Guide · Records and retention

How long must an NDIS provider keep participant records?

Updated 28 July 2026 Ricardo Santos · AI Systems Engineer 8 min read
The short answer

Participant records must generally be retained for a minimum of seven years from creation or from the last date of service. For records relating to a child, retention runs until the participant turns 25, which can be considerably longer.

Worker screening records carry a seven-year requirement of their own, and from 1 July 2026 payment records must also be retained for seven years. A participant leaving your service does not start a deletion clock, it starts a retention clock.

7 yrsminimum for participant records
Age 25for records about a child
7 yrsworker screening records
7 yrspayment records, from 1 July 2026

What has to be kept

Broader than most providers assume. Evidence of services delivered, outcomes and participant responses. Any accident, injury or behavioural concern. Consent forms, risk assessments, goals, service agreements and support plans. Invoices, timesheets and payment claims.

The most commonly missed rule

If a participant leaves, you must retain their records for the full period. Not archive-then-delete, and not delete on request. Retention obligations sit independently of a participant's relationship with you, and independently of a request to erase.

Why retention is a systems problem, not a filing problem

Seven years is longer than most staff tenure, most software contracts and many organisations' memory of why a decision was made. The obligation outlives the people and the tools, which is what makes it structurally difficult.

Records must survive the account that created them

A requirement providers discover late: your system has to retain records without an active user account attached. If deactivating a departed staff member's login makes their records inaccessible, or worse removes them, the system cannot meet the obligation. Many platforms tie record visibility to account state, and the failure only appears when someone leaves.

Premature deletion has to be structurally prevented

Not "staff are trained not to delete". Prevented. A record inside its retention period should not be deletable through the normal interface by anyone, including an administrator having a bad day.

Retention and de-identification are separate lifecycles

This is where organisations accidentally breach. A dataset is de-identified for release or research, and the de-identified copy is treated as the record. The original obligation still attaches to the original. Both lifecycles have to be tracked, and the link between them cannot itself become a re-identification vector.

Practical questions to ask of any system

  • If a staff member leaves tomorrow, what happens to records they created?
  • Can anyone delete a record inside its retention period through the normal interface?
  • Does the system know which records relate to a child, and does it hold the different clock?
  • If you migrate off this platform in three years, does the retention clock survive the migration intact?
  • Can you produce every record for one participant, with dates, without a developer?

That last question is worth running as an exercise. It is the shape of a Commission request, and it is the one that reveals whether retention has been implemented or merely intended.

Common questions

How long do NDIS providers need to keep participant records?

Generally a minimum of seven years from creation or last service date. Records relating to a child must be kept until the participant turns 25, which can be substantially longer.

A participant asked us to delete their data. Do we have to?

Not where a retention obligation applies. Records inside a statutory retention period generally must be kept, and a deletion request does not override that. How you respond, and what you tell the participant, is worth getting advice on.

Do retention rules apply to payment records too?

Yes. From 1 July 2026 payment records must be retained for seven years, alongside the participant and worker screening records already covered.

What happens if our software provider shuts down?

The obligation stays with you. This is why exportability and an intact retention clock after migration are worth testing before you need them, not after.

This guide is general information about how Australian regulatory obligations apply in practice. It is not legal advice, and requirements vary by registration group, jurisdiction and the supports you deliver.

Related

Carrying an obligation your software does not represent?

Two weeks inside your workflow produces a build plan, an accuracy baseline and a risk register. You keep all three either way.

Start a conversation