SCL Care Group
Privacy policy
How we collect, use, store and protect personal information across SCL Support Services and SCL Home Care. Written to be read, not just filed.
The short version
Your information is yours.
We collect only what we need to support you safely, keep it secure, and share it only with your permission or where the law requires it. We do not sell personal information.
What is in this policy
- 1.About this policy
- 2.Privacy laws and standards
- 3.What is personal information?
- 4.What information we collect
- 5.How we collect information
- 6.Anonymity and pseudonyms
- 7.What happens if information is not provided
- 8.Why we collect and use information
- 9.Consent and decision making
- 10.Who we may share information with
- 11.Direct marketing
- 12.Website and digital information
- 13.Overseas storage and processing
- 14.How we store and protect information
- 15.Retention and destruction
- 16.Data breaches
- 17.Accessing your information
- 18.Correcting your information
- 19.Privacy complaints
- 20.External privacy complaints
- 21.Changes to this policy
- 22.Accessible formats
Section 1
About this policy
SCL Care Group is the umbrella name used by The Trustee for SCL Sport and Support Disability Services Trust, ABN 88 308 813 217, for its SCL Support Services and SCL Home Care operations. In this policy, SCL, we, us and our refer to this legal entity and its operations.
We are committed to protecting the privacy of the people we support, older people receiving care, their families, representatives, workers and everyone who interacts with our services or website.
This policy explains what personal information we collect, how we collect and use it, who we may share it with, how we store and protect it, how you can access or correct it, and how you can make a privacy complaint.
Section 2
Privacy laws and standards
We manage personal information in accordance with applicable privacy, disability and aged care requirements, including:
- The Privacy Act 1988
- The Australian Privacy Principles
- The Health Records and Information Privacy Act 2002 (NSW)
- The NSW Health Privacy Principles
- Applicable NDIS legislation, rules and Practice Standards
- The Aged Care Act 2024 and Aged Care Rules 2025, where applicable
Section 3
What is personal information?
Personal information is information or an opinion about an identified person, or a person who can reasonably be identified.
Sensitive information is a category of personal information that requires additional protection. It may include information about your health, disability, racial or ethnic background, religious beliefs, sexual orientation, criminal history, or biometric information.
Sensitive information needs a reason
We only collect sensitive information when it is reasonably necessary for our work and we have your consent, or another lawful reason to collect it.
Section 4
What information we collect
What we collect depends on your relationship with SCL and the services you receive. We may collect:
- Your name, address, telephone number, email address and date of birth
- Identity, citizenship and eligibility information
- Emergency contact information
- Information about your nominee, representative, supporter, advocate or guardian
- NDIS plan, funding and plan management information
- My Aged Care, aged care assessment and aged care funding information
- Health, disability, medication and support information
- Communication and accessibility requirements
- Cultural, religious and personal preferences
- Support Plans, Care Plans, risk assessments and emergency information
- Behaviour support and restrictive practice information where applicable
- Service records, progress notes and attendance records
- Incident, complaint and feedback information
- Consent and information sharing preferences
- Billing, payment and financial information
- Information about your goals, needs and personal circumstances
- Photographs, video or audio recordings where relevant and authorised
- Information submitted through our website, forms, email, telephone or other communications
- Information about job applicants, employees, contractors, volunteers and students
- Information about suppliers, professional advisers and other people who work with SCL
We only collect information that is reasonably necessary for our services, operations or legal obligations.
Section 5
How we collect information
We usually collect personal information directly from you — when you contact us, complete a form, enter into a Service Agreement, take part in an assessment or planning meeting, receive support from us, give feedback or make a complaint, apply for a role, or communicate with our workers.
We may also collect information from another person or organisation where you have authorised it, where it is reasonably expected, or where collection is required or permitted by law. These sources may include:
- Your family, representative, nominee, advocate or guardian
- The National Disability Insurance Agency
- NDIS partners and Local Area Coordinators
- Support Coordinators and Plan Managers
- My Aged Care and aged care assessment organisations
- Hospitals, doctors, nurses and allied health professionals
- Other service providers involved in your support or care
- Government departments, regulators or funding bodies
- Referrers and community organisations
- Employers, referees or screening organisations
We will take reasonable steps to make sure you understand why information is being collected and how it will be used.
Section 6
Anonymity and pseudonyms
You may interact with us anonymously or use a pseudonym where it is lawful and practical. For example, you may make a general website or telephone enquiry without providing your full identity.
We will usually need to confirm your identity when assessing eligibility, providing services, managing health and safety risks, processing payments or funding claims, responding to an incident or emergency, providing access to personal records, or meeting a legal obligation.
