Privacy Policy
Keypoint Law Pty Ltd, its staff, management, Consulting Principals and other team members (Keypoint) understand how important your privacy is to you. We are committed to ensuring that the personal information we collect and hold is handled in accordance with the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) (Privacy Act) as amended from time to time. We will handle your personal information in accordance with the APPs and this Privacy Policy.
Keypoint reviews its policies, statements and procedures to keep up to date with changes in the law, technology and market practices. As a result, we may update and change our Privacy Policy from time to time. We encourage you to occasionally review this Policy so that you are aware of our most up to date practices, including any recent changes or updates.
In general, personal information is information or an opinion (whether true or not) about an identified or reasonably identifiable individual. Keypoint is also committed to ensuring the protection of confidential information that we receive.
If you require any further information concerning privacy and the ways in which we handle your personal information, please contact us using the contact details set out at the end of this Policy.
In what circumstances does Keypoint collect personal information?
Keypoint is an Australian law firm providing legal services across 25 areas of law. In the course of this work Keypoint deals with a wide range of individuals. The types of personal information we collect depends on the nature of those dealings. For example, we may collect personal information from you when you:
- enquire about our legal services or instruct us to provide you with legal advice;
- attend a Keypoint event such as a seminar;
- do business with us as the ‘contact person’ of a supplier or client organisation or otherwise deal with us as part of a transaction;
- engage with us as a regulator; or
- visit our website.
A special section about online privacy issues is included below.
What personal information does Keypoint collect and hold?
We may ask for a range of personal information about you because of the nature of our products and services and the laws and regulations that govern us. We will collect personal information that is reasonably necessary to allow us to provide you with our products and services, send you news and insights, comply with laws and regulations and to assist and support you with your needs. Depending on the requested products or services, the nature of your relationship with Keypoint (e.g. if you are acting on behalf of a corporation or institutional client), and your interactions with members of Keypoint, we may collect the following types of personal information (including but not limited to):
- General information: name, date of birth, gender, occupation;
- Contact details: mobile or telephone number, residential and/or postal address, email address;
- Government issued identifications: driver licence details, passport details, medicare number, Tax File Number (TFN);
- Financial information: banking details, tax, income, assets and liabilities information, employment details;
- Sensitive information: health information, political affiliations, racial or ethnic origin, religious beliefs or affiliations, sexual orientation and criminal convictions; and
- Digital information: Internet Protocol (IP) address, cookies, browsing behaviour.
Wherever possible, Keypoint will collect personal information directly from you as the individual concerned, rather than from publicly-available sources such as government registers or from other third parties. However, sometimes it will be necessary to collect personal information from third parties involved in your matter, such as your financial advisor, accountant or other legal practitioners. Occasionally Keypoint is asked to provide legal services where credit is to be provided. In this rare circumstance we may seek information about you from a credit reporting agency.
If you have a general enquiry, you can choose to submit these anonymously or use a pseudonym. However, we may not always be able to interact with you this way because we are governed by strict regulations that require us to know who we are dealing with. In general, we will not be able to deal with you anonymously or where you are using a pseudonym when it is impracticable, or we are required or authorised by or under law, such as the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act) or a court/tribunal order to deal with you personally.
Some personal information constitutes ‘sensitive information’ under privacy legislation including the Privacy Act. This includes details of your racial or ethnic origin, religious beliefs or affiliations, sexual orientation and criminal convictions. Health information together with genetic or biometric information in some circumstances is also sensitive information. Keypoint will not request sensitive information from you unless we reasonably need it for one or more of our functions or activities, such as providing advice; or collect it unless you agree, or the collection is otherwise permitted under APP3.
If you do not consent to your personal information being used as described in this Privacy Policy or if you do not provide the personal information requested, it may prevent us from arranging for some or all of the products or services you require, or the product or service which we do provide might not fully meet your needs.
How does Keypoint use personal information?
