Privacy Policy

1. Introduction

Jeff Horsey Solicitor (ABN 84 003 134 059) is referred to in this Privacy Policy as we, us or our. This Privacy Policy explains how we
manage personal information that is handled for the purposes of, or in connection with, our obligations under the Anti-Money Laundering and
Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act) and the AML/CTF Rules.

1.1 Application of this Policy

This Policy is
directed to the personal information we handle for AML/CTF purposes. It does
not purport to apply the Privacy Act 1988 (Cth) to other personal information
handled by the firm where a lawful small-business exemption applies.

Our professional
duties of confidentiality, legal professional privilege, court obligations,
undertakings, and obligations under Queensland legal-profession legislation and
professional conduct rules apply independently of this Policy and continue to
protect information relating to clients and other persons.

1.2 Updates to this Policy

We may update
this Policy to reflect changes in our legal obligations, systems or business
practices. The current version will be available on our website at jeffhorsey.com.au.

2. Personal information we collect and hold

The kinds of personal information we may collect and hold for AML/CTF purposes depend on the service, the customer, the structure of any relevant entity, and the assessed money-laundering, terrorism-financing and proliferation-financing risk. They may include:

  • identity and verification information, such as name, date of birth, residential address, citizenship or residency information, signature, identification-document type and number, issue and expiry details, and the outcome of identity verification;
  • contact information, including postal address, email address and telephone number;
  • business, trust and ownership information, including occupation, employer, offices or directorships, entity structure, authorised representatives, beneficial owners, controllers, trustees, beneficiaries and related parties;
  • financial and transaction information, including bank and settlement details, source of funds, source of wealth, transaction purpose, payment information and information relevant to a proposed or completed legal transaction;
  • AML/CTF risk and compliance information, including customer risk assessments, politically exposed person status, sanctions and screening results, adverse information, ongoing customer due-diligence records and compliance decisions;
  • matter-related and communication information that is reasonably necessary for AML/CTF compliance;
  • information required for regulatory reporting, record keeping, audits or lawful requests from regulators or law-enforcement bodies; and
  • personnel due-diligence information for employees, contractors or other persons performing AML/CTF functions, where required.

We may collect sensitive information only where it is reasonably necessary for our functions or activities and the collection is authorised or required by law, or another applicable exception or consent permits the collection.

2.1 Identification documents

We may ask to sight, receive or verify identification documents. For AML/CTF record-keeping purposes from 1 July 2026, our general practice is to retain the verification information and record required by law rather than retain a full copy of an identification document.

We may retain a copy of an identification document where it remains reasonably necessary for another lawful purpose or where another Australian law, court or tribunal order, professional obligation or client instruction requires or authorises its retention. Examples may include verification-of-identity obligations for a land transaction. Copies that are no longer required or authorised will be securely destroyed or de-identified in accordance with section 8.

3. How we collect and hold personal information

3.1 Direct collection

Where reasonable and practicable, we collect personal information directly from you, including when you:

·         instruct us or ask us to provide a legal service;

·         complete a questionnaire, form, client-authorisation, customer due-diligence or verification process;

·         provide identification, financial, ownership, source-of-funds or source-of-wealth information;

·         communicate with us by telephone, email, post, online form, electronic-signing platform or in person; or

·         apply for or perform a role involving AML/CTF responsibilities.

3.2 Indirect collection

We may also collect personal information from third parties, including:

·         your authorised representatives, agents, advisers, employers, related entities, trustees, beneficial owners or controllers;

·         our clients, other parties to a legal matter and their lawyers or representatives;

·         banks, mortgagees, insurers, accountants, real estate agents, settlement participants and other transaction parties;

·         electronic conveyancing, land-registry, duty, identity-verification, search and electronic-signing platforms;

·         courts, tribunals, AUSTRAC, law-enforcement bodies, regulators and other government agencies;

·         public registers, sanctions lists, corporate records, property records, websites and other publicly available sources; and

·         service providers engaged to assist us with legal services, technology, security, storage, verification or compliance.

