KindPath Collective Inc
Information Management and Privacy Policy
Version 1.0 | Effective: 29 August 2026 | Review: 29 August 2027 | Owner: Director
1. Purpose
To set out how KindPath collects, uses, stores, discloses and disposes of personal and health information about participants, workers and others — including information held in KindPath’s own systems (such as the in-development KiNDIS app) as well as paper records.
2. Legislative and standards basis
- Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
- NSW Privacy and Personal Information Protection Act 1998 (PPIP Act).
- NSW Health Records and Information Privacy Act 2002 (HRIP Act) — health information specifically, which covers most participant support data.
- NDIS Practice Standards, Module 2: Governance and Operational Management — Information management.
- Notifiable Data Breaches scheme (Privacy Act Part IIIC).
3. Policy statement
KindPath collects only the personal and health information it genuinely needs to deliver safe, effective support, tells participants clearly what is collected and why, and does not use or disclose it for any other purpose without consent (or a specific legal basis, such as imminent risk to safety).
Health information (which includes most of what KindPath records about a participant’s disability, support needs, and behaviour data) attracts stricter handling obligations than general personal information under the HRIP Act, and is treated accordingly throughout this policy.
4. Collection
- Information is collected directly from the participant wherever possible, in a way and pace they can engage with.
- Where information is collected from a third party (a support coordinator, family member, or previous provider), the participant is told this is happening and why, and consents to it, except where safety requires urgent information sharing.
- Only what is needed for the stated purpose is collected — a comprehensive life history is not required to run a shift routine.
5. Use and disclosure
- Information is used only for the purpose it was collected for (delivering and improving the participant’s support), unless the participant consents to broader use or disclosure is required by law.
- Behaviour and ABC data collected for a participant is used to inform that participant’s own support and, where relevant, shared with their support coordinator or a treating clinician they’ve consented to involve — not used more broadly (e.g. for KindPath’s own product development on KiNDIS) without separate, specific consent.
- Any disclosure to a third party (support coordinator, allied health professional, family member) requires the participant’s informed consent, documented, except where there is a serious and imminent threat to life, health or safety.
6. Storage and security
- Digital records are stored in access-controlled systems; only workers actually involved in a participant’s support can access their file.
- Paper records (if any) are stored securely and not left in vehicles or accessible locations.
- The KiNDIS app, while in development, does not go into live use with real participant data until it meets this policy’s access-control and security standard — this is a build gate, not a retrospective fix.
7. Data breach response
- Any suspected or actual data breach is reported to the Director immediately.
- The Director assesses whether the breach is likely to result in serious harm (triggering Notifiable Data Breaches scheme obligations).
- Where the threshold is met, affected individuals and the Office of the Australian Information Commissioner are notified as soon as practicable, and in any event within the statutory timeframe.
- Every breach, notifiable or not, is logged and reviewed for a system-level fix, not just an apology.
8. Retention and disposal
See the Records Retention and Disposal Schedule (Module 5) for specific retention periods. In general: NDIS-related records are retained for the period required under the NDIS Act and Rules; records are securely destroyed (not just deleted from a visible folder) once the retention period expires, unless the participant requests earlier deletion and no legal obligation requires retention.
9. Roles and responsibilities
- Director: privacy officer function until KindPath is large enough to appoint one separately; handles breach response and access requests.
- Workers: collect and handle only what’s needed, and report anything that looks like a breach immediately.
10. Related documents
Privacy and Dignity Policy · Records Retention and Disposal Schedule · Consent and Capacity Policy
11. Review
Annually, and immediately after any data breach.