PRIVACY POLICY
1. PURPOSE OF THIS PRIVACY POLICY
This Privacy Policy explains how MAP Lawyers Pty Ltd ABN 59 153 151 574 (MAP Lawyers) collects, holds, uses and discloses personal information in connection with its legal practice, including property law, conveyancing, property transactions and related legal services.
This Privacy Policy is intended to comply with the Privacy Act 1988 (Cth), including the Australian Privacy Principles. It also addresses the handling of personal information required for compliance with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and associated rules and guidance, to the extent those obligations apply to the firm.
For the purposes of this Privacy Policy, personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not.
2. APPLICATION OF THIS PRIVACY POLICY
This Privacy Policy applies to personal information collected and handled by MAP Lawyers in relation to:
- clients and prospective clients;
- purchasers, vendors, borrowers, guarantors, mortgagors and other parties to property transactions;
- directors, officers, shareholders, unit holders, partners, trustees, beneficiaries and beneficial owners of clients or counterparties;
- authorised representatives, attorneys and agents;
- referrers, brokers, real estate agents and other professional advisers;
- witnesses and signatories to documents;
- complainants, enquirers and website users; and
- suppliers, contractors and service providers.
This Privacy Policy does not generally apply to employee records of current or former employees where the employee records exemption under the Privacy Act applies. However, MAP Lawyers may still handle employee information consistently with this Privacy Policy where appropriate.
3. TYPES OF PERSONAL INFORMATION COLLECTED
The types of personal information collected by MAP Lawyers will depend on the nature of the legal services, transaction or interaction. Personal information may include:
- full name, former names, aliases and preferred name;
- date and place of birth;
- residential, postal and email addresses;
- telephone numbers and other contact details;
- occupation, employment information and business details;
- identity documents, including driver licence, passport, Medicare card, birth certificate, citizenship certificate and other government-issued identifiers;
- copies, numbers and verification results relating to identity documents;
- tax file numbers, Australian business numbers, Australian company numbers and Australian registered body numbers, where relevant;
- marital or relationship status, family details and information about dependants, where relevant to a matter;
- bank account details, loan details, mortgage information and other financial information;
- contract, title, property, rates, body corporate, land tax and settlement information;
- source of funds, source of wealth and transaction funding information;
- information about trusts, companies, partnerships and other structures, including controllers and beneficial owners;
- information about politically exposed persons, sanctions screening and adverse media screening, where required for AML/CTF compliance;
- immigration, residency or foreign person status where relevant to duties, taxes, FIRB, surcharge purchaser duty or other legal requirements;
- voice recordings, call notes, file notes and electronic communications;
- website analytics information, device identifiers and IP addresses;
- complaints, feedback and enquiry information; and
- other information reasonably necessary for the provision of legal services or compliance with legal obligations.
4. SENSITIVE INFORMATION
Sensitive information is a special category of personal information under the Privacy Act. It may include information about health, racial or ethnic origin, political opinions, religious beliefs, criminal records, biometric information and membership of professional or trade associations.
MAP Lawyers will collect sensitive information only where:
- the individual has consented and the information is reasonably necessary for the firm’s functions or activities;
- the collection is required or authorised by law;
- the collection is necessary to establish, exercise or defend a legal claim;
- the collection is necessary for dispute resolution, complaints handling or regulatory compliance; or
- another exception under the Privacy Act applies.
In property and conveyancing matters, sensitive information may be collected where relevant to capacity, authority, verification of identity, foreign person status, AML/CTF due diligence, fraud prevention, client protection or compliance with court, statutory, regulatory or professional obligations.
5. AML/CTF INFORMATION
As an incorporated legal practice providing property and related legal services, MAP Lawyers may be required to collect, verify, use and retain personal information under the AML/CTF regime when providing designated services.
AML/CTF-related information may include:
- client identification information;
- beneficial ownership and control information;
- information about directors, trustees, partners, attorneys, authorised representatives and agents;
- source of funds and source of wealth information;
- transaction purpose and intended nature of the business relationship;
- politically exposed person screening results;
- sanctions screening results;
- adverse media and risk screening information;
- copies or records of identity verification documents;
- electronic verification results;
- ongoing customer due diligence records; and
- information relevant to suspicious matter reporting, threshold transaction reporting or other AUSTRAC obligations.
Where AML/CTF laws require information to be collected or verified, failure to provide the requested information may mean that MAP Lawyers cannot act, cannot continue to act, cannot complete a transaction, or must delay or cease providing services.
Certain AML/CTF obligations may also restrict what MAP Lawyers can disclose to an individual, including where disclosure may constitute tipping off or may prejudice an investigation, reporting obligation or enforcement process.
