Connected Legal + Commercial Privacy Policy
1. About this Privacy Policy
Connected Legal + Commercial, including its partners, principals, employees, contractors and related entities where applicable, is committed to protecting personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), applicable professional obligations and any anti-money laundering and counter-terrorism financing obligations that apply to the Firm.
This Privacy Policy explains how Connected Legal + Commercial collects, holds, uses, discloses, retains and protects personal information.
In this Privacy Policy, “we”, “us” and “our” means Connected Legal + Commercial. “You” means any individual whose personal information we collect or hold, including clients, prospective clients, beneficial owners, officers, employees, agents, counterparties, witnesses, suppliers, consultants, referrers, website users and other individuals who interact with us.
2. Key definitions
For the purposes of this Privacy Policy:
Personal Information has the meaning given in the Privacy Act. Personal Information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether recorded in a material form or not.
Sensitive Information includes information or an opinion about an individual’s racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, health information, biometric information, genetic information and other categories of sensitive information under the Privacy Act.
AML/CTF laws means the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), the Anti-Money Laundering and Counter-Terrorism Financing Rules, and any related regulatory instruments, guidance or directions issued by AUSTRAC or another competent authority, to the extent applicable to our legal services.
Customer due diligence or CDD means the process of identifying and verifying the identity of a client and, where required, beneficial owners, controlling persons, agents, politically exposed persons and other relevant persons, and assessing money laundering, terrorism financing and proliferation financing risk.
Beneficial owner means an individual who ultimately owns or controls a client, entity, trust, transaction or arrangement, directly or indirectly, within the meaning of applicable AML/CTF laws.
3. Scope of this Privacy Policy
This Privacy Policy applies to Personal Information collected by us in connection with:
legal services and related commercial advisory services;
client intake, onboarding and conflict checks;
AML/CTF compliance, where applicable;
matter management and client communications;
litigation, dispute resolution, transactional and advisory work;
trust accounting and billing;
marketing, events and business development;
recruitment and engagement of contractors and suppliers;
use of our website, digital platforms and technology systems; and
regulatory, professional indemnity, audit, risk management and compliance functions.
4. Types of personal information we collect
The types of Personal Information we collect depend on the nature of our relationship with you and the services we provide. We may collect:
Identity and contact information, including name, date of birth, residential address, business address, postal address, email address, telephone number, nationality and occupation.
Client and matter information, including instructions, background facts, documents, correspondence, transaction details, litigation materials, evidence, settlement information and legal advice.
Identification documents, including driver licence, passport, Medicare card, birth certificate, proof of address, company extracts, trust deeds and other documents used to verify identity.
AML/CTF information, including beneficial ownership information, control information, source of funds, source of wealth, politically exposed person status, sanctions screening results, risk ratings, transaction information and ongoing due diligence records.
Financial information, including billing details, bank account details, trust account information, payment records, financial statements, tax information and commercial records.
Sensitive information, where reasonably necessary for our functions or activities, such as health information, criminal record information, family circumstances, cultural or religious information, or information relevant to litigation, employment, family, succession, property, commercial, regulatory or advisory matters.
Professional and business information, including job title, employer, directorships, shareholdings, professional memberships and business relationships.
Website and technical information, including IP address, device information, browser type, pages visited, time and date of access, cookies and analytics information.
Marketing and communication preferences, including event attendance, subscription preferences and records of communications with us.
Recruitment information, including CVs, qualifications, employment history, references, background checks and interview notes.
Supplier and contractor information, including business contact details, payment information, insurance details and compliance records.
5. How we collect personal information
We may collect Personal Information:
directly from you, including when you contact us, instruct us, complete a form, attend a meeting, provide documents, use our website or communicate with us;
from your authorised representatives, agents, advisers, accountants, brokers or other professional service providers;
from companies, trusts, partnerships, associations or other entities with which you are connected;
from courts, tribunals, government agencies, regulators, law enforcement bodies and public registers;
from counterparties, witnesses, experts, barristers, consultants, investigators, process servers and other persons involved in a matter;
from identity verification providers, electronic verification systems, sanctions screening providers and AML/CTF compliance service providers;
from publicly available sources, including ASIC, ABR, AFSA, land titles registries, court lists, social media and other public databases;
from referrers, introducers and business contacts;
through website cookies, analytics tools and digital platforms; and
from third-party technology providers that support our operations.
