Privacy Policy

Privacy Policy

Home Privacy Policy

What we collect, why we collect it, who sees it, and what you can do about it.

Last updated: 28 August 2026

Compassionate Community Care Pty Ltd looks after some of the most personal information a person can hand over. Your NDIS plan. Your health. What support you need on a hard day, and who to call. This privacy policy explains what we collect, why we collect it, who sees it, and what you can do about it.

We are a registered NDIS provider based in Cairns, Far North Queensland. NDIS Registration 4050097980. ABN 18 609 924 209.

What privacy law applies to us?

Private NDIS providers in Queensland are covered by the Commonwealth Privacy Act 1988 and its 13 Australian Privacy Principles. Queensland's Information Privacy Act 2009 applies only to the state public sector. Providers delivering health services must follow the Privacy Act regardless of annual turnover, so the $3 million small business exemption does not apply.

We deliver community nursing, mental health nursing, exercise physiology and behaviour support. That makes us a health service provider under the Privacy Act, and we are bound by it no matter our size. We say this plainly because plenty of smaller providers assume the exemption covers them. It does not.

Two more sets of rules sit on top:

  • The NDIS Code of Conduct, which requires us to "respect the privacy of people with disability" under section 6(1)(b) of the National Disability Insurance Scheme (Code of Conduct) Rules 2018.
  • The NDIS Practice Standards, where the Privacy and Dignity outcome states that "each participant accesses supports that respect and protect their dignity and right to privacy".

Who does this policy cover?

This policy applies to participants, their families, guardians and nominees, support coordinators and other referrers, our workers and job applicants, and anyone who visits our website or fills in a form on it.

What personal information do we collect?

We collect only what we need to support you properly. Nothing extra.

What we collectExamplesWhy we need it
Identity and contact detailsName, date of birth, address, phone, email, preferred languageTo reach you, confirm who you are, and match you to the right team
NDIS informationNDIS number, plan details, funded supports, plan manager or coordinatorTo deliver and claim for the supports in your plan
Health informationDiagnoses, medications, allergies, mobility needs, mental health history, behaviour support plansTo keep you safe and give our nurses and support workers what they need
Support recordsShift notes, progress notes, incident reports, goals and reviewsTo track how your supports are going and meet our record-keeping duties
Cultural and communication needsAboriginal or Torres Strait Islander identification where you choose to share it, interpreter needs, communication preferencesTo provide culturally safe support and communicate the way you prefer
Financial detailsBank or payment details, invoices, plan manager contactsTo bill correctly and get paid by the right party
Website informationPages visited, form submissions, cookie dataTo keep the site working and see which pages help people

We collect most of this straight from you, or from someone you have authorised, such as a family member, guardian or support coordinator. Sometimes information reaches us from the NDIA, a hospital, a GP or another provider, and that only happens where you have consented or the law allows it.

Do we collect health and sensitive information?

Yes, and we treat it differently.

Compassionate Community Care collects health and disability information because the NDIS supports it delivers cannot be planned safely without it. Under Australian Privacy Principle 3, this counts as sensitive information and needs consent before collection, apart from limited situations such as a serious threat to someone's life, health or safety.

Sensitive information also covers things like your cultural background, religious beliefs and criminal record. You choose what you tell us. We ask for it only where it changes how we support you, and we say why we are asking at the time.

Can you stay anonymous or use a different name?

You can browse our website, ask general questions and give feedback without telling us who you are. Australian Privacy Principle 2 gives you that right.

Anonymity stops working once you become a participant. We cannot deliver supports, claim through the NDIS or keep you safe in an emergency without knowing who you are. We will tell you if we need your real identity and explain why. Our page on how we welcome new participants walks through what happens at that point.

Why do we collect your information?

Six reasons, all of them practical:

  1. To assess whether we are the right provider for you and plan your supports.
  2. To deliver those supports safely, day to day.
  3. To bill your plan manager, the NDIA or you directly.
  4. To meet our duties to the NDIS Quality and Safeguards Commission, including incident reporting and audits.
  5. To train and supervise our workers, using de-identified information wherever we can.
  6. To respond when you contact us, and to improve our services.

We do not sell your information. We do not trade it. We do not use your health information for marketing, ever.

Who do we share your information with?

We share only what is needed, only with people who need it, and only with your consent unless the law requires otherwise.

  • Our own workers, limited to the team supporting you.
  • The NDIA and your plan manager, for plan management and claiming.
  • Your support coordinator or referrer, where you have asked us to keep them updated.
  • Health professionals in your circle of care, such as your GP, allied health team or hospital, with your consent.
  • Family, guardians or nominees you have named.
  • The NDIS Quality and Safeguards Commission, where reportable incident rules apply.
  • Our IT and software providers, who host our systems under contracts that require them to protect your information.
  • Emergency services, where there is a serious threat to someone's life, health or safety.
  • Courts, tribunals and regulators, where the law compels us.

Any other sharing needs your say-so first. You can withdraw consent at any time by contacting us, and we will confirm what that changes.

Is your information sent overseas?

Some of the software we use to run rosters, notes and email may store data on servers outside Australia. Australian Privacy Principle 8 requires us to take reasonable steps to make sure any overseas recipient handles your information under standards equivalent to the Australian Privacy Principles, and we put that obligation into our contracts with suppliers.

Tell us if you want to know exactly which systems hold your records and where. We will give you a straight answer.

How do we keep your information safe?