6. HOW PERSONAL INFORMATION IS COLLECTED
MAP Lawyers may collect personal information:
- directly from the individual;
- through client intake forms, costs agreements, authority forms and verification of identity processes;
- through electronic identity verification platforms;
- by email, telephone, video conference, online forms, website enquiries and correspondence;
- from contracts, title searches, settlement platforms and property transaction documents;
- from other parties to a transaction and their legal representatives;
- from real estate agents, mortgage brokers, lenders, accountants, financial advisers and other professional advisers;
- from government departments, courts, tribunals, regulators and statutory bodies;
- from publicly available registers, including ASIC, Titles Queensland, land valuation, planning, court and insolvency registers;
- from electronic lodgment network operators, including PEXA or other approved platforms;
- from banks, financiers and payment service providers;
- from trustees, companies, partnerships and other entities connected with a matter;
- from fraud prevention, sanctions screening and AML/CTF service providers; and
- from publicly available sources, including websites, search engines, media and social media, where relevant to a matter or compliance obligation.
Where practicable, MAP Lawyers will collect personal information directly from the individual. In some circumstances, collection from third parties is necessary or more practicable, including for property transactions, verification of authority, AML/CTF compliance, conflict checking, due diligence, fraud prevention and regulatory compliance.
7. COLLECTION OF INFORMATION ABOUT THIRD PARTIES
Clients and other persons may provide personal information about third parties to MAP Lawyers including spouses, family members, company officers, shareholders, trustees, beneficiaries, attorneys, guarantors, tenants, agents, employees and other transaction participants.
Where a person provides personal information about a third party, that person must have authority to do so or otherwise ensure that the third party is aware of:
- the disclosure to MAP Lawyers;
- the purposes for which the information is provided; and
- the matters set out in this Privacy Policy.
8. ANONYMITY AND PSEUDONYMITY
Individuals may contact MAP Lawyers anonymously or using a pseudonym where it is lawful and practicable to do so. However, anonymity or pseudonymity will usually not be practicable where MAP Lawyers is asked to provide legal services, act in a property transaction, receive or disburse money, verify identity, lodge documents, complete settlement, comply with AML/CTF obligations, or meet professional and statutory obligations.
9. PURPOSES FOR WHICH PERSONAL INFORMATION IS USED
MAP Lawyers may use personal information for the following purposes:
- providing legal services;
- opening and managing client files;
- conducting conflict checks;
- verifying identity and authority to act;
- advising on property law, conveyancing, contracts, transfers, mortgages, leases and related matters;
- preparing, reviewing, negotiating and settling transaction documents;
- undertaking due diligence and searches;
- communicating with clients, counterparties, advisers, agents, lenders, regulators and government bodies;
- managing trust account transactions, settlement funds and payment directions;
- completing electronic settlements and lodgments;
- complying with professional obligations, including under the Legal Profession Act 2007 (Qld), Legal Profession Regulation 2017 (Qld), Australian Solicitors Conduct Rules and trust accounting requirements;
- complying with AML/CTF, sanctions, fraud prevention, taxation, revenue, land titles, foreign ownership and other legal obligations;
- assessing and managing legal, commercial, operational and reputational risk;
- detecting, preventing and responding to fraud, cybercrime, identity theft, scams and unauthorised transactions;
- managing enquiries, complaints, disputes and regulatory investigations;
- billing, debt recovery and account administration;
- maintaining business records and file archives;
- obtaining professional advice, including from barristers, experts, accountants, auditors, insurers and consultants;
- conducting internal training, supervision, quality assurance and compliance monitoring;
- maintaining and improving services, systems and client communications;
- marketing legal services where permitted by law; and
- any purpose required or authorised by law.
10. LEGAL PROFESSIONAL PRIVILEGE AND CONFIDENTIALITY
MAP Lawyers is subject to duties of confidentiality and professional obligations applicable to Australian legal practitioners and incorporated legal practices.
Nothing in this Privacy Policy is intended to waive legal professional privilege or any other client privilege. Personal information that is subject to legal professional privilege will be handled consistently with applicable privilege, confidentiality, professional conduct and legal obligations.
However, privilege and confidentiality may be subject to exceptions, including where disclosure is required or authorised by law, by court order, by a regulator, for the defence of a legal claim, or with client authority.
