How long do NDIS providers have to keep records?
Last updated 19 September 2026. Applies to National Disability Insurance Scheme (NDIS) providers and support workers in Australia.
In Australia, seven years is the number most NDIS records land on. A provider who claims NDIS funds should keep the records behind those claims for seven years. Incident records, complaints records, restrictive practice records and worker screening records each carry their own express seven year period in the NDIS rules. Employee time and wages records are seven years under the Fair Work Act. Tax and business records are five years under Australian Taxation Office (ATO) rules. Participants keep records for three years and nominees for five.
Those periods come from different laws, they start counting from different events, and only some of them are NDIS rules. Health information in New South Wales, Victoria and the ACT can run considerably longer. The table below is the practical version.
NDIS record retention periods at a glance
| Record | How long | Counted from | Source of the obligation |
|---|---|---|---|
| Records relating to NDIS claims and payments (providers) | 7 years | Detail not yet published, see below | NDIS Act as amended in August 2026 |
| Records relating to NDIS payments (participants) | 3 years | Detail not yet published, see below | NDIS Act as amended in August 2026 |
| Records kept by nominees | 5 years | Detail not yet published, see below | NDIS Act as amended in August 2026 |
| Incident records (all recorded incidents) | 7 years | The day the record is made | Incident Management and Reportable Incidents Rules 2018, section 12(4) |
| Reportable incident records | 7 years | The day notification is given to the Commissioner | Incident Management and Reportable Incidents Rules 2018, section 25(2) |
| Complaints records | 7 years | The day the record is made | Complaints Management and Resolution Rules 2018, section 10(3) |
| Records of the use of a regulated restrictive practice | 7 years | The day the record is made | Restrictive Practices and Behaviour Support Rules 2018, section 15(3) |
| Worker screening records for risk assessed roles | 7 years | The date the record is made | Practice Standards—Worker Screening Rules 2018, section 21 |
| Employee time and wages records | 7 years | The Act sets the period, not the trigger. Treated in practice as running from when the record is made | Fair Work Act 2009 section 535 and Fair Work Regulations 2009 |
| Tax and business records | 5 years | When the record was prepared or the transaction completed, whichever is later | ATO record keeping rules |
| Health information, New South Wales | 7 years, or until the person turns 25 if collected while they were under 18 | The last occasion a health service was provided | Health Records and Information Privacy Act 2002 (NSW), section 25 |
| Health information, Victoria | The later of 7 years, and age 25 where the information was collected while the person was under 18 | The last occasion a health service was provided | Health Records Act 2001 (Vic), Health Privacy Principle 4 |
| Health information, Australian Capital Territory | 7 years, or until the person turns 25 if collected while they were under 18 | The last occasion a service was provided | Health Records (Privacy and Access) Act 1997 (ACT), Schedule 1 |
| Work health and safety (WHS) notifiable incident records | At least 5 years | The day notification was given to the WHS regulator | Model WHS laws as enacted in each state and territory |
The new seven year rule for providers
The National Disability Insurance Scheme Amendment (Securing the NDIS for Future Generations) Act 2026 (Act No. 66 of 2026) received Royal Assent on 20 August 2026. Schedule 2, Part 4 of that Act is titled "Retention of records" and commenced on 27 August 2026, the seventh day after assent. It inserts a new record retention provision into the National Disability Insurance Scheme Act 2013, section 45B, "Keeping and retaining records relating to claims etc."
The National Disability Insurance Agency (NDIA) publishes the periods as:
- 3 years for participants
- 5 years for nominees
- 7 years for providers
The Department of Health, Disability and Ageing describes the provider duty as keeping "records relating to payment and receipt of NDIS funds for 7 years", and states that failure to retain records is subject to a civil penalty.
What is settled and what is not
- Settled. The amending Act is law. The record retention Part commenced on 27 August 2026. The periods the NDIA publishes are three, five and seven years.
- Not yet settled. As at 19 September 2026 the NDIA's page on the new laws still lists record keeping among changes that are coming. There is no published guidance yet on exactly which records are captured, the event each period runs from, or how the duty interacts with records you already hold. Some of that detail is expected to sit in NDIS rules made under the Act.
- Not confirmed. Whether the seven year period applies to registered providers only or to anyone who claims NDIS funds. The NDIA's wording does not draw that distinction, so an unregistered provider or sole trader that claims or receives NDIS funds should not assume it is excluded.
