Community

Free template

Free NDIS Privacy Policy template

A ready-to-use Privacy and Confidentiality Policy for small NDIS providers and sole traders. It covers what personal information you collect, consent, secure storage, sharing, data breaches, and how participants can see and correct their own records - written to line up with the Privacy Act 1988 and the Australian Privacy Principles. Pre-fill your details, download the Word file or copy the text, and tailor the highlighted prompts. Free, with no sign-up.

Who it’s for

Sole traders and small NDIS providers - support workers, community access, personal care, domestic assistance and similar supports. It works whether or not you are NDIS registered: unregistered providers working with plan-managed and self-managed participants still handle sensitive participant information. For providers preparing for a certification audit, a privacy policy supports the Core Module’s Privacy and Dignity outcome.

How to use it

  • Pre-fill your details below and they drop into the [highlighted] prompts automatically.
  • Replace the remaining prompts so the policy describes what you actually do - not what a template guesses you do.
  • Make it available free of charge to anyone who asks - the Privacy Act (APP 1) expects that.
  • Brief your workers on it, and keep evidence of the briefing.

Why an NDIS provider needs a privacy policy

Three separate obligations point at the same document:

  1. The Privacy Act 1988. Where the Act applies to your business, APP 1 requires a clearly expressed, up-to-date privacy policy about how you manage personal information, available free of charge. Whether the Act applies is covered in the next section - for most NDIS support providers the answer is yes.
  2. The NDIS Practice Standards.For providers undergoing certification, Privacy and Dignity is an express Core Module outcome - and it is broader than information handling. This template supports the information-handling and confidentiality parts; you also need to show that workers respect participants’ bodily privacy, personal care preferences, private spaces, confidential conversations and choices about photographs and recordings. Providers on the verification pathway are assessed against the separate Verification Module (human resource management, risk management, complaints management and incident management) - a privacy policy is not an express Verification Module outcome, but it may still be legally required and is useful evidence of good practice.
  3. The NDIS Code of Conduct. Every provider and worker, registered or not, must respect the privacy of people with disability. That does not depend on your size or registration status.

Does the Privacy Act apply to you? The $3 million question

You may have read that small businesses with an annual turnover under $3 million are exempt from the Privacy Act. Many NDIS providers under that threshold are still covered, and this is one of the most common misunderstandings in the sector.

The exemption does not apply where a business provides a health service to an individual and holds health information, other than only in an employee record. The Privacy Act’s definition of a health service is broad and can include activities delivered as part of caring for a person with disability, and OAIC guidance specifically identifies disability service providers where they handle health information. A business covered this way is an APP entity - a business or organisation the Privacy Act requires to comply with the Australian Privacy Principles - regardless of turnover.

The legal test depends on the services you actually provide and the information you hold, so do not assume your NDIS status alone decides the question. But if your business provides health-related disability supports and holds participant health information - the usual position for a support provider - the prudent course is to comply with the Australian Privacy Principles. Obtain advice if your services are limited and you are unsure whether the Privacy Act applies.

What an NDIS privacy policy should cover

Health information and the Notifiable Data Breaches scheme

Much of the information an NDIS provider holds may be health information - information about disability, health conditions, medications, support needs and the health services provided. Health information is sensitive information under the Privacy Act, a more highly protected category of personal information: collection generally requires consent, and use, disclosure and security rules are tighter. Other participant information may be personal information without necessarily being health information.

Covered businesses are also subject to the Notifiable Data Breaches scheme. If personal information is subject to unauthorised access or disclosure, or is lost in circumstances likely to lead to unauthorised access or disclosure, you must act promptly to contain the incident and assess the risk. An eligible data breach - one meeting the Privacy Act’s serious-harm notification test - generally occurs where a reasonable person would conclude that serious harm to someone is likely and remedial action (steps that successfully remove that likely risk) has not removed it. You must carry out a reasonable and expeditious assessment, taking all reasonable steps to complete it within 30 days, and once you have reasonable grounds to believe an eligible breach occurred, notify the OAIC and affected individuals as soon as practicable - 30 days is not a waiting period. A lost unencrypted phone with participant notes on it, or an email to the wrong recipient, can be enough to trigger an assessment.

The template

Pre-fill your details (optional)

Add your details and they fill straight into the template below and the Word download. Nothing is saved or sent anywhere - it stays in your browser.

The template

Download

[your business or your full name] - Privacy and Confidentiality Policy

ABN [your ABN] · Version 1.0 · Effective [date]

Purpose

[your business or your full name] respects the privacy of participants, their families and representatives, and our workers. This policy explains how we collect, use, store, share and protect personal information. It is intended to support compliance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the NDIS Practice Standards where applicable, and any State or Territory health privacy laws that apply to our activities.

