Privacy, Confidentiality and Records Management Policy and Procedures
Policy Statement
Kaizer Community protects and upholds the privacy and confidentiality of young people, children, staff and uses secure systems and processes for record keeping.
To protect and uphold privacy, and to meet relevant record keeping and information management standards, we:
-
collect and use personal information with intentionality, with the relevant person’s consent, for proper purposes, and with appropriate protections;
-
only collect the information needed to perform services;
-
store all data securely as per relevant legislation, contractual and professional requirements; and
-
avoid sharing personal information, purposefully or by omission, unless the relevant person provides informed consent or we are required by law or other binding requirements to do so.
To maintain confidentiality, we:
-
uphold all legal and ethical obligations concerning the handling of confidential information;
-
provide information to individuals and staff about their rights regarding confidentiality, the processes used to protect these rights, and where any limits to confidentiality exist;
-
avoid inappropriate verbal and written disclosure of information about children, young people, clients and staff within and beyond the organisation;
-
only share verbal and written information about a child or young person in our care with agencies and individuals external to Kaizer Community where the department has provided informed consent for sharing
-
take all reasonable steps to protect all information we hold from misuse, loss and unauthorised access, modification or disclosure.
Scope
This policy and associated procedures apply to Kaizer Community as a whole, including all employees, volunteers, and governance body members.
HSQF Related Standards
-
Human Services Quality Standards Indicator 1.7
-
Human Services Quality Standards Indicator 4.1
Related Legislation and Standards
|
Common |
Criminal Code (Child Sexual Offences Reform) and Other Legislation Amendment Act 2020 |
|
|
Information Privacy Principles Privacy Act 1988 (Cth) Privacy Amendment (Notifiable Data Breaches) Act 2017 (Cth) Right to Information Act 2009 Service Agreement – Standard Terms, Clause 27 Department of Child Safety, Seniors and Disability Services Information Privacy Guide Service Agreement – Standard Terms, particularly Material and Information (terms 16-19) Office of the Australian Information Commissioner Guide to Undertaking Privacy Impact Assessments Office of the Australian Information Commissioner Notifiable Data Breaches Office of Information Commissioner Queensland Guidelines – Privacy Principles |
|
Child Protection Placement Services Service Stream: Child and Family Department: DCSSDS |
Child Protection Regulation 2023 (particularly section 29) Department of Children, Youth Justice and Multicultural Affairs Information Sharing Guidelines: To Meet the Protection and Care Needs and Promote the Wellbeing of Children Department of Child Safety, Seniors and Disability Services Recordkeeping Guide for Funded Non-Government Organisations |
|
|
Department of Child Safety, Seniors and Disability Services Service Agreement |
|
|
Queensland Aboriginal and Torres Strait Islander Child Protection Peak Limited (QATSICPP) Practice Standards |
|
|
Queensland Government Child Safety Practice Manual |
|
|
Queensland Government Domestic and Family Violence: Common Risk and Safety Framework |
|
|
Queensland Government Social Media Guidelines |
Definitions
Confidentiality: The protection of personal information and limiting any sharing of personal information to situations in which informed consent has been provided and/or legitimate limitations to the right to confidentiality apply.
Information sharing: Providing information about a young person or child and their family to another service provider or statutory authority.
Informed consent: An ongoing process where a young person or child and their family’s understanding of potential actions is developed, and the young person/child and their family give approval for a particular decision or action with an understanding of all relevant facts. In the context of this document, informed consent refers specifically to approval for relevant information to be shared by one service provider with another.
Integration/service integration/service coordination: Ongoing collaborative planning or service provision by two or more service providers in relation to the same young person/child and their family, to improve the effectiveness and efficiency of service delivery.
Liaising: Communicating between two or more parties for the purposes of arranging or improving support provided by multiple services to a young person/child and their family.
Personal information: Information about an individual, including but not limited to their identifying details (name, date of birth, image, unique characteristics, signature, identity cards, etc.), ethnicity/nationality, religion or culture, health information, and details of service provision.
Prescribed entity: A government agency or specialist non-government service provider as defined in the Domestic and Family Violence Information Sharing Guidelines.
