Information Management Policy
We treat your information with care and respect.
DANS In Home Care documents how we handle your information across our systems and with our approved suppliers.


This policy sets out how DANS In Home Care creates, collects, records, classifies, stores, accesses, uses, shares, reviews, retains, archives and disposes of information. It supports consistent information governance across DANS systems, records, paper files, registers, emails and approved supplier platforms.
1.0 Policy statement
DANS In Home Care is committed to managing information as a critical organisational asset. Information must be accurate, current, secure, accessible to authorised users, retained for required periods, disposed of safely, and capable of supporting safe service delivery, clinical governance, funding claims, business continuity, quality assurance and audit readiness.
DANS will manage records in a way that protects privacy and confidentiality, supports informed choice and consent, enables continuity of supports, and meets legal, regulatory, contractual and funding requirements.
DANS will apply the highest relevant information management requirement where services are delivered across NDIS, aged care, DVA, ACIS / icare or private service arrangements.
2.0 Purpose
This policy defines DANS expectations for how information is created, collected, recorded, classified, stored, accessed, used, shared, reviewed, retained, archived and disposed of. It supports consistent information governance across DANS systems, records, paper files, registers, emails and approved supplier platforms.
- Safety and continuity: ensure workers can access accurate and current information required to deliver safe services.
- Privacy and consent: ensure client information is collected, used, disclosed and recorded in line with consent and lawful authority.
- Audit readiness: ensure records show what occurred, what decisions were made, who approved actions and what evidence supports compliance.
- Security and availability: ensure information remains protected and recoverable during system disruption, emergency or business continuity events.
- Governance oversight: ensure information risks, incidents, audits and improvement actions are reported and monitored.
3.0 Scope
This policy applies to all DANS records and information assets regardless of format, system, storage location or owner, including electronic records, paper files, emails, spreadsheets, registers, system exports, backups, manual downtime records, photographs, scanned documents and approved third-party or cloud-based systems.
Information covered includes client records, clinical and care records, consent records, representative and information-sharing records, service agreements, Participant Planning Tool records, AlayaCare records, workforce records, financial and claiming records, incident and complaint records, governance records, risk registers, audit records, ICT records, supplier records and continuous improvement evidence.
4.0 Legislative and standards alignment
This policy is aligned with the Privacy Act 1988 (Cth), the Australian Privacy Principles, the Health Records and Information Privacy Act 2002 (NSW), the Notifiable Data Breaches Scheme, the Aged Care Act 2024, the Strengthened Aged Care Quality Standards, the NDIS Act 2013, the NDIS Practice Standards, the NDIS Code of Conduct, ACIS / icare requirements, DVA provider requirements and relevant contractual obligations.
DANS demonstrates information management compliance through approved systems, client records, consent and authority records, access control, information incident records, data breach records, retention and disposal records, supplier controls, internal audits, governance minutes and continuous improvement actions.
5.0 Information management principles
- Single source of truth: important service, clinical, consent, risk and governance information must be recorded in the approved system, not left only in emails, messages or informal notes.
- Accuracy and currency: records must be updated when client circumstances, care needs, representatives, consent arrangements, risks, service details or worker instructions change.
- Need-to-know access: information access must be limited to current role, care, business, governance, funding or legal need.
- Findability: information must be saved in a location where authorised users can locate it for service delivery, audit, continuity and governance purposes.
- Security: information must be protected from misuse, interference, loss, unauthorised access, modification or disclosure.
- Auditability: decisions, approvals, reviews, incidents, complaints, access changes and record disposal must be evidenced.
- Retention and disposal control: records must be retained, archived and destroyed through approved processes, not deleted informally.
- Business continuity: critical information must remain accessible through approved downtime and recovery arrangements.
6.0 Information lifecycle requirements
DANS information must be managed across its full lifecycle. Workers and managers must create or collect only information required for an approved purpose, explain collection, use, disclosure and consent arrangements where relevant, classify information according to sensitivity, record information in approved systems, store information securely, use and disclose information only for authorised purposes, review information for accuracy and ongoing need, archive inactive records where required, and securely destroy or de-identify information once retention requirements have ended and no legal, funding, complaint, incident or audit hold applies.
The Information Management Procedure defines the operational workflow, including approved systems, recording requirements, information classification, access control, retention, archiving, disposal, supplier controls, downtime records, monitoring and evidence requirements.
7.0 Approved systems and record locations
DANS records and information must be stored, managed and maintained in approved systems, platforms and record locations appropriate to the type, sensitivity and purpose of the information.
Official records are kept in controlled locations that support authorised access, privacy, confidentiality, record integrity, service continuity, audit readiness and regulatory compliance. Information must not be stored in informal, personal or unmanaged locations where it cannot be accessed, protected, reviewed or retained in accordance with DANS requirements.
Final records must be saved to, or clearly referenced in, the approved record location. Working drafts, emails, temporary files and paper records must be managed so that important information is not lost, duplicated, left outside the official record, or retained longer than required.