Keypoint’s policy is to use personal information only for the purpose(s) for which it was collected. These purposes are to provide our services and carry out our business, including specific activities mentioned above such as responding to enquiries, providing advice and dealing with suppliers. The personal information collected will also be used and disclosed:
- to give you information about a product or service and/or consider whether you are eligible for a product or service;
- to process your instructions or engagement and/or administer the products or services we provide to you;
- to manage our relationship and/or services provided to you;
- to allow us to run our business and perform administrative and operational tasks such as training staff, developing and marketing products and services, risk management, systems development and testing;
- to identify you and prevent or investigate any fraud or crime, or any suspected fraud or crime;
- to verify your identity as required by the AML/CTF Act and associated rules, including conducting customer due diligence and ongoing monitoring;
- to report suspicious matters to the Australian Transaction Reports and Analysis Centre (AUSTRAC) as required by law;
- to screen against sanctions lists and politically exposed persons (PEP) databases;
- if it will prevent or lessen a serious and imminent threat to somebody’s life or health;
- as required by laws, regulations, court orders or codes binding us; and
- for any purpose for which you have provided express (verbal or written) or implied consent.
We also need to collect personal information for communications purposes so that we can, for example, offer new services, alert you to legal or other business developments or invite you to events. If you prefer not to receive these types of communications, please tell us via the contact details set out at the end of this policy.
Marketing activities
We may use personal information that we have obtained about you to directly market our insights, or other products or services that may be of interest to you where you have provided us with consent to do so, or where:
- the personal information does not include sensitive information;
- you would reasonably expect us to use or disclose the personal information for that purpose; and
- you have not opted out of receiving direct marketing communications from us.
We will provide a simple means for you to opt-out of receiving direct marketing offers from us. Alternatively, you may also contact our Head of Marketing to request your removal from any direct marketing communications.
TFNs and other government identifiers
We will not use your TFN, or any other government agency identifier as our internal identifier. We will only use and disclose these numbers for the purposes required by law or with consent from you, such as disclosing your TFN to the Australian Taxation Office.
Does Keypoint give your personal information to other people?
Keypoint does not trade in the personal information it has collected. To make sure we can meet your specific needs, and for the purposes described above, we sometimes need to share your personal information with others including, but not limited to:
- External service providers: Many kinds of external service providers help Keypoint to operate its legal practice and provide legal services to you. Notably these include legal practitioners such as barristers, incorporated legal practices, IT, and other software and systems providers and consultants and third parties who assist us in providing products and services to you and in managing your personal information. Keypoint seeks to ensure that all its external service providers understand and comply with the APPs when handling your personal information, and in particular that they are not authorised to use it for any purpose other than as specified in our agreement with them.
- Overseas providers: Your personal information may be provided to service providers overseas, such as IT services providers and also partners of our affiliated firm Keystone Law in the United Kingdom, for the purpose of obtaining legal advice. Keypoint uses industry-leading software and IT services provided by suppliers such as Microsoft Azure and our data is stored in servers located within Australia. Where personal information is disclosed overseas to a third party recipient, we take reasonable steps to ensure that the recipient does not breach the Privacy Act and the APPs, that the recipient is subject to an information privacy scheme similar to the Privacy Act, or that you have consented to the disclosure.
- Government or regulatory bodies: We may disclose personal information to government or regulatory bodies (including ASIC, the Australian Taxation Office and AUSTRAC) as required or authorised by law or regulations, including under the AML/CTF Act.
- As required or permitted by law: Outside these circumstances, Keypoint will only disclose your personal information when required to do so, for example by court order or when permitted by the Privacy Act, for example if a threat arose posing significant danger to one or more individuals.
We will take reasonable steps to ensure third parties have the necessary controls and practices to comply with the relevant privacy legislation and to only use personal information for the prescribed purposes.
Online privacy issues
Our website and use of cookies
When you visit our website we may record certain information about how you use it, such as which pages you visit, and the time and date of your visit. We and our ISP also collect information such as the documents visitors download, links from other sites they visit to reach our site, and the type of browser they use. However, this information does not contain personal information and is only used for statistical and website development purposes.
By default, most web browsers accept small data files called cookies. Our website makes limited use of cookies and other similar tracking technologies to measure usage sessions and to better understand how visitors navigate our site. Google Analytics cookies are also used for ads personalisation when using Google services. We also use cookies to improve the functionality of our website. The information collected by a cookie or other such tracking file does not contain your personal information.
If you do not wish to receive cookies, you may be able to change the settings of your browser to refuse all cookies or to notify you each time a cookie is sent to your computer, so that you can choose whether to accept it or not. If you block all cookies, you may not be able to access or use some or all pages of our website.
Though Keypoint does not use your browsing information to identify you personally, in some circumstances the IP address assigned to your device may mean that you are identifiable. If you elect to use the Pay Online facility on Keypoint’s website, your personal information may be collected.
