NDIA Offsite Data Record Storage Policy and Procedures

Shirley made this Freedom of Information request to National Disability Insurance Agency

This request has been closed to new correspondence from the public body. Contact us if you think it ought be re-opened.

The request was partially successful.

Dear National Disability Insurance Agency,

Please provide a copy of the NDIA Offsite Data Records Storage Policy and Procedures. That is, the specific policy and procedures that guide, manage and evaluate the NDIA’s data records stored and/or accessed from the various NDIS physical sites or locations.

Context:

As a national Commonwealth entity, the NDIA occupies many physical locations [1]. Therefore, it is reasonable to assume that recorded data and information are contained both at NDIS locations and ‘other’ locations. That is, non-NDIA offices and controlled or managed physical space. According to the National Archives of Australia (NAA), this may present as a risk for Commonwealth Government Agency. As a result, the NAA provides specific guidance on conducting risk assessments [2], further suggesting that “Agencies may have other records management risks that apply specifically to their business functions. In addition, other general risks relating to outsourcing and data storage will need to be considered”. The NAA also provides guidance on other sources of information and regulatory compliance for Data Record Storage and management. This includes:

• Outsourcing digital data storage: Storing Commonwealth records in Data Centres, Digital Repositories and in the Cloud
• Risk Management: principles and guidelines (Australian Standard for Risk Management, AS/NZS ISO 31000:2009)
• ‘Security risk management’, Australian Government Protective Security Policy Framework (Attorney-General’s Department)
• Advice on Managing the Record keeping Risks Associated with Cloud Computing (Australasian Digital Record keeping Initiative)
• Australian Government Data Centre Strategy 2010–2025 (Department of Finance and Deregulation and Australian Government Information Management Office)
• Records Issues for Outsourcing including General Disposal Authority 25 (National Archives of Australia)

It is therefore reasonable to assume the NDIA’s policy and procedure aligns with these and other Commonwealth regulatory and legislative requirements.

Thank you for your assistance.

Yours faithfully,

Shirley

References:

1. NDIS (2021) Office and Contacts in your area, National Disability Insurance Agency, Australian Government, Available at: < https://www.ndis.gov.au/contact/locations >. Accessed [8 Jul 21]
2. NAA (2021) Records Management Risk Assessment Offsite Data Storage, version 1, National Archives of Australia, Australian Government, Available at: < https://www.naa.gov.au/sites/default/fil...>. Accessed [8 Jul 21]

foi, National Disability Insurance Agency

Thank you for your email to the National Disability Insurance Agency
(NDIA) Freedom of Information (FOI) team.  

 

If your email relates to an FOI application made under the Commonwealth
Freedom of Information Act 1982 (FOI Act), the Agency will respond to you
as soon as practicable. 

 

This email address is for applications under the FOI Act only. The Agency
is unable to respond to non-FOI related enquiries sent to this email
address. Any correspondence received that is not an information access
request will not be responded to or forwarded.  

 

If you are seeking to access your personal documents, please consider
submitting your request through our [1]Participant Information Access
(PIA) web-form, which will allow the matter to be processed
administratively. 

 

Should you have a query unrelated to FOI, please contact us by emailing at
[2][email address] or via webchat at [3]NDIA Web Chat (ndis.gov.au).
Alternatively you can also contact us by phoning 1800 800 110. 

 

If you have any questions about making an FOI request, or to enquire about
a current FOI request, please email us with your phone number and a
preferred time for us to call you, and an FOI Decision Maker will call you
back. 

 

Kind regards 

 

Freedom of Information team 

Parliamentary, Ministerial & FOI Branch  

Government  

National Disability Insurance Agency 

Email: [4][NDIA request email]  

show quoted sections

References

Visible links
1. https://aus01.safelinks.protection.outlo...
2. mailto:[email address]
3. https://aus01.safelinks.protection.outlo...
4. mailto:[NDIA request email]

foi, National Disability Insurance Agency

1 Attachment

Dear Shirley

Freedom of Information Request: Acknowledgement

Thank you for your request of 8 May 2022, made under the Freedom of
Information Act 1982 (FOI Act), for copies of documents held by the
National Disability Insurance Agency (NDIA).

Scope of your request

You have requested access to the following documents:

 

Please provide a copy of the NDIA Offsite Data Records Storage Policy and
Procedures. That is, the specific policy and procedures that guide, manage
and evaluate the NDIA’s data records stored and/or accessed from the
various NDIS physical sites or locations.

 

Processing timeframes

A 30-day statutory period for processing your request commenced from 9 May
2022, in accordance with section 15(2A)(c) of the FOI Act. You should,
therefore, expect a decision from us by 7 June 2022.

 

This period may be extended if we need to consult with third parties or
for other reasons. We will advise you if this happens.

 

Charges

We may apply a processing charge to your request and will advise you as
soon as practicable if a charge is payable.

 

Disclosure Log

Information released under the FOI Act may be published on the NDIA’s
disclosure log located on our website, subject to certain exceptions.

If you have any concerns about the publication of information you have
requested, please contact us.

 

Further help

Please contact us at [1][NDIA request email] if you have any questions or need
help.

We will contact you using the email address you provided. Please advise if
you would prefer us to use an alternative means of contact.

 

Kind regards

 

Freedom of Information Officer

Parliamentary, Ministerial & FOI Branch

Government Division

National Disability Insurance Agency

E: [2][NDIA request email]

 

[3]cid:image001.png@01D81DD8.7204AC80

 

show quoted sections

References

Visible links
1. mailto:[NDIA request email]
2. mailto:[NDIA request email]

foi, National Disability Insurance Agency

Dear Shirley

 

Thank you for your request for information.

 

We’re sorry to let you know that it’s taken us longer than expected to
process your request.  This is because of the need to consult with multple
areas to search for the information.

 

We are therefore writing to seek your agreement to a 30 day extension of
time under section 15AA of the FOI Act, making the new due date for a
decision 7 July 2022 if you agree.

 

Please let us know whether you agree by COB 7 June 2022. 

 

If you don’t agree, we may need to seek an extension from the Office of
Australian Information Commissioner.

 

We’re sorry that it’s taken us longer than expected and we appreciate your
patience.

 

Please contact us at [1][NDIA request email] if you have any questions or
require help.

 

Kind regards

 

 

show quoted sections

References

Visible links
1. mailto:[NDIA request email]

foi, National Disability Insurance Agency

5 Attachments

Dear Shirley

 

Thank you for your request for information.

 

Please find attached correspondence and documents in relation to your
request.  If you require these in a different format, please let us know.

 

Please contact us at [1][NDIA request email] if you have any questions or
require help.

 

Thank you.

 

Kind regards

 

Freedom of Information Officer

Parliamentary, Ministerial and FOI Branch

Government Division

National Disability Insurance Agency

E: [2][NDIA request email]

 

[3]Title: NDIS delivered by the National Disability Insurance Agency

[4]LGBTIQA+ rainbow graphic

The NDIA acknowledges the Traditional Custodians of Country throughout
Australia and their continuing connection to land, sea and community. We
pay our respects to them and their cultures and to Elders past, present
and emerging.

[5]Aboriginal and Torres Strait Islander flags graphic

 

show quoted sections

References

Visible links
1. mailto:[NDIA request email]
2. mailto:[NDIA request email]
4. https://intranet.ndiastaff.ndia.gov.au/h...