Skip to main content

PRIVACY POLICY

Background

Respecting a person’s privacy is protected under the Australian Privacy Act 1988 and a key element in meeting the obligations of aged care
providers to treat consumers with dignity and respect. Privacy relates to both the personal information collected and held about all people
including consumers, staff, contractors and other health professionals and to the physical environment, possessions, physical needs and personal
relationships.

Personal information is defined as ‘Information or an opinion about an identified individual, or an individual who is reasonably identifiable

  •  whether the information or opinion is true or not and
  •  whether the information or opinion is recorded in a material form or not.’ (RL-Office of the Australian Information Commissioner)

Health information is one of the most sensitive types of personal information so it is essential practices for collecting, storing and using this protect
the privacy of the individual it relates to.

Applicability

All residential care providers:

  • all categories of employees
  • governing body
  • all volunteers
  • students on placement
  • contractors and consultants, whether or not they are employees
  • all other service providers

Consumer outcome

I am treated with dignity and respect, and can maintain my identity. I can make informed choices about my care and services, and live the life I
choose.

Organisation statement

The organisation has a culture of inclusion and respect for consumers, supports consumers to exercise choice and independence and respects
consumers’ privacy.

Governing regulations for this policy

  • Aged Care Act 1997
  • Privacy Act 1988 (Cth)
  • Standard 1 (3)(f) Privacy is respected
  • User Rights Principles 2014

Applicable processes for this policy

  • RC-Data Breach Response

Documents relevant to this policy

  • RC-Data Breach Response

Policy Commitment

Dalrymple Villa commits to:

  • Maintaining a publicly available Privacy Policy that is available free of charge on request and explains
  • the kinds of personal information collected and held
  • how personal information is collected and held
  • the purposes for which personal information is collected and used
  • how an individual may access their personal information and seek its correction
  • how an individual may complain if they believe the organization has breached the Australian Privacy Principles and
  • whether the organization is likely to disclose personal information to overseas recipients and if so, the countries in which such recipients
    are likely to be located (if it is practicable to specify those countries in the policy).
  • Appointing a Privacy Officer role to ensure the organization complies with its legislative and regulatory responsibilities. The Privacy Officer role responds to all requests for information and complaints related to privacy.
  • Providing initial and ongoing training and support to staff on protecting privacy and confidentiality.
  • Providing information about, and explaining to individuals. in a way they understand, the types of personal information collected, how it is
    collected and used and the importance of complete and accurate information.
  • Collecting personal information directly from the individual unless they consent to collection from someone else or it is unreasonable or
    impractical to do so.
  • Collecting only the information about the individual necessary for the activity e.g. to provide care and services.
  • Obtaining informed consent prior to undertaking assessment, care coordination and planning processes, taking and each instance of using an
    image or making a recording of a person or releasing their information to any third party.
  • Documenting all file notes objectively, observing:
  • respect for the individual’s feelings and dignity
  • the individual’s right to request and have access to their own records and
  • freedom of information and court requirements that may subpoena consumer files.
  • Implementing practices to ensure personal information is accurate, up-to-date and complete including providing staff training, collecting and
    recording information consistently, verifying it with the person concerned on an annual basis and conducting regular file audits (refer to
    RC-Clinical Documentation Policy).
  • Informing individuals:
  • that our organization is authorized to collect, use, and disclose certain personal information in accordance with the Aged Care Quality and
    Safety Commission Act 2018 (and the Aged Care Act 1997) for the purposes of:
  • protecting and enhancing the safety, health, well-being and quality of life of aged care consumers
  • promoting the provision of quality care and services
  • developing and promoting best practice models for engagement between aged care service providers and their consumers
  • dealing with complaints about aged care service providers and
  • regulating and monitoring the provision of aged care services. Information to provide consumers is available on the Notice of

Collection page on the Aged Care Quality and Safety Commission website.

  • of their right to access their information and correct it if required by requesting this in writing. A response will be provided within 14 days of receipt or a reason given if access is denied
  • of the process and contact details to advise about a privacy breach (refer RC-Data Breach Response Process)
  • that if their information will be disclosed to overseas recipients who are not bound by Australian Privacy Principles, their privacy cannot be assured and seeking their specific consent for that disclosure
  • that if a significant threat to consumer or staff safety affects the consumer’s right to privacy and confidentiality, staff safety will prevail and
  • of the circumstances when access to their personal information will be granted without obtaining consent i.e.
  • if there is a serious threat to the life, health or safety of any individual or public health and safety including locating a missing person
  • it would unreasonably infringe the privacy of other individuals or
  • the information relates to legal proceedings or is in some way illegal.

Roles and Responsibilities

Governing Body

The Governing Body is responsible for providing leadership and fostering a culture that respects individual dignity and choice, including protecting
privacy and confidentiality. The Governing Body will identify appropriate systems and processes to monitor, review and continuously improve this
policy.

Management

Management is responsible for ensuring the workforce (whether employed or contracted) follow this policy and respect the privacy and
confidentiality of all individuals. Management is also responsible for monitoring implementation and compliance with this policy including ensuring
completion of education and training, and providing feedback and performance review where required.

All staff including volunteers and contractors

All staff, contractors, students and volunteers are responsible for understanding and following this policy and completing all education and training
as directed.

REFERENCES

Name

Australian Privacy Principles

Notifiable Data Breaches Scheme

Privacy for Health Service Providers –

Source

Office of the Australian Information Commissioner

Office of the Australian Information Commissioner

Office of the Australian Information Commissioner

Version: 1 Published:
18 Jul 2023, 12:26 PM
Last edited: 18 Jul 2023, 10:35 AM
Approved: 18 Jul 2023, Joanne Boschetti