WEK services logo with a hand holding a heart

Privacy and Confidentiality Policy

Privacy and Confidentiality Policy for WEK Services

At Weks Services, we are dedicated to respecting and protecting the privacy of all individuals associated with our organisation, including participants, providers, employees, contractors, and community partners.

Privacy and Confidentiality Guidelines

Purpose of Information Collection: The information we collect is used to provide services to participants in a safe and healthy environment, tailored to their individual needs. It helps us fulfil our duty of care obligations, initiate appropriate referrals, and conduct business activities that support these services.


Compliance: We are committed to complying with the privacy requirements of the Privacy Act, the Australian Privacy Principles, and the Privacy Amendment (Notifiable Data Breaches) as required by organisations providing disability services.


Consent Requirements: We fully adhere to the consent requirements of the NDIS Quality and Safeguarding Framework and relevant state or territory regulations.


Access to Information:We ensure all individuals have access to information about the privacy of their personal data.


Right to Opt-Out: Individuals have the right to opt out of consenting to and providing their personal details if they choose.


Access to Personal Records: Individuals can request access to their personal records through their contact person/coordinator.


Reporting to Funding Bodies: When reporting to government funding bodies, the information provided is non-identifiable and relates only to services and support hours provided, age, disability, language, and nationality.


Use of Personal Information: Personal information will only be used by our organisation and will not be shared without your permission unless required by law (e.g., reporting assault, abuse, neglect, or compliance with a court order).


Use of Images or Video Footage: Images or video footage of participants will not be used without their consent.


External Audits: Participants have the option to be involved in external NDIS audits if they wish.


Security of Information Protection Measures:
We take all reasonable steps to protect the personal information we hold against misuse, interference, loss, unauthorised access, modification, and disclosure.


Access Control: Personal information is accessible only to the participant and relevant workers. Security measures include password protection for IT systems, locked filing cabinets, and physical access restrictions, allowing access only to authorised personnel.


Disposal of Information: Personal information that is no longer required is securely destroyed or de-identified.


Data Breaches

Prevention: We take reasonable steps to reduce the likelihood of a data breach by storing personal information securely and making it accessible only to relevant workers.


Response to Breaches: If we know or suspect that your personal information has been accessed by unauthorised parties, and we believe this could cause you harm, we will take reasonable steps to mitigate the harm and advise you of the breach. If necessary, we will also inform the Office of the Australian Information Commissioner.



Breach of Privacy and Confidentiality

Incident Management: A breach of privacy and confidentiality is considered an incident and will be managed through our internal incident resolution process.


Investigation: Breaches may require an investigation.



Disciplinary Action: Intentional breaches of privacy and confidentiality will result in disciplinary action, up to and including termination of employment.


Definitions

Term: Data Breach

A data breach is a type of security incident where personal, sensitive, or confidential information is deliberately or mistakenly copied, sent, viewed, stolen, or used by an unauthorised person or parties. Data breaches that put people at risk of serious harm are reportable to the Office of the Australian Information Commissioner.


Term: Personal Information

Personal information includes (regardless of its accuracy):

  • Name
  • Address
  • Phone number
  • Email address
  • Date of birth
  • Recorded opinions or notes about someone
  • Any other information that could be used to identify someone.


Term: Sensitive Personal Information

Sensitive personal information can include personal information that is normally private, such as:

  • Health information
  • Ethnicity
  • Political opinions
  • Membership of a political association, professional or trade association, or trade union
  • Religious beliefs or affiliations
  • Philosophical beliefs
  • Sexuality
  • Criminal record
  • Biometric information (such as fingerprints).


Share by: