Our commitment to your privacy
Camden Care respects your privacy and is committed to protecting the personal and sensitive information entrusted to us.
We handle personal information in accordance with applicable Australian privacy legislation, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), together with applicable NDIS requirements and other privacy or health-record legislation that applies to our services.
As an NDIS provider, we recognise that participants may provide us with sensitive information about their disability, health, personal circumstances and support needs.
We take reasonable steps to protect this information and only collect, use or disclose it where required to provide services, operate our organisation, meet legal obligations or where otherwise authorised by law.
Information we may collect
Depending on your relationship with us, we may collect information including:
your name, date of birth and contact details
address and emergency contact information
NDIS number and NDIS plan information
information about your disability and support requirements
health and medical information relevant to your supports
communication and accessibility requirements
cultural or language information where relevant to your support
information about your goals, preferences and circumstances
service agreements and consent records
support notes and service records
incident, complaint or risk-management information
information about guardians, nominees, family members or authorised representatives
funding and billing information
information supplied by Support Coordinators, health professionals, government agencies or other providers where authorised
communications between you and our organisation
information provided through our website, referral forms or enquiry forms.
We will only collect information that is reasonably necessary for our functions and activities or where collection is required or authorised by law.
Sensitive and health information
Some information we handle is considered sensitive information, including health and disability information.
We take additional care when handling sensitive information.
Where required, we obtain consent before collecting sensitive information unless collection is otherwise permitted or required by law.
How we collect information
We may collect information:
directly from you
from your nominee, guardian or authorised representative
from a family member or support person with appropriate authority
from another provider or Support Coordinator
from health or allied health professionals
from the NDIA or another government body where authorised
through referral forms
through our website
through telephone, email or written communications
during assessments or the delivery of supports.
Where practicable, we collect personal information directly from you.
Why we collect personal information
We may collect and use information to:
assess whether we can provide appropriate services
establish and manage your supports
develop service agreements and support arrangements
deliver NDIS supports and services
communicate with you and people you have authorised
coordinate services with other providers or professionals
respond to changes in your needs or circumstances
manage participant safety and risks
respond to incidents
investigate complaints and feedback
maintain required records
process invoices and NDIS claims
manage our workforce and business operations
comply with NDIS requirements
comply with legal, regulatory, insurance and reporting obligations
improve the quality and safety of our services.
We will not use your information for an unrelated purpose unless you consent or the use is otherwise permitted by law.
Disclosure of information
We may disclose relevant personal information to another person or organisation where this is necessary and authorised.
This may include:
the NDIA
the NDIS Quality and Safeguards Commission
plan managers
health and allied health professionals
Support Coordinators
other NDIS providers
emergency services
guardians, nominees or authorised representatives
government or regulatory authorities
professional advisers, insurers or auditors
technology or records-management service providers.
We only disclose information reasonably necessary for the relevant purpose.
Information may also be disclosed where required or authorised by law, including where necessary to respond to serious risks to health or safety.
Choice and consent
Where appropriate, we explain:
what information we need
why we need it
how it may be used
who it may be shared with.
Participants may withdraw consent to particular uses or disclosures where legally permitted.
Withdrawal of consent may affect our ability to provide a particular service where that information is necessary to provide the support safely or comply with our obligations.
Storage and security
We take reasonable steps to protect personal information from:
misuse
interference
loss
unauthorised access
unauthorised modification
unauthorised disclosure.
Security measures may include access controls, passwords, secure electronic systems, staff confidentiality requirements, secure document storage and limitations on who can access participant records.
Access to information is restricted to workers and other persons who require that information to perform their role.
9. Retention and disposal
Personal information is retained for as long as required to provide services and satisfy applicable NDIS, legal, insurance, employment, financial and record-keeping obligations.
When personal information is no longer required to be retained, we take reasonable steps to securely destroy or de-identify it where permitted by law.
10. Website information, cookies and analytics
When you visit our website, some technical information may be collected automatically, including information such as:
IP address
browser type
device type
pages visited
dates and times of access
referring website.
Our website may use cookies and analytics technologies to understand website usage and improve our services.
Third-party platforms used on our website may process information in accordance with their own privacy policies.
Overseas storage or disclosure
Some technology, cloud-storage, communications or software providers may store or process information outside Australia.
Where personal information is disclosed overseas, we take reasonable steps required by applicable privacy law to protect that information.
Our current overseas disclosure or storage arrangements include:
We store email and documentation that is located in Switzerland. We use Shiftcare who uses Amazon Web Services to host its data. Shiftcare states that your data may be stored in the following regions. Amazon services in Australia, the UK and the USA.
Accessing your personal information
You may request access to personal information we hold about you.
Contact us using the details below.
We may need to verify your identity before releasing information.
In some circumstances, access may be limited or refused where permitted by law. If this occurs, we will explain the reason where we are legally able to do so.
Correcting your personal information
We take reasonable steps to ensure personal information is accurate, complete and current.
If you believe information we hold about you is incorrect or incomplete, contact us and request that it be corrected.
Privacy complaints
If you believe we have mishandled your personal information, contact our Privacy Officer.
Please contact us with the paperwork provided to you on sign up.
Please provide enough information for us to understand and investigate your concern.
We will review your complaint and respond within a reasonable period.
If you are not satisfied with our response, you may be able to contact the Office of the Australian Information Commissioner (OAIC).
OAIC enquiries: 1300 363 992
You may also contact the NDIS Quality and Safeguards Commission where your concern relates to the provision, quality or safety of NDIS supports.
Data breaches
If we become aware of a data breach involving personal information, we will assess the incident and take appropriate steps to contain and respond to it.
Where required under the Privacy Act's Notifiable Data Breaches scheme, affected individuals and the Office of the Australian Information Commissioner will be notified.
Changes to this policy
We may update this Privacy Policy when our services, technology, legal obligations or information-handling practices change.
The current version will be published on our website with the date of the latest update.
Last updated 15/09/2026