Privacy & Policy
Purpose
Connecting Futures is committed to protecting the privacy, dignity, and rights of all participants we support. This Privacy Policy explains how we collect, use, store, disclose, and manage personal information in accordance with:
The Privacy Act 1988 (Cth)
Australian Privacy Principles (APPs)
The NDIS Practice Standards and Quality Indicators
NDIS (Incident Management and Reportable Incidents) Rules 2018
NDIS Terms of Business for Registered Providers
The Inclusive Employment Australia (IEA) Grant Agreement/Deed requirements
Other relevant Commonwealth and State legislation
This policy ensures that personal information is handled lawfully, transparently, and respectfully, while enabling safe and effective service delivery.
Scope
This policy applies to:
All Connecting Futures employees, contractors, students, and volunteers
All participants, including young people aged 15–25, and their families, carers, nominees, and guardians
All records, information systems, and communication channels used by Connecting Futures
Definitions
Personal Information: Information or an opinion about an identified individual or an individual who is reasonably identifiable.
Sensitive Information: A subset of personal information including health, disability, cultural background, or criminal history.
Participant: Any individual receiving services from Connecting Futures.
Duties, Responsibilities and Accountability
Management (Director and Compliance and Performance Lead):
Ensure Connecting Futures complies with all applicable privacy legislation, the Australian Privacy Principles, NDIS Practice Standards, and IEA requirements.
Implement, maintain, and review systems, policies, and procedures relating to privacy and information management.
Ensure all staff receive appropriate training and understand their privacy obligations
Monitor compliance and respond to any breaches, complaints, or risks
Staff and Representatives (Employees, Contractors, Volunteers, Students):
Collect, use, store, and disclose personal information in accordance with this policy.
Maintain confidentiality of all participant information at all times.
Access only the information necessary to perform their role.
Accurately record information in line with organisational standards.
Report any suspected privacy breaches, unauthorised access, or concerns immediately, and no greater than 24hrs after becoming aware.
Participants and Representatives:
Provide accurate and up-to-date information where possible.
Respect the privacy of other participants and staff.
Raise any concerns or complaints regarding privacy with Connecting Futures.
Types of Information Collected
We collect only information necessary to deliver safe and effective services, including:
Personal details (name, date of birth, contact details)
NDIS information (NDIS number, plan details, goals)
Employment and education information
Health and disability-related information
Risk, incident, and safeguarding information
Support plans, progress notes, and outcomes
Financial and billing information (where relevant)
Images, recordings, or testimonials (with consent)
How Information is Collected and Recorded
Information is collected through:
Direct engagement with participants and families
Referral agencies/providers or schools, NDIA, NDIS Commission and Department of Social Services
Service delivery interactions and case notes
Forms, agreements, and digital systems
Observations relevant to supports and outcomes
Documentation Requirements
Information is only documented where it is necessary for service delivery, compliance, duty of care or for social media purposes, with consent.
Informed consent is obtained and documented using Connecting Futures Consent Forms.
Participants are informed what information is collected and why, typically during intake or commencement appointments.
All records must be:
Accurate, factual, and relevant
Written in clear, respectful, and easy-to-understand language
Concise and professional (generally written in past tense for case notes)
Record Keeping Practices
Connecting Futures maintains:
Progress notes and outcome tracking aligned to participant goals
Records of supports, capacity building activities, and engagement
Incident reports (retained in line with legal requirements)
Records of communication with NDIA, DSS, and other providers
Documentation of any information shared, including what was shared, why, and whether consent was obtained
Records are maintained using secure digital systems, including:
MYP (NDIS Participants)
Buddy Note (IEA program)
Microsoft Teams
WAOP (IEA Program)
Connecting Futures does not keep any hard copy of Participant files and operates electronically. Any paper based evidence, is uploaded to the relevant system, and then destroyed using security bins provided at all sites by Connecting Futures.
Record Retention and Disposal
Connecting Futures retains Participant records only for as long as necessary to meet legal, regulatory, and operational requirements.
Participant records are retained for a minimum of 7 years after exit from service, unless a longer period is required by law.
Records relating to incidents, complaints, or reportable incidents are retained in accordance with relevant legislative requirements and may be kept longer where required.
Records associated with Inclusive Employment Australia (IEA) services are retained in line with Department of Social Services requirements.
After the retention period has expired:
Records are securely destroyed or de-identified.
