1.0 Purpose and scope
This policy demonstrates Each’s commitment to protecting and upholding the right to privacy and confidentiality of our customers, our personnel, the organisation, and key stakeholders. It also ensures that Each meets all legislative and regulatory requirements. This policy applies to our customers and Each personnel, including any third-parties working for Each.
2.0 Policy statement
2.1 Introduction
We respect everyone’s right to privacy of their personal, health and sensitive information in accordance with relevant privacy laws, principles, obligations and cultural respect. Relevant privacy laws and principles include:
- The Privacy Act 1988 (Cth) and the Australian Privacy Principles contained in this Act.
- State health privacy legislation principles.
- Other service-specific legislation, including:
- The Mental Health and Wellbeing Act 2022 (Vic), to include but not limited to: Division 1, Division 3, section 31, section 45, section 248, section 258, section 300, section 301, 302, section 304; and
- The Aged Care Act 2024 (Cth) and the Aged Care Rules 2025 (Cth) to include but not limited to: section 14-5(c), section 15-10 (3 )(4 ), section 154-3, section 155-85, section 133-112, section 230-15 (1 )(a)(b), section 507-10, and section 164 in relation to management of incidents and complaints.
We regularly review this policy in line with updates and changes to both Commonwealth and State/Territory legislation.
All Each personnel receive training on privacy practices and understand their obligations under the Each Code of Conduct relating to privacy and confidentiality. Personnel will always ensure that the privacy of customer and Each personnel information is protected.
Privacy and confidentiality are to be always respected and in all transactions. We do this by:
- Only collecting information which the organisation requires for its primary function.
- Ensuring that people are informed as to why we collect the information and how we manage that information.
- Using and disclosing personal information only for our primary functions, a directly related purpose, or for another purpose with the person’s consent.
- Storing personal information securely, protecting it from unauthorised access.
- Providing stakeholders with access to their own information, and the right to seek its correction.
We are committed to conducting a Privacy Impact Assessment (PIA) for our programs and services to identify any risks and improvements. We ensure that the PIA aligns with applicable accreditation standards, program and practice governance and guidelines, and complies with the Australian Privacy Principles and the requirements of the Office of the Australian Information Commissioner (OAIC).
2.2 Health records
We maintain a customer health records system that supports Each’s integrated models of care and service delivery and provides a complete, relevant, timely and accurate description of all supports provided to customers and of the organisation’s contact with the customer.
A hybrid (hard copy and electronic) customer records system is maintained and these records are: i. Unique to the individual customer. ii. Used by Each personnel to assist with and inform for assessment, care and treatment, continuity of care, customer and safety of personnel, quality, education, research, evaluation, medico-legal, funding, and statutory requirements. iii. Kept up to date. iv. Handled and stored in a manner that preserves the customer’s rights to privacy. v. Accessible to the customer upon request (as directed by legislation and regulations). vi. Locatable. vii. Retained, archived, and destroyed in accordance with relevant legislation and the requirements of our funding agreements.
2.3 Data management
2.3.1 Consent
Consent to collect, use, share and disclose personal, health or sensitive information is discussed at varying times from initial contact with Each through to the ongoing provision of services. Consent is an ongoing process and we check in with customers and personnel from time to time to ensure the information that we hold is current and maintained accurately.
Refer to the Collection, Use and Sharing of Personal and Sensitive Information Procedure
All personnel will discuss privacy with the customer at the time of collecting information and provide a copy of the Delivering services with trust and respect brochure. This brochure outlines:
- Why we collect personal (including health and sensitive) information.
- How their personal information is protected.
- Require express customer consent to share information with external services.
The information a customer provides may be collected, recorded and stored from the initial point of inquiry with implied consent, for example, basic demographic information and the reason for inquiry.
2.3.2 Anonymity
It is the right of an individual not to identify themselves when accessing services from Each. If a customer chooses not to disclose their identity, the level or type of service that we can offer may be limited. Most of our services require collection of personal information as this enables us to provide the most appropriate care, support and/or treatment. If a customer does not consent to collection of their personal information, the level or type of service that we can offer may be limited.