Privacy: A human right that, for the purposes of this policy and associated procedures, includes the right to control who receives and uses personal information, how personal information is handled, and physical privacy.1
Referral: Providing a client with information about a service or services that may be useful to them (‘cold referral’) or directly linking a client with a service or services by contacting the service/s and arranging or facilitating their contact with the client (‘warm referral’).
Principles
The principles supporting high quality confidentiality-related practices at Kaizer Community are:
-
Confidentiality: We protect the confidentiality of young people, children and their families, including their personal information and details about their access to services.
-
Cultural awareness and safety: We take cultural identities and communities into account when making decisions about personal information and information-sharing.
-
Human rights: We recognise and uphold the rights to privacy and confidentiality as defined within and beyond the Human Rights Act 2019 and Information Privacy Principles; the right to access and request amendments to their information held by the service; and the right to be treated with dignity and respect in all aspects of service involvement, including in relation to privacy and confidentiality.
-
Privacy: Our collection of information about young people, children and their families is limited to what is necessary for the delivery of high-quality services and to meet our legal and contractual obligations.
-
Safety: We recognise that information-sharing has safety implications; we assess and respond to safety risks related to information sharing, particularly but not only in relation to domestic and family violence-related information.
-
Self-determination and informed consent: We actively engage, the department, young people, children and their families in determining when and how information about them is shared, and we ensure that everyone engaging with our service is provided with accessible and comprehensible information about the information we collect about them, including how this is and may be used. We recognise that this information must be provided and confirmed in a variety of ways to meet the accessibility and learning needs of diverse young people/clients/client family members and use appropriate methods to facilitate this. As a provider of care to children and young people, we refer to standards including the Information Sharing Guidelines: To Meet the Protection and Care Needs and Promote the Wellbeing of Children.
Procedures
Protection of Privacy and Confidentiality
Kaizer Community only collects information about young people, children, their families and employees that is necessary for effective service provision, such as adequate assessment, planning and service review, and to meet our contractual and legal obligations.
We have controls in place to protect the security and privacy of the information we hold about young people, children and their families, as well as governance body members, management, staff and volunteers. These controls include:
-
Induction, training and supervision of all staff (including managers and volunteers) and governance body members in privacy and confidentiality, including:
-
An overview of relevant privacy legislation, organisational policies and sector-specific confidentiality requirements at induction.
-
Practical guidance on handling personal, sensitive, and confidential information in accordance with organisational standards and legal obligations.
-
Operation in accordance with applicable privacy legislation (e.g., Privacy Act 1988 (Cth), Australian Privacy Principles) and relevant industry codes of conduct.
-
-
All staff and governance body members are provided with:
-
The organisation’s Privacy and Confidentiality Policy.
-
The Code of Conduct and/or Confidentiality clauses in Employment Agreements outlining obligations, acceptable standards of behaviour, and compliance requirements.
-
Information on legal consequences for breaches of confidentiality (including disciplinary action, termination of employment or appointment, and potential civil or criminal penalties).
-
Individuals are required to read, understand, and sign these policies, procedures, contracts and agreements prior to commencing their role, confirming their commitment to uphold these obligations.
-
The organisation embeds continuous professional development on privacy, confidentiality, and information management responsibilities into all roles through:
-
Regular inclusion of privacy/confidentiality topics in team meetings, supervision and governance meetings.
-
Access to targeted professional development opportunities in legal compliance, record- keeping standards and secure information management systems.
-
Incident reviews and debriefs to strengthen practice and reinforce obligations.
-
-
Respectful engagement with information about young people, children and their families, including:
-
Respect for people regardless of special/protected or marginalised characteristics/group membership.
-
Use of objective and non-judgemental notetaking and documentation practices.
-
-
Informed consent processes (as detailed below) for the collection, storage, use and disclosure of personal data.
-
Secure information storage (as detailed below).
-
Processes for protecting privacy in meetings and appointments, including use of private meeting rooms, secure/encrypted messaging or online meeting systems, and adherence to privacy principles.
-
Avoiding inclusion of any personal information in the use of online tools, including but not limited to ‘artificial intelligence’, ‘AI’ or ‘text generation’ tools, except AI Minutes that are used to gather and process meeting minutes across the organisation. This AI Minutes tool meets the Information Privacy Act standards.
