top of page
KCH Lawyers Rockhampton Family Law Criminal Law Conveyancing Wills & Estates work license

Privacy Policy.

Introduction

KCH Lawyers ([52 691 979 748]) are referred to in this Privacy Policy as we, us or our.

This Privacy Policy explains how we manage personal information. It also describes your rights to access and correct personal information we hold about you, and how you can make a complaint about our management of your personal information. This is in addition to our obligations of confidentiality to clients and other parties arising from sources other than the Privacy Act.

 

Application of this Policy

This Privacy Policy only applies to some of the personal information we manage. It only applies to personal information we manage for the purposes of or in connection with our obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (the AML/CTF Act).

 

Other personal information we manage remains excluded by applicable exemptions in the Privacy Act.

 

Related Entities

Not Applicable.

 

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements.

 

Personal information: what we collect

In the process of providing services to the members of the public and acting on behalf of clients, we collect and hold the following information:

 

Standard information – names, addresses, email addresses, telephone numbers and date of birth.

 

Sensitive information – health details, racial or ethnic origin, criminal records or religious affiliations. This type of sensitive information we would not generally collect, however there may be exceptions to that rule.

 

Financial/Activity information – transaction details, employment history and educational backgrounds.

 

Types of personal information

We collect your contact and identity details, financial information and case related information about you and any relevant entity or person. This may include sensitive information.

 

A more detailed description of the information that we collect and hold includes:

 

Identity information: name, date of birth, gender, signature, photographic identification, offices or directorships held;

Contact information: residential and postal addresses, email addresses, telephone numbers;

Professional and business information: occupation, employer, job title, professional qualifications, business holdings and structures;

Financial information: bank account details, billing information, payment card details, tax file numbers*;

Matter-related information: information relevant to your legal matter or the legal matter of our client;

Transaction information: details of services provided to you or your organisation;

Communication records: records of correspondence and communications with you;

Website and technical data: IP address, browser type, device information, pages visited, cookies;

Recruitment information: employment history, qualifications, references, right to work status, background check results; and

Sensitive information: including: sexual orientation, racial and ethnic origin, political beliefs, religious affiliation, criminal record, and health information**.

 

* Rarely will we need to obtain your tax file number. If we receive your tax records your tax file number may have been deleted by your Accountant. However, if it hasn’t been, we will take all steps to ensure it is deleted before providing it to another party.

 

** It is highly unlikely that we will need to disclose this type of information, however with the AML/CTF Act there may be exceptions to this situation.

 

Identity Verification and the AML/CTF Act

We may be required to verify your identity and collect certain information under the AML/CTF Act when we provide designated services. Identity documents might also be required for other services such as court matters, real property transactions and asset dealings.

 

This includes collecting identification documents and information about the source of funds and beneficial ownership of entities.

 

How we collect personal information

Generally, all information that we collect from you will be collected directly from you in a face to face situation, via a digital meeting or some other direct manner. There may be exceptions to this rule in relation to AML/CTF Act scenarios.

 

Your personal information will be stored by us in a digitally secure manner using LEAP, which is a cloud based data retention system.

 

Sources of information

We collect information directly from our clients, from other lawyers, government sources or public sources such as registers or the internet.

 

Direct Collection

Where reasonable and practicable, we collect personal information directly from you. This may occur when you:

engage us to provide legal services;

respond to communication with us or engage a solicitor or agent to do so;

contact us by telephone, email, post or in person;

complete forms or provide documents to us;

visit our website or use our online services; or

apply for employment with us.

 

Indirect Collection

We may also collect personal information about you from third parties, including:

our client(s), where we collect information in the course of providing legal services;

other parties to legal proceedings or transactions and their lawyers;

witnesses of fact, expert witnesses, health care providers and hospitals;

courts, tribunals, law enforcement and government agencies;

publicly available sources, including public registers, websites and social media;

referrers who introduce you to us or lead agencies and advertising sites;

recruitment agencies and previous employers (for job applicants); and

identity verification, commercial data brokers and background check service providers.

 

Anonymity and Pseudonymity

If you are a client, you have the option of requesting to deal with us anonymously or by using a pseudonym. However, in most cases this is not lawful nor practical for legal services. If you do not provide us with the personal information we request, we may not be able to provide you with legal services or respond to your enquiry.

 

Why we collect personal information and how we use it

We collect, hold, use and disclose personal information for the primary purpose of providing legal services to our clients, complying with regulatory and insurance obligations and operating our legal practice.

 

Secondary purposes include financial management, system improvement, enforcement of our right to payment and managing the relationship between our firm and former clients once the retainer has concluded.

 

The primary purpose of collecting data is as follows:

 

providing legal advice and representation to you or to our clients;

managing client matters and files;

conducting legal research and investigations;

preparing and reviewing legal documents;

communicating with you and other parties;

billing and collecting fees, including pursuit of our rights under a Costs Agreement or retainer;

complying with our legal, professional and insurance obligations; and

administering and managing our firm.

 

We may also use and disclose personal information for secondary purposes that are related to our primary purposes, including:

maintaining and developing our relationship with you;

quality assurance and improvement of our services, including training our AI models or those of AI providers (subject to our obligations of confidentiality to you);

training and professional development;

ongoing Customer Due Diligence as required by the AML/CTF Act;

training AI or automated systems including AI development by our vendors with appropriate confidentiality safeguards in place;

enforcement of our right to payment of fees;

internal reporting and analysis; and

risk management and insurance purposes.