2.3.3 Collection
The primary purpose for Each to collect information is to ensure we provide high-quality, personalised services. When you contact Each, all information provided is recorded, including from an initial inquiry before receiving an Each service. Information is collected in a respectful, lawful, and non-intrusive way. Wherever possible, information is collected directly from the customer. If this is not possible or practical then personal information may be collected from a representative, from a carer or relative or from a third party such as another health service provider. The customer is notified if we have collected information from a third party. We only collect personal information for purposes that are directly related and necessary to our activities, the services that we provide and which is essential to the quality and effective administration of our services. We also collect personal information related to our personnel and others who participate in the functions and operations of Each. We only collect information necessary to facilitate employment with Each and meet compliance requirements. All records of a personal and confidential nature are maintained securely, and access restricted to authorised personnel.
With customer consent we may use an approved artificial intelligence (AI) scribe to support note taking during service delivery. Customers may decline the use of an AI scribe at any time and declining this will not affect the services, or any care or support they receive. AI scribes approved for use at Each must comply with our Australian privacy and other legislative obligations.
2.3.4 Use and disclosure
We only use personal information for the purpose for which it was given to us, or for purposes that are directly related to one of our functions or activities which would be reasonably expected, including our legal duty of care. Only personnel who are involved with customer care, support and treatment can access customer personal information. Information that is essential for continuing service and Each’s management, funding and quality assurance may be accessed by other appropriate personnel within Each. For example, some administrative personnel may have access to personal information in the course of their duties. The extent of this access is limited to information that is relevant for them to perform their official duties. We do not disclose personal information to other organisations or anyone else unless:
- there is consent for the disclosure.
- it would be reasonably expected, or have been told, that information of that kind is usually passed to those individuals, bodies, or agencies.
- it prevents or lessens a serious threat to somebody’s life or health.
- it is reasonably necessary for a law enforcement function.
- it is otherwise required or authorised by law.
Some information we collect is used to help plan our services, for reporting purposes to our funding bodies and for quality improvement. This information may also be used for research to help us to provide better overall healthcare for the community. As this information is not personally identifiable, specific consent to this is not required. For some services, information may be shared to assess or manage family violence risk, or to promote the wellbeing or safety of a child. This information may be shared without the customer’s consent if there is a serious threat to the customer’s or another person's life, health, safety, or welfare. It may also be shared without consent if it is necessary to assess or manage family violence, or to promote the wellbeing or safety of a child. Some of our funding agreements with government require transfer of personal files and information back to the funding body at the conclusion of the contract. Each is a national organisation. Personal information may be transmitted to organisations outside the customer’s home state. This is only done where there is explicit consent, or where the recipient organisation is subject to similar, binding privacy obligations and it is impracticable for the customer to provide consent, but it is reasonably believed that the customer would give consent. We do not disclose personal information to overseas recipients. Some examples of organisations that we regularly disclose information to include:
- Government departments such as
- The Department of Health and the Department of Fairness, Families and Housing (Vic)
- Primary Health Networks (Commonwealth)
- We may be required to disclose personal information and return files to them, for example at the conclusion of funding contracts.
- The National Disability Insurance Agency (NDIA). The National Disability Insurance Scheme Act 2013 s55(1) gives the NDIA the power to require production of information that is, among other matters, relevant to the functions of the NDIA.
- The Aged Care Quality and Safeguards Commission.
- Organisations included in the Family Violence Information Sharing Scheme (Family Violence Protection Act 2008 (Vic)) and Child Information Sharing Scheme (The Children Legislation Amendment (Information Sharing) Act 2018 (Vic)).
2.3.5 Data quality
We take steps to ensure that the personal information we collect is accurate, current, and complete. This includes maintaining and updating personal information when we are advised that personal information has changed, and at other times as necessary.