11. DISCLOSURE OF PERSONAL INFORMATION
MAP Lawyers may disclose personal information to third parties where reasonably necessary for the purposes set out in this Privacy Policy, including to:
- clients and authorised representatives;
- other parties to a transaction and their legal representatives;
- real estate agents, buyers’ agents and property managers;
- lenders, mortgagees, brokers and financial institutions;
- PEXA or other electronic lodgment network operators;
- Titles Queensland, Queensland Revenue Office, local councils, water authorities and body corporate managers;
- the Australian Taxation Office, Australian Securities and Investments Commission, Australian Financial Security Authority, Foreign Investment Review Board and other government agencies;
- AUSTRAC, law enforcement agencies and regulators where required or authorised by law;
- courts, tribunals, dispute resolution bodies and statutory authorities;
- barristers, experts, consultants, search providers, valuers, surveyors and other professional advisers;
- verification of identity providers and AML/CTF screening providers;
- insurers, auditors, external examiners, professional indemnity bodies and regulatory bodies;
- trust account banks and payment service providers;
- IT, cloud storage, practice management, document management, cybersecurity and data hosting providers;
- debt recovery agencies and enforcement service providers;
- external complaint handlers or investigators;
- successors, assigns or proposed purchasers of the firm or part of its business, subject to confidentiality protections; and
- any person or body where disclosure is required or authorised by law.
12. DISCLOSURE TO AUSTRAC AND AML/CTF AUTHORITIES
Where required or authorised by AML/CTF laws, MAP Lawyers may disclose personal information to AUSTRAC, law enforcement agencies, regulators or other competent authorities.
This may include disclosure in connection with:
- enrolment or registration obligations;
- suspicious matter reports;
- threshold transaction reports, where applicable;
- compliance reporting;
- AUSTRAC notices or requests;
- investigations or enforcement action;
- sanctions compliance; and
- other AML/CTF statutory obligations.
In some circumstances, MAP Lawyers may be prohibited by law from notifying an individual about the making of a report or disclosure.
13. OVERSEAS DISCLOSURE
MAP Lawyers may disclose personal information to overseas recipients where necessary for the provision of services, technology support, cloud hosting, identity verification, AML/CTF screening, document processing, cybersecurity, professional advice or regulatory compliance.
Before disclosing personal information overseas, MAP Lawyers will take reasonable steps required by the Privacy Act, unless an exception applies. This may include using contractual protections, confidentiality obligations, security requirements and due diligence on service providers.
14. GOVERNMENT IDENTIFIERS
MAP Lawyers may collect and use government-related identifiers, such as passport numbers, driver licence numbers, Medicare numbers, tax file numbers, Australian business numbers or Australian company numbers, where required or authorised by law or reasonably necessary for legal services.
Government-related identifiers will not be adopted as the firm’s own identifier of an individual, except where permitted by law.
Tax file numbers will be handled in accordance with applicable tax file number rules and privacy requirements.
15. ELECTRONIC VERIFICATION OF IDENTITY
MAP Lawyers may use electronic verification of identity providers to verify identity, authority and transaction risk. This may involve checking identity information against government, commercial or other reliable data sources.
Electronic verification may involve collection or processing of:
- identity document details;
- copies or images of identity documents;
- facial images or biometric information, where liveness or facial matching technology is used;
- device information and IP address;
- verification results and risk indicators; and
- audit records of the verification process.
Where biometric information or other sensitive information is collected, MAP Lawyers will do so only where consent has been obtained or where collection is otherwise permitted by law.
16. TRUST MONEY, PAYMENT DIRECTIONS AND FRAUD PREVENTION
Property transactions involve elevated risks of cyber fraud, payment redirection fraud, identity theft and scam activity. MAP Lawyers may collect, use and disclose personal information to verify payment instructions, confirm bank account details, identify suspicious activity and protect client funds.
This may include disclosure to banks, payment service providers, electronic settlement platforms, insurers, regulators, law enforcement agencies and fraud prevention service providers.
Clients and other transaction participants may be required to complete additional verification steps before funds are received, transferred or released.
17. DIRECT MARKETING
MAP Lawyers may use personal information to send updates, publications, invitations or information about legal services that may be of interest, where permitted by law. An individual may opt out of direct marketing at any time by using the unsubscribe function in an electronic communication.
MAP Lawyers will not use sensitive information for direct marketing without consent, unless permitted by law.
18. WEBSITE, COOKIES AND ANALYTICS
When an individual uses the MAP Lawyers website, certain information may be collected automatically, including:
- IP address;
- browser type;
- device type;
- operating system;
- pages viewed;
- time and date of access;
- referring website; and
- general location information.
The website may use cookies, pixels, analytics tools or similar technologies to improve functionality, security, user experience and service delivery.
Website users may adjust browser settings to disable cookies. Some website features may not function properly if cookies are disabled.
19. SECURITY OF PERSONAL INFORMATION
MAP Lawyers will take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure.
Security measures may include:
- access controls and password protections;
- multi-factor authentication;
- encryption and secure file transfer systems;
- secure document management and practice management systems;
- staff confidentiality obligations and training;
- AML/CTF and privacy compliance procedures;
- cyber risk controls and monitoring;
- physical security for offices and files;
- secure destruction or de-identification of records;
- supplier due diligence and contractual confidentiality protections; and
- incident response and data breach procedures.
