INRS Support Services Privacy Policy
INRS Support Services Privacy Policy
Overview
The information we record and store should only allow us to deliver our NDIS registered services, that is: Support Coordination, Specialist Behaviour Support and Therapy (as per your position description/ role). Information about participants will not be shared, including overseas or across borders, except with consent or as otherwise required or permitted by law (see 'Disclosing information' below)
For up to date information on applicable Acts, please consult with the Quality Systems Manager, who will provide relevant information and resources.
This Privacy Policy is for anyone who is an INRSSS Participant, staff member, volunteer. This policy covers all personal information we gather and hold about participants, staff and volunteers, that is, information, or an opinion about an individual whose identity is apparent, or can be reasonably ascertained, from that information or opinion. This includes information we have collected from people through our office, over the phone and over the internet.
Collecting information
We will collect personal information by lawful and fair means, and not in a way that is unreasonably intrusive and let the individual know where and how to contact our organisation. We will only collect information that is necessary for us to be able to do our job. This information must also be accurate and correct.
We will advise individuals of the purpose for which their personal information is collected.
If we collect sensitive information, we will treat it with the utmost security and confidentiality. We will ensure that it is not collected for any purposes other than those for which we have obtained the individual’s consent, unless the law requires otherwise, or other exceptional circumstances apply as detailed under the relevant Act.
Where an individual chooses not to provide requested information, we will advise that individual of what consequences this non-disclosure may have. For example, withholding certain information may limit our ability to provide relevant information or services to individuals.
Disclosing information
We will only disclose personal information in accordance with the appropriate Act.
This means that personal information may be disclosed:
· For the purposes for which we have advised that we are collecting it, and for related purposes that the individual would reasonably expect,
· Where we have the consent of the individual to do so,
· As required by law, or
· Under other circumstances where permitted under the Act (e.g.: if there is a warrant from the courts).
In the course of our business activities, we may need to disclose some of your personal information to relevant staff.
Please ensure that you refer to the disclosure statement (and related documents) in these instances.
Unauthorised disclosure or access
INRSSS is committed to protecting the privacy of individuals, we will view unauthorised disclosure of, or access to, personal information by our employees or contractors, as a serious breach of this policy. Appropriate action (which may include disciplinary or legal action) will be taken in such cases.
Access to personal information
Individuals will be able to access their personal information upon request. However, INRSSS may occasionally need to deny access to information in accordance with the exemptions contained in the Act (e.g.: if we believe that accessing the information would reasonably cause undue harm to the person described). Where a request for access is made by someone other than the individual themselves (e.g. a carer, family member, or guardian), INRSSS will take reasonable steps to verify that person's identity and authority before releasing any information.
Security
Our goal is to protect the personal information collected by the INRSSS and its associations. Personal information will be managed confidentially and securely and destroyed appropriately when no longer required. As a minimum, records are retained for 7 years from the date of creation or the date of last service. Records relating to child participants are retained until the child turns 25. Staff personnel records are retained for 7 years after the end of employment. Detailed retention schedules for specific record types are maintained by the Quality Systems Manager.
INRSSS management will monitor and implement appropriate technical advances or management processes, to safeguard personal information.
In the event of a suspected or actual data breach involving personal information, INRSSS will respond in accordance with our Data Breach Response Policy, which includes assessment and, where required, notification to affected individuals and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme.
Data Quality
We will take all reasonable steps to ensure that the data we collect, use or disclose is accurate, complete and up to date, and has been obtained directly from individuals or other reputable sources.
If inaccurate information is discovered, it is updated and corrected promptly, and Management is to be notified if it pertains to information used for invoicing.
Privacy Inquiries
Privacy related enquiries or concerns can be directed to the INRSSS administration email address at: admin@inrssupportservices.com.au
This is separate from, and may be handled alongside, our general Complaints and Feedback Management Policy.
If you have a concern or complaint about how we have handled your personal information, please contact us using the details above. We will investigate and respond to your complaint within a reasonable timeframe. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or 1300 363 992.