Privacy explained

Privacy means things we know about you and what we do with what we know. There are laws to protect your personal information.

Personal information could be about:

  • your name
  • where you live
  • your date of birth
  • your health or disability information.

We’ll keep your information private and won’t tell people about it unless we have to. 

What information we keep

We keep personal information about different people. For example, people who use the NDIS, our staff and disability service providers.

The personal information we keep is your name, your bank account, information about your disability, what supports you get.

We won't tell anyone about your personal information.

How we get personal information

We get personal information from you or someone who helps you with the NDIS. For example, a carer, disability service providers, or other government departments.

You can give consent for other people to give us your information. Consent means you say yes.

You don't have to give us all your personal information. If you don't consent we might not give you an NDIS plan or supports you need.

We might ask you for your information by phone, by email, in person.

If you aren't sure the person you speak to is from the NDIS you can:

  • ask them to say your NDIS reference number
  • call the NDIS and ask for the person.

If you think you spoke to someone who isn't from the NDIS:

How we use personal information

We use personal information to help us give you services, manage the NDIS and contact you.

We might need to tell other people about you because they help with your NDIS plan or give you supports you need.

When you get an NDIS plan you consent for us to tell service providers about you.

How we keep personal information safe

We keep paper records safe in our offices. Our offices have secure access where you need a special pass to get in the building.

We keep information on our computers safe and we only tell people your information if the law says they can know.

About our website and social media

We might find out your personal information from our:

  • website
  • myplace or my NDIS portal or my NDIS app
  • social media.

We get information about how people use our website. For example:

  • what website pages people look at
  • what documents people look at online
  • what people search for online.

You can see the personal information we have about you on your participant portal or the my NDIS app

You can tell us if the personal information we have about you is wrong.

We can tell other service providers about changes to your personal information for you.

NDIA privacy policy

The NDIA privacy policy sets out in detail how we handle your personal information, including:

  • when we collect information about you
  • how we use your personal information
  • who your personal information may be shared with
  • your choices about the way that we use your information.

The NDIA privacy policy is relevant to individuals who interact with, or are considering interacting with, the NDIA or the NDIS.

Download the NDIA privacy policy :

Download the NDIA privacy policy in easy read:

Privacy collection notices

In addition to the privacy policy, we may provide a Privacy Collection Notice that contains important information about a specific collection of personal information, such as when you download the my NDIS app.

You can download our privacy collection notices in the participant and provider portals and in the my NDIS app.  

Protecting your personal information after a data breach

We take the protection of individuals’ data and information security extremely seriously. We have systems and processes in place to protect participants’ and other stakeholders’ information.

You can be a target of identity theft and fraud if your personal information is exposed in a data breach.

A data breach is when personal information is accessed, disclosed or used without authorisation. Identity theft and fraud can have serious implications. This can include financial loss and emotional harm.

Previous large data breaches

For information on specific large data breaches, you can visit:

How you can protect your personal information after a data breach

There are actions you can take to reduce the risk of harm if your personal information was accessed after a data breach. You can:

  1. Stay alert to increased scam activity, particularly email and SMS or telephone phishing scams. These scams look like they come from an organisation you know but are fake.
  2. Do not click on any suspicious links or provide your passwords or any personal information. Always refuse any unprompted request from an individual to access your computer even if they say they're from a credible organisation.
  3. Change your online account passwords. Always use strong passwords. The Australian Cyber Security Centre has guides on good password practices.
  4. Enable multi-factor authentication for your accounts where possible. This means using extra checks to prove your identity.
  5. Install up-to-date anti-virus software on any devices you use to access your online accounts.
  6. Monitor your bank account transactions and check your credit report to see if it has any unauthorised loans or applications.

Learn more about protecting your myGov, Centrelink, Medicare and Child Support accounts on the Services Australia website.

How the NDIA protects your personal information after a data breach

When a data breach happens, we take extra steps to protect your personal information and NDIS account.

