Inspiring Ability Through Creativity - Call us on 0415 334 834

Privacy and Information Management Policy and Procedure

1.       Introduction

Inspire Ability is committed to the responsible management, security, and protection of personal and sensitive information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs) and the Privacy Amendment (Notifiable Data Breaches) Act 2017.
This policy outlines Inspire Ability’s approach to privacy, record and information management, and notifiable data breach reporting.

2.     Purpose and Objectives

To provide clear, actionable guidelines for all staff, clients, and stakeholders regarding:

  • The collection, storage, access, and use of personal and sensitive data;
  • The management and retention of records;
  • The identification, assessment, and notification of notifiable data breaches;
  • Legal obligations and internal responsibilities.

3.     Scope

This policy applies to all Inspire Ability employees, contractors, students, volunteers, and third-party service providers who collect, access, manage, or store personal or sensitive information.
It also applies to all individuals who provide personal information to Inspire Ability including clients, families, carers, and authorised representatives.

4.     Definitions

  • Australian Privacy Principles (APPs): Rules under the Privacy Act 1988 governing how personal data must be managed.
  • Confidentiality: Protection of personal information from unauthorised access or disclosure.
  • Eligible Data Breach: A data breach causing or likely to cause serious harm.
  • Notifiable Data Breach Scheme (NDB): Framework requiring notification to the OAIC and affected individuals.
  • Office of the Australian Information Commissioner (OAIC): National data protection authority.
  • Personally Identifiable Information: Any data that can identify an individual.
  • Privacy Act 1988: Australian law regulating the handling of personal information.
  • Sensitive Information: Includes health, race, sexual orientation, religious beliefs, political opinions, and criminal records whether solicited or unsolicited.

5.     Policy Content

Inspire Ability’s Privacy and Information Management Policy outlines how the organisation manages the privacy of personal and sensitive information collected, stored, and held in both electronic and hard copy formats. The policy complies with the Australian Privacy Principles (APPs) as set out in the Privacy Act 1988.

5.1 APP 1 – Open and Transparent Management of Personal Information

Inspire Ability ensures compliance with the Privacy Act 1988 and APPs by implementing and sharing this policy with clients, associates, stakeholders, and the public upon request. All reasonable steps will be taken to manage personal information transparently.

5.2 APP 2 – Anonymity and Pseudonymity

Clients, families, and carers will be offered the option to remain anonymous or use a pseudonym where practicable.

5.3 APP 3 – Collection of Solicited Personal Information

All personal information collected during service delivery is handled securely and confidentially. Only authorised staff who require access to fulfil their duties may access this information.

5.4 APP 4 – Dealing with Unsolicited Personal Information

Sometimes individuals may voluntarily provide personal information, either verbally or in writing, that Inspire Ability has not requested. Any unsolicited personal information will be treated with the same level of privacy, confidentiality and security as solicited information. If the information is relevant to the services we provide, it will be managed in accordance with this policy. If it is not required and there is no legal reason to retain it, it will not be recorded.

5.5 APP 5 – Notification of the Collection of Personal Information

Clients, families, and carers will be informed when information is collected, how it will be stored, and how it will be used to deliver high-quality services.

5.6 APP 6 – Use or Disclosure of Personal Information

Inspire Ability will not disclose personal information except where required for service provision, with consent, or where there is a reasonable expectation of information sharing between providers.
Information recorded by staff about a client, will be the minimum necessary to enable the efficient and effective provision of services. Information will not be accessed by Inspire Ability employees unless required to enable them to carry out their duties within the organisation.
Information used for compliance, reporting, or statistical purposes will be de-identified before use.

5.7 APP 7 – Direct Marketing

Inspire Ability does not use or share personal information for direct marketing or with third-party marketers. Information is only used to communicate service-related updates to clients, families, or carers.

5.8 APP 8 – Cross-Border Disclosure of Personal Information

Personal information will not be shared outside Australia unless written consent is provided for ongoing service delivery. All reasonable steps will be taken to ensure security.

5.9 APP 9 – Adoption, Use or Disclosure of Government-Related Identifiers

Government identifiers such as NDIS Participant Number, Medicare Number, Centrelink Customer Reference Number etc., that are accessed for service purposes will remain confidential and will not be used or disclosed.

5.10 APP 10 – Quality of Personal Information

Inspire Ability takes reasonable steps to ensure that all personal information is accurate, up to date, and complete. Prior to disclosure for service purposes, all shared information will be verified for accuracy.

5.11 APP 11 – Security of Personal Information

Inspire Ability implements best practice security measures to protect all personal and sensitive information collected, used, and held.
Security measures include:

  • Role-based access control protocol;
  • Password and two-factor authentication protocols;
  • Antivirus protection and firewalls;
  • Secure OneDrive/cloud backups.

Staff using personal devices for work must:

  • Use passwords or PINs;
  • Install antivirus protection;
  • Log out of work systems when not in use.

Where third-party providers are involved, Inspire Ability ensures data security and privacy-conscious practices.

5.12 APP 12 – Access to Personal Information

Clients may request access to their personal information by submitting a written request to the Manager. Information will only be shared with approval.

5.13 APP 13 – Correction of Personal Information

Clients may request correction of inaccurate information by submitting a written request to the Manager, who will take all reasonable steps to ensure records are accurate and complete.

6. Confidentiality Obligations

6.1 Staff Responsibilities

All Inspire Ability staff, including volunteers and contractors, must:

  • Uphold privacy principles;
  • Maintain discretion when handling personal and sensitive data.