Practical controls, reviewed as our systems change:

  • Paper records locked away, digital records password protected.
  • Access limited by role, so a support worker sees what they need and no more.
  • Multi-factor authentication on our core systems.
  • Privacy and confidentiality training for every worker, plus signed confidentiality agreements.
  • NDIS worker screening checks before anyone starts.
  • Backups, and a documented process for responding to a suspected breach.

No system is perfectly safe, and we would rather say so than pretend otherwise.

How long do we keep your information?

We keep participant records for at least seven years after our last service to you, in line with our records management policy and our NDIS record-keeping duties. Records about children are held longer where required. Once a record is no longer needed and no legal duty applies, we destroy or de-identify it securely.

What happens if there is a data breach?

We act fast. Where a breach involving your personal information is likely to cause serious harm, the Notifiable Data Breaches scheme requires us to notify you and the Office of the Australian Information Commissioner.

The Privacy Act gives us up to 30 calendar days to assess a suspected breach after we become aware of it. We aim to move much faster, because delay makes harm worse. You will hear from us about what happened, what information was involved, and what to do next.

Can you see and correct your information?

Yes. You can ask for a copy of the personal information we hold about you at any time.

Ask us in writing at info@carecompassion.com.au or by phone on 0435 330 666. We will confirm who you are, then respond within 30 calendar days, which is the timeframe the OAIC treats as reasonable under Australian Privacy Principle 12. There is no charge for making the request. A reasonable cost may apply for photocopying or postage on large record sets, and we will tell you before any cost is incurred.

Something wrong in your file? Tell us and we will fix it. Australian Privacy Principle 13 requires us to correct information that is inaccurate, out of date, incomplete or misleading. Where we disagree with a correction you have asked for, we will note your view on the record so anyone reading it sees both.

Access can be refused in narrow situations, such as where giving it would seriously threaten someone's life or safety, or reveal information about another person. We will explain our reasons in writing and tell you how to challenge the decision.

How do you make a privacy complaint?

Come to us first. Most privacy issues get sorted quickly once someone knows about them.

  1. Contact our Privacy Officer on 0435 330 666 or at info@carecompassion.com.au. Put it in writing where you can, and tell us what you would like to see happen.
  2. We acknowledge your complaint within 2 business days and give you a written response within 30 days. It costs you nothing to complain, and it will never affect the supports you receive.
  3. Take it further if you are not happy with our answer. You have three routes, and you can use any of them.
Where to goWhat they handleContact
Office of the Australian Information CommissionerPrivacy and personal information complaints1300 363 992
oaic.gov.au
NDIS Quality and Safeguards CommissionComplaints about NDIS providers and workers1800 035 544
TTY 133 677
ndiscommission.gov.au
Translating and Interpreting ServiceFree interpreter for either of the above131 450

The OAIC asks you to give us 30 days to respond before you take a privacy complaint to them.

Complaints about our services rather than your privacy belong on our feedback and complaints page.

Cookies and our website

Our website uses cookies to keep the site working, remember your preferences and measure which pages people find useful. We use Google Analytics, which collects information about how the site is used in a form that does not identify you personally.

You can block or delete cookies in your browser settings. Some parts of the site may not work as well afterwards.

Forms on this site send your details straight to our team. We use that information to answer your enquiry, and we keep it with your file if you go on to become a participant.

Changes to this privacy policy

We review this privacy policy every 12 months, and sooner where the law or our systems change. The date at the top always shows the current version. Material changes are flagged to current participants directly rather than left for you to find.

Contact our Privacy Officer

Compassionate Community Care Pty Ltd
63 Mulgrave Road, Parramatta Park QLD 4870
Phone: 0435 330 666
Email: info@carecompassion.com.au
NDIS Registration: 4050097980
ABN: 18 609 924 209

Need this policy in Easy Read, large print, another language, or read aloud? Ask us and we will arrange it. Section 6(1)(b) of the NDIS Code of Conduct is not much use to anyone who cannot read the page it sits on.

Contact us

Frequently asked questions

Do NDIS providers have to follow the Privacy Act?

Yes, where the provider delivers health services. Health service providers are covered by the Privacy Act 1988 regardless of annual turnover, so the $3 million small business exemption does not apply to them. Compassionate Community Care delivers nursing and allied health supports and is bound by the Act and all 13 Australian Privacy Principles.

Can I ask to see the records you keep about me?

Yes. Ask us by phone or email and we will confirm your identity, then give you access within 30 calendar days. There is no fee to make the request. We may charge a reasonable amount for copying or postage on large record sets, and we will tell you the cost first.

Who can see my NDIS information?

Only the people who need it. That means the workers supporting you, the NDIA and your plan manager for claiming, and anyone you have specifically authorised, such as a support coordinator or family member. Anything beyond that needs your consent, unless the law requires us to report something.

Can I withdraw my consent to share my information?

Yes, at any time. Contact our Privacy Officer and tell us what you want changed. We will confirm in writing what stops being shared and explain anything we still have to report by law, such as a reportable incident to the NDIS Commission.

What happens if my information is involved in a data breach?

We assess the breach and notify you and the Office of the Australian Information Commissioner where serious harm is likely. The Privacy Act allows up to 30 calendar days to complete that assessment. We tell you what was involved and what steps to take to protect yourself.

Can I use your services without giving my real name?

You can contact us, ask questions and give feedback anonymously. It works differently once you become a participant, because we cannot deliver supports, claim through the NDIS or respond in an emergency without knowing who you are.

Do you send my information overseas?

Some of our software providers may store data on servers outside Australia. Australian Privacy Principle 8 requires us to take reasonable steps to make sure they protect your information to Australian standards, and our supplier contracts say so. Ask us and we will tell you which systems hold your records.