Privacy Policy
Version 2.0 | 2 July 2026 | Supersedes the policy last updated 1 October 2025
Your privacy is important to us. This policy explains what personal information New Era Lawyers Pty Ltd (ABN 69 608 860 519, trading as New Era Law) (“we”, “us”, “our”, “the firm”) collects, holds, uses and discloses, how we protect it, and how you can access it, correct it, or make a complaint.
This policy forms part of any costs agreement you enter into with us. By accepting the terms of our costs agreement, you consent to our handling of your information in accordance with this policy.
If you have any questions, please contact our Privacy Officer using the details at the end of this policy.
1. Scope of this policy
From 1 July 2026, law firms that provide one or more “designated services” under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act) are regulated entities under the Privacy Act 1988 (Cth) (Privacy Act) in respect of the personal information they collect, use or disclose for AML/CTF purposes.
In this policy, regulated personal information means personal information that we collect, hold, use or disclose for the purposes of, or in connection with, our obligations under the AML/CTF Act -for example, information collected to verify your identity (KYC) and to carry out customer due diligence. We handle regulated personal information in accordance with the Australian Privacy Principles (APPs) in the Privacy Act.
We also voluntarily apply the standards in this policy to other personal information we hold, as a matter of good practice and consistent with our professional duties of confidentiality. Nothing in this policy is intended to extend our obligations under the Privacy Act beyond regulated personal information, except where we have chosen to do so.
2. Our Privacy Officer
We have appointed a Privacy Officer who is responsible for overseeing our privacy compliance, dealing with access and correction requests, and handling privacy complaints. The Privacy Officer can be contacted using the details in section 16.
3. What information we collect and hold
The information we collect depends on the services we provide and how you interact with us. It may include personal information (information that identifies you or from which you can reasonably be identified). Depending on the circumstances, this may include your:
- name, and any former or alternative names;
- date of birth;
- e-mail address;
- residential and postal address;
- telephone number and other contact details;
- bank account and payment details;
- occupation, and business, employment, financial and tax-related details;
- technical information when you use our website or online services (such as IP address, device, browser and usage data);
- details relevant to the legal matter on which you instruct us;
- information about a third party that you provide to us (see section 9); and
- any other information you disclose to us through interacting with us or our services.
To meet our customer due diligence obligations under the AML/CTF Act, we also collect identification and verification information, which may include:
- government-issued photographic identification (such as a driver licence or passport);
- government identifier details;
- source of funds and source of wealth information; and
- information about beneficial owners, and the control and ownership structure of a client that is a company, trust or other entity.
Sensitive information. Some of this information (for example, government identifiers and photographic ID) is “sensitive information” under the Privacy Act. We collect it only where it is reasonably necessary, and where we are required or authorised to do so under the AML/CTF Act and associated rules, or with your consent.
It is optional for you to provide us with Personal Information. However, we may not be able to provide some or all of our services to you without certain Personal Information. This includes information we are required to collect to verify your identity under the AML/CTF Act.
4. How we collect information
We generally collect information directly from you – for example when you meet or speak with us, send us correspondence or documents, complete our forms, or interact with us through our website. Where it is reasonable and practicable, we collect personal information directly from the individual concerned.
We may also collect your information from third parties such as:
- other service providers affiliated with you, such as your accountant or financial advisor;
- identity verification and electronic verification service providers;
- government bodies, departments or agencies;
- anyone who forwards us correspondence from or about you;
- publicly available sources;
- cookies and other data tracking technologies.
5. How we hold and protect your information
Any information held by us is stored on our business premises in Maroochydore, Queensland, and/or stored digitally on the cloud or third party servers.
Stripe Payments Australia Pty Ltd ACN 160 180 343 (Stripe) processes any payments made through our website on our behalf. Information collected by Stripe will be handled in accordance with Stripe’s Privacy Policy.
We have taken all reasonable steps, including implementing security systems and protocols, to prevent any misuse, loss, interference, modification or unauthorised access or disclosure of the information held by us and require our contractors to do the same. We take the security of identity documents and other sensitive information particularly seriously, and work towards recognised cyber-security standards appropriate to a firm of our size.
6. Why we collect, hold, use and disclose your information
We do not sell your personal information. We collect, hold, use and disclose your information for purposes connected with providing legal services to you and running our practice, including to:
- to verify your identity;
- to communicate with you and with others involved in your matter;
- to provide legal advice and services and legal services and conduct legal research;
- to process payments and to collect and pay any amount on your behalf or to make a payment to you;
- to meet our obligations under the AML/CTF Act and other laws (see section 7);
- to manage, administer, maintain and improve our practice and services;
- to investigate any complaint made by or against you or to investigate any unlawful or improper use of our services;
- to establish, exercise or defend legal rights or claims; and
- to comply with our legal and professional obligations.