3.3 How information is held

We may hold personal information covered by this Policy in electronic and physical form. Electronic information may be held in our legal-practice, document-management, email, accounting, identity-verification, electronic-signing, electronic-conveyancing, backup and other business systems. Physical documents may be held securely while required and may be converted to a reliable electronic form.

3.4 Anonymity and pseudonymity

 

You may ask whether you can deal with us anonymously or by using a pseudonym. In most legal matters this will not be lawful or practicable because we must know who is instructing us, verify authority, manage conflicts and comply with legal and AML/CTF obligations. If required personal information is not provided, we may be unable to act, continue acting or provide a designated service.

4. Why we collect, hold, use and disclose personal information

We may collect, hold, use and disclose personal information for purposes including:

·         identifying and verifying customers, authorised representatives, beneficial owners and other relevant persons;

·         understanding entity ownership and control and confirming authority to act;

·         assessing and managing money-laundering, terrorism-financing and proliferation-financing risk;

·         understanding the purpose and intended nature of a service or transaction, including source of funds and source of wealth where relevant;

·         conducting initial and ongoing customer due diligence and reviewing information for accuracy and currency;

·         meeting AML/CTF record-keeping, governance, training, audit, reporting and regulatory obligations;

·         responding to lawful requests, notices, warrants, subpoenas or directions from AUSTRAC, law-enforcement bodies, courts, tribunals or regulators;

·         managing our AML/CTF program, systems, risk controls, service providers and personnel due diligence; and

·         complying with related legal, professional, insurance, cybersecurity and risk-management obligations.

We may limit, delay or omit information in a notice or response where disclosure would be inconsistent with a legal restriction, including an AML/CTF tipping-off prohibition.

5. Disclosure of personal information

Subject to our professional duties of confidentiality and any applicable legal restrictions, we may disclose personal information covered by this Policy for the purposes described in this Policy to:

  • AUSTRAC, law-enforcement bodies, courts, tribunals, regulators and government agencies;
  • other legal practitioners, barristers, experts, consultants and persons engaged to deliver or administer legal services;
  • parties to legal proceedings or transactions and their representatives, where instructed, reasonably necessary or required by law;
  • banks, mortgagees, insurers, accountants, settlement participants, electronic lodgement network operators, land registries and duty authorities;
  • identity-verification, screening, search, electronic-signing and electronic-conveyancing providers, including platforms such as PEXA, InfoTrack and DocuSign where relevant;
  • IT, cybersecurity, cloud hosting, document-management, backup, accounting, archiving and secure-destruction providers;
  • our professional indemnity insurer, auditors, costs assessors and professional advisers; and
  • any person you expressly or impliedly authorise, or to whom disclosure is otherwise permitted or required by law or professional conduct rules.

6. Overseas disclosure

Some service providers, their related entities or subcontractors may store, access or process personal information outside Australia. Overseas disclosure may also occur where a matter involves an overseas party, adviser, regulator, institution or transaction.

Countries in which recipients are likely to be located include the United States.

Where the Australian Privacy Principles require it, we take reasonable steps before an overseas disclosure to ensure that the recipient will handle personal information consistently with the Australian Privacy Principles. Different requirements or exceptions may apply where a disclosure is required or authorised by the AML/CTF Act, AML/CTF Rules or another Australian law.

7. Security of personal information

We take reasonable technical and organisational steps appropriate to the nature, volume and sensitivity of the personal information we hold. Depending on the circumstances, those measures may include:

·         access controls, unique user accounts, role-based permissions and multi-factor authentication where available;

·         secure passwords, encryption, protected communications and secure backup arrangements;

·         physical security for offices, paper files and devices;

·         software updating, malware protection, logging, monitoring and incident-response procedures;

·         staff privacy, confidentiality and cybersecurity training;

·         vendor due diligence and contractual confidentiality, security, breach-notification, data-location and return-or-destruction requirements; and

·         secure disposal of paper and electronic records.

No method of transmission or storage is completely secure. Our measures are reviewed and adjusted having regard to the risks, available technology, legal requirements and the size and nature of our practice.