Fill in: If you operate as a private health service provider in NSW, Victoria or the ACT, those jurisdictions have their own health privacy legislation that can apply alongside the federal Privacy Act (with different rules on things like access charges and record retention). Identify whether it applies to you and obtain advice if unsure.

Who this policy binds

An "APP entity" is a business or organisation covered by the Privacy Act and required to comply with the Australian Privacy Principles. Many NDIS providers are APP entities even with an annual turnover under $3 million: the small-business exemption does not apply where a business provides a health service to an individual and holds health information, other than only in an employee record. The definition of a health service is broad and can include activities delivered as part of caring for a person with disability.

[your business or your full name] complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles to the extent they apply to our activities, including:

  • APP 1 - maintaining privacy governance and a clear, current privacy policy, including processes for enquiries and complaints.
  • APP 3 - collecting only personal information reasonably necessary for our functions, by lawful and fair means; sensitive information generally also requires consent unless an exception applies.
  • APP 5 - taking reasonable steps, at or before collection or as soon as practicable afterwards, to make sure the person is aware of the relevant collection matters.
  • APP 6 - using or disclosing information for its primary collection purpose, or for a secondary purpose where the person consents or an APP exception applies.
  • APP 8 - taking the required steps before disclosing personal information to an overseas recipient, subject to the APP 8 exceptions.
  • APP 11 - taking reasonable steps to protect personal information, and destroying or de-identifying it when it is no longer needed and no law or order requires it to be kept.
  • APP 12 - giving people access to their personal information, subject to lawful refusal grounds.
  • APP 13 - taking reasonable steps to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.

Fill in: Whether the Privacy Act applies depends on the services you actually provide and the information you hold, not your NDIS status alone. If [your business or your full name] provides health-related disability supports and holds participant health information (the usual position for a support provider), you can also state plainly: "We are an APP entity because we provide a health service and hold health information about participants." If your services are limited and you are unsure, obtain advice before making that statement.

What information we collect

  • Identity and contact details (name, date of birth, address, phone, email).
  • NDIS details (NDIS number, plan information relevant to the supports we provide).
  • Health and disability information needed to deliver safe, appropriate support.
  • Records of the supports we provide, including notes, incidents and consents.
  • Photographs, video recordings and audio recordings, but only where necessary and where we have specific agreement or another lawful basis.
  • Worker information needed for employment and screening.

We only collect information that is reasonably necessary to provide our supports and meet our legal obligations. Much of the participant information we hold - such as information about disability, health conditions, medications, support needs and the health services we provide - is health information, which is sensitive information under the Privacy Act and receives additional protection. Other participant information may be personal information without being health information.

Fill in: Check this list matches the personal information you actually collect, and add or remove items so it is correct for [your business or your full name]. State who in your business can access participant information (for example: only you, or you and named support workers through their own logins).

How we collect it

We collect information directly from the participant wherever possible, and with their consent. Sometimes we collect it from a representative, family member, the NDIA, or another provider - only where the participant has agreed or the law allows.

Anonymity and pseudonyms

People may deal with us anonymously or using a pseudonym where this is lawful and practicable - for example, when making a general enquiry. It will generally not be practicable where we need to verify identity, deliver funded supports, manage safety, bill for services or keep legally required records.

Unsolicited information

If we receive personal information we did not ask for, we decide within a reasonable period whether we could lawfully have collected it ourselves. If not, we securely destroy or de-identify it where it is lawful and reasonable to do so.

How we use and share it

We use or disclose personal information for the primary purpose for which it was collected. We may also use or disclose it for a related secondary purpose the person would reasonably expect, with consent, or where another APP exception or law permits or requires it. For sensitive information, an expected secondary purpose must be directly related to the primary purpose. In practice this means we handle information:

  • To plan and deliver supports, and to keep participants safe.
  • To meet our obligations to the NDIS Commission and the NDIA, including reporting reportable incidents.
  • Where we reasonably believe the use or disclosure is necessary to lessen or prevent a serious threat to an individual’s life, health or safety, or to public health or safety.
  • We never sell personal information.

Direct marketing

We do not use participant health or disability information for direct marketing without valid consent. Any other direct marketing is conducted in accordance with APP 7 and applicable marketing laws, and always includes a simple way to opt out.

Government-related identifiers

We do not adopt a government-related identifier, such as an NDIS participant number, as our own internal identifier for a person unless permitted by law, and we use and disclose such identifiers only where APP 9 permits.

Information quality

We take reasonable steps to ensure the personal information we collect is accurate, up to date and complete, and that the information we use or disclose is accurate, up to date, complete and relevant for that purpose.

Consent

Where consent is required for the collection, use or disclosure of information, we obtain and record it - usually using our Participant Consent Form. Consent may be written, verbal or otherwise clearly indicated, but it must be voluntary, informed, current and specific, and given by a person with capacity or by a person with lawful authority to decide on their behalf.