We use and disclose personal information for the purpose for which it was collected, for a directly related secondary purpose you would reasonably expect, where you have consented, or where we are otherwise permitted or required to do so by law.
7. Who we disclose information to
Where necessary for the purposes above, and only to the extent necessary, we may disclose personal information to:
- third-party service providers who help us run our practice, such as IT, data-hosting, identity-verification and payment providers;
- other advisers or parties involved in your matter, where authorised;
- AUSTRAC, and other regulators, courts, tribunals or government agencies, where required or authorised by law; and
- a purchaser or successor, as part of any sale, merger or reorganisation of our business.
When Personal Information is disclosed by us to third parties as above, it will only be disclosed to that party to the extent necessary for the disclosure purpose identified.
Reporting and confidentiality under the AML/CTF Act. We are required to report certain matters to AUSTRAC, including suspicious matters and threshold transactions. The law restricts us from disclosing the existence or content of a suspicious matter report (the “tipping-off” rules). As a result, our obligation to give you access to your information (section 11) is subject to these restrictions, and there are some things we may be unable to tell you.
8. Overseas disclosure
Our office and operations are based in Australia. However, some of our service providers (for example, data-hosting and software providers) may be located, or store data, overseas — including in [the United States and India]. Where we disclose regulated personal information overseas, we take reasonable steps to ensure that the overseas recipient handles it consistently with the Australian Privacy Principles.
9. Information about third parties
Please do not provide us with Personal Information of a third party unless requested by us. If you provide us with Personal Information about a third party, you warrant that you have the consent of that third party to provide that Personal Information. If you provide us with personal information about a third party (for example, about a beneficial owner or another party to a transaction), you confirm that you are authorised to provide it to us and will, where appropriate, make that person aware of this policy.
10. How long we keep your information
We keep personal information only for as long as it is needed for the purposes set out in this policy, or as required by law. We are required to keep certain AML/CTF records for at least seven years. As a law firm, we may also need to retain file material for longer periods to meet our professional obligations and to establish or defend legal claims.
When information is no longer needed for any of these purposes, and we are not required by law to retain it, we take reasonable steps to destroy it or to de-identify it.
11. Accessing and correcting your information
You may request access to the personal information we hold about you, and ask us to correct it if you believe it is inaccurate, out of date, incomplete, irrelevant or misleading. This right is available to individuals generally, including people who are not our clients.
To make a request, please contact our Privacy Officer using the details in section 16. We do not charge you to make a request. We may charge a reasonable amount to cover the cost of giving access, but we will not charge an amount that is excessive.
We will respond within a reasonable time. In some cases we may be unable to give access or make a correction — for example, where doing so would breach legal professional privilege, affect another person’s privacy, relate to anticipated or current legal proceedings, or be prohibited by law (including the AML/CTF “tipping-off” rules). If we refuse a request, we will tell you why (to the extent we are able to) and how you may complain.
12. Data breaches
We maintain a data breach response plan. If we experience a data breach involving personal information that is likely to result in serious harm, we will respond in accordance with the Notifiable Data Breaches scheme under the Privacy Act, which may include notifying affected individuals and the Office of the Australian Information Commissioner (OAIC).
13. Automated decision-making
We do not use computer programs to make, or to substantially assist in making, decisions about you in a way that could significantly affect your rights or interests.
14. Complaints
If you have a concern or complaint about how we have handled your personal information, please contact our Privacy Officer in the first instance using the details below. We will acknowledge your complaint, investigate it, and aim to respond as soon as we can. Please allow us up to 30 days to respond before taking any other action. We will tell you the outcome of our investigation and any steps we propose to take.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au. The OAIC generally requires that you have complained to us first.
15. Changes to this policy
We may update this policy from time to time. The current version will always be available on our website, and the version number and date below will be updated when we make changes. Where appropriate, we will notify you of material changes.
16. Contact details
For any request, question or complaint about this policy or your personal information, please contact:
Managing Director
New Era Lawyers Pty Ltd
PO Box 1779, Sunshine Plaza, Queensland 4558
Phone: (07) 5444 5496
Email: [email protected]
Version 2.0 | Last updated: 2 July 2026 | Next review due: 1 July 2027