This Privacy Policy applies to all operations conducted by Bridges Lawyers.
Bridges is committed to protecting the privacy and confidentiality of Personal Information in accordance with the Privacy Act, the APPs, the AML/CTF Act, other applicable Australian State and Commonwealth laws and our professional obligations as legal practitioners.
This Privacy Policy outlines how we collect, hold, use, disclose and otherwise manage Personal Information in the course of providing legal services, operating our business, and complying with our legal and regulatory obligations.
Differing data protection laws may apply where we obtain Personal Information from people outside of Australia. We endeavour to apply with that legislation where applicable.
This Privacy Policy applies to Personal Information we collect and handle in connection with:
In this Privacy Policy the terms listed have the following meanings:
| Term | Definition |
|---|---|
| AML/CTF Act | Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). |
| AML/CTF Framework | The AML/CTF Act, Rules and AUSTRAC-issued guidance. |
| AML/CTF Rules | Anti-Money Laundering and Terrorism Financing Rules 2025 (Cth) made under the AML/CTF Act. |
| APPs | The Australian Privacy Principles in Schedule 1 of the Privacy Act. |
| Bridges, we, us, our | Bridges Lawyers Pty Ltd, ABN 13 160 506 114, practising as Bridges Lawyers. |
| Designated Services | All the services described as Professional Services in Table 6 of section 6 of the AML/CTF Act and its relevant subsections, including:
|
| KYC Information | Customer identification and verification information required under the AML/CTF Framework. |
| OAIC | Office of the Australian Information Commissioner. |
| Personal Information | Information or an opinion about an identified individual or an individual who is reasonably identifiable. |
| Privacy Act | Privacy Act 1988 (Cth). |
| Sensitive Information | As defined in the Privacy Act, including health, criminal records, ethnicity, political or religious beliefs, sexual orientation, biometric or genetic data. |
| You, your, yours | The user of our Services or user or viewer of our Website. |
As a supplier of legal services, the Personal Information we may collect depends how you use our Services as well as the type of relationship we have with you and may include:
We are required by law under the AML/CTF Act to collect and verify certain Personal Information and may be prohibited from providing services if we cannot do so.
In particular, we collect KYC Information as required by the AML/CTF Act which may include the information detailed above as well as:
We may infer information about you from your engagement with us and your activities.
We may also collect Sensitive Information where required for compliance with the AML/CTF Framework or where permitted by law.
We may conduct ongoing monitoring of transactions and client information to comply with our AML/CTF obligations.
If you do not provide requested Personal Information, we may be unable to provide Designated Services and/or comply with our legal obligations.
We will collect and hold personal information in relation to job applications. Such information includes name, address, telephone number and any CVs submitted by job applicants.
We will collect and hold personal information of the type described as an ‘employee record’ within the meaning of the Privacy Act 1988. Such information includes but is not limited to, health information about the employee and information which includes their contact details, referral documents, employment contract, employment record including any disciplinary proceedings, taxation, banking and superannuation affairs.
We collect Personal Information only by lawful and fair means.
We will collect Personal Information directly from the individual who is the subject of the information unless:
We may collect Personal Information when you, your organisation or those acting on your or your organisation’s behalf:
We collect and use Personal Information to carry out our activities and functions including providing you with Services including Designated Services, complying with our regulatory obligations in relation to the delivery of those services, including adherence to the Legal Profession Uniform Law and its related rules and legislation, the Legal Profession Uniform Law Australian Solicitors’ Conduct Rules 2015 (NSW) and the Legal Profession Uniform General Rules 2015 (NSW). Other relevant legislation which may require us to collection and use your Personal Information includes the Duties Act 1997 (NSW) and the Australian Registrars National Electronic Conveyancing Council’s Model Participation Rules.
Unless you consent to us doing so otherwise, we will only use your Personal Information for the primary purposes for which it was collected and for any secondary purpose if you would reasonably expect and the purpose is related to the primary purpose of collection.
In the case of Sensitive Information, any secondary purpose will be one that you would reasonably expect and directly related to the primary purpose of collection.
Subject to legal requirements, we do not share your Personal Information with any third parties except:
This may include service providers that support our due diligence processes associated with complying with our AML/CTF obligations.
We will ensure that such service providers commit to protecting your Personal Information appropriately and agree to not use or disclose your Personal Information for any other purpose (other than as required by law).
We may use or disclose your Personal Information in circumstances where required by law and/or expressly permitted by the Privacy Act, including if:
Nothing in this Privacy Policy limits our obligations of confidentiality or client legal privilege.
However, there may be circumstances where we are compelled to disclose confidential information to AUSTRAC under the AML/CTF Framework.
If we are involved in a merger, acquisition or asset sale, your Personal Information may be disclosed in confidence as part of a due diligence process and may be transferred to the new owner. We will provide notice before your Personal Information is transferred.
We hold Personal Information in electronic formats.
We take reasonable steps to prevent unauthorised access, disclosure, alteration, destruction or loss of Personal Information including by using a range of physical, operational and technological security measures to protect this information.
These measures include organisational and technical measures such as:
Where a data breach is likely to result in serious harm, we will comply with the Notifiable Data Breaches scheme in the Privacy Act including notifying the OAIC and affected individuals as required.
When we consider that Personal Information is no longer needed for any purpose for which the information may be used or disclosed in accordance with this Policy and that we are not required by law or court order to retain the Personal Information, we will take reasonable steps to destroy or de-identify this information.
AML/CTF KYC Information and transaction records are kept for seven years after the business relationship ends or the transaction is completed, as required by the AML/CTF Framework.
You may request access to or correction of your Personal Information that we hold. Access will be provided if it is reasonable and practicable to do so. Instances where we may refuse your request as set out in the Privacy Act include:
If you believe that Personal Information we or our contracted third party hold about you is inaccurate, out-of-date, incomplete, irrelevant or misleading, you may request that we correct this information.
We may require proof of identify before granting access to information and we may charge a reasonable fee for providing access (but not for making a correction).
We will take reasonable steps to correct your information to ensure it is accurate, complete and up-to-date within a reasonable period (usually within 30 days) of receiving your request.
Our website may use standard technologies such as cookies or analytics tools to support basic website functionality and security.
However:
If you have a complaint about how we handle Personal Information, please reach out to your direct contact at the firm or by the contact details provided at the end of this policy.
Your complaint will be acknowledged promptly and we will endeavour to respond to you within 30 business days.
If you are not satisfied with the outcome of your complaint to Bridges, you may contact OAIC.
We may make changes to this policy from time to time in accordance with legislative updates or when OAIC material is updated.
Changes to this policy will be posted to our Website and we recommend you review this privacy policy periodically when rendering our Services or visiting our Website.
If you require any further information regarding this Privacy Policy or have any concerns, please reach out via the details below or directly to your solicitor.
Email: admin@bridgeslawyers.com.au