Electronic records are permanently deleted in accordance with system processes.
Physical records (if any) are securely destroyed.
Where records are held in external systems (e.g., WAOP), retention and access may be subject to external system controls and government data management policies.
Participant Rights and Access to Information
Connecting Futures recognises the right of participants to access and control their personal information.
Participants, or their authorised representatives (e.g., guardian or nominee), have the right to:
Request access to their personal records.
Be informed about where and how their information is stored.
Request corrections where information is inaccurate, incomplete, or unclear.
Receive support to understand the information contained in their file.
Access Process
Requests for access should be made to Connecting Futures in writing. Requests should be escalated to Management if the request is for confidential records requested by a Partipcant who’s services have ceased, or by a person requesting information about another Participant.
Access will be provided within a reasonable timeframe, unless restricted by law to the authorised person.
Connecting Futures will provide assistance to ensure participants can understand the information provided.
If access cannot be granted, this will be clearly communicated with a rationale provided.
Amendments and Corrections
Participants may request changes to their records if information is incorrect, incomplete, or unclear.
Corrections will be made promptly where appropriate.
If a correction is not made, a note of the requested amendment will be recorded in the file.
Privacy and Third-Party Access
No third party will be granted access to a participant’s personal information without the participant’s consent, unless required or authorised by law.
Any access by third parties must be approved by the Director or their nominee.
Connecting Futures Management will request appropriate evidence to verify the identity of the person requesting access to records, to ensure they are authorised to access those records. If reliable and sufficient evidence cannot be provided, records cannot be released.
Transfer of Information
Participant files remain the property of Connecting Futures and are maintained on behalf of the participant.
Where a participant transitions to another provider, relevant information may be shared only with consent and approval from management.
Full files will not be transferred; instead, appropriate summaries or extracts will be provided as needed for continuity of support.
Use of Information for Research and Reporting
Information may be used for internal reporting, program evaluation, or research purposes only with participant consent.
Any data used will be de-identified to ensure individuals cannot be recognised.
Limits on Access to Information
While Connecting Futures supports participant access to personal information, there are limited circumstances where access may be restricted or not granted, in line with the Australian Privacy Principles.
Access may be refused or limited where:
Providing access would pose a serious threat to the life, health, or safety of the participant or another person.
Information relates to other individuals and cannot be reasonably separated or de-identified.
The request is frivolous, vexatious, or repeated in a way that is unreasonable.
Connecting Futures is no longer in possession of the information, for example:
Where records were held in external systems such as the Workforce Australia Online Portal (WAOP) and access has ceased following program exit.
The information has been lawfully destroyed or archived in line with retention requirements (e.g., records older than 7 years)
Access would prejudice legal proceedings or regulatory investigations.
Where access is refused or limited:
Participants will be provided with a clear explanation of the reasons (unless unlawful to do so).
Alternative options may be offered, such as access to a summary of information where appropriate.
Participants will be informed of their right to make a complaint.
Connecting Futures will always aim to provide the greatest level of access possible, while balancing legal, safety, and privacy obligations.
Staff Training and Awareness
Connecting Futures is committed to ensuring all staff understand and uphold privacy and confidentiality obligations in accordance with legislation, the NDIS Practice Standards, and IEA program requirements.
Inclusive Employment Australia (IEA) Requirements
All employees delivering IEA program services must complete the Privacy Information Training module available on the Workforce Australia Online Portal (WAOP) prior to commencing service delivery.
Access to the WAOP Case Management System will not be granted until this training has been successfully completed.
The Privacy Information Training module must be completed annually to maintain access to WAOP systems and ensure continued compliance.
NDIS Workforce Requirements
All employees delivering NDIS supports complete internal privacy and confidentiality training at induction
Training includes obligations under the Privacy Act, Australian Privacy Principles, and NDIS Practice Standards.
Ongoing Responsibilities
All staff are required to:
Maintain confidentiality of participant information at all times
Access only information necessary for their role
Follow organisational policies and procedures for storing and sharing information
Immediately report any suspected data breaches or privacy concerns
Connecting Futures maintains records of staff training and monitors compliance with mandatory privacy training requirements.
Related Documents
Feedback Policy and Procedure
Safeguarding Policy
Code of Conduct
Cyber Security Strategy
Acceptable Use of Artificial Intelligence Policy
Information Security and Management Policy
Risk Management Policy