Section 7
What happens if information is not provided
You do not have to provide personal information unless it is required by law or necessary for a particular service. But if we do not receive what we reasonably need, we may be unable to assess whether we can provide a service, deliver safe support, respond to an emergency, communicate with your representatives, process funding claims, meet our regulatory responsibilities, or consider an application.
We will explain where possible why information is required and what may happen if it is not provided.
Section 8
Why we collect and use information
We may collect, hold, use and disclose personal information to:
- Respond to enquiries and referrals
- Assess your needs and determine whether we can provide services
- Plan, coordinate and deliver disability or aged care services
- Prepare and maintain Support Plans, Care Plans and risk assessments
- Match workers with your needs and preferences
- Communicate with you and people you have authorised
- Manage appointments, rosters and service changes
- Respond to incidents, emergencies and safeguarding concerns
- Manage medication, health and clinical support where applicable
- Prepare Service Agreements, quotes, invoices and funding claims
- Work with the NDIA, My Aged Care, Plan Managers and other funding bodies
- Monitor the quality, safety and effectiveness of our services
- Receive and respond to feedback and complaints
- Meet NDIS, aged care, workplace and other regulatory requirements
- Complete audits, quality reviews and continuous improvement activities
- Manage worker screening, recruitment, training and performance
- Manage our financial, insurance, taxation and administrative responsibilities
- Maintain and improve our systems, website and services
- Prevent, identify and respond to fraud, misconduct or unlawful activity
- Obtain legal, accounting, insurance, technology or professional advice
We will not use personal information for an unrelated purpose unless you consent, or the use is otherwise required or permitted by law.
Section 9
Consent and decision making
Where consent is required, we take reasonable steps to make sure you understand what you are agreeing to, that information is provided in a way you can understand, that you have a chance to ask questions, that you are not pressured to agree, and that your decision is recorded.
You may ask a trusted person, advocate, representative or nominee to help you understand information and make decisions.
You can change your mind
You may withdraw or change your consent by contacting us. Withdrawing consent does not affect information that was lawfully collected, used or disclosed beforehand.
There may be circumstances where we are required or permitted to collect, use or disclose information without consent — emergencies, serious safety risks, mandatory reporting obligations, court orders and other legal requirements.
Section 11
Direct marketing
We may use your contact information to tell you about SCL services, events, resources or updates where you have consented or would reasonably expect us to. We will not use sensitive information for direct marketing without appropriate consent.
Every electronic marketing communication provides a way to unsubscribe. You can also ask us to stop at any time by using the unsubscribe option, phoning us, or emailing us. We will action your request within a reasonable period, and there is no charge.
Section 12
Website and digital information
When you use our website, we may collect technical information such as your IP address, browser and device type, the date and time of access, pages viewed, time spent on pages, the referring website, information submitted through online forms, and cookie and analytics information.
We use this to operate and secure the website, respond to enquiries, understand how the site is used, identify technical problems, and improve performance and accessibility.
Our website may use cookies or similar technologies. You can control cookies through your browser settings, though disabling some may affect how parts of the site work.
Our website may link to sites operated by other organisations. SCL is not responsible for the privacy practices or content of external websites.
Section 13
Overseas storage and processing
Some technology, cloud, authentication, website, communication and professional service providers may store or process limited personal information outside Australia. Our current arrangements may involve limited overseas processing, including in the United States, particularly for authentication, technical support, security and website services.
Care related customer information held in ShiftCare for Australian customers is hosted in Australia under ShiftCare’s current service arrangements. Limited operational user identity information may be processed overseas for authentication and account security purposes.
Overseas locations and supplier arrangements may change as technology providers update their services. Where personal information may be handled outside Australia, we take reasonable steps to review the provider’s privacy and security arrangements, limit the information made available, use appropriate contractual protections, require information to be used only for authorised purposes, and manage overseas access consistently with Australian privacy requirements.
You may contact our Privacy Officer for current information about likely overseas processing locations relevant to your information.
Section 14
How we store and protect information
We store information using approved electronic systems, including ShiftCare and Microsoft SharePoint, as well as secure physical records where required. We use administrative, physical and technical safeguards appropriate to the sensitivity of the information.
- Restricted access based on worker roles
- Individual user accounts and password controls
- Multifactor authentication where available
- Encryption and secure communication methods
- System monitoring and audit records
- Secure backups
- Worker confidentiality obligations
- Privacy, cyber security and information handling training
- Locked storage for physical records and controlled access to offices
- Processes for responding to suspected privacy or security incidents
No electronic or physical storage system can be guaranteed to be completely secure. We regularly review our safeguards and respond to identified risks.
