Privacy Policy
Your privacy matters
DANS In Home Care protects your personal information with care and respect.


DANS In Home Care is committed to protecting your personal, sensitive and health information. This policy explains what we collect, why we collect it, how we use and share it, and the choices you have. It works alongside our Client Handbook, Service Agreement and Data Breach Response and Notification Plan.
1.0 Policy statement
DANS In Home Care is committed to protecting personal information, sensitive information and health information, and to managing information in a way that protects dignity, autonomy, privacy, informed choice and safe service delivery.
DANS will collect, use, disclose, store, retain and dispose of information lawfully, fairly, securely and only where necessary for an intended and authorised purpose.
DANS will apply the highest relevant privacy and confidentiality requirement where services are delivered across NDIS, Support at Home, DVA, ACIS / icare or private service arrangements.
2.0 Legislative and standards alignment
This policy is aligned with the Privacy Act 1988 (Cth), the Australian Privacy Principles, the Notifiable Data Breaches Scheme, the Health Records and Information Privacy Act 2002 (NSW), the Aged Care Act 2024, the Strengthened Aged Care Quality Standards, the NDIS Act 2013, the NDIS Practice Standards, the NDIS Code of Conduct, ACIS / icare requirements and relevant funding and contractual obligations.
For DANS, these requirements are put into practice through privacy information provided at intake and onboarding, the Client Handbook, the Service Agreement, the approved client record, consent records, authorised representative checks, complaint pathways, incident pathways, data breach response controls, internal audits and governance reporting.
3.0 What information DANS collects
DANS collects only information that is reasonably necessary for its services, functions and legal obligations. This may include contact details, demographic information, emergency contacts, representative or nominee information, support needs, health information, Care / Support Plans, clinical notes, Service Agreements, funding details, billing and payment information, complaints, incidents, feedback, worker details, and information required for employment or contractor management.
DANS may also collect sensitive information, including health information, where you have given informed consent, where collection is required or authorised by law, where a permitted health situation applies, or where the information is required for service delivery, safety, employment or business activities.
4.0 How information is collected
DANS may collect information directly from you, your authorised representative, a referral source, family or support network where authorised, health professionals, support coordinators, case managers, government or funding bodies, workers, contractors, approved digital systems, service delivery records, and complaints or incident processes.
Where information is collected from a third party, DANS will take reasonable steps to make sure you understand the collection, use, disclosure and consent arrangements, unless a lawful exception applies.
5.0 How information is used and disclosed
DANS uses and discloses information for the purpose it was collected for, for directly related purposes you would reasonably expect, with your consent, or where required or authorised by law. DANS shares only the minimum information necessary for the authorised purpose.
- Care and support delivery: to assess needs, plan supports, provide care, coordinate services, manage risks and respond to changes.
- Service coordination: shared with authorised representatives, health practitioners, support coordinators, other providers, advocates, funders, regulators or emergency services where required for care, safety, service delivery or compliance.
- Funding and administration: used for Service Agreements, claiming, billing, payment processing, reconciliation, audit and reporting.
- Governance and quality: used to manage complaints, incidents, safeguarding, continuous improvement, audits, training, risk management and governance reporting.
- Legal and emergency disclosure: disclosed where required by law, subpoena, regulator request, reporting obligation, serious threat to life, health or safety, suspected unlawful activity, or other lawful authority.
6.0 Communication, marketing and website information
DANS will only use your personal information for communication or marketing where permitted by law, where you have consented, or where you would reasonably expect the communication. You may opt out of marketing communications at any time.
Where the DANS website or online systems use cookies, analytics or similar technologies, information collected is limited, used for legitimate business purposes, and never sold or disclosed to advertisers.
7.0 Employee, contractor and volunteer information
DANS may collect, use and disclose worker, applicant, contractor, student and volunteer information for recruitment, screening, onboarding, workforce management, payroll, training, supervision, performance, conduct, safety, legal compliance and regulatory obligations.
Worker information is handled confidentially, stored securely and disclosed only where authorised, necessary for workforce management, required for regulatory compliance, or permitted by law.
8.0 Third-party providers and associated providers
DANS may disclose personal information to third-party contractors and service providers who support DANS operations or service delivery, including ICT providers, clinical and allied health providers, payment and financial service providers, accountants, legal advisers, business advisers, referral services, subcontractors, associated providers, and authorised funding or regulatory bodies.
DANS requires third parties to protect information, use it only for agreed purposes, maintain confidentiality and security controls, notify DANS of actual or suspected breaches, and comply with applicable privacy and contractual obligations.
9.0 Representatives, relatives, guardians and support persons
DANS will not assume that a relative, friend or support person is authorised to receive information. Before sharing information, workers confirm the person's consent, representative authority, nominee status, guardianship, power of attorney or other lawful basis.