These steps include:

  • We'll try to identify if you're affected by the data breach so that we can take appropriate actions.
  • If you're affected, we may contact you with information about protecting yourself and supports available to you.
  • We actively monitor your accounts for irregular activity.
  • If we identify unauthorised activity on your account, we’ll review it and take appropriate actions.
  • We may take extra steps to verify your identity when you contact us. This is to make sure we are speaking with the right person.

How can I make a complaint about privacy at the NDIA?

To make a complaint, you can get in touch by:

Privacy Impact Assessment Register

The Privacy (Australian Government Agencies – Governance) Australian Privacy Principles Code 2017 (Cth) (the Code) requires the NDIA to conduct a Privacy Impact Assessment (PIA) for all projects that involve personal information.

This register lists PIAs completed since the Code came into effect on 1 July 2018.

Reference list

ReferenceDateDescription

5575

August 2019Partner Access to the NDIA Staff Portal (Partner Portal)

7607

December 2019NDIA Business to Government Application Programmable Interface Phase 1

8600

April 2020Bring your own device

12614

June 2020NDIA Business to Government Application Programmable Interface Phase 2

15044

October 2020ACE Foundation Program (Release 1)

17910

March 2021Future Operating Environment

16871

May 2021NDIA Monitoring Aggregator

20095

June 2021Participant Portal Refresh Project

24616

November 2021Eligibility Integrity Uplift Project

23858

December 2021Assisting NDIS Participants with COVID-19 Vaccinations

24184

March 2022Object Storage and Analysis Service Project (OSAS) (Phase 1)

28721

October 20223P Project

31547

November 2022Processes in 3P (Participants, Platforms and Processes) Improvement Initiative

29485

December 2022Dynatrace

29569

June 2023Staff Identity and Access Management Project

34370

June 2023National Contact Centre Transformation Strategy 

37680

July 2023Migration of the i2 iBase Case Management System 

34617

October 2023ASIC Data for NDIA Project

34638

December 2023Investigations analysis capabilities

41696

March 2024Purview eDiscovery Project

50392

August 2024Microsoft Viva Insights Pilot

48938

October 2024CDoF Data Platform

52474

October 2024Simply Stakeholders (Darzin Software)

53178

December 2024Posit Benchwork

52085

January 2025External Code of Conduct Investigations

54112

January 2025Digital Collaboration Platform

46451

February 2025Fraud investigation support platform

53908

March 2025Integrity Management System (IMS)

55315

March 2025Form.io data form builder

50265

June 2025Data Sharing Agreement between the NDIA and the Department of Home Affairs

63510

June 2025Log Landing Zone

53121

July 2025Purview eDiscovery

51362

August 2025NDIA Application Programming Interface (API) Gateway – Release 1

57326

August 2025Blended Payments Initiative

51366 

November 2025CDoF – CIAM Releases 1-4 

62781

November 2025CDoF 11 – eInvoice

63068

November 2025Risk Scoring and Response Capability Project

7453

December 2025Data Sharing Agreement between Services Australia and the NDIA for identity checking and related purposes

66739 

December 2025Data Sharing Agreement between NDIA and the Australian Skills Quality Authority (ASQA) 

70200

January 2026Managed File Transfer – Go Anywhere

71401

March 2026Talent Database

70874 

April 2026 CDoF 10 Measures 

59743 

May 2026Data Sharing Agreement between NDIA and Department of Health, Disability and Ageing

71417

June 2026Geographical Information System

62251

June 2026Data Sharing Agreement between NDIA and the Australian Financial Crimes Exchange

For further information, please email [email protected].

Last updated: September 2026

Video

Common questions about privacy

Learn about the answers to common questions about our privacy policy in this video.

Contact supports and services

Translating and interpreting

Find out about language interpreting services or phone 131 450.

National relay service

Visit the National Relay Service website.

Family violence support

This page current as of
4 September 2026