The practical conclusion is straightforward. If a record is part of the evidence trail behind a claim, keep it for seven years. That matches the Fair Work period, so it gives you one rule instead of several. The only records that routinely run longer are health records in New South Wales, Victoria and the ACT collected while the participant was under 18.
Registered providers already had an obligation under section 73Q of the NDIS Act, "Record keeping by registered NDIS providers", and the Act also deals with record keeping by former registered providers in section 73R. Those provisions operate through rules that prescribe what to keep and for how long. The 2026 change sits alongside them rather than replacing them.
What happens if you cannot produce records
The consequence providers ask about most is money, not penalties. The NDIA's own record keeping guidance puts it plainly in the context of its payment assurance reviews: "Failure to provide complete and accurate records during a review may result in funds having to be repaid to us." The NDIA makes the same point about the new retention periods, noting that you may need to repay funding if you cannot show NDIS funding was used correctly.
Which NDIS rules set a seven year retention period
A common assumption is that the seven years comes from the NDIS Practice Standards. It does not. The Practice Standards and the Quality Indicators contain no retention period at all.
The express seven year periods sit in four separate sets of NDIS rules made under the NDIS Act, and they do not all start counting from the same event.
How long to keep incident records
The National Disability Insurance Scheme (Incident Management and Reportable Incidents) Rules 2018 contain two different retention provisions.
Section 12(4) covers the records a registered provider must make about each incident and each alleged reportable incident: "A record made for the purposes of subsection (2) or (3) must be kept for 7 years from the day the record is made."
Section 25(2) covers records of reportable incidents specifically, and it runs from a different point: the record "must be kept for 7 years from the day that notification of the reportable incident is given" to the Commissioner.
That difference matters. If an incident is notified some weeks after the record was first made, the reportable incident record has to survive longer than the underlying incident record. A retention schedule that applies a single "seven years from the record date" rule to everything will dispose of reportable incident records early. Our guide to the 24 hour and 5 business day reportable incident rules covers the notification timeframes those dates depend on.
How long to keep complaints records
The National Disability Insurance Scheme (Complaints Management and Resolution) Rules 2018, section 10(3): "A record made for the purposes of subsection (2) must be kept for 7 years from the day the record is made." Subsection (2) covers information about complaints, any action taken to resolve them, and the outcome of that action.
The current version of these Rules is Compilation No. 1, dated 28 January 2026, so a policy still citing the 2018 as made version is carrying a stale citation even though the period has not changed. See our guide to what the Complaints Rules require of providers.
How long to keep restrictive practice records
The National Disability Insurance Scheme (Restrictive Practices and Behaviour Support) Rules 2018, section 15(3): "A record made for the purpose of this section must be kept for seven years from the day the record is made." That period attaches to records of the use of a regulated restrictive practice.
There is no express retention period anywhere in those Rules for a behaviour support plan itself. Plans containing a regulated restrictive practice are lodged with the Commissioner, but the Rules do not say how long the provider must keep its own copy. Keeping the plan for at least as long as the restrictive practice records it authorises is sound practice rather than a stated legal requirement, because the plan is what explains those records. State and territory authorisation requirements may impose their own recording obligations on top.
How long to keep worker screening records
The National Disability Insurance Scheme (Practice Standards—Worker Screening) Rules 2018, section 21: "A record subject to this Part must be kept for 7 years from the date the record is made."
Section 18 sets what goes in them: a written, current list of every worker in a risk assessed role, with identifying details and either the exception being relied on and its dates, or the worker's screening check number, outcome and expiry, and any suspension or revocation. Our guide to who needs a worker screening clearance covers what providers must hold on file.
Records with no stated NDIS retention period
A large part of a provider's file has no number attached to it in NDIS law. Service agreements, support plans, progress notes, risk assessments, consent forms, medication charts, supervision notes and training records are all required to exist, and the Practice Standards require them to be managed properly, but no NDIS instrument says how long to keep them.
The relevant standard is Information management, at Schedule 1 clause 12 of the National Disability Insurance Scheme (Provider Registration and Practice Standards) Rules 2018. It is short: each participant's information must be identifiable, accurately recorded, current and confidential, and easily accessible to the participant and appropriately used by relevant workers.