No method of transmission or storage is completely secure. MAP Lawyers will take reasonable steps proportionate to the sensitivity of the information and the risks associated with its handling.
20. DATA BREACHES
MAP Lawyers maintains procedures for identifying, assessing and responding to suspected data breaches.
Where a data breach is likely to result in serious harm to an individual, MAP Lawyers will comply with the Notifiable Data Breaches scheme under the Privacy Act. This may include notifying affected individuals and the Office of the Australian Information Commissioner, unless an exception applies.
Data breach response may also involve notification to insurers, regulators, law enforcement agencies, banks, electronic settlement platforms, cybersecurity providers and professional bodies where appropriate or required.
21. RETENTION OF PERSONAL INFORMATION
MAP Lawyers will retain personal information for as long as reasonably necessary for the purposes for which it was collected, including to provide legal services, maintain client files, comply with legal and professional obligations, resolve disputes and manage risk.
Retention periods may be affected by:
- legal professional obligations;
- client file retention requirements;
- trust accounting requirements;
- AML/CTF record-keeping obligations;
- taxation and revenue laws;
- limitation periods;
- insurer requirements;
- court, tribunal or regulatory requirements; and
- the nature of the matter.
As a general guide, client files and related records may be retained for at least 7 years after completion or termination of the matter, unless a longer retention period is required or appropriate. AML/CTF records may also need to be retained for prescribed statutory periods.
When personal information is no longer required, MAP Lawyers will take reasonable steps to destroy it securely or de-identify it, unless retention is required or authorised by law.
22. ACCESS TO PERSONAL INFORMATION
An individual may request access to personal information held by MAP Lawyers about that individual.
Requests should be made in writing to:
Megan Roberts
Director
MAP Lawyers
Level 3 193 North Quay, Brisbane QLD 4000
Email: contact@maplawyers.com.au
MAP Lawyers may require verification of identity before providing access.
Access may be refused or limited where permitted by law, including where:
- providing access would pose a serious threat to life, health or safety;
- access would have an unreasonable impact on the privacy of others;
- the request is frivolous or vexatious;
- the information relates to existing or anticipated legal proceedings and would not be accessible by discovery;
- access would reveal evaluative information generated in connection with a commercially sensitive decision-making process;
- access would prejudice enforcement activities or regulatory functions;
- access would be unlawful;
- access would prejudice AML/CTF reporting, investigation or compliance obligations;
- access would reveal a suspicious matter report or related information where disclosure is prohibited;
- legal professional privilege applies; or
- another exception under the Privacy Act applies.
Where access is refused, MAP Lawyers will provide written reasons, unless it would be unreasonable or unlawful to do so.
23. CORRECTION OF PERSONAL INFORMATION
MAP Lawyers will take reasonable steps to ensure that personal information it holds is accurate, up to date, complete, relevant and not misleading.
An individual may request correction of personal information by contacting the Privacy Officer. If MAP Lawyers is satisfied that the information is inaccurate, out of date, incomplete, irrelevant or misleading, reasonable steps will be taken to correct it.
Where a correction request is refused, MAP Lawyers will provide written reasons and, where required by law, take reasonable steps to associate a statement with the information noting that the individual considers it to be inaccurate, out of date, incomplete, irrelevant or misleading.
24. COMPLAINTS
An individual may make a complaint about how MAP Lawyers has handled personal information.
Complaints should be made in writing to:
Megan Roberts
Director
MAP Lawyers
Level 3 193 North Quay, Brisbane QLD 4000
Email: contact@maplawyers.com.au
Phone: 1300 680 584
A complaint should include sufficient detail to enable MAP Lawyers to assess and respond to the issue.
MAP Lawyers will usually:
- acknowledge the complaint within a reasonable time;
- investigate the complaint;
- request further information if required;
- provide a written response within a reasonable time, generally within 30 days; and
- take appropriate remedial action where the complaint is substantiated.
If an individual is not satisfied with the response, the individual may complain to the Office of the Australian Information Commissioner:
Office of the Australian Information Commissioner
GPO Box 5288
Sydney NSW 2001
Australia
Website: www.oaic.gov.au
Telephone: 1300 363 992
25. PRIVACY AND AML/CTF COMPLIANCE OFFICER
The contact for privacy enquiries and complaints is:
Megan Roberts
Director
MAP Lawyers
Level 3 193 North Quay, Brisbane QLD 4000
Email: contact@maplawyers.com.au
Phone: 1300 680 584
26. CHANGES TO THIS PRIVACY POLICY
MAP Lawyers may update this Privacy Policy from time to time to reflect changes in law, regulatory guidance, professional obligations, technology, business practices or services.
The current version will be available at www.maplawyers.com.au or on request.