6. Collection of sensitive information
Collection of Sensitive Information may be necessary in legal matters involving health, employment, family relationships, estates, criminal or regulatory issues, disputes, discrimination, personal injury, insurance, insolvency, trust structures, source of wealth inquiries or AML/CTF risk assessment.
We only collect Sensitive Information where:
you consent and the information is reasonably necessary for one or more of our functions or activities;
the collection is required or authorised by law;
the collection is necessary for the establishment, exercise or defence of a legal or equitable claim;
the collection is necessary for confidential alternative dispute resolution;
the collection is necessary for professional disciplinary, regulatory, insurance or risk management purposes; or
another exception under the Privacy Act applies.
7. AML/CTF collection and verification
Where AML/CTF laws apply to our services, we may be required to collect and verify information before providing, or while providing, certain services.
This may include information about:
the client’s identity;
any person acting on behalf of the client;
beneficial owners and controlling persons;
directors, trustees, partners, officeholders, shareholders, unit holders, appointors, protectors, beneficiaries or classes of beneficiaries;
ownership and control structures;
politically exposed person status;
sanctions, adverse media and other risk indicators;
source of funds and source of wealth;
the nature and purpose of the matter, transaction or business relationship;
the intended use of our services;
ongoing changes in identity, ownership, control, instructions or risk profile; and
transaction records and supporting documents.
We may verify this information using reliable and independent documentation, electronic identity verification services, public and private databases, government registers, document verification systems and other appropriate sources.
If information required for AML/CTF compliance is not provided, or cannot be verified to our satisfaction, we may be unable to act, may need to delay work, may be required to cease acting, or may be required to take other steps under applicable law and professional obligations.
8. Purposes for which we use Personal Information
We collect, hold, use and disclose Personal Information for purposes including:
providing legal and commercial advisory services;
assessing whether we can act, including conflict checks and risk assessment;
opening, managing and closing client matters;
verifying identity and authority to instruct;
complying with AML/CTF obligations, including CDD, enhanced due diligence, ongoing due diligence, transaction monitoring, sanctions screening and record keeping;
managing trust money, controlled money and billing;
communicating with clients, courts, tribunals, regulators, counterparties and advisers;
preparing documents, correspondence, advice, agreements, pleadings, submissions and transaction materials;
conducting litigation, dispute resolution, negotiation, mediation, arbitration and settlement processes;
managing professional obligations, including confidentiality, conflicts, privilege, undertakings and file retention;
complying with laws, court orders, notices, regulatory requirements and professional standards;
preventing, detecting and responding to fraud, money laundering, terrorism financing, proliferation financing, sanctions breaches, cyber incidents and unlawful conduct;
making insurance notifications or claims and managing risk;
managing complaints, disputes, audits, investigations and disciplinary matters;
improving our services, systems, training and business processes;
conducting marketing, events, publications and client relationship management, where permitted by law;
recruiting personnel and managing suppliers and contractors; and
any other purpose notified to you or permitted by law.
9. Legal professional privilege and confidentiality
Legal professional privilege and confidentiality are fundamental to our relationship with clients.
We will not disclose privileged or confidential client information unless:
authorised by the client;
required or authorised by law;
required by a court, tribunal, regulator or professional body with lawful authority;
necessary to obtain advice from counsel, experts, insurers, auditors or other professional advisers;
necessary to defend or respond to a claim, complaint or regulatory inquiry;
permitted by applicable professional conduct rules; or
necessary for AML/CTF compliance, sanctions compliance or other legal obligations.
Nothing in this Privacy Policy is intended to waive legal professional privilege.
10. AML/CTF reporting and tipping-off restrictions
Where AML/CTF laws apply, we may be required to make reports or provide information to AUSTRAC, law enforcement agencies or other competent authorities. This may include suspicious matter reports, threshold transaction reports, compliance reports, or information requested under compulsory powers.