The Quality Indicators go one step further and describe a process rather than a period. Clause 14(4) sets the indicator that "documents are stored with appropriate use, access, transfer, storage, security, retrieval, retention, destruction and disposal processes relevant and proportionate to the scope and complexity of supports delivered". The Guidelines say these indicators should be demonstrated, and auditors assess against them.
Read plainly, that means an auditor is not looking for a magic number. They are looking for a documented retention and disposal process that you actually follow. A small provider with a one page retention schedule and a register showing what was destroyed and when is in a stronger position than a large provider keeping everything forever with no rule at all. Our guide to the policies and procedures you actually need sets out where document control fits in the wider set.
Employment records: seven years
If you employ anyone, the Fair Work Ombudsman is unambiguous: "Employers have to keep time and wages records for 7 years." Records must be legible, in English and readily accessible to a Fair Work Inspector. The obligation sits in section 535 of the Fair Work Act 2009 and regulations 3.31 to 3.44 of the Fair Work Regulations 2009.
The records covered are broader than payroll: employment status and start date, pay rates, gross and net amounts, deductions, overtime and penalty rate details, hours worked where pay is set by reference to time worked, leave taken and balances, superannuation contributions and fund details, any individual flexibility arrangement, and how employment ended. Pay slips are a separate obligation under section 536 and must be issued within one working day of pay day.
Contractors are different, with three catches
The seven year employee records obligation is an obligation about employees. It does not extend to genuine independent contractors. Three things follow, and each one catches small providers out.
- Records still have to be kept, just under different law. Contractor invoices and payments are business records under the ATO's five year rule.
- Superannuation can still be payable. Where a contractor is engaged wholly or principally for their labour, super obligations can apply, and that generates records of its own.
- If the working relationship is in substance employment, the seven year obligation applied the whole time and was being breached the whole time. Sham contracting is unlawful under the Fair Work Act.
Tax and business records: five years
The ATO's position is that "you need to keep most records for 5 years", counted "from when you prepared or obtained the record or completed the transactions or acts those records relate to, whichever is later". Records must be kept in a way that protects them from being changed or damaged, must be in English or easily convertible to English, and must be producible on request.
Two extensions are easy to miss. Records about an asset must be kept for as long as you own the asset and then another five years after you sell or otherwise dispose of it. And where information from one year's records is used in a later return, the records need to survive until the period of review for that later return has ended.
For most support businesses the ATO period is shorter than the NDIS and Fair Work periods, so it rarely drives the decision. It is the floor, not the answer.
When you must destroy records: Privacy Act obligations
Everything above is a reason to keep records. The Privacy Act 1988 is a reason to get rid of them.
Australian Privacy Principle (APP) 11.2 requires an APP entity to take reasonable steps to destroy or de-identify personal information once it no longer needs the information for any purpose for which it may be used or disclosed, unless the information is in a Commonwealth record or the entity is required by an Australian law or a court or tribunal order to retain it.
That last exception is the hinge. The NDIS, Fair Work, ATO and state health records periods are exactly the kind of legal requirement that displaces the duty to destroy. Once a period expires, the pressure reverses: continuing to hold participant information you no longer need is itself a privacy issue.
Does the Privacy Act small business exemption apply to disability providers?
Many sole traders assume the Privacy Act does not apply to them because they turn over less than $3 million. For disability support, that assumption is usually wrong.
The Office of the Australian Information Commissioner (OAIC) confirms the small business threshold is annual turnover of $3 million or less, but also lists categories of small business that are covered regardless of turnover. One of them is a health service provider. The OAIC's Guide to Health Privacy lists "disability service providers (where they handle health information)" among its examples of health service providers.
If you record a participant's medication, seizures, bowel care, mealtime management, mental health or any other health information, you are very likely inside the Privacy Act no matter how small you are. Plan on that basis.
On reform: an exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 was released for consultation, which closed on 18 September 2026. It has not been introduced to Parliament and is not law. Commentary describing 2026 privacy changes as already in force should be read with that in mind.