 

Disclosure of Personal Information

We may disclose personal information to third parties to facilitate the purposes of collection noted in section 4. These purposes include disclosure to parties to proceedings or transactions and their representatives, to Courts, government and regulatory agencies as may be necessary or appropriate to establish legal rights and to progress transactions in which we are instructed. We also disclose information to third parties (such as data storage or archiving companies, our regulators or our insurers) who hold or process information for us.

 

Your personal information and confidential data is held by us subject to our duty of confidentiality under the Australian Solicitor’s Conduct Rules (“ASCR”) and any applicable undertakings or court rules. We may disclose personal information to third parties subject to those obligations and for the purposes described in this Privacy Policy, including:

 

to discharge our professional obligations to you or to our clients or in the reasonable execution of our instructions;

to comply with our legal obligations or in answer to a compulsory notice such as a subpoena or warrant, or to disclose information under the AML/CTF Act, Criminal Code(s), Legal Profession Act or other relevant legislation;

to barristers, mediators, expert witnesses, investigators and consultants, and other legal practitioners engaged to act for you (and/or our client) or in relation to the matter;

other parties to legal proceedings or transactions as instructed, reasonably necessary or required by law;

courts, tribunals, government agencies and regulators;

our professional indemnity insurers;

a Costs Assessor in the event that an assessment is ordered or reasonably necessary;

service providers who assist us to operate our business (including IT providers, AI providers, document management providers, and marketing service providers);

related entities;

as permitted under the ASCR confidentiality exceptions; and

any person you expressly or impliedly authorise us to disclose information to.

 

Overseas Disclosure

We will disclose information to overseas recipients where this is reasonably necessary to progress our instructions (dealing with a company with an overseas office, for example).

 

We may disclose personal information to recipients located outside Australia where reasonably necessary or convenient to facilitate the purposes of collection, holding, use and disclosure of information stated in sections 2 and 5 of this policy.

 

The circumstances where disclosure of your information to overseas recipients may occur is as follows:

where your matter involves overseas parties or overseas proceedings;

to overseas law firms or legal practitioners engaged in a matter;

to our staff, staff of a related entity or contractors if working or travelling overseas;

to parties such as regulators and auditors who may use overseas processors or offices;

to service providers whose systems or servers are located overseas (including cloud storage, AI and IT service providers if we consider that the confidentiality arrangements that will apply to such information is sufficient); and

where you instruct or authorise us to do so.

 

Security of Personal Information

Security Measures

We hold your personal information using a system designed to protect against data breaches, however like all data security systems, risks may only be mitigated but not eliminated. It is our practice to require our storage service providers to be reputable and we have assurances from them regarding security and confidentiality being protected.

 

Retention and Destruction

We retain personal information for as long as necessary to fulfil the purposes for which it was collected, to comply with our legal and professional obligations and to ensure that pertinent evidence remains available if reasonably required.

 

Third party websites

Our website may contain links to third party websites, such as payment processors. We are not responsible for the privacy practices of those websites, and we encourage you to read their privacy policies.

 

Access and Correction

Access to and correction of your Personal Information

You have the right to request access to or correction of the personal information we hold about you. To make an access request, please contact our Privacy Officer (see Section 10).

 

If we refuse to correct your personal information, we will provide written reasons for the refusal and information about how you may complain.

 

The Privacy Act permits us to refuse access in some circumstances. If we refuse your access request, we will provide you with written reasons for the refusal (unless unreasonable to do so or we are prohibited from doing so by law) and information about how you may complain.

 

We will respond to your request within a reasonable period, generally within 30 days. We may charge a reasonable fee to cover the costs of locating, retrieving and providing the information. If you are a client or former client we do not charge for recovery or storage of records that are your property, but may charge for costs incurred in retrieval of other records or where urgent timelines or requests for documents to be delivered remotely, incur additional outlays.

 

If you are not a client or former client, our confidentiality obligations to them and other relevant exemptions under the Privacy Act may preclude us giving you the information requested. Request for search or recovery costs in advance does not mean that information will necessarily be released. We will inform you of any applicable fees before processing your request.

 

Correction of Your Personal Information

We take reasonable steps to ensure that the personal information we hold during the currency of your matter is accurate, up-to-date, complete and relevant. Records held subsequent to the completion of our work for you will not be monitored or updated unless further instructions are issued. If you believe that personal information we hold about you is inaccurate, out-of-date, incomplete, irrelevant or misleading, you may request that we correct it.

 

We will respond to correction requests within a reasonable period. If we correct information that we have previously disclosed to a third party, we will notify that third party of the correction if you request us to do so.

 

Complaints and questions

If you have a question about this policy or complaint about how we have handled your personal information, please contact our Privacy Officer. We ask that you provide details of your complaint in writing. We will acknowledge your complaint within ten (10) business days and investigate it promptly. We aim to resolve complaints within 30 days. If we need more time, we will keep you informed of our progress.

 

You may also contact the relevant legal services regulator in your State or Territory.

If you are not satisfied with our response, you may escalate your complaint to:

Office of the Australian Information Commissioner (“OAIC”) or the Legal Services Commission.

 

Website: www.oaic.gov.au

Phone: 1300 363 992

Email: enquiries@oaic.gov.au

Post: GPO Box 5218, Sydney NSW 2001

ADDRESS

First Floor

99 Bolsover Street

Rockhampton, QLD 4700

CONTACT

P: 07 4927 9477

F: 07 4922 1440

E: reception@kchl.com.au

GET SOCIAL

  • Facebook
  • LinkedIn

Liability limited by a scheme approved under professional standards legislation.

© 2021 KCH Lawyers, Rockhampton

bottom of page