Introduction

Roach Corporate Law Pty Ltd ACN 602 864 068 t/a LRB Legal (“LRB Legal”) (“we”, “our”, “us”) is bound by the Australian Privacy Principles (“APP”) as set out in the Privacy Act 1988 (Cth) (the “Privacy Act”), as well as the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (the “AML/CTF Act”).

LRB Legal has adopted all the principles set forth in the APP that govern the collection, use, disclosure, quality, security, access, and correction of personal information. Under the Privacy Act, ‘personal information’ means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether the information or opinion is recorded in material form or not.

This Privacy Policy applies to all personal information that LRB Legal may collect, use, and disclose, whether that information is manually or digitally processed.

By accessing our website and/or using our services, you agree to this Privacy Policy. Your use of the website and/or our services constitutes your consent to the collection, storage, use, and disclosure of your personal information in accordance with this Privacy Policy.

This Privacy Policy is additional to any other terms and conditions applicable to the website and our services.

Personal Information and Collection

LRB Legal collects personal information from you when you engage our services. We collect this information in order to provide the services you request from us. The personal information we may collect includes your title, full name, residential and postal address, telephone number, email address, date of birth, citizenship, and transactional information, including your method of payment for our services. We may also collect relevant personal information relating to your dependants where necessary for the provision of our services. This information is generally collected at the time you engage our services.

We may also be required to collect further information from you as part of our services in order to comply with the relevant customer due diligence requirements under the AML/CTF Act, including where the services we provide are considered designated services under section 6 of the AML/CTF Act. This may include collecting information to:

  • Establish and verify your identity before providing certain services to you or to the person or entity on whose behalf you are acting; or
  • Assess and manage potential money laundering, terrorism financing, proliferation financing, or related compliance risks associated with the provision of our services; or
  • Meet record keeping obligations and make reports required by law under the AML/CTF Act.

We will usually collect your personal information directly from you unless it is unreasonable or impracticable to do so. Collection occurs through but may not be limited to:

  • Face-to-face meetings and telephone calls;
  • Electronic communication, client onboarding forms, and our website; or
  • Approved third-party electronic identity verification providers, including but not limited to Infotrack service provider.

We may also collect relevant information from third parties where appropriate, including government agencies, credit reporting services, and publicly available sources.

Please note that if you do not provide us with your personal information to allow us to undertake the relevant verification pursuant to the AML/CTF Act, we may not be able to verify your identity, and therefore cannot provide you (or the person/entity you are acting on behalf of) with the services you have requested.

Sensitive Information

LRB Legal does not generally collect sensitive information about an individual. Under the Privacy Act, ‘sensitive information’ includes, but is not limited to, information or an opinion about an individual’s racial or ethnic origin, religious beliefs, and health information.

If sensitive information is required, LRB Legal will only collect that information with the individual’s consent, where it is reasonably necessary for the delivery of our services, or where otherwise permitted or required by law. This clause does not apply to sensitive information we are required to collect under the AML/CTF Act, which may, for example, relate to your political, professional, or trade associations in order to determine whether you are a politically exposed person.

Credit Card Details

Credit card details may be used to process payments for our services. Your credit card may be charged to secure our services, either before or after those services are provided, in accordance with any terms that apply to the provision of our services from time to time. We will advise you in advance when charges will be made and obtain your prior consent. We use a third-party provider, Square, to process credit card payments and will notify you if this changes.

Use of Information

LRB Legal uses the personal information it collects to provide our services and to carry out the administrative functions associated with those services, including billing and entering into contracts with you or relevant third parties.

We will not use or disclose your personal information for a purpose other than:

  • as set out in this Privacy Policy;
  • a purpose you would reasonably expect, including communications with relevant industry professionals and information about related services;
  • verifying your identity under the AML/CTF regulatory frameworks;
  • a purpose required or authorised by law; and/or
  • a purpose for which we have otherwise sought your prior consent.

Disclosure of Personal Information

LRB Legal does not disclose personal information it holds without the individual’s prior consent unless disclosure is permitted under the Privacy Act or the AML/CTF Act, otherwise required by law, or reasonably necessary to provide the services requested from us. We respect the privacy of users who visit our website or use our services and do not share personally identifiable information with third parties unless consent has been provided or disclosure is otherwise permitted by law.

The uploading or transmission of data, including personal information, may be handled by third parties. In those circumstances, we are not responsible for that uploading or transmission, and you are responsible for the personal information you choose to disclose.

Data Integrity

LRB Legal only uses the personal information necessary to perform the services requested. In some cases, you may provide more information than is required for that purpose. Where that occurs, LRB Legal will identify and use only the information necessary for the relevant purpose. Any additional information will remain secure and unused until it is destroyed or returned to you on request. LRB Legal only stores personal information where required for the provision of services, where specifically requested by the client, or as part of standard backup and archiving processes. All archived files are stored securely.