In some circumstances, AML/CTF laws may restrict what we can tell you about a report, inquiry, investigation or decision to collect, use, retain or disclose information. We may refuse, limit or defer access, correction, explanation or notification where doing so is required or authorised by law, including to avoid contravening tipping-off restrictions or prejudicing an investigation.
11. Disclosure of Personal Information
We may disclose Personal Information to:
courts, tribunals, registries and dispute resolution bodies;
barristers, experts, mediators, arbitrators, investigators, search agents, process servers and consultants;
counterparties, their lawyers and other persons involved in a matter;
government agencies, regulators, law enforcement bodies and statutory authorities;
AUSTRAC and other AML/CTF supervisory or enforcement bodies, where required or authorised by law;
identity verification, sanctions screening and AML/CTF compliance providers;
banks, financial institutions, payment processors and trust account service providers;
insurers, brokers, professional indemnity providers and external advisers;
auditors, accountants, bookkeepers and tax advisers;
technology providers, cloud service providers, data hosting providers, document management providers, email and communications providers, cyber security providers and IT support providers;
outsourced administrative, transcription, printing, mailing, storage and archiving providers;
debt recovery providers, where necessary;
referrers or other professional advisers, with consent or where otherwise permitted;
related entities, if applicable; and
any other person or organisation where required or authorised by law or with your consent.
We take reasonable steps to ensure that third parties who handle Personal Information on our behalf protect that information appropriately.
12. Overseas disclosure
Some of our service providers, including but not limited to data storage, payment processors and technology service providers, may be located or operate outside of Australia.
We may disclose Personal Information to overseas recipients where necessary for our services or operations, including where:
a matter involves an overseas party, adviser, court, regulator, transaction, asset or jurisdiction;
a client instructs us to communicate with an overseas recipient;
an overseas service provider supports our technology, data hosting, document management, cyber security, identity verification, AML/CTF screening, analytics or communications systems; or
disclosure is required or authorised by law.
Where we share Personal Information overseas, we will take reasonable steps to ensure that our service providers are obliged to protect this Personal Information in accordance with Australian legal requirements and that they are only permitted to use Personal Information for the purpose for which it is shared.
You consent to overseas disclosure where you have expressly agreed to it, or where disclosure is otherwise permitted by law. We remain accountable under the Privacy Act for the acts and omissions of our overseas recipients unless an exception in the Privacy Act applies (for example, where the recipient is subject to a law or binding scheme substantially similar to the APPs, or a prescribed country/recipient is specified by regulation).
If you do not consent to the overseas disclosure of your Personal Information as described in this clause, we may be unable to provide certain products, services, or access to events, websites, or other benefits.
If you would like information about the countries to which we commonly disclose Personal Information, or to obtain a copy of the standard contractual clauses we use, please contact us at info@connectedlegal.com.au
13. Website, cookies and analytics
Our website may use cookies, pixels, analytics tools and similar technologies to:
operate and secure the website;
understand website traffic and user behaviour;
improve website performance and content;
manage enquiries and communications;
support marketing and event activities; and
detect and prevent misuse or security threats.
You may disable cookies through your browser settings. Some website functionality may be affected if cookies are disabled.
Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites.
14. Direct marketing
We may use Personal Information to send legal updates, invitations, publications, event information and other marketing communications where permitted by law.
You may opt out of marketing communications at any time by using the unsubscribe function in the communication or by contacting us.
We will comply with applicable direct marketing laws, including the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth), where applicable.
15. Artificial intelligence and automated tools
We may use technology tools, including search, document management, due diligence, review, analytics, automation and artificial intelligence tools, to support legal services and business operations.
Where we use such tools, we will take reasonable steps to protect confidentiality, privilege, personal information and client data. We will not knowingly input confidential or privileged client information into public artificial intelligence tools in a way that is inconsistent with our professional obligations, privacy obligations or client instructions.
We do not make decisions with legal or similarly significant effects about individuals solely by automated means unless this is disclosed, authorised by law or consented to.
16. Security of personal information
We take reasonable steps to protect Personal Information from misuse, interference, loss, unauthorised access, modification and disclosure.