Links to other websites
Keypoint’s website contains some links to other websites, which are provided for your convenience and to supply you with more information. Please note that Keypoint is not responsible for the handling of your personal information at these sites. We recommend that you review the privacy policies of any other sites you visit.
Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) Compliance
As a reporting entity under the AML/CTF Act and associated rules, Keypoint is required to collect, verify, and retain certain personal information for the purposes of complying with its AML/CTF obligations. This section explains how we handle personal information in connection with those obligations.
Customer identification and verification (Know Your Customer)
Before providing certain services, we may be required to verify your identity. This may include collecting and verifying government-issued identification documents (such as a passport or driver licence), proof of address, date of birth, and in some cases information about beneficial owners, controlling persons or PEPs. We may use third-party electronic verification services to assist with this process.
Ongoing customer due diligence
We are required to undertake ongoing customer due diligence throughout the course of our relationship with you. This may involve periodically re-verifying your identity, updating your personal information, and monitoring transactions and activities for consistency with our knowledge of you, your business and risk profile.
Transaction monitoring and suspicious matter reporting
We monitor transactions and activities as part of our AML/CTF compliance program. Where we form a suspicion that a transaction or activity may be related to money laundering, terrorism financing, or other serious criminal offences, we are required by law to report the matter to AUSTRAC. We are prohibited from informing you (known as ‘tipping off’) if such a report has been made.
Record-keeping
Under the AML/CTF Act, we are required to retain records relating to customer identification and verification, transactions, and other AML/CTF compliance activities for a minimum of seven (7) years after the end of our relationship with you, or seven (7) years after the relevant transaction, whichever is later. This record-keeping obligation may override any shorter retention period that would otherwise apply under our general privacy practices.
Is your personal information secure?
Keypoint takes reasonable steps to ensure that your personal information, whether in hard copy or digital form, is held securely. All Keypoint staff, management, service providers and other team members are contractually required to treat personal information held by Keypoint as confidential and maintain its security. Keypoint regularly provides its team with privacy and data protection training, including cybersecurity awareness.
Keypoint’s offices are located in secure premises accessed by pass cards. Passwords and, in certain applications, , multi-factor authentication protect our IT systems, and our anti-virus software is regularly updated to protect our systems and the data held there. We also regularly conduct system audits and integrity checks to protect your personal information against unauthorised access, misuse, loss or other data breaches. Keypoint does not retain your personal information any longer than is needed for the purpose for which we collected it, or for the duration we are required by law to keep it for.
Despite these measures, it is not possible for Keypoint to guarantee the security of your personal information. You should recognise in particular that the internet is not a secure environment. Accordingly, if you do use the internet to send us any information, including your email address, please be aware of potential risks to the information both in transit and upon receipt, and adopt protective practices wherever possible.
What are your access and correction rights?
Under the Privacy Act, if Keypoint holds your personal information you have the right to:
- seek access to it;
- request that we update or correct it when it is inaccurate, incomplete or out of date;
- opt-out of receiving any marketing communications from us.
If you would like to access the personal information Keypoint holds about you, please set out your request in writing and send it to Keypoint’s General Counsel, using the contact details provided at the end of this policy.
For personal information held in current records, we generally provide a copy as an electronic printout or photocopy, at no cost, though you can request access in other formats if preferred. If your personal information is stored in archived non-current records held for legal or administrative purposes, including in offsite storage or as backup data files, we may need to charge you for the cost of access provision.
If you consider that the personal information we hold about you is not accurate or is out of date, or you have queries about it, please contact Keypoint’s General Counsel, using the contact details set out at the end of this policy.
How can you make a complaint?
If you think Keypoint has breached the Privacy Act, or you wish to make a complaint about the way we have handled your personal information, you can contact us using the details set out at the end of this policy. Please include your name, email address and/or telephone number and clearly describe your complaint.
Any complaint will be investigated by the firm’s General Counsel and any other relevant member of the firm’s management team, and the outcome of that investigation communicated to you (please allow at least 30 days for us to do so).
If you are not satisfied with the outcome of any internal investigation that we conduct, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at enquiries@oaic.gov.au or on 1300 363 992. More information is available on the OAIC’s website at https://www.oaic.gov.au/.
Contact us
General Counsel | Keypoint Law
Mail: L12, Exchange House, 10 Bridge Street, Sydney NSW 2000
Email: general.counsel@keypointlaw.com.au
Phone: +61 2 8035 5200
Fax: +61 2 8035 5201
AML/CTF Act requires retention of records for 7 years