Trust & Compliance
Data Security & Residency
Your data — and the data of the communities we serve — stays in Australia, encrypted, and protected by controls aligned to the Australian Government Information Security Manual (ISM), the ACSC Essential Eight, and the Privacy Act 1988 (Cth).
Australian Data Residency
All personal data — including NDIS participant records, employee HR data, video interview recordings, and form submissions — is stored exclusively on servers located in Australia. We do not transfer personal data offshore except where explicitly required by law and with your consent.
Encryption in Transit & at Rest
All data in transit is encrypted using TLS 1.2 or higher. HSTS (HTTP Strict Transport Security) with a 2-year max-age and preload is enforced across all endpoints. Sensitive fields including passwords and health information are encrypted at rest using AES-256. Video interview recordings are stored with server-side encryption.
Access Controls & Authentication
All administrative portals (Admin Portal, ATS, Yarning Connect) require authenticated sessions with role-based access controls. API endpoints are protected by server-side session validation. Sensitive operations (delete, export) require elevated permissions. All access attempts are logged.
Security Headers & Browser Protection
All HTTP responses include a comprehensive set of security headers: Content Security Policy (CSP), X-Frame-Options, X-Content-Type-Options, Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy, and Permissions-Policy. These prevent clickjacking, XSS injection, MIME sniffing, and cross-origin data leaks.
Rate Limiting & Abuse Prevention
All API endpoints are protected by IP-based rate limiting. Sensitive endpoints (form submissions, login, career applications, video interview submissions) are subject to strict limits of 20 requests per 15 minutes per IP. This prevents brute-force attacks, credential stuffing, and automated abuse.
Data Minimisation & Retention
We collect only the minimum personal information necessary for each purpose (data minimisation). Retention periods are defined per data category: recruitment records (7 years — Fair Work Act 2009), NDIS service records (7 years or until participant turns 25), employee records (7 years post-employment), general enquiries (3 years). Data is securely deleted at end of retention period.
Notifiable Data Breaches
Yarning Crescent is subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988. In the event of an eligible data breach, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) within 30 days of becoming aware of the breach. We maintain an internal breach response plan.
NDIS-Specific Data Obligations
As an NDIS service provider, we comply with the NDIS Practice Standards for data governance and information management. Participant health information is treated as sensitive information under the Privacy Act. NDIS Worker Screening data is handled per the NDIS (Worker Screening) Act 2020. We do not share participant data with the NDIA beyond what is required for service delivery.
Continuous Security Review
Security controls are reviewed regularly against the Australian Cyber Security Centre (ACSC) Essential Eight maturity model and the Australian Government Information Security Manual (ISM). Dependencies are monitored for known vulnerabilities. Staff receive annual privacy and security awareness training.
Regulatory Framework
Privacy
- Privacy Act 1988 (Cth) — Australian Privacy Principles (APPs)
- Notifiable Data Breaches scheme (Part IIIC)
- Office of the Australian Information Commissioner (OAIC)
NDIS
- National Disability Insurance Scheme Act 2013 (Cth)
- NDIS Practice Standards — Quality Indicators
- NDIS (Worker Screening) Act 2020 (Cth)
Employment
- Fair Work Act 2009 (Cth) — record-keeping obligations
- Anti-Discrimination Act 1977 (NSW)
- Work Health and Safety Act 2011 (Cth)
Cyber Security
- Australian Government Information Security Manual (ISM)
- ACSC Essential Eight Maturity Model
- OWASP Top 10 & API Security Top 10
Questions about our security practices?
Our Privacy Officer is available to answer questions about data handling, security controls, or to process access and deletion requests.