Where a person cannot give or communicate consent, DANS may disclose limited information to an authorised or appropriate person where necessary for care, treatment, compassionate reasons, quality review, safety or another lawful purpose, provided the disclosure is not contrary to a known expressed wish and is limited to what is reasonable and necessary.
10.0 Overseas disclosure
In some circumstances, personal information may be stored in or accessed from overseas, for example through secure cloud-based systems or approved service providers. Where this occurs, DANS takes reasonable steps to make sure overseas recipients handle personal information in a manner consistent with the Australian Privacy Principles, or are otherwise subject to substantially similar privacy obligations.
DANS discloses overseas access or storage arrangements where required, through privacy information, collection notices, service documents or other appropriate communication, and maintains governance oversight of overseas access, including approval, access limitation, confidentiality, security and breach notification controls.
11.0 Information held in a client's home
Where personal or health information is held in a client's home as part of service delivery, DANS takes reasonable steps to limit access to authorised workers for the purpose of providing care. Due to the nature of in-home services, access by others in the home may occur and is not always within DANS' direct control.
Workers minimise paper records where practical, keep any required in-home information discreet and secure, use approved record systems, and report any lost, damaged, exposed or inappropriately accessed information immediately.
12.0 Data security, cloud and AI technology
DANS takes reasonable steps to protect information from misuse, interference, loss, unauthorised access, modification or disclosure. Controls include role-based access, secure authentication, approved systems, device and email controls, physical security for paper records, worker training, confidentiality obligations, supplier controls and incident reporting.
Where DANS uses cloud, digital, automation or AI-enabled systems, information is classified and handled according to sensitivity. Access is limited to authorised users, confidential information is protected in transit and at rest where systems allow, and third-party technology vendors are subject to appropriate confidentiality, privacy and security obligations.
13.0 Retention, disposal and de-identification
DANS retains personal information only for as long as required for service delivery, legal, funding, employment, quality, governance, audit or legitimate business purposes. When information is no longer required, DANS takes reasonable steps to securely destroy or de-identify it, unless retention is required or authorised by law.
14.0 Access, correction and changes to consent
You may request access to personal information DANS holds about you, and may request correction if information is inaccurate, out of date, incomplete, irrelevant or misleading. DANS will verify identity and authority before providing access or making a correction.
DANS may refuse or limit access where permitted by law, including where access would unreasonably affect another person's privacy, relate to legal proceedings, create safety concerns, be frivolous or vexatious, or where refusal is otherwise required or authorised by law. Where DANS refuses access or correction, reasons are provided where appropriate.
You may amend or withdraw consent where lawful and practical. DANS will document the change and assess any impact on care planning, service coordination, information sharing, safeguarding, clinical care, funding or continuity of supports.
15.0 Notification and privacy information
When DANS collects information, it takes reasonable steps to make sure you understand what is collected, why it is collected, how it is used, who it may be shared with, how it is stored and protected, how you can access or correct it, how you can change your consent, and when information may be disclosed without consent where required or authorised by law.
Privacy information is provided in a language, format, mode of communication and terms you are most likely to understand. Workers offer support, interpreter assistance, representative involvement or advocacy information where needed.
16.0 Privacy incidents, data breaches and complaints
Any suspected privacy incident, unauthorised disclosure, unauthorised access, lost record, lost device, cyber concern, supplier incident, inappropriate information sharing or confidentiality breach must be reported immediately. DANS contains the incident, preserves evidence, assesses harm, determines notification obligations and completes corrective actions.
Where an eligible data breach is likely to cause serious harm, DANS assesses whether notification to affected individuals and the Office of the Australian Information Commissioner is required under the Notifiable Data Breaches Scheme. Depending on the service context, DANS also assesses whether notification to the NDIS Commission, Aged Care Quality and Safety Commission, ACIS / icare, DVA, police, emergency services or another body is required.
Privacy complaints are managed through the DANS complaints management process. Complaints are acknowledged, recorded, assessed, investigated where required, responded to, monitored for closure and reviewed for continuous improvement. You may also be given information about external complaint pathways, including the Office of the Australian Information Commissioner where relevant.
17.0 Governance, training and audit evidence
The Governing Body approves this policy and receives oversight of material privacy risks, serious data breaches, significant complaints, audit findings and improvement actions. The Executive Manager is responsible for implementing privacy governance, reviewing risks, approving high-risk information handling arrangements and ensuring corrective actions are completed.
DANS maintains evidence of privacy implementation through training records, worker acknowledgements, consent records, authorised representative records, disclosure notes, access and correction request records, privacy complaint records, data breach records, supplier controls, internal audits, governance minutes and continuous improvement actions.