State and territory health records law
Only three jurisdictions impose a minimum retention period on private sector health records.
| Jurisdiction | Legislation | Minimum retention |
|---|---|---|
| New South Wales | Health Records and Information Privacy Act 2002 (NSW), section 25 | 7 years from the last occasion a health service was provided. If the information was collected while the person was under 18, until they turn 25. Records of what was deleted, and of any transfer, must also be kept. |
| Victoria | Health Records Act 2001 (Vic), Schedule 1, Health Privacy Principle 4 | The later of two dates: 7 years after the last occasion a health service was provided, and, where the information was collected while the person was under 18, the day they turn 25. Notes of deletion and transfer must also be kept. |
| Australian Capital Territory | Health Records (Privacy and Access) Act 1997 (ACT), Schedule 1 | 7 years after the day a service was last provided, where the information was collected while the person was an adult. If collected while the person was under 18, until they turn 25. A register of destroyed or transferred records is also required. |
| Queensland, South Australia, Western Australia, Tasmania, Northern Territory | No equivalent private sector health records retention statute | Retention is driven by the Commonwealth periods above, professional requirements and limitation periods rather than a health records Act. |
Providers operating across borders should apply the longest applicable period rather than running different rules per state. The under 18 rule is the one most often missed. Where information is collected about a participant aged 12 and that is also the last occasion a service is provided, a seven year rule points to age 19 while the "until 25" rule points to 25, a difference of six years. In Victoria it is not a choice between the two, you apply whichever date is later.
Keeping records properly, not just keeping them
Three things sit alongside the periods and come up repeatedly in audits.
Integrity. A record should never be overwritten. If a progress note or an incident record needs correcting, the accepted approach is to strike through, add the correction, and date and initial it, so the original entry and the amendment are both visible. This is good practice rather than a numbered NDIS rule, but it aligns with the ATO's requirement that records be protected from being changed and with the Information management standard's requirement that records be accurate and current.
Storage. Retention means retrievable. Participant information in personal email accounts, unmanaged phone photos or a single unbacked laptop cannot be reliably produced on request or reliably destroyed at the end of its period. APP 11.1 requires reasonable steps to protect personal information from misuse, interference, loss and unauthorised access.
Access. Retention and access are two sides of the same file. APP 12 gives an individual the right to ask for the personal information an APP entity holds about them, and the Information management standard expects each participant's information to be easily accessible to them. A retention policy that no one can search is a policy that cannot answer an access request.
How to build a retention schedule
Four steps, and the whole thing fits on one page for most small providers.
- List your record types. Participant records, incident records, complaints records, restrictive practice records, worker files and screening records, employment and payroll records, financial and claiming records, training records, policy versions.
- Assign the longest applicable period to each type, using the table at the top of this guide. Where two laws apply, the longer one wins. Where no period applies, set one yourself and write down why.
- Record the trigger, not just the number. "Seven years" is meaningless without "from what". Reportable incidents run from notification. Health records in New South Wales, Victoria and the ACT run from the last service. Employment records run from when the record was made.
- Log disposal. A disposal log is not itself required by APP 11.2, but it is how you demonstrate the reasonable steps that APP 11.2 does require, and in New South Wales, Victoria and the ACT the health records legislation separately requires a record of what was deleted or transferred.
Then keep the schedule current. Three of the instruments above were re-compiled in 2026, and the NDIS Act changed in August. A retention schedule written in 2024 is already citing superseded versions.
What auditors look for
Auditors assessing information management are generally less interested in the period itself than in whether the system you described in your policy is the system you actually run. Common findings:
- A retention policy that states periods no one can trace to a source.
- A document register that is out of date, so the version in the policy folder is not the version in use.
- Participant information stored in personal email or unmanaged phone photos, which cannot be retrieved or disposed of reliably.
- No destruction log, so there is no evidence the policy was ever applied.
- Worker screening records missing the detail section 18 of the Worker Screening Rules requires.
Our guide to the Core Module self-assessment walks through scoring your own evidence before an audit, and the verification audit guide covers what a smaller scope audit involves.
Templates that cover records and document control
MRSS sells editable Australian NDIS templates. Document control, registers and record keeping sit in the NDIS Provider Core Library, which includes a master document register and the incident, complaints and restrictive practice registers the periods above attach to. Employment and payroll records are covered in the NDIS Employer Essentials Pack, and sole traders working towards a verification audit generally start with the Independent Support Worker Verification Pack.
A retention policy is only useful evidence once it has been customised to how you actually work, implemented, and backed by completed registers and disposal records. Audit outcomes depend on your actual practice, not on the template.
Frequently asked questions
How long do NDIS providers need to keep records?
Seven years is the practical answer for anything supporting a claim. Following the August 2026 amendments to the NDIS Act, the NDIA publishes the provider period as seven years, participants as three years and nominees as five years. Separately, incident, complaints, restrictive practice and worker screening records each carry an express seven year period in the NDIS rules, and employee time and wages records are seven years under the Fair Work Act.
