The NDIS Quality and Safeguards Commission has responded to feedback on the proposed changes to the NDIS Act (Bill No. 2), which aim to enhance the safety and wellbeing of NDIS participants receiving services from funded providers.

A key proposal is the introduction of a new statutory duty requiring NDIS provider key personnel to exercise due diligence in ensuring compliance with the NDIS Act, particularly in relation to enhanced safety measures for participants. Failure to comply with these new obligations could result in more severecivil penalties than currently imposed.


Key Proposed Changes

The proposed changes include new requirements relating to several key areas:

  • New statutory duties for key personnel and providers
  • Changes to penalties the Commission can impose, including banning orders and anti-promotion orders
  • Changes to the conditions and timeframes for providing information or documents to the Commission on demand
  • Changes to information gathering, storing and distribution, including the requirement to store all data in Australia.

Another key element of the proposal is that providers will need to demonstrate they are taking a more proactive approach to preventing harm to their participants. This raises an important concern.

How much will this new approach impinge on participants’ dignity of risk, and how far will the line shift in relation to providers having a statutory obligation to exercise their duty of care?

Also included in the proposal is a more robust set of reporting requirements, with shorter timeframes and a wider scope for what information or documents can be demanded by the Commission.

There is still uncertainty about the scope of the proposed change, who it would actually cover, and whether small or unincorporated providers should be excluded. Some suggest it could deter people from stepping into leadership roles or lead to overly cautious decision-making that stifles innovation. Others argue it could improve accountability within organisations and should even extend to frontline workers.


Child and Youth Risk Management Strategy

At the same time, the Commission is implementing changes to its Child and Youth Risk Management Strategy, which is a more complex task given the need to incorporate each State and Territory’s guidelines into a national approach.

From my initial reading of the proposed initiative on the Queensland Family & Child Commission’s website, the 10 Child Safe Standards mirror the existing NDIS Quality and Safeguards Commission’s framework, but with additional measures designed to strengthen child-centric and culturally inclusive practice.

In addition to those changes, there are also new measures relating to the gathering and storage of data and incident reporting, including policies about:

  • The safe use of digital technology
  • A 24-hour notification timeframe for the reporting of abuse incidents
  • New rules relating to photos, videos, parental consent, CCTV, and the use of service-provided devices.

While individual states have adopted these measures at different times over the past two years, all of these changes are scheduled to be embedded into the National Quality Standards from 1 January 2026.


Requirement that Information Be Held in Australia

One of the proposed changes across both initiatives that may have significant ramifications for providers using international cloud-based services, such as OneDrive or Google Drive, is that all data, including cloud-based data, must be stored in Australia.

Some stakeholders have protested that this change could add significant costs and administrative burden, particularly for smaller organisations. However, these objections often overlook the local IT sector. For example, Sonic Software already meets these stringent requirements through its ISO 27001 Compliance measures and use of Australian-based Google servers for enhanced data protection.

By leveraging this robust security architecture, Support Coordination Software provides a reliable and secure platform for Support Coordination providers, offering peace of mind to participants and partners in an ever-evolving cybersecurity landscape.

Additional features such as inbuilt action plans and risk management planning tools, a folder system for file notes, and a powerful internal search engine to assist in the retrieval of key records, add to Support Coordination Software’ ability to help providers not only meet compliance requirements but also achieve best practice in their daily operations.


What’s Next

The NDIS Commission will use the feedback received to shape an Exposure Draft of the new Bill, giving people another opportunity to provide input. Unfortunately, the timeframes set at the beginning of the year have already passed, and we are yet to hear any updates.


Useful Links


Benefits of using purpose built software

Apart from helping you manage all of your person-centred planning and compliance resources in one place, Support Coordination Software ensures your data is securely stored in Australia, meeting all proposed data requirements under the new Bill.

All of our subscribers are part of a Community of Support Coordinators with access to Masterclasses and Communities of Practice, where we discuss the latest NDIS developments and provide practical guidance on how to continue achieving best practice in an ever-changing environment.

👉 Want to find out more about how Support Coordination Software helps you deliver best practice in Support Coordination.

Click here to book a demo or sign up for a no obligation 14-day free trial.