Privacy Policy
This is the Privacy Policy of GILLIS & CO. PTY LTD ABN 56 699 019 595 trading as GILLIS+Co. and GILLIS+Co. Lawyers & Advisors (“we”, “us” and when relating to us, “our”).
We are committed to protecting the privacy of our contacts, customers, suppliers and employees (“you” and when relating to you, “your”) and complying with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth) (Privacy Act).
In this policy we describe how we manage your personal information.
1. The kinds of personal information we collect
The kinds of personal information that we collect include:
- contact details such as name, role or position, address, email address, mobile number, landline number and fax number;
- information relating to your circumstances and affairs relevant to the matter/s in which we are instructed;
- information about your legal interests and requirements and the legal services that you may wish to purchase;
- information regarding our communications with you and your attendance at seminars and promotional events held by us;
- if you are an employee or prospective employee, information about your qualifications, skills and work experience;
- if you are a supplier or prospective supplier, information about your business skills, services, products and prices.
2. How we collect personal information
We collect personal information by various means including when:
- you contact us with a question or inquiry;
- you subscribe to our newsletter or legal updates service;
- you attend a seminar or event where we are hosting or presenting;
- you instruct us to act for you and we open a file and conduct a conflict check;
- our clients provide information relating to related and adverse parties relevant to the advice or services we are providing;
- we undertake a search or investigation;
- you visit our website.
Where practicable we collect personal information about you directly from you. However, we may have collected information about you from a third party such as a client, a third party information provider, the courts or a person responding to our questions or inquiries.
We are required to collect the full name and address of our clients by the Solicitors Rules made under the Legal Profession Act 2004 (NSW). Accurate name and address information must also be collected in order to comply with the trust account record keeping requirements in the Legal Profession Regulation 2005 (NSW) and to comply with our duty to the courts.
If you are a client and do not provide us with name and address information we cannot act for you.
If you do not provide us with accurate personal information we may not be able to carry out our instructions or achieve the purpose for which the information has been sought.
3. The purposes for which we collect, hold, use and disclose personal information
We collect, hold, use and disclose personal information in order to:
- respond to your enquiries;
- provide legal services;
- employ competent and diligent personnel;
- monitor or improve the use of and satisfaction with our legal services; and
- let you know about legal developments, our expertise and legal services that may be of interest to you.
We disclose personal information:
- in order to carry out the instructions of our clients; and
- subject to our confidentiality obligations, when using services in support of our legal practice.
4. Personal information collected for AML/CTF compliance
GILLIS & CO. PTY LTD is a reporting entity under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act) in relation to certain services we provide. We are required by law to collect and verify certain personal information, and we may be prohibited from providing services to you if we are unable to do so.
Where required to comply with the AML/CTF Act and the rules and regulations made under it (AML/CTF Rules), we may collect, hold, use and disclose personal information for purposes including initial and ongoing customer due diligence, transaction monitoring, risk assessment, sanctions and politically exposed person screening, reporting to AUSTRAC and other regulators, and record keeping. In particular, we may collect the following information (KYC Information):
- the identity and contact details of our customer;
- information supporting the verification of a person’s identity, including government-issued identity document details, images of identity documents, facial images, liveness information, biometric information and verification metadata;
- the identity of any person on whose behalf our customer is receiving the service;
- the identity of any person acting on behalf of our customer, and evidence of their authority to act;
- if the customer is not an individual, the identity of any beneficial owners;
- whether the customer, a beneficial owner, or any person acting on their behalf is a politically exposed person or a person or entity designated for targeted financial sanctions;
- information about source of wealth and source of funds;
- information about the nature and purpose of the business relationship or the transaction; and
- information about any other matter specified in the AML/CTF Rules.
Some KYC Information is sensitive information for the purposes of the Privacy Act – in particular, biometric information used for the purpose of automated biometric verification or biometric identification, biometric templates, and information that may reveal a person’s membership of a professional or political association or their political opinions. We collect that information because its collection is required or authorised by or under an Australian law, namely the AML/CTF Act and the AML/CTF Rules.
We collect personal information (including sensitive information) for AML/CTF purposes only where reasonably necessary to comply with our legal obligations, and only in connection with matters where a designated service is, or is reasonably likely to be, provided. Not all legal engagements require the collection of personal information for AML/CTF purposes.
Where we use electronic or biometric identity verification, we may use third-party verification providers to verify identity information against official and other data sources, to assess whether a person matches an identity document, to conduct liveness and fraud checks, and to provide verification outcomes to us. Some of those providers, and some of the data sources they use, may be located outside Australia – see clause 6.
We may disclose KYC Information to AUSTRAC and to other regulators, law enforcement and government agencies where required or authorised by law, to our identity verification, screening and technology providers, and to our professional advisers and insurers.
Where required by law, or where reasonably necessary having regard to ongoing AML/CTF risk, the verification method used, auditability, fraud risk, disputes, regulatory enquiries, enhanced customer due diligence, suspicious matter assessment or ongoing customer due diligence, we may retain limited copies or images of identity documents, facial images or related verification artefacts. The AML/CTF Act and AML/CTF Rules impose minimum record-keeping periods, which are generally seven years, and we may be required to retain KYC Information for that period even if you ask us to delete it.
