Guide · Records and retention
How long must an NDIS provider keep records?
There is no single number. NDIS providers are usually subject to several overlapping retention obligations from different legal sources, each with its own clock, and the one that binds you depends on the record type and on what else you are regulated as.
The clearest NDIS-specific requirement is for incident records: the NDIS (Incident Management and Reportable Incidents) Rules 2018 require these be kept for a minimum of seven years from the date the record is made. Beyond that, the Practice Standards set principles rather than periods, and state and territory laws frequently impose longer obligations.
A great deal of published guidance states a single retention period for NDIS providers as though it were settled. Much of it is repeating state health records law, or one rule generalised to everything. Where a period below is not clearly attributable to a source, that is stated. Check your own obligations against the Commission and your state regulator rather than against any blog, including this one.
The three sources, and they do not agree
| Source | What it covers | The period |
|---|---|---|
| NDIS Incident Management Rules 2018 | Incident records | Minimum 7 years from the date the record is made |
| NDIS Practice Standards | Records generally | Principles-based. Requires retention, storage, destruction and disposal processes relevant and proportionate to the scope and complexity of supports delivered. No fixed period |
| State and territory law | Depends what else you are | Often the longest, and frequently the one that actually binds you |
That third row is where most of the confusion comes from, and it is worth being precise about.
The rule people quote, and where it actually comes from
The figure repeated most often is "seven years, or until the person turns 25 if they were a child". That is a real rule, and it is state health records legislation, not NDIS.
- In New South Wales it sits in the Health Records and Information Privacy Act 2002. In Victoria and the ACT there are equivalents. Those three jurisdictions prescribe minimum periods; others do not, in the same way.
- It applies to health service providers. Seven years from the date of last contact for adults, and until the person turns 25 where the information was collected while they were under 18.
A large share of NDIS providers are health service providers as well: allied health, behaviour support practitioners, nursing. If that describes you and you operate in NSW, Victoria or the ACT, this rule binds you directly, and it is longer than anything in the NDIS rules. If it does not describe you, do not assume the number applies just because everyone repeats it.
What this means in practice
Stop looking for the number. Start mapping which obligations attach to which records, because that map is what an auditor or a regulator will ask you to demonstrate, and it is what your system has to encode.
Why retention is a systems problem, not a filing problem
Seven years is longer than most staff tenure, most software contracts and many organisations' memory of why a decision was made. The obligation outlives the people and the tools, which is what makes it structurally difficult regardless of which period applies to you.
Records must survive the account that created them
A requirement providers discover late: the system has to retain records without an active user account attached. If deactivating a departed staff member's login makes their records inaccessible, or worse removes them, the system cannot meet any retention obligation. Many platforms tie record visibility to account state, and the failure only appears when someone leaves.
Different clocks on different record types
This is the part generic document management handles badly. If incident records run on one clock and clinical records on another, and a participant's file contains both, a single retention rule applied to the folder is wrong in one direction or the other. Either you destroy something early, or you hold personal information longer than you can justify, which is its own problem under the Privacy Act.
Retention and de-identification are separate lifecycles
Organisations breach here accidentally. A dataset is de-identified for release or research, and the de-identified copy is treated as the record. The original obligation still attaches to the original. Both lifecycles have to be tracked, and the link between them cannot itself become a re-identification vector.
Questions to ask of any system
- If a staff member leaves tomorrow, what happens to records they created?
- Can anyone delete a record inside its retention period through the normal interface?
- Can the system hold different retention clocks for different record types on the same participant?
- If you migrate off this platform in three years, does the retention clock survive the migration intact?
- Can you produce every record for one participant, with dates, without a developer?
That last one is worth running as an exercise. It is the shape of a regulator's request, and it reveals whether retention has been implemented or merely intended.
Common questions
How long must NDIS providers keep records?
There is no single period. Incident records must be kept for a minimum of seven years from the date the record is made under the NDIS (Incident Management and Reportable Incidents) Rules 2018. The NDIS Practice Standards require retention processes that are relevant and proportionate rather than setting a fixed period. State and territory laws often impose longer obligations, and where they apply they usually govern.
Where does the "seven years, or until 25" rule come from?
State health records legislation, not the NDIS. New South Wales, Victoria and the ACT prescribe minimum retention for health service providers: seven years from last contact for adults, and until the person turns 25 where the information was collected while they were under 18. It binds NDIS providers who are also health service providers in those jurisdictions.
A participant asked us to delete their data. Do we have to?
Not where a retention obligation applies. Records inside a statutory retention period generally must be kept, and a deletion request does not override that. How you respond, and what you tell the participant, is worth getting advice on.
What happens if our software provider shuts down?
The obligation stays with you. This is why exportability and an intact retention clock after migration are worth testing before you need them, not after.
This guide is general information about how Australian regulatory obligations apply in practice. It is not legal advice, and requirements vary by registration group, jurisdiction and the supports you deliver.