Privacy Policy and Procedures

  • Version: 2.0 (replaces the Privacy policy of 12 August 2008)

  • Approved by: Board of ACTION for People with Disability Inc

  • Date approved: June 2026

  • Next review: June 2029

  • Responsible officer: Executive Officer (Privacy Officer)

1. Purpose

This policy sets out how ACTION collects, stores, uses, discloses and disposes of personal information, and how people can access their information or raise a concern. It protects the privacy of the people we support and everyone else whose information ACTION holds.

Privacy is a human right. Article 22 of the United Nations Convention on the Rights of Persons with Disabilities (CRPD) recognises the right of people with disability to privacy on an equal basis with others, and Article 12 recognises their right to make their own decisions with support where needed. This policy is written to uphold both.

2. Scope

This policy applies to personal information about:

  • people we support, including children and young people, and their families, carers, guardians and nominated supporters

  • members, stakeholders and people who contact ACTION

  • staff, Board members, placement students and volunteers

It applies to everyone who works or volunteers with ACTION, including Board members, staff, placement students, volunteers and contractors, and to information in any form: paper, electronic, audio, photographs and video.

3. Legal and contractual framework

ACTION handles personal information in line with:

  • Privacy and Personal Information Protection Act 1998 (NSW) (PPIP Act). ACTION'S NSW Government funding agreements require ACTION to comply with the Information Protection Principles as if it were a NSW public sector agency.

  • Health Records and Information Privacy Act 2002 (NSW) (HRIP Act), and its Health Privacy Principles, for health and disability-related information.

  • Privacy Act 1988 (Cth). ACTION adopts the Australian Privacy Principles as good practice, and will comply with them in full where they apply to ACTION by law or contract.

  • Contractual obligations under ACTION's Disability Advocacy Futures Program (DAFP) agreement with the Department of Communities and Justice (DCJ), its icare Lifetime Care and Support agreement, and any other funding agreement.

  • Children and Young Persons (Care and Protection) Act 1998 (NSW), including the reporting of risk of significant harm and information exchange under Chapter 16A.

Where a funding agreement sets a higher standard than this policy, the higher standard applies.

4. Definitions

TermDefinitionPersonal information

Information or an opinion about an identified person, or a person who is reasonably identifiable, whether true or not and whether recorded or not.

Health information

Personal information about a person's physical or mental health or disability, the health services provided to them, or their wishes about future health services.

Sensitive information

Information about a person's racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sexual orientation or activities, criminal record, and health, genetic or biometric information.

Consent

Voluntary, informed, current and specific agreement, given by a person with the capacity to give it (with support if needed), which can be withdrawn at any time.

Supported decision-making

Assistance a person chooses to receive to make their own decision, such as information in accessible formats, time, or help from a trusted supporter. The decision remains theirs.

Data breach

Unauthorised access to, disclosure of, or loss of personal information held by ACTION.

5. Policy principles

5.1 Collection

  • Lawful and necessary. ACTION collects only information that is directly related to its advocacy and organisational functions and that it needs to do that work.

  • Direct. Information is collected from the person themselves wherever possible. Information is collected from others (such as schools, services, family members or guardians) only with the person's consent, or where the law allows.

  • Open. At intake, each person is told in plain language what information is collected, why, who will see it, how it is stored, and how they can access it or complain.

  • Relevant and not intrusive. Information is accurate, current and not excessive, and advocates do not ask about personal matters that are not relevant to the issue.

5.2 Consent and decision-making

  • Adults are presumed able to make their own decisions about their information. ACTION provides support for decision-making where a person wants or needs it.

  • A guardian or other substitute decision-maker gives consent only where a formal appointment (such as a guardianship order or enduring guardianship) covers that decision. The person's will and preferences are still sought and recorded.

  • For children and young people, a parent or legal guardian usually gives consent. The young person is still involved, their views are sought and recorded, and their views carry more weight as their maturity and understanding grow.

  • Consent is recorded in Salesforce, including what it covers and any limits. People can withdraw consent at any time.

5.3 Storage and security

  • Electronic records are kept in Salesforce and ACTION's approved systems, with access limited to staff who need it for their role.

  • Paper records are kept in locked storage at the office and are not left unattended. Files taken off site are kept to a minimum and kept secure.

  • Devices are password-protected, and personal information is not stored on personal devices or personal email or cloud accounts.

  • Personal information about people we support must not be entered into artificial intelligence (AI) tools or other third-party applications unless the Executive Officer has approved the tool for that purpose.

  • Care is taken when emailing, printing or discussing personal information, including checking recipients before sending and not discussing cases where others can overhear.

5.4 Retention and disposal

  • ACTION keeps records for seven years after a matter is closed (or after a person's last contact with ACTION), unless a funding agreement or the law requires a longer period.

  • After that period, records are securely destroyed: paper records are securely shredded, and electronic records are permanently deleted from Salesforce and any other system where they are held.

  • Records are not destroyed while a complaint, legal proceeding, audit or access request involving them is underway.

  • The Executive Officer keeps a register of records destroyed (the category of record, date range and date of destruction, without personal details).