The AML/CTF Act restricts what we may tell you about our compliance activities. In particular, it is an offence in certain circumstances to disclose information about a suspicious matter report we have made, or about certain notices we have received from AUSTRAC. This means that if you ask us for access to, or correction of, your personal information, we may be unable to tell you whether we hold information of that kind, and we may be required or permitted to refuse your request without giving reasons that would themselves amount to a prohibited disclosure.
Nothing in this clause affects legal professional privilege. Our obligations under the AML/CTF Act do not require us to give AUSTRAC information that is subject to legal professional privilege, and we will assert privilege on your behalf where it properly applies.
5. The parties to whom your personal information is disclosed
Subject to our confidentiality obligations, we may share some relevant personal information with:
- parties related to a matter you have with us, government authorities and service providers as reasonably required to carry out your instructions;
- our e-mail marketing provider for the purposes of providing you our newsletter, invitations and legal updates; and
- third party service providers who assist us with archival, auditing, accounting, legal, business consulting, website or technology services.
We also will disclose your information if required by law to do so or in circumstances permitted by the Privacy Act – for example, where we have reasonable grounds to suspect that unlawful activity, or misconduct of a serious nature, that relates to our functions or activities has been, is being or may be engaged in, in response to a subpoena, discovery request or a court order.
6. Disclosure of information outside the jurisdiction of collection
Some of the third parties described above, including our service providers and Related Bodies Corporate, are located outside Australia. We are therefore likely to disclose your personal information to overseas recipients.
The countries in which those overseas recipients are likely to be located are New Zealand, Singapore, the United States of America, the United Kingdom and the European Union.
It is not practicable for us to specify in this policy every country in which an overseas recipient is likely to be located. This is because:
- we disclose personal information to numerous overseas recipients, and the country in which a particular recipient is located may change from time to time; and
- we rely on cloud infrastructure and hosting services provided by third parties who operate distributed networks of data centres in multiple countries. Those providers may store, replicate, back up, route or process data across, or transfer data between, data centres in different countries, and may add, change or discontinue the locations they use, without our direction and from time to time.
Determining the likely location of each of those recipients on a continuing basis would be excessively time-consuming, costly and inconvenient in all the circumstances. If you would like further information about the countries in which our overseas recipients are located, please contact our Privacy Officer using the contact details in clause 12.
Before we disclose your personal information to an overseas recipient, we take such steps as are reasonable in the circumstances to ensure that the recipient does not breach the Australian Privacy Principles (other than Australian Privacy Principle 1) in relation to that information. Those steps may include entering into contractual arrangements requiring the recipient to handle your personal information consistently with the Australian Privacy Principles.
We are not required to take those steps where an exception in Australian Privacy Principle 8.2 applies – for example, where we reasonably believe the recipient is subject to a law or binding scheme that has an effect substantially similar to the Australian Privacy Principles and that you can access mechanisms to enforce, or where you consent to the disclosure after we have expressly informed you that Australian Privacy Principle 8.1 will not apply.
7. Opting out of marketing communications
We may, from time to time, send you newsletters, invitations and legal updates about our services. You can opt out of receiving further such communications by notifying us using our contact details below or by clicking the “unsubscribe” option at the bottom of any marketing e-mail received from us.
8. Security
We take reasonable physical, technical and administrative safeguards to protect your personal information from misuse, interference, loss, and unauthorised access, modification and disclosure. For example, we maintain our files in secure offices and limit access to personal information to individuals with a need to know.
9. Access, correction and updating personal information
You can contact us to access, correct or update your personal information. Unless we are subject to a confidentiality obligation or some other restriction on giving access to the information and we are permitted to refuse you access under the Privacy Act, we will endeavour to make your information available to you within 30 days. Examples of circumstances where we may refuse to give you access to your personal information include where:
- giving access would be unlawful;
- we reasonably believe that giving you access would pose a serious threat to the life, health or safety of any individual or to public health or public safety;
- giving access would have an unreasonable impact on the privacy of others;
- the information could reveal the intentions of a party in negotiations;
- giving access could prejudice the taking of appropriate action in relation to unlawful activity;
- giving access could reveal evaluative information in a commercially sensitive decision making process.
If you request to correct your personal information, we will correct, or, if we consider more appropriate, note your request for amendment of the information on your record.
We will not charge you to make a request to access your record but we may charge you to actually provide access depending on the costs associated with obtaining and providing the material.
These actions can usually be taken by contacting a customer relations representative using the contact information in the “Contact us” section below.
10. Notification of changes
If we decide to change our Privacy Policy, we will send you a copy of our revised policy or post a copy on our website.
11. Complaints
If you wish to make a complaint about how we handle your personal information, please contact us setting out your complaint in writing, and forward it to our Privacy Officer, using the contact details in clause 12 of this policy.
We will endeavour to respond to any complaint within 30 days.
If you are not satisfied with our response to your complaint you may seek a review by contacting the Office of the Australian Information Commissioner using the information available at oaic.gov.au/privacy/privacy-complaints.
12. Contact
This Privacy Policy may change from time to time and will be made available to anyone who requests it, whether at our offices or by use of our website.
If you have any questions or comments about the Privacy Policy, please set out your request in writing, and forward this to our Privacy Officer, using the contact details below.
Level 10, 179 Elizabeth Street
SYDNEY NSW 2000
OUR PRIVACY POLICY WAS LAST REVIEWED ON 1 JULY 2026