How we can help
Privacy law now determines what organisations can do with data, not merely how it is protected. We partner with clients to design and implement data strategies that enable innovation, digital transformation, and responsible data exploitation, while ensuring compliance with regulatory frameworks and community expectations
Our advice spans the full privacy lifecycle: collection and consent; use and secondary use; disclosure and data sharing; cross-border transfers; data governance, retention, and secure disposal. We guide clients through the privacy dimensions of emerging technologies – including AI, advanced analytics, the Internet of Things and connected services – across clinical, government, and commercial settings.
We bring deep sector expertise in regulated financial services, health and life sciences, telecommunications, consumer and retail, social media, and across government (Commonwealth, State and Territory), and advise across all other industries where personal information and data are critical business assets. We also act for adjacent services providers, system integrators, cloud and SaaS providers, data processors, and outsourced service operators, who handle personal information on behalf of regulated entities.
Our team combines specialist privacy law expertise with deep experience in technology transactions, cyber security, regulatory enforcement, and corporate governance. We conduct privacy audits, impact assessments, and governance framework design; manage cyber breach response and notifiable data breach obligations; and advise on compliance with the Privacy Act 1988, the Australian Privacy Principles, sector-specific legislation, and international regimes including the GDPR and APEC Cross-Border Privacy Rules.
Collaborating with legal, compliance, technology, data science, and operational teams, we proactively identify privacy and data protection risks, assess lawful and ethical use cases, map data flows and translate complex regulatory requirements into actionable, organisation-wide controls.
Experience
-
Major Australian trading bank
Advising on privacy, data protection and information security matters, including the practical application of APRA CPS 234 to FinTech onboarding arrangements, Consumer Data Right compliance and engagement with the ACCC, and privacy advisory in connection with customer scam-related issues. -
International hospitality platform
Advised on Australian data privacy and UK GDPR compliance program, including undertaking a detailed enterprise-wide audit of privacy practices. -
Multinational consumer goods group
Advised on privacy policy redesign, including automated decision-making and chatbot disclosures, Children’s privacy considerations, and development of scalable policies across brand portfolio. -
Leading healthcare provider
Advised on a significant data breach affecting its core Australian clinical services business, including sensitive information of government customers and end-users. -
Baby Bunting
Conducted an audit of privacy and spam compliance program, including data retention compliance, assessing existing operations, processes and procedures, preparing a gap analysis report and recommendations plan, and implementing remediation actions. -
Health Partners
Conducted a comprehensive review of privacy arrangements across insurance and health services divisions, including advice on data practices involving AI tools in clinical settings and sensitive health information. -
Federal Government
Delivered privacy, secrecy and legal risk advice on an agency-wide rollout of AI tools across a workforce which handles sensitive data regulated by multiple pieces of Commonwealth legislation. -
Tabcorp
Advised on group-wide data privacy strategy, including designing the Group's data breach response plan, structuring data-sharing arrangements between entities, developing privacy policies, undertaking AI-related privacy audits, and providing ongoing privacy compliance and breach readiness advice.