7.1 Data breaches

We maintain procedures for responding to suspected or actual data breaches. Where the Notifiable Data Breaches scheme applies and an eligible data breach occurs, we will assess and notify the Office of the Australian Information Commissioner and affected individuals as required by law.

8. Retention, digitisation and destruction

8.1 Retention

We retain personal information covered by this Policy for as long as it is needed for a permitted purpose, including AML/CTF compliance, provision of legal services, regulatory or insurance requirements, the establishment or defence of legal rights, and compliance with Australian laws or court and tribunal orders.

Different records may have different retention periods. These may include AML/CTF records, trust records, conveyancing verification-of-identity records, financial records and client documents. We do not destroy a record before an applicable legal or professional retention period has expired.

8.2 Digitisation of paper records

Where personal information covered by this Policy forms part of a paper legal file, we may scan the paper record and hold it in electronic form. Before a paper source is destroyed, we seek to ensure that the electronic record is complete, legible, reliable, accessible for later reference and protected against unauthorised alteration.

Original documents, documents held in safe custody and client-owned documents are not destroyed merely because a copy has been scanned. They are retained, returned or destroyed only in accordance with the client’s instructions and applicable law and professional obligations.

8.3 Secure destruction and de-identification

When personal information covered by this Policy is no longer needed and is not required or authorised to be retained, we take reasonable steps to securely destroy it or ensure that it is de-identified. Paper records are securely shredded or destroyed by an appropriate provider. Electronic records are deleted or placed beyond use where immediate irreversible deletion is not technically practicable, and are destroyed when this becomes possible.

We seek to apply retention and destruction requirements to duplicate, archived and backup copies to the extent reasonably practicable.

9. Our website and third-party websites

Where our website or an online service is used to collect personal information for AML/CTF purposes, technical information such as IP address, browser and device information, pages visited, cookies and information submitted through an online form may also be collected. Some online functions may be supplied by third-party providers. You can control cookies through your browser settings, although disabling cookies may affect website functionality. This section does not extend the scope of this Policy to unrelated website activities that are outside the Privacy Act.

Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites and encourage you to review their privacy information.

10. Access and correction

You may request access to, or correction of, personal information we hold about you by contacting our Privacy Officer. We may ask you to verify your identity and provide enough information for us to locate the relevant record.

The Privacy Act and other laws permit or require us to refuse or limit access or correction in some circumstances. Our duties of confidentiality and legal professional privilege, the rights of other persons, court or tribunal restrictions, law-enforcement requirements and AML/CTF tipping-off restrictions may also affect what we can provide.

We will respond within a reasonable period and generally aim to respond within 30 days. We may charge a reasonable fee for the cost of locating, retrieving and providing access where permitted, but we will not charge for making a request or for correcting personal information. If we refuse a request, we will provide written reasons and complaint information unless it would be unreasonable or unlawful to do so.

11. Questions and complaints

Questions about this Policy or complaints about our handling of personal information should be made in writing to our Privacy Officer. Please describe what happened, when it happened, how it affected you and the outcome you are seeking. We will acknowledge a complaint within five business days and aim to respond within 30 days. If more time is required, we will keep you informed.

Privacy Officer

Kodi Croonen, Jeff Horsey Solicitor

Postal address

PO Box 2, Upper Coomera QLD 4209

Street address

Suite 13, The Hub, 90 Days Road, Upper Coomera QLD 4209

Email

admin3@jeffhorsey.com.au

Telephone

(07) 5665 6000

Website

jeffhorsey.com.au

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC). You may also contact the Queensland Legal Services Commission where your concern relates to the conduct of a legal practitioner or law-practice employee.

Office of the Australian Information Commissioner
Telephone: 1300 363 992
Email: oaicintake@oaic.gov.au
Privacy complaints

Queensland Legal Services Commission
Telephone: 07 3564 7726 or 1300 655 754 outside Brisbane
Email: lsc@lsc.qld.gov.au
Make an enquiry