2.3.6 Data security
We take reasonable steps to protect the personal information we hold against loss, unauthorised access, use, modification, or disclosure and against other misuse. These steps may include password protection and encryption of digital information and securing paper files with physical access restrictions. Access to personal information held on computer systems is controlled and monitored. Only personnel required by their duties to have access to records and information systems are authorised to access such information. When no longer required, personal information is destroyed in a secure manner in accordance with the law and the requirements of our funding agreements.
2.3.7 Access and correction
Access to personal information is available on request. However, information relating to others or where the information would otherwise be exempt from disclosure by law is not provided. Proof of identity must be presented to us before personal information is released. Requests are made in writing and addressed to the Privacy & Health Records Coordinator. If we do not agree to provide access to personal information, the steps to take to seek a review or to appeal our decision (as applicable) are explained. Each provide contracted government services and as a result we may receive personal information requests under Freedom of Information legislation. This would occur when an individual receiving services at Each has made a request for access to their personal information directly with the government agency responsible for administering and funding that service. Each is contractually obliged to comply with these requests. Requests to correct personal information held by Each can be made to the Privacy & Health Records Coordinator (Privacy Officer). Requests are made in writing and must provide evidence to support the requested changes. If we do not agree to make the requested changes to personal information, a statement about the requested changes can be made and attached to the customer file.
2.3.8 Complaints about privacy
If there are concerns about the way we handle personal information, or a complaint relating to privacy matters, please forward details of the complaint to [email protected]. The complaint is then referred to the Each Customer Relations Coordinator who investigates the matter if this is required. Privacy complaints at Each are handled in line with the Each Customer Feedback Procedure.
2.3.9 Privacy breaches
A privacy breach is unauthorised access or disclosure of Each personnel, customer, or organisational information. A privacy breach may trigger reporting obligations under the Privacy Act 1988 (Cth).
2.4 Closed-Circuit Television (CCTV) Cameras
2.4.1 Collection
Each uses CCTV cameras at selected sites to enhance safety and security. Cameras may be located both inside and outside our premises and are installed for the following purposes:
- Safety and Security: To help protect staff, visitors, contractors, and property.
- Theft Prevention: To deter and investigate theft or damage.
- Incident Review: To provide a record of events if an investigation is required, such as threats or incidents involving staff or visitors.
CCTV cameras will never record any audio.
2.4.2 How CCTV works
Cameras automatically record footage, which may include images of individuals moving through monitored areas. In some areas, real-time footage may be displayed on screens.
CCTV does not use any facial recognition technology.
Some cameras are for live viewing only, while others record footage for a maximum of 30 days before it is securely deleted.
2.4.3 Signage and notification
Clear signage will always be displayed in areas where CCTV cameras are installed, ensuring transparency for customers and personnel, and any visitors.
2.4.4 CCTV compliance
All CCTV usage complies with relevant privacy laws and organisational policies.
Access to recorded footage is strictly controlled and limited to authorised personnel only.
Recorded footage is retained for no longer than 30 days, unless required for an investigation.
Individuals may request access to or review of, CCTV footage. Each will assess all requests on a case-by-case basis, taking into account factors including privacy obligations, the purpose of the request, operational requirements and any legal or regulatory considerations.
To obtain further information about our CCTV processes please contact our Privacy Officer, or refer to the CCTV Procedure.
2.5 Information collected online by Each
2.5.1 Collection
It is our usual practice to collect information about all visitors to our online resources. That information is very limited and only used to identify generic visitor behavioural patterns. Sometimes we use third party platforms to deliver information. These are sites hosted and managed by organisations other than Each. Before deciding if you want to contribute to any third-party site read their privacy policy. There are several methods that we use to collect visitor behaviours on each of our online platforms. We use Google Analytics on our website. Information and data collected through Google Analytics is stored by Google on servers in the United States of America, Belgium, and Finland. Customers can opt out of the collection of information via Google Analytics by downloading the Google Analytics Opt-out browser add on. When you visit any of our online resources, our metric tools may collect the following information about your visit for statistical purposes:
• server address • top level domain name (for example .com, .gov, .au, .uk etc.) • the date and time of your visit to the site • the pages you accessed, and documents downloaded during your visit • the previous site you visited • if you've visited our site before • the type of browser used.
