NDIS Provider Privacy and AI Documentation: Consent, Access, and Human Review

A practical privacy guide for NDIS providers using AI or digital documentation tools, covering consent, data handling, access, accuracy, retention, and human oversight.

Published by Privacy and Security Team

AI Convenience Does Not Remove Provider Responsibility

AI can help structure a draft, identify missing detail, or reduce repetitive typing. The provider remains responsible for lawful collection and use, participant privacy, record accuracy, access controls, retention, and the final professional judgement applied to the note.

Do not paste participant information into a public or unapproved AI service. First confirm the provider's governance, contract, security assessment, and permitted data flow.

Map the Information Before Selecting a Tool

  • What personal, health, audio, behavioural, or location information enters the system?
  • Where is the information processed and stored?
  • Which vendors or subprocessors can access it?
  • Is provider data used to train models?
  • How are deletion, retention, backup, and data export handled?
  • What happens if the service is unavailable or the contract ends?

Privacy Act coverage, state or territory requirements, health-record rules, service agreements, and contractual obligations may all be relevant.

Consent Must Be Meaningful

Where consent is the basis for a feature such as audio capture, explain the purpose, information collected, people with access, alternatives, retention, and how the participant can change their choice. Provide accessible communication and avoid bundling optional recording into acceptance of essential support.

Use Human Review Before Saving

An AI-generated draft can omit context, merge speakers, introduce facts, or use stigmatising language. The worker should compare the draft with the actual support, correct errors, remove irrelevant information, confirm names and times, and take responsibility for the saved record.

Example AI Documentation Workflow

  1. Worker records factual session details in the approved secure system.
  2. The tool structures a draft using the provider's note framework.
  3. The worker verifies every statement and checks participant-centred language.
  4. Required escalation or incident processes are completed separately.
  5. The final note is saved with user identity, date, time, and audit history.

Control Access by Role

Workers should only access information needed for their authorised duties. Use individual accounts, strong authentication, prompt access removal, audit logs, secure devices, and processes for unusual access or suspected breaches. Shared logins undermine accountability.

Common Privacy Failures

  • Using consumer AI accounts for identifiable participant notes.
  • Recording audio without a clear approved process.
  • Assuming a polished draft is factually correct.
  • Giving every worker unrestricted access to every participant file.
  • Keeping exports on personal devices or email accounts.

Review AccuNote's approach on the security page and use the NDIS digital progress-note guide when planning a documentation workflow.


This article was written by AccuNote's Privacy and Security Team for general education. It is not legal advice. Providers should assess current privacy, records, consent, cyber security, NDIS, contractual, and jurisdictional requirements.