5.5 Access and correction

  • People can ask to see the information ACTION holds about them, and ask for it to be corrected, updated or added to. Access is free.

  • ACTION will provide access within a reasonable time and in an accessible format, and will explain its reasons in writing if access is refused (for example, where giving access would put someone's safety at risk or would disclose another person's private information).

  • Where ACTION does not agree that information should be changed, the person can ask for a statement of their view to be attached to the record.

5.6 Use

  • Information is checked for accuracy before it is used.

  • Information is used only for the purpose it was collected for, or a directly related purpose the person would reasonably expect, unless the person consents or an exception in section 5.7 applies.

5.7 Disclosure

ACTION discloses personal information only with the person's consent (or the consent of their authorised decision-maker), except where:

  • ACTION reasonably believes disclosure is necessary to prevent or lessen a serious and imminent threat to the life, health or safety of the person or another person

  • disclosure is required to report a child or young person at risk of significant harm, or is permitted under Chapter 16A of the Children and Young Persons (Care and Protection) Act 1998

  • disclosure is required or authorised by law, including a subpoena, summons or court or tribunal order

Sensitive information is never disclosed without consent, except in the circumstances above.

Any disclosure without consent must be approved by the Executive Officer where practicable, and is recorded on the person's file, including what was disclosed, to whom, when and why. The person is told unless doing so would increase a risk to anyone's safety.

5.8 Stories, photographs and reporting

  • Case stories, quotes, photographs and video are used in reports, grant applications, submissions, media or promotion only with separate, specific written consent, which states how they will be used and can be withdrawn.

  • Information used in systemic advocacy and case studies is de-identified unless the person has consented to being identified. Care is taken that small details do not make a person identifiable in a small community.

  • Data reported to funders is de-identified unless a funding agreement requires otherwise and people have been told this at intake.

6. Responsibilities

Role Responsibility Board

Approves this policy, ensures ACTION has the resources to comply with it, and receives reports of privacy complaints and data breaches.

Executive Officer (Privacy Officer)

Leads privacy practice at ACTION; handles access requests, privacy complaints, internal reviews and data breaches; approves disclosures without consent and new technology tools; ensures staff training; keeps the destruction register.

Staff

Follow this policy in all advocacy, membership, research and consultation work; complete privacy training; report any privacy concern or suspected breach to the Executive Officer immediately.

Placement students and volunteers

Sign a confidentiality agreement before starting, follow this policy under the direction of their supervisor, and report concerns to their supervisor or the Executive Officer.

7. Procedures

7.1 Privacy notice at intake

  1. At first contact, the advocate explains ACTION's privacy practices using the privacy notice and offering support to understand it.

  2. The advocate seeks consent for collecting information and for any contact with third parties, and records the consent and its scope in Salesforce.

  3. Where a guardian or parent gives consent, the advocate records the basis of their authority and the person's own views, where possible.

7.2 Requests for access or correction

  1. A request can be made verbally or in writing to any staff member and is passed to the Executive Officer.

  2. The Executive Officer confirms the person's identity (or the requester's authority) and acknowledges the request within 5 working days.

  3. ACTION responds within 20 working days, providing access in the format the person needs, or explaining in writing why access is refused or limited.

  4. Corrections are made promptly, or the person's statement is attached to the record, and the outcome is confirmed in writing.

7.3 Privacy complaints and internal review

  1. Anyone can raise a privacy concern with any staff member, verbally or in writing. If the concern is about the Executive Officer, it goes to the Chairperson of the Board.

  2. The complaint is acknowledged within 5 working days, and the person is offered support (including from an advocate not involved in their matter).

  3. The Executive Officer (or Chairperson) reviews what happened against this policy and the relevant privacy principles and completes the review within 60 days.

  4. The person receives a written outcome explaining the findings, any action taken, and their right to take the matter further.

  5. If the person is not satisfied, they can contact the Information and Privacy Commission NSW (1800 472 679, www.ipc.nsw.gov.au) or the relevant funding body.

7.4 Data breach response

Anyone who suspects a data breach (for example, an email sent to the wrong person, a lost file or device, or unauthorised access to Salesforce) must tell the Executive Officer immediately. The Executive Officer will:

  1. Contain: take immediate steps to stop the breach and limit harm (such as recalling an email, changing passwords or disabling access).

  2. Assess: work out what information was involved, whose, and whether the breach is likely to result in serious harm to anyone.

  3. Notify: tell affected people where there is a risk of serious harm, with advice on steps they can take; notify DCJ, icare or other funders as their agreements require and notify any regulator where required by law.

  4. Record: record the breach, the response and the outcome in the breach register.

  5. Review: identify the cause and change practices to prevent it happening again, and report the breach to the Board.

8. Training and review

  • All staff, placement students and volunteers receive privacy training at induction, with refreshers at least every two years.

  • This policy is reviewed every three years, or sooner if the law, ACTION's funding agreements or its systems change. Anticipated reforms to the Privacy Act 1988 (Cth) will be monitored and this policy updated if they change ACTION's obligations.