Privacy Policy
Introduction
This policy ensures we protect and handle personal information in accordance with the Privacy Act 1988 (Cth) including the Australian Privacy Principles, and all NDIS requirements.
Blue Wing acknowledges and respects every person’s right to privacy, dignity, and confidentiality while recognising that personal information is required to be collected, maintained, and administered in order to provide a safe working environment and a high standard of quality supports.
The information we collect is used to provide services to clients in a safe and healthy environment with individual requirements, to meet duty of care obligations, to initiate appropriate referrals, and to conduct business activities to support those services.
The Australian Privacy Principles apply to all people Blue Wing holds personal information about.
Applicability
When
Applies to all personal information and sensitive personal information including the personal information of employees and clients.
Applies to all Blue Wing confidential information—that is, any information not publicly available.
Who
All Blue Wing personnel—including management, directors, full-time workers, part-time workers, casual workers, and contractors—have a responsibility to ensure personal information is handled in accordance with this policy and that any personal and/or sensitive information accessed in the course of their duties are bound by their commitment to confidentiality.
Privacy and Confidentiality Guidelines
To support the privacy and confidentiality of individuals:
- Blue Wing is committed to complying with the privacy requirements of the Privacy Act, the Australian Privacy Principles, and the Privacy Amendment (Notifiable Data Breaches) as required by organisations providing disability services.
- We are fully committed to complying with the consent requirements of the NDIS Quality and Safeguarding Framework and relevant state requirements.
- We provide all individuals with access to information about the privacy of their personal information.
- Each individual has the right to opt out of consenting to and providing their personal details if they wish.
- Individuals have the right to request access to their personal records by requesting this with their contact person.
- Where we are required to report to government funding bodies, information provided is non-identifiable and related to services and support hours provided, age, disability, language, and nationality.
- Personal information will only be used by us and will not be shared outside the organisation without your permission unless required by law (e.g., reporting assault, abuse, neglect, or where a court order is issued).
- Images or video footage of clients will not be used without their consent.
- Clients have the option of being involved in external NDIS audits if they wish.
Types of Information Collected
Blue Wing will collect personal information that is necessary for us to provide the supports and services requested by the client; this may include:
- Name
- Address
- Phone number
- Date of birth/age
- Health-related information
How Information Is Collected
Blue Wing will collect personal information directly from the person unless it is unreasonable or impracticable to do so.
With the person's consent, personal information may be collected from a third party, such as other individuals or organisations, health professionals, and the government.
Reasons for Collecting Personal Information
Blue Wing collects personal information to:
- Provide services and supports to clients
- Enable claims and payments for services
- Ensure client and employee records are up-to-date
- Support our administrative and business functions
- Support reporting obligations
- Process and manage complaints
- Support communications and marketing activities
- Comply with any legal requirements
Security of Information
Blue Wing takes steps to protect personal information against loss, unauthorized access, use, modification, or disclosure and against any other misuse.
To keep information secure:
- We have put in place appropriate technical and organisational measures to help protect personal information as required by law and in accordance with good industry practice.
- We ensure personal information is accessible to the client.
- Permission to access personal and sensitive information for clients and staff is limited to only those staff who require access to undertake their role.
- We ensure security for personal information includes password protection for IT systems, locked filing cabinets, and physical access restrictions with only authorised personnel permitted access.
- All Blue Wing data is stored in Australia.
- We ensure personal information no longer required is securely destroyed or de-identified.
Disclosure of Personal Information
By providing Blue Wing with your personal information, you give consent to us disclosing your information when permitted by law to do so.
As part of the client onboarding process with Blue Wing, we ask for consent to exchange and obtain information with third-party bodies such as:
- Any organisation or provider that will provide support or care in connection with the provision of a service to the client
- Hospitals and other healthcare professionals providing the client with treatment
- Enquiring on the client's behalf regarding previous medical diagnosis/personal information as per current legislation
- Receiving copies of correspondence
- Attending appointments with the client or on their behalf
- Suppliers of any personal equipment
Consent to disclose information can be revoked at any time by notifying Blue Wing in writing.
Blue Wing may disclose de-identified data to meet regulatory obligations for other purposes, such as statutory reporting or quality assurance.
Cross-Border Disclosure of Personal Information
Blue Wing shares some information with staff in their offices in India and the Philippines. This is considered an internal movement of information as they are part of the Blue Wing entity and not a disclosure to an overseas recipient as referred to in Australian Privacy Principle (APP) 8.
Data Breaches
As part of our information security responsibilities:
- We will take reasonable steps to reduce the likelihood of a data breach occurring, including storing personal information securely and making it accessible only by relevant workers.
- If we know or suspect your personal information has been accessed by unauthorized parties, and we think this could cause you harm, we will take reasonable steps to reduce the chance of harm and advise you of the breach, and if necessary, notify the Office of the Australian Information Commissioner.
Refer to our Data Breaches Policy.
Breach of Privacy and Confidentiality
A breach of privacy and confidentiality is an incident:
- Follow the internal incident management process to resolve.
- May require an investigation.
- An intentional breach will result in disciplinary action up to and including termination of employment.
Access to and Correction of Personal Information
Blue Wing takes reasonable steps to ensure the quality of the information we hold about clients and staff is accurate, up-to-date, complete, and relevant.
Clients who wish to access or correct their personal information can do so. This request should be made in writing, detailing what information is being requested. All such requests will be reviewed by the General Manager of Blue Wing Care.
Direct Marketing
Blue Wing may use personal information to:
- Provide clients and families with information about our services
- Request feedback through a brief survey
- Alert clients of any sudden changes to service provision, such as site closures due to a COVID outbreak
By providing Blue Wing with personal information, clients consent to us using this information to contact them for these purposes, including by mail, email, SMS, and telephone.
Blue Wing does not provide personal information to other organisations for the purposes of direct marketing.