You can help too
- Keep passwords and access codes private
- Check the identity of people requesting information
- Tell us if your contact information changes
- Report suspicious messages or activity
- Contact us if you believe your information has been accessed or used incorrectly
Section 15
Retention and destruction
We retain personal information for as long as reasonably required for service delivery, participant and care recipient safety, legal and regulatory obligations, funding and financial requirements, insurance and professional obligations, complaints and investigations, employment records, and our approved records retention schedule.
Different types of records have different minimum retention periods. When information is no longer required, we take reasonable steps to securely destroy or permanently deidentify it, unless we are required to retain it. When health records are destroyed or transferred, we maintain any destruction or transfer records required by law.
Section 16
Data breaches
A data breach may occur when personal information is lost, or accessed, used or disclosed without authorisation.
If we become aware of a suspected breach, we will take reasonable steps to contain the incident, protect affected information, investigate what occurred, assess the possible consequences, reduce the risk of harm, and prevent a similar incident happening again.
When we will notify you
Where we have reasonable grounds to believe an eligible data breach has occurred and it is likely to result in serious harm that cannot be prevented, we will notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable.
We will also notify the NDIS Quality and Safeguards Commission, the Aged Care Quality and Safety Commission, law enforcement or other authorities where another reporting requirement applies.
Section 17
Accessing your information
You may ask to access the personal information we hold about you. Access may be provided by giving you an electronic or printed copy, letting you view the information, providing a summary, explaining it to you, or providing it in another accessible format.
- We will acknowledge your request within 5 business days
- We may ask you to verify your identity or authority
- We aim to respond within 30 calendar days, or the applicable legal timeframe where NSW health information requirements apply
- We do not charge you for making a request
- We may charge reasonable costs for providing access where permitted by law, and will tell you before doing so
In limited circumstances we may be required or permitted to refuse access — where it would create a serious risk to someone’s health or safety, unreasonably affect another person’s privacy, reveal information connected with legal proceedings, be unlawful, affect an investigation, or reveal commercially sensitive decision making information.
Where we refuse access, we will provide written reasons where required and explain how you can complain.
Section 18
Correcting your information
You may ask us to correct personal information you believe is inaccurate, incomplete, out of date, irrelevant or misleading. We may ask for information supporting the correction.
If we agree, we will take reasonable steps to update it, and where appropriate notify another organisation that previously received the incorrect information.
If we do not agree
You may ask us to attach a statement to the record explaining that you believe the information is incorrect. We will provide written reasons where required and explain how you can complain.
Section 19
Privacy complaints
You may complain if you believe we have mishandled your personal or health information. Contact our Privacy Officer and explain what happened, when, who was involved, how you were affected, and what outcome you are seeking.
You may complain yourself, or ask an advocate, representative or trusted person to help you.
What we will do
- Acknowledge your complaint within 5 business days
- Consider any immediate privacy or safety risks
- Review the circumstances and keep appropriate records
- Give you an opportunity to provide relevant information
- Explain the outcome and any action taken
- Aim to provide a written response within 30 calendar days
Complaining will not be held against you
Making a complaint will not result in retaliation or unfair treatment. If we need additional time, we will tell you and explain why.
Section 20
External privacy complaints
If you are not satisfied with our response, or we have not responded within 30 days, you may contact the Office of the Australian Information Commissioner. Privacy complaints to the OAIC must generally be submitted in writing.
For complaints about health information handled by a private health service provider in NSW, you may also contact the Information and Privacy Commission NSW.
You may also contact the relevant disability or aged care regulator where the matter relates to the quality, safety or delivery of a regulated service.
Section 21
Changes to this policy
We may update this policy when privacy laws or regulatory requirements change, our services or systems change, we begin using a new technology or service provider, we identify an improvement through an audit, incident or complaint, or our information handling practices change.
The current version is always published here. Where a change is significant, we may take additional steps to inform affected people.
Section 22
Accessible formats
This policy is available in alternative and accessible formats on request. You may ask for plain language information, Easy Read, large print, an electronic copy, assistance from an interpreter, or assistance from an advocate or trusted person.
Going outside SCL
You do not have to come to us first, and it will not affect your services.
Office of the Australian Information Commissioner
Privacy complaints under the Privacy Act. Complaints must generally be in writing.
Information and Privacy Commission NSW
Health information handled by a private health service provider in NSW.
Our Privacy Officer
Ask us anything about your information.
Access requests, corrections, complaints, or a question about how something is handled. You can also ask for this policy in Easy Read, large print, another language, or with an interpreter.
Privacy Officer
SCL Care Group
enquiries@sclsupportservices.com.au
2/19 Gordon Street,
Coffs Harbour NSW 2450
Policy owner: Privacy Officer
Approved by: SCL Care Group Board
The Trustee for SCL Sport and Support Disability Services Trust,
ABN 88 308 813 217