Do the NDIS Practice Standards say how long to keep records?
No. Neither the Practice Standards nor the Quality Indicators state a retention period. The Information management standard requires participant information to be identifiable, accurate, current, confidential and accessible, and the Quality Indicators set an indicator that retention, destruction and disposal processes should be documented and proportionate to the supports delivered. The numbers come from other instruments.
When does the seven years start for a reportable incident?
From the day notification of the reportable incident is given to the NDIS Commissioner, under section 25(2) of the Incident Management and Reportable Incidents Rules 2018. That is different from ordinary incident records under section 12(4), which run seven years from the day the record is made.
How long do I keep progress notes?
No NDIS instrument sets a period for progress notes specifically. In practice they are evidence for claims, incidents and the supports described in a service agreement, so they should follow the longest period that applies to what they evidence, which for most providers means seven years. If they contain health information and you operate in New South Wales, Victoria or the ACT, the state health records period applies as well.
Does an unregistered provider or sole trader have to keep records for seven years?
Assume yes for anything connected to a claim. The NDIA's published periods refer to providers without distinguishing registered from unregistered, and tax, employment and privacy obligations apply regardless of registration status. The rules in the NDIS instruments listed above apply to registered NDIS providers.
Can I delete a participant's records once they stop working with me?
Not immediately. The retention periods run from events such as the date of the record, the date of notification, or the last occasion a service was provided, not from the date the participant left. In New South Wales, Victoria and the ACT, health information collected while the person was under 18 must be kept until they turn 25. Once every applicable period has passed and you no longer need the information, Australian Privacy Principle 11.2 requires you to take reasonable steps to destroy or de-identify it.
Sources
- National Disability Insurance Scheme Amendment (Securing the NDIS for Future Generations) Act 2026 (No. 66, 2026), Royal Assent 20 August 2026, Schedule 2 Part 4 commenced 27 August 2026
- NDIA, Securing the NDIS for future generations, page current as at 17 September 2026
- NDIA, What are the record keeping requirements, page current as at 20 August 2026
- Department of Health, Disability and Ageing, About the changes to the NDIS
- NDIS (Incident Management and Reportable Incidents) Rules 2018, sections 12 and 25
- NDIS (Complaints Management and Resolution) Rules 2018, Compilation No. 1, 28 January 2026, section 10
- NDIS (Restrictive Practices and Behaviour Support) Rules 2018, section 15
- NDIS (Practice Standards—Worker Screening) Rules 2018, sections 18 and 21
- NDIS (Provider Registration and Practice Standards) Rules 2018, Compilation No. 6, 1 July 2026, Schedule 1 clause 12
- NDIS (Quality Indicators for NDIS Practice Standards) Guidelines 2018, Compilation No. 3, 1 July 2026, clause 14
- Fair Work Ombudsman, Record keeping
- Fair Work Ombudsman, Pay slips
- ATO, Overview of record keeping rules for business, last updated 18 June 2026
- ATO, Records to keep longer than five years
- OAIC, Australian Privacy Principles, APP 11 and APP 12
- OAIC, Small business
- OAIC, Guide to Health Privacy
- OAIC, State and territory privacy legislation
- Attorney-General's Department, Privacy reform consultation, closed 18 September 2026
- Health Records and Information Privacy Act 2002 (NSW), section 25
- Health Records Act 2001 (Vic), Schedule 1, Health Privacy Principle 4
- Health Records (Privacy and Access) Act 1997 (ACT), Schedule 1
- Safe Work Australia, Incident notification requirements
This guide is general information about Australian regulatory requirements, current as at 19 September 2026. It is not legal advice, and requirements change. Check the current version of any instrument before relying on it, and seek professional advice for your own circumstances.
Related guides
- NDIS reportable incidents: the 24 hour and 5 business day rules explained
- NDIS complaints management: what the Rules require of providers
- NDIS worker screening check: who needs a clearance and how to get one
- Restrictive practice authorisation by state and territory
- NDIS Core Module self-assessment: check your evidence before an audit
- The NDIS verification audit: a practical guide for sole traders and small providers
- NDIS policies and procedures: what you actually need
These templates are general information, not legal advice. No template pack can guarantee registration or audit outcomes.