We do not rely on consent where the handling is instead required or authorised by law or another APP exception applies. A participant can change or withdraw consent at any time. Withdrawal applies going forward - it does not undo previous lawful handling, and we may still be required to keep information the law says we must retain. We explain what changing or withdrawing consent means for the participant’s supports.

Photographs, video and audio recordings

Before any photograph, video or audio recording of a participant is made, we explain its purpose, intended use, who will have access, and how it will be stored and retained, and we record the participant’s specific agreement. A participant can withdraw that agreement for future recordings or future use at any time, subject to legal retention requirements for material already lawfully held. Workers must not make recordings of participants on personal devices, or publish participant images or recordings on personal or business social media, unless expressly authorised under our procedures.

Keeping information secure

  • Records are stored securely - locked storage for paper, password protection and access controls for digital files.
  • Only workers who need the information to do their job can access it.
  • Devices are kept secure and information is not left where others can see it.
  • We do not discuss participants in public or on personal social media.

Fill in: Write here, at a general level, how you actually store personal information securely (for example: records held in a secure client-management system behind individual logins, and paper records in locked storage). Do not publish exact addresses, cabinet locations, device details, passwords or security configurations in this policy - keep those specifics in your internal records.

Third-party and cloud service providers

Where [your business or your full name] uses third-party software, cloud storage or other service providers to hold or process personal information on our behalf, we take reasonable steps to ensure they protect the information to a standard consistent with the Australian Privacy Principles. Before using a provider we check that they apply appropriate security controls (such as encryption, access controls and breach notification), and we only share the information the provider needs to perform the service. We remain accountable for personal information handled on our behalf.

Fill in: Write here the main third-party systems you use that hold participant or worker information (for example: your client-management system, accounting software, email and cloud storage), and confirm each one stores data securely.

Sending information overseas

Some software, cloud services or subcontractors [your business or your full name] uses may store or process information outside Australia, or may allow access by personnel located overseas. Overseas hosting is not automatically an overseas disclosure: we consider whether each arrangement involves disclosing personal information to an overseas recipient - a separate person or organisation outside Australia - for the purposes of APP 8. Before making a disclosure covered by APP 8, we take reasonable steps to ensure the overseas recipient does not breach the Australian Privacy Principles, unless an APP 8 exception applies. Where practicable, the countries where likely overseas recipients are located are: [list the countries, or state that no personal information is currently disclosed overseas].

Fill in: Check each provider’s hosting locations, support-access arrangements, subcontractors and privacy terms. Note that Australian hosting alone does not establish that there is no overseas disclosure - overseas support staff, parent companies or subcontractors may still have access. If nothing you use involves an overseas recipient, say so in the paragraph above and the register below stays empty.

Overseas disclosure register (APP 8)

Where [your business or your full name] discloses personal information to an overseas recipient, we record the due-diligence steps we took in the register below. We complete a row for each arrangement that involves an overseas recipient.

Provider / systemType of dataRecipient countryContract / privacy terms reviewedBreach-notice obligationSecurity (encryption / MFA)

Access and correction

Participants can ask to see the information we hold about them (APP 12) and ask us to correct anything that is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13). We respond within a reasonable period after the request is made. We do not charge a fee for making a request. If giving access involves a lawful charge (for example the cost of supplying copies), we explain that charge first and the charge is not excessive.

As our internal target, [your business or your full name] acknowledges an access or correction request within 2 business days and responds to it within 30 calendar days, unless the matter is complex - in which case we tell the person the reason for the delay and the expected timeframe.

We refuse access only where APP 12 permits. If we refuse access, or cannot give it in the way the person asked, we give written reasons, explain how they can complain, and consider whether access can be given in another way (for example through an agreed intermediary). If we refuse a correction request, we give written reasons and explain how to complain, and - on request - we take reasonable steps to attach the person’s statement that the information is inaccurate, out of date, incomplete, irrelevant or misleading to the relevant record. If we corrected information that was previously given to another APP entity, we take reasonable steps to tell that entity when the person asks, unless doing so would be impracticable or unlawful.

Accessible formats

We take reasonable steps to provide and explain privacy information in a language, mode or format the participant is likely to understand. Depending on the person’s needs, this may include Easy Read, large print, an interpreter, translated information, assistive communication, or talking the policy through with the participant and a support person of their choosing.

Worker, applicant and contractor information

This policy primarily explains how we handle participant, representative and other client information. We also hold information about workers, job applicants, contractors and volunteers. Some records directly related to a current or former employment relationship may fall within the Privacy Act’s employee-records exemption; records about applicants, contractors and volunteers generally do not, and we handle them consistently with the Australian Privacy Principles.

Keeping and destroying records

We retain each category of record for the period set out in our Records and Information Management Policy, taking account of applicable NDIS, health-records, employment, taxation and other legal requirements. When personal information is no longer needed for a permitted purpose and no law or court or tribunal order requires it to be kept, we securely destroy it or de-identify it.