Collection of Personal Information
Children, Young People & Clients
The Organisation will only collect personal information from individuals, the department and other third parties if it is reasonably necessary for the Organisations functions or activities, specifically, the company may collect personal information such as:
-
Personal Identification Information
-
Full name, date of birth, gender, cultural background, and language preferences.
-
Contact details (address, phone number, email).
-
Photographs or other identifying images.
-
Sensitive and Health Information
-
Medical history, current health needs, allergies, medications, and treatment plans.
-
Disability status and support requirements.
-
Mental health information and behavioural support needs.
-
Religious or cultural requirements.
-
Case and Care Information
-
Placement history and reasons for care.
-
Case plans, care team meeting notes, and progress reports.
-
Incident reports, behavioural observations, and safety plans.
-
Educational history and school reports.
-
Legal and Administrative Information
-
Court orders, guardianship details, and consent forms.
-
Child protection case notes and Department of Child Safety correspondence.
-
Authorisations for medical treatment, travel, or activities.
-
Family and Social Information
-
Names and contact details of family members, carers, and key support people.
-
Relationship history and cultural connections.
-
Contact visit schedules and related case notes.
Employment
It is the Company’s usual practice to also collect personal information from those who work with and for the Company. In addition, as part of the recruitment process, the Company may obtain information directly from a candidate as a result of their application to a job advertisement.
Furthermore, if a candidate’s application is successful, as a condition of employment with the Company, the successful candidate will likely be asked to provide evidence of their identity and legal entitlement to work in Australia. It is likely a successful candidate will also be asked to provide personal information, such as emergency contact details, tax file number, superannuation and bank account details, paid blue card details and police check details (if applicable) which will form part of an employee file.
Specifically, the Company may collect personal information directly from an individual including:
-
Recruitment and on-boarding information such as an application form and resume, emergency contact details, and details of previous employment;
-
Contact details, including address, email address and phone number;
-
Date of birth;
-
Details of next of kin and emergency contact details;
-
gender;
-
identification documents including passport and drivers’ licence;
-
Paid blue card details
-
National Police Check details
-
marital status and family details, including in relation to personal leave;
-
bank details (including bank name and location, BSB and account number) and information in relation to tax status; .
The organisation manages the archiving and disposal of all records in accordance with the Privacy Act 1988 (Cth), state child protection recordkeeping requirements, and applicable retention schedules.
Our Website
We collect personal information that you voluntarily provide to us when you use our contact form or apply for a job via Employment Hero. This may include:
-
Name
-
Email address
-
Phone number
-
Message content (for contact form)
-
Employment details (for job applications via Employment Hero)
We also use Google Analytics to collect information about how you interact with our website. This information helps us understand website traffic and usage patterns. The data collected includes:
-
IP address
-
Browser type and version
-
Pages visited
-
Time spent on pages
-
Referring site details
-
Other usage data
Our website uses cookies and other tracking technologies to enhance your browsing experience and analyse our website traffic. You can control cookies through your browser settings.
Disclosure of Personal Information
All personal information is protected and, where disclosure is required, the information shared is limited to:
-
Information the children and young people and the Department has provided informed consent for sharing, such as providing information about ongoing work with the children and young people to another service provider working with the children and young people, in accordance with the Collaborating with Other Organisations Policy and Procedures or writing a support/advocacy letter to promote the children and young people’s wellbeing or to uphold their rights.
-
The information required to access emergency/urgent assistance to address an immediate risk (e.g., information that must be provided to Queensland Ambulance Service in order for emergency paramedic assistance to be accessed or for police to attend an emergency situation).
-
The information required to assess and address a child safety or domestic and family violence-related risk, in accordance with the relevant service guidelines/requirements.
-
The information relates to a form of abuse or violence that we must report, such as:
-
reporting sexual offending against a child, to the police or other relevant authority as per the Criminal Code (Child Sexual Offences Reform) and Other Legislation Amendment Act 2020;
-
reporting abuse or reasonable suspicion of child abuse to police or Child Safety Services; and
-
responding to domestic and family violence indicators in accordance with the Domestic and Family Violence: Common Risk and Safety Framework and the Domestic and Family Violence Information Sharing Guidelines (see below).
-
-
Responding to your enquiries submitted through our website contact form.
-
Processing and managing job applications submitted via Employment Hero.
-
Analysing website traffic and improving our website and services.
-
To comply with legal obligations and resolve disputes.
Wherever possible, practicable and safe, informed consent will be sought prior to sharing information to address a risk, as required under relevant legislation or standards. To promote good practice, in a situation where risk and information sharing requirements, or the potential thereof, are identified, the staff member and their manager must ensure that the following steps have been taken:
-
Consult with a senior staff member, unless the situation requires an emergency response that must not be delayed by the time required for consultation.
-
Document the risk, any assessment processes, and all decisions made, and actions taken in relation to the risk.
-
Make any reports to funding bodies or authorities that are necessary as per the relevant Service Agreement or standards (specify relevant requirements).
Facilitating Informed Consent for Information Collection and Use
In order to carry out our service responsibilities, Kaizer Community collects, stores, uses and discloses personal information about employees, children, young people and their families engaging with our services. In doing so, we comply with the Privacy Act 1988 (Cth), the Information Privacy Principles, the Right to Information Act 2009 (Qld), the Human Rights Act 2019 (Qld), our service agreement (particularly Standards 3. and 18.4), and professional standards for Queensland services.
We ensure that informed consent is obtained, understood, and reviewed on an ongoing basis to support the safe and appropriate delivery of services.
Information Collection and Storage Practices
Kaizer Community informs employees, children, young people and their families of:
-
Why information is collected: to meet contractual and service agreement requirements, ensure continuity and quality of care, and enable oversight and accountability of services provided.
-
Options if consent is withheld negotiation regarding the type and amount of information collected, use of pseudonyms where appropriate, and advice on any limitations to service provision where essential information is not provided.
-
How information is stored: securely in encrypted systems (e.g., CTARS, EMPLOYMENT HERO) with access limited to authorised staff, in accordance with organisational information security procedures.
-
Access rights: their right to request access to personal information held by Kaizer, and the process for reviewing, amending or correcting records.
-
Usual uses of information: including internal case reviews, monitoring, reporting to funding bodies, and supporting continuity of care.
-
Potential further uses: sharing information with consent to support collaborative work with other providers, or without consent when legally required (e.g., to meet child protection requirements or to address an immediate safety risk through emergency services).
-
Amendment rights: their right to request corrections to their records and the process for making these amendments.
-
Record retention: that records will be kept for at least seven years in line with Service Agreement Standard Terms, or longer where required (e.g., sexual violence-related information).
-
Record destruction: how and when records will be securely destroyed once retention periods have expired.
Information Sharing and Confidentiality
Children & Young People
Kaizer Community explains our legal, contractual and professional requirements for information sharing, including the limits of confidentiality. Children, young people and their families are advised that information may be shared in the following ways:
-
Privacy Notices: Each person receives a clear Privacy and Confidentiality statement or information sheet in line with Service Agreement Standard Terms 18.3.
-
Accessible formats: Privacy information is available in plain English, easy-read formats, alternative languages, or other adaptations as required to ensure understanding.
-
Verbal consent discussions: Staff engage in conversations about consent at intake and regularly throughout service delivery, reinforcing rights and choices.
-
Rights and protections: Children, young people and their families are informed of their rights, including:
-
The right to privacy.
-
The right to give or withhold informed consent.
-
The right to withdraw consent at any time.
-
The right to make complaints regarding privacy or confidentiality breaches.
-
Kaizer Community upholds these rights through transparent processes, documented consent records, staff training, and accessible complaints procedures.
Employment
The purposes for which the Company may collect, use, and disclose personal information include (but are not limited):
-
to establish, maintain and manage relationships, including to serve functions such as recruitment, payroll, appraisals, and any disciplinary action (including any termination of any employment or engagement) and managing employees’ work and any claim in relation to any injuries or illnesses;
-
to assess or respond to claims, complaints, or conduct, or co-operate with investigations when required;
-
to obtain professional services as required including legal, human resources, industrial relations, accounting and insurance services;
-
work-related administrative purposes;
-
to finalise the terms of a contract, including pay rates;
-
to confirm eligibility to work in Australia;
-
to carry out a contract including, where relevant, its termination;
-
to pay and provide other benefits in accordance with a contract;
-
to make travel bookings on an individual’s behalf;
-
to allow you access to the Company’s buildings, and to ensure the security of Company buildings, confidential information and other Company property;
-
to reimburse expenses claimed;
-
to operate any share scheme including the granting of share options;
-
to operate schemes relating to sick leave, maternity leave, paternity leave, adoption leave, and parental leave;
-
deducting and paying appropriate tax and superannuation contributions;
-
to monitor and protect workplace health and safety;
-
to provide a reference upon request from another employer;
-
monitoring compliance with Company policies and The Company’s contractual obligations;
-
to comply with all applicable law;
-
to liaise with any insurers in respect of any insurance policies that relate to you;
-
running the Company business and planning for the future;
-
the prevention and detection of fraud or other criminal offences;
-
to defend the Company in respect of any investigation or litigation and to comply with any court or tribunal orders for disclosure;
-
otherwise as permitted or required by law; or
-
otherwise with your consent.
The Company may use your personal information (for example, your name, image, job title and work contact details) on its website or in other publicly available resources where this is necessary for legitimate business purposes.
Our website uses cookies and other tracking technologies to enhance your browsing experience and analyse our website traffic. You can control cookies through your browser settings.
The Company may also use this personal information for other marketing purposes, such as for displaying photos of staff on its website and in other marketing materials. In some circumstances it will be necessary to continue to use certain personal information (such as photos of you) on the Company website or in other marketing materials even after your employment has come to an end.
The Company will always only use such personal information in a reasonable manner, taking into account your position within the Company and the nature of your role. If you have any concerns about such use of your personal information, you should discuss this with your manager. The Company will consider any such points raised.
The Company may disclose personal information to third parties including:
-
other companies within the Company’s group;
-
employees and contractors working for the Company, to the extent this is necessary for the operation of the Company’s business;
-
technology service providers, including, internet service providers, cloud hosting service providers, software suppliers, maintenance and support service providers, and security services on a confidential basis so that they can provide services to the Company;
-
service providers such as banks;
-
external consultants such as legal, human resources, industrial relations, accounting, and insurance;
-
travel agents and suppliers of accommodation and travel services;
-
government agencies such as the ATO, Fair Work Ombudsman, WorkCover, etc;
-
superannuation funds;
-
to other third parties as allowed by law or with your consent.
Information Storage
All records that contain client or staff personal information are stored in secure environments with appropriate controls on access. This includes:
-
Using systems across our organisation that enable strong security measures that may include ISO 27001 certification, user authentication techniques i.e. MFA and/or other strong data security measures.
Information Access
Children, Young People & Clients
-
Residential Management have access to all records relevant to their responsibilities. The Services Manager and General Manager have access to all records. Youth Workers have access to limited record information. Such information is provided to them to perform their duties effectively.
-
Individuals and their nominated representatives have a right to access the personal information we hold about them. Requests to access personal information can be made to the Services Manager or, if made to another staff member, referred by that staff member to the Services Manager. All requests are met with respect and understanding.
-
The staff member receiving the request is responsible for providing the client/nominated person with a summary of the access process and anticipated length of time to comply with the request.
-
The Services Manager is responsible for reviewing the request, determining the suitability of access, and providing or directing another staff member in how to provide access to the relevant information.
-
Where safety, legal or contractual issues limit the information it is suitable for a client/nominated person to access, the Services Manager is responsible for determining an appropriate response to the request.
-
No staff member may provide information or facilitate access to information where this could breach another person’s confidentiality or place the individual or another person at risk.
Employment
-
Personal information held by the Company in respect of employees is subject to the “employee records exemption” under the Privacy Act and does not have to be disclosed on request.
-
Other persons, such as job applicants can request copies of their personal information by contacting the General Manager via admin@kaizer.com.au
-
The Company may make reasonable charges for access to personal information and may refuse to provide access to, or delete, information where this is required or authorised by the Privacy Act or another law.
-
If personal information is incorrect, individuals may request that the Company amend its records, and the Company will take reasonable steps to do so. Employees can do this by contacting their manager, other persons, such as job applicants should use the contact details referred to above.
Managing Breaches
Inappropriate and illegitimate exposure or sharing of client or staff information is a serious breach of our responsibilities. To manage the risk of breaches and to address the effects when breaches occur:
-
Kaizer Community has a responsibility to report any confidentiality or information privacy breach to the person whose information has been inappropriately shared or exposed. Where the breach is likely to result in harm, we report this to the affected individual(s), the relevant funding body/Department, and Office of the Australian Information Commissioner if applicable. This should happen within 30 days of becoming aware of the breach.
-
All suspected or actual breaches must be reported to your line manager and the organisation’s General Manager as soon as practicable — ideally within 24 hours of becoming aware of the incident.
-
Failure to report a suspected breach within required timeframes may result in disciplinary action and, in some cases, legal penalties.
Privacy and Confidentiality Complaints
All staff, children, young people and their families have the right to make a complaint about Kaizer Community’s privacy, confidentiality and related policies, procedures and practices. Complaints may be made directly to Kaizer Community or externally to the Office of the Information Commissioner.
Kaizer Community manages these matters in line with our Young Person Complaints and Feedback Policy for children and young people in our care and the Grievance Handling Policy for employees which outlines the processes for raising, recording, and responding to complaints Principles followed include:
-
Informing of rights: Children, young people, families and staff are informed of their right to complain through the informed consent process, privacy notices, induction training, and accessible materials (including plain language and youth-friendly formats).
-
Receiving and responding: Complaints are acknowledged and responded to within the timeframes set out in the Young Person Complaints and Feedback Policy. Roles and responsibilities for managing complaints are clearly defined (e.g., frontline staff, Team Leaders, Managers).
-
Management process: All complaints are addressed using the organisation’s Complaints Management Policy and Procedures, ensuring consistency, fairness, and compliance with legal and contractual requirements.
Child Protection Placement Services and/or Child Protection Support Services and/or Family Services
All our work with children and young people is subject to the same requirements for the protection of privacy and confidentiality as outlined in other parts of this policy and procedures, with due consideration to their increased vulnerability and the involvement of parents/guardians as appropriate to the developmental level of the child/young person.
In supporting children’s and young people’s safety, rights and self-determination, Kaizer Community:
-
Modifies informed consent and information sharing processes to reflect the child or young person’s developmental level and capacity to understand. This includes providing information in plain language, using age-appropriate explanations, and involving parents/guardians where appropriate while respecting the child or young person’s right to privacy.
-
Applies additional protections to children’s/young people’s records, including secure storage, limited access by authorised staff only, and heightened scrutiny before any disclosure is made. Where young people are subject to the Child Protection Act, we also ensure compliance with all legislative reporting and confidentiality requirements.
-
Shares information with parents/guardians in a way that balances safety and rights, ensuring that disclosures do not increase risks (e.g., in cases involving child abuse or domestic and family violence). Strategies include consulting with senior staff, assessing risks before information is shared, and withholding certain information where sharing could compromise the child/young person’s safety.
-
Manages privacy/confidentiality risks in organisational activities by:
-
Seeking explicit informed consent for participation in group activities, community events, or media/social media engagement.
-
Ensuring that no images, names or identifying details of children/young people are used without written consent from the child/young person (where appropriate) and their parent/guardian.
-
Reviewing consent regularly, with the option for withdrawal at any time.
-
Maintaining safe practices when children/young people are interacting with other clients or groups, with staff supervision to safeguard against inappropriate disclosures or breaches of privacy.
-
Where our work is carried out with children/young people under the Child Protection Act 1999 and in relation to the relevant DCSSDS Service Agreement (Child Safety and Youth), we are required to meet obligations under both the Act and the Child Protection Regulations 2023, including that we:
-
Keep and share information in accordance with relevant guidelines and only for proper purposes.
-
Keep a record for each relevant child/young person with information as outlined in the Recordkeeping Guide for Funded Non-Government Organisations and Service Agreement Funding and Service Details
-
Transfer client files to DCSSDS following the steps set out in the Recordkeeping Guide for Funded Non-Government Organisations, including when a child/young person exits the service, is no longer subject to the Child Protection Act or turns 18, or if we cease to provide the relevant service.
-
Provide DCSSDS with access to each child’s/young person’s file upon request.
-
Follow any directions given by DCSSDS in relation to the storage or destruction of the file.
-
Notify DCSSDS immediately of the death or life-threatening injury or risk or other incident or harm as defined by the Child Protection Act and/or clause 4.5(d) (notifying major incidents) of the Standard Terms.