We record this data to maintain our server and improve our services. We do not use this information to identify anyone personally.
2.5.2 Cookies
Most of our online platforms use sessions and cookies. The core functionality on these platforms is largely unaffected if cookies are disabled in the user’s browser but the user may be unable to access some advanced functions.
2.5.3 Data quality
We correct any personal information that we hold on request. If you are on one of our automated email lists, you may opt out of further contact from us by clicking the 'unsubscribe' link at the bottom of the email.
2.5.4 Data security
There are inherent risks in transmitting information across the internet and we do not have the ability to control the security of information collected and stored on third party platforms. In relation to our own servers, we take all reasonable steps to manage data stored on our servers to ensure data security, as outlined in 2.3.6.
2.5.5 Access and correction
For information about how to access or correct personal information collected on our website see 'Access and correction' (section 2.3.7) in this document.
2.5 Further information
To obtain further information regarding this privacy policy or to provide any comments, Each can be contacted as follows:
Telephone 1300 00 Each (1300 00 3224) Email [email protected] Post 20 Melbourne Street, Ringwood, Victoria 3134
3.0 Definitions
Customer: Each is committed to being a customer centric organisation. Our broad definition of customer means we are inclusive of all people who interact or engage with us, either externally or internally. Our customers include consumers, clients, participants, patients, carers, the community, stakeholders, partners, staff, volunteers and members. Consent: Refers to the agreement of the customer (or authorised representative) to a proposed action. Consent can be expressed or implied and must be current, specific, voluntary and the customer must have the capacity to understand what they are consenting to and its effects.
Each Personnel: All employees (whether employed full-time, part-time, fixed term or on a casual basis) Board members, volunteers, students, contractors and sub-contractors performing work on behalf of Each. Health Information: All information, (personal and health) collected to provide, or in the course of providing, health services. Implied Consent: In situations where we have not yet or are unable to obtain express consent, consent to record and store information a customer has provided may be inferred. Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable whether the information or opinion is true or not; and whether the information or opinion is recorded in a material form or not. Sensitive Information: Information or an opinion about an individual's race, ethnic origin, political opinion, beliefs or affiliations sexual preference or criminal record. It also includes health information.
4.0 Document owner
The Privacy Officer is the subject matter expert and person responsible for this document review.
5.0 References and related documents
5.1 External sources, resources, standards, regulation and law
The main legislation and regulations that apply are listed below. There may be other legislation and regulation that intersects and therefore this list is not exhaustive.
- Aged Care Act 2024 (Cth)
- Aged Care Rules 2025 (Cth)
- Child Wellbeing and Safety Act 2005 (Vic)
- Children Legislation Amendment (Information Sharing) Act 2018 (Vic)
- Crimes (Domestic and Personal Violence) Act 2007
- Domestic and Family Violence Protection Act 2012 (Qld)
- Family Violence Act 2016 (Act)
- Family Violence Act 2004 (Tas)
- Family Violence Protection Act 2008 (Vic)
- Freedom of Information Act 1982 (Vic)
- Health Records Act 2001 (Vic)
- Health Records and Information Privacy Act 2002 (NSW)
- Health Records (Privacy and Access) Act 1997 (ACT)
- Health Services Act 1988 (Vic)
- Information Privacy Act 2014 (ACT)
- Information Privacy Act 2009 (Qld)
- Mental Health and Wellbeing Act 2022 (Vic)
- My Health Record Act 2012 (Cth)
- National Disability Insurance Scheme Act 2013
- Privacy Act 1988 (Cth)
- Privacy and Data Protection Act 2014 (Vic)
- Privacy and Personal Information Protection Act 1998 (NSW)
- Personal Information Protection Act 2004 (Tas)
- Surveillance Devices Act 1999 (Vic)
- Surveillance Devices Act 2007 (NSW)
- The Children Legislation Amendment (Information Sharing) Act 2018 (Vic)