All Inspire Ability staff, including employees, students, volunteers and contractors, must uphold the Australian Privacy Principles by:

  • Maintaining the privacy and confidentiality of all personal and sensitive information.
  • Only collecting, accessing, using and disclosing information necessary to perform their role.
  • Explaining to clients what personal information will be collected and recorded.
  • Not discussing client information in public or unauthorised settings.
  • Keeping paper records, electronic devices and passwords secure.
  • Logging out or shutting down of devices when they are not in use.
  • Reporting any actual or suspected privacy breach immediately in accordance with this Policy.

6.2 Breaches of Confidentiality

Breaches of confidentiality may result in disciplinary action and/or legal consequences.

7. Record and Information Management

7.1 Record Keeping

Client records include personal, financial, and medical information and are core to Inspire Ability’s service delivery.

Records are:

  • Created upon intake using the Client Initial Enquiry Form
  • Maintained throughout service delivery
  • Stored in Splose and/or Inspire Ability OneDrive (electronic)

7.2 Ownership and Access

All records remain the property of Inspire Ability. Clients may request access to their records in writing. Records may only be released to a third party with written consent of the client or where required by law. Release is authorised by the Managing Director following identity verification.

7.3 Retention and Review

After a client exits the service, records will be archived and kept secure by Inspire Ability until the client turns 25 years old, or for a period of 7 years (whichever is longer).

Archived records will be reviewed annually. Records that are no longer required to be held, will be securely destroyed.

7.4 Destruction of Records

Paper records will be securely destroyed through cross-cut shredding, and electronic records will be securely and permanently deleted or destroyed by physical destruction of the storage media where appropriate.

 

8. Notifiable Data Breaches (NDB)

8.1 Responsibility

The Practice Manager is responsible for ensuring all procedures are followed in the event of a data breach requiring notification under the Privacy Amendment (Notifiable Data Breaches) Act 2018, as guided by the Office of the Australian Information Commissioner (OAIC).

8.2 Identifying a Notifiable Data Breach

A data breach occurs when personal information held by Inspire Ability is lost, accessed, or disclosed without authorisation.

Examples include:

  • Loss or theft of a device containing client information;
  • Hacking of a database containing personal information;
  • Personal information mistakenly sent to the wrong person.
  • A staff member accesses records without authorisation;

The OAIC must be notified when:

  • The breach is likely to result in serious harm;
  • The risk of harm cannot be mitigated through remedial action.

8.3 Notifiable Data Breach Procedure

When a potential data breach is suspected, Inspire Ability must assess whether it is a notifiable data breach likely to cause serious harm.
Assessments must be completed within 30 days of identifying the suspected breach.

Initial Steps

  1. Determine if an investigation is required – The Practice Manager (or delegate) decides if a full investigation is necessary.
  2. Investigate – Gather all relevant details about the suspected breach, identify affected information, and assess potential impact.
  3. Evaluate – Decide if the breach meets the criteria for a notifiable data breach and requires notification to the OAIC.

If a breach is identified, Inspire Ability will take all reasonable steps to contain the breach by contacting its IT provider to implement controls and prevent further access.

 

Notifiable Data Breach Management Procedure

Where a notifiable data breach is confirmed:

  1. Prepare a formal statement including:
    • Organisation’s identity and contact details;
    • Description of the breach;
    • Types of information affected;
    • Recommendations for affected individuals.
  2. Submit the statement to the OAIC.
  3. Notify affected individuals directly or indirectly by publishing the statement on Inspire Ability’s website and publicising its contents.
  4. Review and test security measures to prevent recurrence. The IT provider will assist in strengthening data protection and mitigating future risks.
  5. Implement remediation actions to minimise harm, including updating access controls and recovering lost data where possible.

OAIC reporting forms are available at:
🔗 https://forms.business.gov.au/smartforms/landing.htm?formCode=OAIC-NDB


9. Unauthorised Disclosure of Personal Information

An unauthorised disclosure of personal information occurs when personal or sensitive information is accidentally or inappropriately shared with a person who is not authorised to receive it. Examples include sending an email to the wrong recipient, discussing client information where it may be overheard, or providing documents to the wrong individual.

Not all unauthorised disclosures constitute a Notifiable Data Breach. Where an unauthorised disclosure is unlikely to result in serious harm and the risk can be effectively managed through prompt remedial action, it will be managed internally in accordance with this policy.

9.1 Unauthorised Disclosure Procedure

In the event of an unauthorised disclosure, Inspire Ability will:

  • Report the incident to management as soon as practicable.
  • Document the incident using the Incident Report Form.
  • Assess the nature and potential impact of the disclosure.
  • Notify the affected individual(s), where appropriate.
  • Take reasonable steps to recover, delete or securely destroy the information, where possible.
  • Review the incident during staff supervision meetings and implement measures to reduce the risk of recurrence e.g. training or process improvements.


10.
Information Received in Error

If Inspire Ability receives personal or sensitive information that was not intended for us, we will treat the information as confidential and will not use or disclose it except as necessary to address the error. Where appropriate, we will notify the sender, securely delete or destroy the information if there is no lawful reason to retain it.

11. Training and Awareness

11.1 Staff Training

All staff must complete training on:

  • Privacy and confidentiality;
  • Safe information handling;
  • Data breach response.

11.2 Refresher Training

Refresher training is provided during staff meetings and policy reviews.

12. Policy Review

This policy will be reviewed annually or within 30 days of any legislative or regulatory change.

Liquid error (layout/theme line 185): Could not find asset snippets/azexo-footer-scripts.liquid