Skip to main content
TRINGALI LAWYERS
LEGAL

Privacy Policy

Last updated: 6 July 2026~10 min read

Tringali Lawyers | ABN 81 697 063 040 | Melbourne VIC | talia@tringalilawyers.com.au | 0432 651 326

This Privacy Policy applies to personal information we collect and handle in connection with our legal services, client onboarding and administration, conflict checking, AML/CTF compliance, recruitment, events, publications, website use and general practice operations.

We maintain practices, procedures and systems designed to support compliance with the APPs and the AML/CTF Act, including controls relating to confidentiality, information security, records management, direct marketing, access and correction requests and complaints handling.

The kinds of personal information we collect and hold depend on the nature of your relationship with us, including whether you are a client, prospective client, a person connected with a client matter, a supplier, service provider, job applicant, employee, contractor, subscriber, event attendee or website user. This may include:

Sensitive information: where you or another person voluntarily provide health information, criminal history or other sensitive information as part of your legal matter or our AML/CTF obligations, we collect and handle that information only where permitted by law, including where you consent and the information is reasonably necessary for our functions, where collection is required or authorised by law, or where necessary for legal claims or the provision of legal services.

We usually collect personal information directly from you when you instruct us, provide information or documents, communicate with us, complete a form or identity verification process, subscribe to our publications, register for an event, interact with our Website, or apply for employment or engagement with us.

We may also collect personal information from third parties where permitted by law, including clients, counterparties, witnesses, representatives, advisers, courts, tribunals, regulators, government bodies, public registers, commercial databases, identity verification providers, AML/CTF screening providers, financial institutions, recruitment agencies, referees, former employers and technology or analytics providers.

If you provide us with personal information about another individual, please take reasonable steps to ensure that person is aware their information has been provided to us and of this Privacy Policy. You should only provide sensitive information about another individual where you have their consent or authority to do so, or where otherwise permitted by law.

We use personal information for purposes including:

We do not use personal information to make decisions solely by automated means where that decision would significantly affect your rights or interests (see clause 7).

We may disclose personal information to:

We do not sell, rent or trade personal information to third parties for marketing purposes.

Where AML/CTF laws apply, we may be required to collect, verify, use, disclose and retain personal information about clients and other relevant persons before we provide a service and throughout a matter.

This may include information required to verify your identity, understand the nature and purpose of the service you have asked us to provide, identify beneficial owners (broadly, individuals with 25% or more ownership or control) or persons on whose behalf you act, verify your authority to act, establish source of funds or source of wealth, conduct sanctions and politically exposed person checks, assess risk and monitor transactions or behaviours on an ongoing basis.

If you do not provide the information we request, we may be unable to provide the requested service, or may need to pause, limit or terminate our work, subject to our professional obligations and applicable law.

We may be required to disclose information to AUSTRAC or another authority where required or authorised by AML/CTF laws. Those laws restrict what we can tell you about certain reports, notices, investigations, requests or disclosures (see clause 8).

We use technology, including automated and computer-assisted tools, for functions such as identity verification, document verification, sanctions and politically exposed person screening, transaction monitoring, risk assessment and conflict checking.

We do not use these tools to make solely automated decisions that significantly affect an individual's rights or interests. Automated outputs may inform decisions made by appropriately trained personnel, including whether we can act for you, whether enhanced customer due diligence is required, or whether AML/CTF or other legal steps are required.

Our duties of confidentiality and legal professional privilege remain important and are not displaced by this Privacy Policy. Some laws, including the AML/CTF Act, may require or authorise us to collect, use, disclose or retain personal information despite those duties. Where privilege may apply to information or documents requested under AML/CTF laws or other laws, we assess and manage privilege claims in accordance with applicable legal requirements.

Where we form a suspicion that must be reported to AUSTRAC, the law may prohibit us from telling you, or anyone else, that a report has been made or is proposed to be made (this is known as tipping off). Separately, if the sole basis for a suspicious matter report is privileged information, we are not required to make that report and we will only ever disclose non-privileged information where privilege applies to part of our reasons for suspicion.

We do not adopt a government-related identifier as our own identifier of an individual unless permitted by law. We may collect, use or disclose government-related identifiers where reasonably necessary for identity verification, legal services, AML/CTF compliance, court or tribunal processes, regulatory compliance, or where otherwise required or authorised by law.

Where we are permitted by law to do so, we may use your contact details to send you marketing communications, legal updates, publications and event invitations about our services. Marketing communications sent by electronic means are sent in accordance with the Spam Act 2003 (Cth) and only to recipients who have consented, expressly or by inference, to receive them.

Each electronic marketing message will identify us as the sender and include a functional unsubscribe facility. You can opt out at any time by using the unsubscribe link, replying STOP to an SMS, or contacting us using the details in clause 17. We do not use sensitive information for direct marketing without your consent.

Some of our service providers (for example, cloud hosting, email, practice management and AML/CTF screening providers) may store or process personal information outside Australia. We may also disclose personal information overseas where necessary for your legal services, where you have consented, or where a matter involves an overseas party, transaction, court, tribunal, regulator, registry or authority.

The countries in which overseas recipients are located will depend on the particular matter, service provider or technology used. Before we disclose personal information overseas, we take the reasonable steps required by APP 8 to ensure the overseas recipient handles your personal information in a way that is consistent with the APPs, unless an exception applies.

We take reasonable steps to ensure the personal information we collect, use and disclose is accurate, up to date, complete and relevant and to protect it from misuse, interference, loss, unauthorised access, modification and disclosure, as required by APP 11. Those steps include physical, technical and administrative safeguards, such as access controls, password protection, secure cloud services, staff training and confidentiality obligations on our staff and contractors.

We retain personal information only for as long as we reasonably need it for the purposes set out in this Privacy Policy, or as otherwise required or permitted by law, including legal profession record-keeping obligations, tax and audit requirements, professional indemnity insurance arrangements and AML/CTF compliance. Records required under AML/CTF laws may need to be retained for a prescribed period of at least 7 years.

When we no longer need personal information for a lawful purpose, we will take reasonable steps to destroy it or de-identify it, subject to these retention requirements.

We have a data breach response plan. If we have reasonable grounds to believe that an eligible data breach has occurred, in line with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act, we will notify the Office of the Australian Information Commissioner (OAIC) and any affected individuals as soon as practicable.

You have the right to ask for access to personal information we hold about you and to ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.

To make a request, please contact us using the details in clause 17. We will respond within a reasonable period (usually within 30 days) and we may need to verify your identity before providing access. We will tell you if there is a reason we are unable to provide access or make a correction.

If you believe we have handled your personal information in a way that does not comply with the APPs or this Privacy Policy, please contact us to make a complaint. We will respond within a reasonable period (usually within 30 days). If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner:

Our Website may use cookies, pixels, analytics tools and similar technologies to enable functionality, understand website usage, improve our services and support communications. Analytics data is collected in aggregated and de-identified form where practicable.

Most internet browsers allow you to delete or block cookies, or to receive a warning before a cookie is stored. If you disable cookies, some parts of the Website may not function as intended.

We may update this Privacy Policy from time to time. The current version will always be available at tringalilawyers.com.au/privacy.

If you have any questions about this Privacy Policy or wish to exercise any of your rights, please contact us via the contact details set out on this Website.

This Privacy Policy does not form part of any client engagement agreement. For information about how we handle client confidentiality, please see your costs agreement or engagement letter.

Questions about this policy? Contact talia@tringalilawyers.com.au.