Security measures may include:
access controls and permissions;
password protection and multi-factor authentication;
encryption and secure transmission protocols;
secure document management systems;
cyber security monitoring and threat detection;
staff training and confidentiality obligations;
physical security at offices and storage facilities;
secure archiving and destruction procedures;
due diligence on service providers;
incident response planning; and
backup, disaster recovery and business continuity arrangements.
No system is completely secure. We encourage clients and other persons communicating with us to take reasonable precautions when sending sensitive information electronically.
17. Notifiable data breaches
If we suspect or become aware of a data breach, we will assess the incident in accordance with the Privacy Act and our incident response procedures.
Where a breach is likely to result in serious harm to affected individuals and remedial action has not prevented the risk of serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
We may also notify regulators, insurers, professional bodies, law enforcement agencies or affected clients where required or appropriate.
18. Retention of personal information
We retain Personal Information for as long as reasonably necessary for the purposes for which it was collected, and as required or permitted by law, professional obligations, insurance requirements, limitation periods, dispute management and legitimate business purposes.
Retention periods may vary depending on the nature of the information, matter, client, transaction and applicable legal requirements.
Where more than one retention period applies, we will generally retain information for the longest applicable period.
19. AML/CTF record retention
Where AML/CTF laws apply, we may be required to retain AML/CTF records for prescribed periods. These records may include:
client identification and verification records;
beneficial ownership and control records;
records of persons acting on behalf of clients;
politically exposed person and sanctions screening records;
source of funds and source of wealth records;
risk assessments and risk ratings;
enhanced due diligence records;
ongoing due diligence and transaction monitoring records;
records of transactions or designated services;
records relating to suspicious matter reports or other AML/CTF reports;
AML/CTF program documents, policies, procedures and training records; and
records of decisions made for AML/CTF compliance purposes.
Subject to the final form of applicable AML/CTF laws and rules in force at the relevant time, AML/CTF records are commonly required to be retained for at least 7 years, including, where applicable:
for customer identification records, 7 years after the end of the business relationship or after the relevant designated service ceases;
for transaction records, 7 years after the transaction;
for AML/CTF program and compliance records, 7 years after the record ceases to be current or the relevant obligation ceases; and
for reports and related records, the period required by AML/CTF laws.
We may be prohibited from destroying, de-identifying or disclosing certain AML/CTF records where retention, secrecy, investigation or enforcement obligations apply.
20. General retention guide
Unless a longer period is required or appropriate, our general retention practices may include:
This table is a guide only and may be varied by law, client agreement, matter requirements, litigation holds, regulatory notices, professional obligations or our internal policies.
21. Destruction and de-identification
When Personal Information is no longer required, and we are not required or permitted to retain it, we will take reasonable steps to destroy it securely or de-identify it.
Secure destruction may include secure deletion, shredding, certified destruction, decommissioning of storage media or secure destruction by an approved provider.
We may retain de-identified information for statistical, research, training, risk management, business improvement or compliance purposes.
22. Access to Personal Information
You may request access to Personal Information we hold about you by contacting the Privacy Officer.
We may ask you to verify your identity before providing access.
We will respond to access requests within a reasonable period and in accordance with the Privacy Act.
We may refuse or limit access where permitted by law, including where:
access would unreasonably affect another person’s privacy;
the information is subject to legal professional privilege;
access would reveal commercially sensitive decision-making information;
access would prejudice legal proceedings, negotiations, enforcement activities or investigations;
access would breach confidentiality, professional obligations, court orders or legal restrictions;
access would create a serious threat to life, health or safety;
the request is frivolous, vexatious or unlawful;
access would contravene AML/CTF tipping-off restrictions or other secrecy obligations; or
another exception under the Privacy Act applies.
If access is refused, we will provide reasons where it is lawful and reasonable to do so.
23. Correction of Personal Information
You may request correction of Personal Information we hold about you if you believe it is inaccurate, out of date, incomplete, irrelevant or misleading.
We will take reasonable steps to correct Personal Information where appropriate.
Where we disagree with a requested correction, you may ask us to associate a statement with the information noting that you consider it to be inaccurate, out of date, incomplete, irrelevant or misleading.
