Skip to main content

Trust & Compliance

Data Security & Residency

Your data — and the data of the communities we serve — stays in Australia, encrypted, and protected by controls aligned to the Australian Government Information Security Manual (ISM), the ACSC Essential Eight, and the Privacy Act 1988 (Cth).

Australian Data ResidencyTLS 1.2+ EncryptionAES-256 at RestHSTS PreloadPrivacy Act 1988 (Cth)NDIS Practice Standards

Australian Data Residency

All personal data — including NDIS participant records, employee HR data, video interview recordings, and form submissions — is stored exclusively on servers located in Australia. We do not transfer personal data offshore except where explicitly required by law and with your consent.

Privacy Act 1988 (Cth) — APP 8 (cross-border disclosure)NDIS Practice Standards — Data governanceAustralian Government ISM — Data residency controls

Encryption in Transit & at Rest

All data in transit is encrypted using TLS 1.2 or higher. HSTS (HTTP Strict Transport Security) with a 2-year max-age and preload is enforced across all endpoints. Sensitive fields including passwords and health information are encrypted at rest using AES-256. Video interview recordings are stored with server-side encryption.

Australian Government ISM — Control 1407 (HSTS)ISM — Control 0460 (TLS)OWASP Transport Layer Security Cheat Sheet

Access Controls & Authentication

All administrative portals (Admin Portal, ATS, Yarning Connect) require authenticated sessions with role-based access controls. API endpoints are protected by server-side session validation. Sensitive operations (delete, export) require elevated permissions. All access attempts are logged.

Privacy Act 1988 (Cth) — APP 11 (security of personal information)NDIS Practice Standards — Governance and operational managementAustralian Government ISM — Access control

Security Headers & Browser Protection

All HTTP responses include a comprehensive set of security headers: Content Security Policy (CSP), X-Frame-Options, X-Content-Type-Options, Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy, and Permissions-Policy. These prevent clickjacking, XSS injection, MIME sniffing, and cross-origin data leaks.

OWASP Secure Headers ProjectAustralian Government ISM — Web application securityACSC Essential Eight — Application control

Rate Limiting & Abuse Prevention

All API endpoints are protected by IP-based rate limiting. Sensitive endpoints (form submissions, login, career applications, video interview submissions) are subject to strict limits of 20 requests per 15 minutes per IP. This prevents brute-force attacks, credential stuffing, and automated abuse.

ACSC Essential Eight — Restrict administrative privilegesOWASP API Security Top 10 — API4 (Rate Limiting)Australian Government ISM — Network access controls

Data Minimisation & Retention

We collect only the minimum personal information necessary for each purpose (data minimisation). Retention periods are defined per data category: recruitment records (7 years — Fair Work Act 2009), NDIS service records (7 years or until participant turns 25), employee records (7 years post-employment), general enquiries (3 years). Data is securely deleted at end of retention period.

Privacy Act 1988 (Cth) — APP 3 (collection) & APP 11.2 (destruction)Fair Work Act 2009 (Cth) — s.535 (record-keeping)NDIS Practice Standards — Records management

Notifiable Data Breaches

Yarning Crescent is subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988. In the event of an eligible data breach, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) within 30 days of becoming aware of the breach. We maintain an internal breach response plan.

Privacy Act 1988 (Cth) — Part IIIC (Notifiable Data Breaches)OAIC — NDB scheme guidanceACSC — Cyber Incident Response Plan

NDIS-Specific Data Obligations

As an NDIS service provider, we comply with the NDIS Practice Standards for data governance and information management. Participant health information is treated as sensitive information under the Privacy Act. NDIS Worker Screening data is handled per the NDIS (Worker Screening) Act 2020. We do not share participant data with the NDIA beyond what is required for service delivery.

NDIS Act 2013 (Cth) — Part 8 (information management)NDIS Practice Standards — Quality Indicator 1.5NDIS (Worker Screening) Act 2020 (Cth)Privacy Act 1988 (Cth) — Sensitive information

Continuous Security Review

Security controls are reviewed regularly against the Australian Cyber Security Centre (ACSC) Essential Eight maturity model and the Australian Government Information Security Manual (ISM). Dependencies are monitored for known vulnerabilities. Staff receive annual privacy and security awareness training.

ACSC Essential Eight Maturity ModelAustralian Government ISM (current edition)OWASP Top 10 Web Application Security Risks

Regulatory Framework

Privacy

  • Privacy Act 1988 (Cth) — Australian Privacy Principles (APPs)
  • Notifiable Data Breaches scheme (Part IIIC)
  • Office of the Australian Information Commissioner (OAIC)

NDIS

  • National Disability Insurance Scheme Act 2013 (Cth)
  • NDIS Practice Standards — Quality Indicators
  • NDIS (Worker Screening) Act 2020 (Cth)

Employment

  • Fair Work Act 2009 (Cth) — record-keeping obligations
  • Anti-Discrimination Act 1977 (NSW)
  • Work Health and Safety Act 2011 (Cth)

Cyber Security

  • Australian Government Information Security Manual (ISM)
  • ACSC Essential Eight Maturity Model
  • OWASP Top 10 & API Security Top 10

Questions about our security practices?

Our Privacy Officer is available to answer questions about data handling, security controls, or to process access and deletion requests.