Privacy Policy
Home » Privacy Policy
Le Bon Care is committed to protecting the privacy of personal information. This statement explains how we collect, use, disclose, and protect personal information, and sets out the rights of the people whose information we hold.
We comply with the Privacy Act 1988 (Cth) as amended by the Privacy and Other Legislation Amendment Act 2024 (Cth), the thirteen Australian Privacy Principles (APPs), the Notifiable Data Breaches (NDB) scheme, the NDIS Act 2013 (Cth) and the NDIS Quality and Safeguarding Framework.
1. Our Commitment
Le Bon Care manages personal information in an open and transparent way. We are committed to ensuring that:
- personal information is collected and handled fairly and only for lawful purposes
- the privacy of participants, staff, and other individuals is protected
- individuals can access and correct the information we hold about them
- personal information is stored securely and disposed of appropriately
- individuals are informed about how their information is used and can exercise their privacy rights
2. What Information We Collect
We collect personal information necessary to deliver and coordinate your supports. This may include:
- name, address, telephone number, and email address
- date of birth and gender
- NDIS number and plan details
- cultural background and diversity information
- communication preferences and support needs
- details of your advocate, emergency contact, or nominated representative
- referral source and service history
Sensitive information — including health information, disability information, case notes, treatment plans, and support strategies — is given a higher level of protection under the Privacy Act. We collect sensitive information only with your consent or where otherwise permitted by law, and we handle it with additional care.
3. How We Collect Personal Information
We collect personal information directly from you wherever possible. With your consent, we may also collect information from:
- family members, carers, or significant others
- your advocate or nominated representative
- your doctor, allied health practitioners, or other service providers
- referring organisations or government agencies
We will collect information from another source only where we have your consent, we are required or authorised to do so by law, or it is unreasonable or impractical to collect it directly from you. You may withdraw your consent at any time by contacting us, though this may affect our ability to deliver some or all of your supports.
4. Why We Collect Personal Information
Personal information is collected for the purpose of delivering and coordinating your supports. Specifically, we use it to:
- assess eligibility and design supports tailored to your needs and goals
- deliver, monitor, and review the supports we provide
- communicate with you, your support network, and your other service providers
- process NDIS funding claims and manage invoicing
- comply with legal, regulatory, and reporting obligations
- respond to complaints, incidents, and safety concerns
- maintain accurate and current records as required by the NDIS Practice Standards
5. Disclosure of Personal Information
We may disclose your personal information to people and organisations involved in your care and supports, including:
- health professionals, allied health practitioners, and medical facilities
- the NDIS Commission, the National Disability Insurance Agency (NDIA), and other relevant government bodies
- your nominated advocate, emergency contact, or legal representative
- other support providers involved in your care, where relevant and with your consent
- our contracted service providers (such as IT systems) who are bound by confidentiality obligations
We will not use or disclose your personal information for any purpose other than delivering your supports, unless:
- you have given explicit consent
- it is reasonably necessary to prevent a serious or imminent threat to life, health, or safety
- we are required to report to the NDIS Commission under the NDIS Act or related legislation
- we have reasonable grounds to suspect unlawful activity and disclosure is required by law
6. Overseas Disclosure
Le Bon Care does not intentionally disclose personal information to overseas recipients. Some of our cloud-based systems may store data on servers located outside Australia. Where this occurs, we take reasonable steps to ensure those systems comply with the Australian Privacy Principles. We will advise you if overseas disclosure is required for any other reason and obtain your consent unless otherwise required by law.
7. Security of Personal Information
We take all reasonable steps to protect personal information against misuse, interference, loss, unauthorised access, modification, and disclosure. Personal information is held in both physical and secure cloud-based systems, accessible only by authorised Le Bon Care staff. Our security measures include user authentication, access controls, encryption, and staff training on privacy and confidentiality obligations.
8. Retention and Destruction of Records
We retain personal information only for as long as it is needed for the purpose it was collected, or as required by law. NDIS provider records are retained in accordance with the NDIS Practice Standards, the NDIS Act 2013 (Cth), and applicable Queensland records management legislation. When personal information is no longer required, it is securely destroyed or de-identified in a manner that prevents unauthorised recovery or access.
9. Notifiable Data Breaches
Le Bon Care is subject to the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth). If we have reasonable grounds to believe that a data breach has occurred that is likely to cause serious harm to any individual, we will:
- contain the breach and assess the risk of harm as quickly as possible
- notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable
- notify the affected individual(s) directly, unless an exception applies
- take all reasonable steps to prevent further harm
All suspected or confirmed data breaches are managed in accordance with our Data Breach Policy and Procedure, which sets out the assessment, notification, and remediation process in detail.
10. Accessing and Correcting Your Information
Under the Privacy Act 1988 (Cth), you have the right to access personal information we hold about you and to request corrections where that information is inaccurate, incomplete, or out of date.
To make a request, contact us using the details below. We will:
- require proof of identity before providing access
- respond within seven (7) days of receiving your request
- provide access in a format that is reasonably accessible to you
- correct information promptly or note your disagreement on the record if we are unable to make the correction
11. Privacy complaints
If you have a concern or complaint about how we have handled your personal information, you may raise it with us using our standard complaints process. All privacy complaints will be:
- taken seriously and handled with confidentiality
- investigated promptly and impartially
- responded to in writing with the outcome of our investigation
- managed without affecting your existing supports or our obligations to you
If you are not satisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or call 1300 363 992. You may also contact the NDIS Quality and Safeguards Commission at 1800 035 544 for matters related to NDIS service delivery.