We may not be able to correct records where doing so would compromise legal professional privilege, court records, evidentiary integrity, AML/CTF records, regulatory obligations, audit trails or professional obligations. In such cases, we may add a supplementary note where appropriate.
24. Anonymity and pseudonymity
Where lawful and practicable, you may deal with us anonymously or using a pseudonym.
However, anonymity or pseudonymity will usually not be practicable where we provide legal services, conduct conflict checks, verify identity, manage trust money, comply with AML/CTF obligations, act in transactions, appear in court or comply with professional and regulatory obligations.
25. Accuracy of Personal Information
We take reasonable steps to ensure that Personal Information we collect, use and disclose is accurate, complete and up to date.
You should notify us promptly if your personal information changes, including changes to contact details, identity information, authority to instruct, ownership or control structures, beneficial owners, directors, trustees, agents, source of funds, source of wealth or other information relevant to AML/CTF compliance.
26. Third-party information provided to us
If you provide Personal Information about another person to us, you must ensure that you are authorised to do so and that the person has been informed, where appropriate, that their personal information may be handled in accordance with this Privacy Policy.
This may include information about directors, shareholders, beneficial owners, trustees, beneficiaries, employees, officers, agents, family members, witnesses, counterparties and other individuals relevant to a matter.
27. Children and vulnerable persons
We may collect Personal Information about children or vulnerable persons where necessary for a legal matter or where required or authorised by law.
Where appropriate, we will collect information through a parent, guardian, litigation guardian, attorney, administrator, authorised representative or other legally recognised decision-maker.
28. Cross-border matters and foreign laws
Where we act in matters involving overseas jurisdictions, foreign parties, foreign assets or foreign regulators, Personal Information may be subject to disclosure or handling under foreign laws.
We will take reasonable steps to manage confidentiality, privilege and privacy in cross-border matters, subject to client instructions, legal obligations and practical requirements of the matter.
29. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, professional obligations, regulatory guidance, technology, business operations or our information handling practices.
The current version will be available at https://www.connectedlegal.com.au/privacy or on request.
30. Privacy complaints
If you have a concern or complaint about how we have handled personal information, you may contact the Privacy Officer.
Privacy Officer
Connected Legal + Commercial
Level 5, The Brewery
5 Central Park Avenue
Chippendale NSW 2008
Email: info@connectedlegal.com.au
Telephone: 1300 804 195
Please include sufficient details to allow us to assess and respond to the complaint.
We will acknowledge and respond to privacy complaints within a reasonable period.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
Office of the Australian Information Commissioner
GPO Box 5288
Sydney NSW 2001
Australia
Website: www.oaic.gov.au
Telephone: 1300 363 992
31. Questions
Questions about this Privacy Policy or our handling of personal information should be directed to:
Privacy Officer
Connected Legal + Commercial
Level 5, The Brewery
5 Central Park Avenue
Chippendale NSW 2008
Email: info@connectedlegal.com.au
Telephone: 1300 804 195
Effective date: 19 June 2026
Last reviewed: 19 June 2026
| Record type | Indicative retention period |
|---|---|
| Client matter files | Usually at least 7 years after matter closure |
| Trust accounting records | At least 7 years, or longer if required |
| AML/CTF records | At least 7 years, subject to applicable AML/CTF laws |
| Conflict check records | As long as reasonably necessary for conflict management and professional obligations |
| Client identification documents | As required for legal, AML/CTF, risk and professional obligations |
| Original wills, deeds and title documents | Until returned, transferred, destroyed with authority, or retained in accordance with client instructions and law |
| Corporate, trust and transaction records | At least 7 years, or longer where required for limitation periods, taxation, regulatory, AML/CTF or professional reasons |
| Billing and accounting records | At least 7 years, or longer where required |
| Complaints, claims and professional indemnity records | As long as reasonably necessary for insurance, limitation, risk and regulatory purposes |
| Recruitment records | As long as reasonably necessary for recruitment, employment, legal and risk purposes |
| Marketing records | Until no longer required or until consent is withdrawn, subject to suppression list requirements |