understand and uphold privacy and confidentiality obligations in accordance with legislation, the NDIS Practice Standards, and IEA program requirements.

Inclusive Employment Australia (IEA) Requirements

  • All employees delivering IEA program services must complete the Privacy Information Training module available on the Workforce Australia Online Portal (WAOP) prior to commencing service delivery.

  • Access to the WAOP Case Management System will not be granted until this training has been successfully completed.

  • The Privacy Information Training module must be completed annually to maintain access to WAOP systems and ensure continued compliance.

NDIS Workforce Requirements

  • All employees delivering NDIS supports complete internal privacy and confidentiality training at induction

  • Training includes obligations under the Privacy Act, Australian Privacy Principles, and NDIS Practice Standards.

Ongoing Responsibilities

All staff are required to:

  • Maintain confidentiality of participant information at all times

  • Access only information necessary for their role

  • Follow organisational policies and procedures for storing and sharing information

  • Immediately report any suspected data breaches or privacy concerns

Connecting Futures maintains records of staff training and monitors compliance with mandatory privacy training requirements.

Related Documents

  • Feedback Policy and Procedure

  • Safeguarding Policy

  • Code of Conduct

  • Cyber Security Strategy

  • Acceptable Use of Artificial Intelligence Policy

  • Information Security and Management Policy

  • Risk Management Policy