Fill in: Make sure your Records and Information Management Policy states the actual retention period for each record category (participant records, incidents, complaints, financial, employment). Do not leave "as long as the law requires" as the only operational rule.

Data breaches

If personal information is subject to unauthorised access or disclosure, or is lost in circumstances likely to lead to unauthorised access or disclosure, we act promptly to contain the incident and assess the risk. Where we have reasonable grounds to suspect an eligible data breach - one where a reasonable person would conclude that serious harm to one or more individuals is likely, and remedial action has not removed that likelihood - we carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days. We do not treat 30 days as a waiting period. Once we have reasonable grounds to believe an eligible data breach has occurred, we prepare and give the required statement to the Office of the Australian Information Commissioner (OAIC) and notify affected individuals in accordance with the Notifiable Data Breaches scheme as soon as practicable. Our full process is set out in the [your business or your full name] Data Breach Response Plan.

Privacy complaints and questions

A person can make a privacy complaint, or ask a privacy question, by contacting [your name]: [your email], [your phone]. We acknowledge a privacy complaint within 5 business days, investigate it fairly, and aim to give a written response within 30 calendar days. If more time is needed, we explain the reason and the expected timeframe.

If the person is not satisfied with our response, or we have not responded within a reasonable period, they can complain to the Office of the Australian Information Commissioner (oaic.gov.au) about a matter covered by the Privacy Act. Concerns about the quality or safety of NDIS supports, or about compliance with the NDIS Code of Conduct, can also be raised with the NDIS Commission.

Fill in: Confirm [your name] is the right person to handle privacy complaints, and name a backup contact in case they are away. State where you record each complaint, your investigation and your response (for example: in your complaints register).

This template is general information to help you get started, not legal advice. Whether and how the Privacy Act applies depends on your services and the information you hold - tailor every prompt to your business, and obtain advice if you are unsure.

How to tailor it (and what an auditor actually checks)

The template gets you the structure and the legal framing. The value - and the audit evidence - comes from making it true:

Frequently asked questions

Do I need a privacy policy to become a registered NDIS provider?

It depends on your audit pathway. Certification audits assess the Core Module, which includes the Privacy and Dignity outcome. Verification audits assess the separate Verification Module (human resource management, risk management, complaints management and incident management), which does not contain that outcome - though your auditor may still ask about privacy where it is relevant to your legal obligations or actual operations. Either way, a privacy policy is generally required under the Privacy Act itself where the Act applies to you.

My turnover is under $3 million. Does the Privacy Act really apply to me?

In many cases, yes. The small-business exemption does not apply where a business provides a health service to an individual and holds health information (other than only in an employee record), and the definition of a health service is broad enough to include many activities delivered while caring for a person with disability. It does depend on the services you actually provide and the information you hold, not your NDIS status alone. If you provide health-related disability supports and hold participant health information, the prudent position is to comply with the Australian Privacy Principles - and to obtain advice if your services are limited and you are unsure.

What is the difference between a privacy policy and a consent form?

The privacy policy is your standing public commitment - how your business handles personal information generally. Consent is the individual participant’s agreement to how their information will be collected, used and shared, and it must be voluntary, informed, current and specific. A signed consent form is useful evidence of that agreement, but consent can also be given verbally or in other clearly indicated ways - what matters is that you keep reliable evidence of it.

Is this template enough to pass an audit?

No. It is a draft policy only. Whether this policy is relevant to your registration audit depends on your audit pathway and registration groups, and an auditor will assess the applicable standards and evidence of your actual practice. Tailoring the policy, keeping appropriate evidence of consent or agreement, training workers and maintaining records may support compliance, but cannot guarantee registration, conformity or any particular audit result.

Does an unregistered provider need this?

The audit requirement only arises if you register, but the NDIS Code of Conduct applies to registered and unregistered providers alike, and the Privacy Act will apply to many unregistered providers too. Plan managers, support coordinators and participants also increasingly ask unregistered providers for a privacy policy before engaging them.

Need the rest of the documents?

This privacy policy is one of the 64 editable Word documents in the Bluetail registration pack, pre-filled with your business name and logo. The pack is designed to support common registration and audit-preparation tasks for small providers - the documents and evidence you actually need will depend on your registration groups, audit pathway, business structure and services, and the pack does not guarantee registration, audit conformity or legal compliance. Consultant pricing for an equivalent document set varies considerably, commonly running into the thousands. Preview every page free, then unlock all 64 for $50 once.

See the $50 pack

This page is general information, not legal advice. Bluetail is not affiliated with the NDIS Commission or the NDIA. For advice on your obligations under the Privacy Act or any State or Territory health privacy laws, speak to a qualified professional.