Our commitment to your privacy

Camden Care respects your privacy and is committed to protecting the personal and sensitive information entrusted to us.

We handle personal information in accordance with applicable Australian privacy legislation, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), together with applicable NDIS requirements and other privacy or health-record legislation that applies to our services.

As an NDIS provider, we recognise that participants may provide us with sensitive information about their disability, health, personal circumstances and support needs.

We take reasonable steps to protect this information and only collect, use or disclose it where required to provide services, operate our organisation, meet legal obligations or where otherwise authorised by law.

Information we may collect

Depending on your relationship with us, we may collect information including:

  • your name, date of birth and contact details

  • address and emergency contact information

  • NDIS number and NDIS plan information

  • information about your disability and support requirements

  • health and medical information relevant to your supports

  • communication and accessibility requirements

  • cultural or language information where relevant to your support

  • information about your goals, preferences and circumstances

  • service agreements and consent records

  • support notes and service records

  • incident, complaint or risk-management information

  • information about guardians, nominees, family members or authorised representatives

  • funding and billing information

  • information supplied by Support Coordinators, health professionals, government agencies or other providers where authorised

  • communications between you and our organisation

  • information provided through our website, referral forms or enquiry forms.

We will only collect information that is reasonably necessary for our functions and activities or where collection is required or authorised by law.

Sensitive and health information

Some information we handle is considered sensitive information, including health and disability information.

We take additional care when handling sensitive information.

Where required, we obtain consent before collecting sensitive information unless collection is otherwise permitted or required by law.

How we collect information

We may collect information:

  • directly from you

  • from your nominee, guardian or authorised representative

  • from a family member or support person with appropriate authority

  • from another provider or Support Coordinator

  • from health or allied health professionals

  • from the NDIA or another government body where authorised

  • through referral forms

  • through our website

  • through telephone, email or written communications

  • during assessments or the delivery of supports.

Where practicable, we collect personal information directly from you.

Why we collect personal information

We may collect and use information to:

  • assess whether we can provide appropriate services

  • establish and manage your supports

  • develop service agreements and support arrangements

  • deliver NDIS supports and services

  • communicate with you and people you have authorised

  • coordinate services with other providers or professionals

  • respond to changes in your needs or circumstances

  • manage participant safety and risks

  • respond to incidents

  • investigate complaints and feedback

  • maintain required records

  • process invoices and NDIS claims

  • manage our workforce and business operations

  • comply with NDIS requirements

  • comply with legal, regulatory, insurance and reporting obligations

  • improve the quality and safety of our services.

We will not use your information for an unrelated purpose unless you consent or the use is otherwise permitted by law.

Disclosure of information

We may disclose relevant personal information to another person or organisation where this is necessary and authorised.

This may include:

  • the NDIA

  • the NDIS Quality and Safeguards Commission

  • plan managers

  • health and allied health professionals

  • Support Coordinators

  • other NDIS providers

  • emergency services

  • guardians, nominees or authorised representatives

  • government or regulatory authorities

  • professional advisers, insurers or auditors

  • technology or records-management service providers.

We only disclose information reasonably necessary for the relevant purpose.

Information may also be disclosed where required or authorised by law, including where necessary to respond to serious risks to health or safety.

Choice and consent

Where appropriate, we explain:

  • what information we need

  • why we need it

  • how it may be used

  • who it may be shared with.

Participants may withdraw consent to particular uses or disclosures where legally permitted.

Withdrawal of consent may affect our ability to provide a particular service where that information is necessary to provide the support safely or comply with our obligations.

Storage and security

We take reasonable steps to protect personal information from:

  • misuse

  • interference

  • loss

  • unauthorised access

  • unauthorised modification

  • unauthorised disclosure.

Security measures may include access controls, passwords, secure electronic systems, staff confidentiality requirements, secure document storage and limitations on who can access participant records.

Access to information is restricted to workers and other persons who require that information to perform their role.

9. Retention and disposal

Personal information is retained for as long as required to provide services and satisfy applicable NDIS, legal, insurance, employment, financial and record-keeping obligations.

When personal information is no longer required to be retained, we take reasonable steps to securely destroy or de-identify it where permitted by law.

10. Website information, cookies and analytics

When you visit our website, some technical information may be collected automatically, including information such as:

  • IP address

  • browser type

  • device type

  • pages visited

  • dates and times of access

  • referring website.

Our website may use cookies and analytics technologies to understand website usage and improve our services.

Third-party platforms used on our website may process information in accordance with their own privacy policies.

Overseas storage or disclosure

Some technology, cloud-storage, communications or software providers may store or process information outside Australia.

Where personal information is disclosed overseas, we take reasonable steps required by applicable privacy law to protect that information.

Our current overseas disclosure or storage arrangements include:

We store email and documentation that is located in Switzerland. We use Shiftcare who uses Amazon Web Services to host its data. Shiftcare states that your data may be stored in the following regions. Amazon services in Australia, the UK and the USA.

Accessing your personal information

You may request access to personal information we hold about you.

Contact us using the details below.

We may need to verify your identity before releasing information.

In some circumstances, access may be limited or refused where permitted by law. If this occurs, we will explain the reason where we are legally able to do so.

Correcting your personal information

We take reasonable steps to ensure personal information is accurate, complete and current.

If you believe information we hold about you is incorrect or incomplete, contact us and request that it be corrected.

Privacy complaints

If you believe we have mishandled your personal information, contact our Privacy Officer.

Please contact us with the paperwork provided to you on sign up.

Please provide enough information for us to understand and investigate your concern.

We will review your complaint and respond within a reasonable period.

If you are not satisfied with our response, you may be able to contact the Office of the Australian Information Commissioner (OAIC).

OAIC enquiries: 1300 363 992

You may also contact the NDIS Quality and Safeguards Commission where your concern relates to the provision, quality or safety of NDIS supports.

Data breaches

If we become aware of a data breach involving personal information, we will assess the incident and take appropriate steps to contain and respond to it.

Where required under the Privacy Act's Notifiable Data Breaches scheme, affected individuals and the Office of the Australian Information Commissioner will be notified.

Changes to this policy

We may update this Privacy Policy when our services, technology, legal obligations or information-handling practices change.

The current version will be published on our website with the date of the latest update.

Last updated 15/09/2026