8.0 Client information, consent and representative authority
DANS must ensure clients are provided with information about privacy, information collection, information sharing and consent arrangements during intake, onboarding and review, in a language, format, communication mode and terms the person is most likely to understand.
Consent, information-sharing arrangements, authorised representatives, nominees, guardians, attorneys and any restrictions on information sharing must be documented in the approved client record. Where consent is amended or withdrawn, DANS must document the change, review the impact on service delivery, and communicate relevant changes appropriately.
DANS must verify representative authority before accepting instructions or disclosing information. Workers must not assume that a family member, friend or support person has authority to access information or make decisions.
9.0 Records creation and quality
Records must be factual, objective, timely, complete and respectful, describing observations, actions, decisions, outcomes, follow-up and escalation where relevant.
Records must clearly show current consent arrangements, representative authority, information-sharing restrictions, risks, care instructions, service changes, incidents, complaints, review outcomes, worker instructions and governance decisions where relevant. Errors must be corrected through approved processes and must not be deleted or overwritten to hide an error.
10.0 Access control and identity governance
Access to DANS information must be based on role, current duties and need-to-know. New access, changed access, privileged access, supplier access and removal of access must be approved and evidenced. DANS maintains documented access governance controls, including an approved System Access and Permissions Matrix.
Supplier access must be limited to the systems and information required for the agreed service, and removed when no longer required. Administrative or privileged access must be limited to named users with documented need and subject to review.
11.0 Information security and technology controls
DANS must maintain reasonable security safeguards for information, including role-based permissions, secure authentication, multi-factor authentication where required, device security, email security, endpoint protection, physical security for paper records, backup arrangements, access logging, supplier controls and worker training.
DANS systems and any AI-enabled or automated tools must be used in accordance with DANS ICT, cyber security, privacy and information management requirements. DANS information must not be entered into public AI tools or unapproved external systems.
12.0 Retention, archiving and disposal
DANS must retain records for applicable legal, clinical, funding, governance, employment, audit and business requirements. Records must not be destroyed while they are required for active service delivery, complaint handling, incident review, investigation, funding audit, legal matter, regulator request, business continuity review or other organisational purpose.
Inactive records must be archived in approved locations where retention is still required. Records may only be destroyed or de-identified after a retention check confirms that no legal, funding, complaint, incident, audit or business hold applies. Disposal must be secure and evidenced through an approved disposal log, certificate or record.
13.0 Supplier and third-party information management
Before engaging a supplier or third-party provider that handles DANS information, DANS must consider privacy, security, data location, support location, subcontracting, breach response and exit arrangements. Contractual arrangements must require confidentiality, privacy, access limitation, breach notification, return or destruction of information and appropriate security controls.
Where a supplier stores or accesses information from overseas, DANS must ensure this is disclosed and controlled in accordance with privacy, APP 8, NSW health privacy and DANS legal advice requirements. NDIS portal-derived information must not be accessed, stored, transferred or processed outside Australia unless prior written NDIA approval has been obtained.
14.0 Information incidents and data breaches
Any suspected information incident, privacy breach, unauthorised access, unauthorised disclosure, lost record, lost device, supplier breach, cyber incident, incorrect recipient, incorrect attachment, inappropriate information sharing or record integrity concern must be reported immediately.
DANS will contain the incident, preserve evidence, identify affected information, assess harm and notification obligations, complete corrective actions and record outcomes. Where required, the Data Breach Response and Notification Plan, Incident Management Procedure, Complaints Management Procedure, Business Continuity Plan and regulator notification pathways must be activated.
15.0 Governance, monitoring and audit
The Governing Body approves this policy and receives oversight of material information risks, data breaches, audit findings and improvement actions. The Executive Team is responsible for implementing information governance, reviewing information risks, approving high-risk information handling arrangements and ensuring corrective actions are completed.
DANS monitors information management through access reviews, client file audits, CMS quality reviews, consent and information-sharing audits, retention and disposal checks, supplier reviews, backup and recovery evidence, incident reviews, complaint trend reviews, governance reporting and continuous improvement actions.
16.0 Roles and responsibilities
- Governing Body: approves the policy and oversees material information governance risks, serious incidents, audit findings and corrective actions.
- Executive Team: implements governance controls, approves high-risk changes and monitors compliance, security and information risk.
- Management: maintains procedures, registers, audits, access reviews, retention/disposal controls, supplier controls and improvement actions.
- Care Partners and managers: ensure client records, consent, representatives, information-sharing restrictions, care plans and service records are complete and current.
- Clinical Lead / Registered Nurses: ensure clinical and health information is accurate, objective, secure and available for safe care.
- All workers: record information accurately, use approved systems, protect confidentiality, follow consent restrictions and report information incidents immediately.
- Contractors and suppliers: handle DANS information only for approved purposes and notify DANS of actual or suspected privacy, cyber or information incidents immediately.