Data Security

LRB Legal takes reasonable steps to protect personal information in its care from misuse, interference, loss, and unauthorised access, modification, or disclosure. Access to personal information stored on LRB Legal’s servers is restricted to employees and contractors who require access for a legitimate business purpose relating to service delivery, maintenance, internal security, or related operational matters. All employees and contractors with access to personal information are subject to confidentiality obligations.

In the event of a data security breach, the affected individual/s and the Office of the Australian Information Commissioner (“OAIC”) will be notified.

When personal information is no longer required, and LRB Legal is not required by law or by order of a court or tribunal to retain it, LRB Legal will take reasonable steps in the circumstances to destroy or de-identify that information.

Data Storage

LRB Legal stores data securely on servers located in Australia. Where LRB Legal or its agents store data on LRB Legal’s behalf, LRB Legal will take reasonable steps to ensure that the Australian Privacy Principles apply to those arrangements. During electronic communications, LRB Legal or its agents may deliver information requested by you to nominated email accounts or websites, and data associated with those communications may not always be stored in Australia. If this is a concern, you should check your nominated delivery address.

Please be aware that when you access electronic communications, the relevant data may be stored on an overseas server. Where your nominated electronic delivery address stores data overseas, LRB Legal expects that you are aware of this and consent to the communication being delivered in that way.

Where LRB Legal communicates personal information to our agents or our service providers through a server that is overseas, LRB Legal will only do so where we have your consent, where we are expressly allowed through other means, or where we hold a reasonable belief that the recipient is subject to a law, binding scheme, or contract which effectively upholds the principles for the fair handling of the information that are substantially similar to our obligations under the APP.

Correction of Personal Information

LRB Legal takes reasonable steps to ensure that all personal information it holds is accurate, complete, and up to date. You should also promptly notify LRB Legal if any personal information that it holds about you is incorrect or out of date. We will take reasonable steps to ensure the personal information we hold remains accurate and, if you advise us of a change of details, we will amend our records accordingly.

Access to Personal Information

Individuals may request access to the personal information that LRB Legal holds about them by contacting LRB Legal’s Privacy Officer using the details set out below. LRB Legal will respond within a reasonable period and, where reasonable and practicable, provide access in the manner requested or in another suitable way. LRB Legal may charge its reasonable costs for responding to a request for access. If LRB Legal refuses access to any personal information, it will provide a written explanation of the reasons for the refusal and how the individual may make a complaint.

Online Links to Third-Party and Co-Branded Sites

LRB Legal may have relationships with third parties that allow visitors to our website to link directly to sites operated by those third parties. Some of those sites may be co-branded with our logo; however, they may not be operated, controlled, or maintained by us or on our behalf. We do not accept responsibility for any third-party sites. Those sites may collect personal information from you that may be shared with us. This Privacy Policy applies to any personal information LRB Legal receives in this way.

LRB Legal is not responsible for the content or practices of websites operated by third parties that are linked to our website. These links are provided for convenience only and do not constitute sponsorship, endorsement, or approval by LRB Legal of the content, policies, or practices of those third-party sites. Once you leave our website via such a link, you should review the applicable privacy policy of the third-party site.

Updates to Policy

This Privacy Policy is effective from 1 July 2026. We reserve the right to change this Privacy Policy from time to time, including as required under relevant legislation, without further notice to you. Any variations made will be updated on our website. Your use of our website or of the services following any such change to the Privacy Policy will confirm your acceptance of the changes.

Applicable Law

Our services are governed and construed according to the laws of the State of South Australia. By using our website and/or our services, you agree to submit to the jurisdiction of the courts of South Australia.

Knowing Your Privacy Rights

You may interact with us anonymously where this is lawful and practicable.

You have the right to request access to the personal information you provide, and to correct or update your personal information. This right is subject to certain exceptions allowed by law.

You can obtain further general information about your privacy rights and privacy law from the OAIC by:

  • Calling the Privacy Hotline on 1300 363 992; or
  • Visiting the official website at privacy.gov.au

How to Contact Us

If you have any enquiries, concerns, or complaints relating to this Privacy Policy or practices, or you wish to request access to and correct any of the personal information LRB Legal holds about you, please contact LRB Legal’s Privacy Officer as follows:

If you wish to make a formal privacy complaint, you should contact LRB Legal by emailing Melanie Bird at mbird@lrblegal.com.au  and including ‘PRIVACY COMPLAINT’ in the subject line. LRB Legal will deal with all complaints fairly and in confidence. If, after making an initial complaint, you are dissatisfied with our resolution, you may escalate your complaint to the OAIC after 30 days have passed since you informed LRB Legal of your complaint.

If you are unsure whether you can complain to the OAIC, please use the OAIC’s ‘complaint checker’ on its website: https://www.oaic.gov.au/privacy/privacy-complaints/lodge-a-privacy-complaint-with-us or contact the OAIC enquiries line on 1300 363 992. Complaints can be made to the OAIC online or by completing and submitting the OAIC’s Privacy Complaint Form.