Our commitment
We are committed to protecting your privacy. We collect, use, share, process, and manage Personal Information only as reasonably necessary for carrying out our functions and activities.
If we prepare to provide, provide you with, or reasonably anticipate that we may provide you with, any Designated Services, we will handle your Personal Information provided in relation to those services in an open and transparent way, subject to our legal obligations, in accordance with this Privacy Policy.
What does this Privacy Policy cover?
This policy applies only to Personal Information handled in connection with our AML/CTF obligations under the AML/CTF Framework. Other parts of our legal practice may be outside the Privacy Act. We still handle that information confidentially under the legal profession legislation (as defined in section 3A of the Legal Profession Uniform Law Application Act 2014 (NSW)), including the Legal Profession Uniform Law Australian Solicitors’ Conduct Rules 2015 (NSW).
Meaning of words used in this Privacy Policy
In this Privacy Policy the terms listed have the following meanings:
What privacy law applies to our relationship?
We are a “small business operator” under s 6D of the Privacy Act and become subject to the Privacy Act, for the first time, only in relation to AML/CTF-related activities by operation of s 6E(1A) of that Act.
Accordingly, the Privacy Act,including the APPs, applies only to our collection, use, sharing, processing, and management of Personal Information required to comply with our obligations under the AML/CTF Framework.
Under APP 2 you may interact with us anonymously, or using a pseudonym, where lawful and practicable. However, interacting anonymously or using a pseudonym is not possible where we are required to verify identity under the AML/CTF Framework.
How do we collect Personal Information?
We collect Personal Information only by lawful and fair means.
We will collect Personal Information directly from the individual who is the subject of the information unless:
We may collect Personal Information when you, your organisation, or those acting on your or your organisation’s behalf:
We may use a credit reporting body for electronic identity verification, unless you instruct us in writing to arrange an alternative means of verification (for example, certified copies of identification documents), as legally required.
We will provide you with a collection notice at or before the time we collect your Personal Information.
What Personal Information do we collect?
We are required by law under the AML/CTF Act to collect and verify certain Personal Information and may be prohibited from providing services if we cannot do so.
In particular, we collect KYC Information as required by the AML/CTF Act which may include names, addresses, location, contact details, job titles, services and transactions obtained, offered and supplied including usage history, including information about the time, place, and circumstances of our interactions with you.
We may infer information about you from your engagement with us and your activities. We may also collect Sensitive Information where required for compliance with the AML/CTF Framework or where otherwise permitted by law.
We may conduct ongoing monitoring of transactions and client information to comply with our AML/CTF obligations.
What happens if you don’t provide us with requested Personal Information?
If you do not provide requested Personal Information, we may be unable to provide Designated Services and/or comply with our legal obligations.
Purposes of collection of Personal Information
We collect and use Personal Information to carry out our activities and functions including providing you with Designated Services, complying with our regulatory obligations in relation to the delivery of those services, including adherence to the Legal Profession Uniform Law and its related rules and legislation, the Legal Profession Uniform Law Australian Solicitors’ Conduct Rules 2015 (NSW) and the Legal Profession Uniform General Rules2015 (NSW). Other relevant legislation which may require us to collect and use your Personal Information includes the Duties Act 1997 (NSW) and the Australian Registrars National Electronic Conveyancing Council’s Model Participation Rules.
Unless you consent to us doing so otherwise, we will only use your Personal Information for the primary purpose for which it was collected, and for any secondary purpose if you would reasonably expect, and the purpose is related to, the primary purpose of collection. Examples of secondary purposes you might reasonably expect are listed in the previous paragraph.
In the case of Sensitive Information, any secondary purpose will be one that you would reasonably expect and directly related to the primary purpose of collection.
Disclosure of Personal Information
Third parties
Subject to legal requirements, we do not share your Personal Information with any third parties except:
We will ensure that such service providers commit to protecting your Personal Information appropriately and agree not to use or disclose your Personal Information for any other purpose (other than as required by law).
Legal requirements.
We may use or disclose your Personal Information in circumstances where required by law and/or expressly permitted by the Privacy Act, including if:
Nothing in this Privacy Policy limits our obligations of confidentiality or client legal privilege. However, there may be circumstances where we are compelled to disclose confidential information to AUSTRAC under the AML/CTF Framework.
We are prohibited from notifying you of disclosures to AUSTRAC and may be prohibited from notifying you of disclosures to other government agencies or authorities.
Business transactions
If we are involved in a merger, acquisition or asset sale, your Personal Information may be disclosed in confidence as part of a due diligence process and may be transferred to the new owner. We will provide notice before your Personal Information is transferred and becomes subject to a different Privacy Policy.
How do we protect your information?
We hold Personal Information in hard copy and electronic formats. We take reasonable steps to prevent unauthorised access, disclosure, alteration, destruction or loss of Personal Information including by using a range of physical, operational and technological security measures to protect this information. These measures include organisational and technical measures such as:
When we consider that Personal Information is no longer needed for any purpose for which the information may be used or disclosed in accordance with this Policy and that we are not required by law or court order to retain the Personal Information, we will take reasonable steps to destroy or de-identify the information. AML/CTF KYC Information and transaction records are kept for seven years after the business relationship ends or the transaction is completed, as required by the AML/CTF Framework.
Can your Personal Information be accessed offshore?
We maintain your Personal Information physically and electronically within Australia unless we have agreed with you to share your Personal Information with third parties offshore (such as local law experts in another jurisdiction).
Some electronic services we use may process data offshore, but those services are not entitled to access or use the Personal Information held by us except as required for delivery of the contracted service.
We take reasonable steps to ensure overseas recipients do not breach the APPs.
How you can access and correct your Personal Information
We will respond to inquiries from an individual regarding whether we hold any Personal Information relating to that individual and will allow access to and correction of any such Personal Information subject to our contractual arrangements where Personal Information is held by a third party, and the conditions and limitations set out in the Privacy Act, including:
If you believe that the Personal Information we, or our contracted third party, hold about you is inaccurate, out-of-date, incomplete, irrelevant, or misleading, you may request that we correct it by contacting our Privacy Officer. We may ask you to verify your identity before giving you access or making corrections, and we may charge a reasonable fee for providing access (but not for making a correction).
You can contact our Privacy Officer by email at claudia@interstatelawyers.com.au.
We will take reasonable steps to correct your information to ensure it is accurate, complete, and up-to-date within a reasonable period (usually within 30 days) of receiving your request.
How you can complain about our information handling practices.
All privacy-related inquiries and complaints are handled by our Privacy Officer. If you have any concerns regarding our management of your Personal Information, or if you believe we have breached the APP/s, please contact our Privacy Officer in writing setting out the details of your complaint.
We are committed to achieving a fair and equitable resolution of any privacy concerns. When you lodge a complaint, we will follow this internal review process:
If you are not satisfied with our response, or if we do not resolve your complaint within 30 days, you are entitled to escalate your complaint by lodging a complaint with the Office of the Australian Privacy Commissioner at this link: https://www.oaic.gov.au/privacy/privacy-complaints/lodge-a-privacy-complaint-with-us.
If you require a copy of this Privacy Policy in a particular form (e.g. large print, accessible PDF) please contact our Privacy Officer.
Interstate Lawyers Pty Ltd
claudia@interstatelawyers.com.au
Date reviewed: 28 June 2026.
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.