Privacy Policy

Tri-meridian Corporate & Commercial Law Pty Ltd (ABN 45 621 261 489) (we, us, our) is committed to protecting your privacy and complying with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This Privacy Policy explains how we collect, hold, use and disclose your personal information, including in connection with our anti-money laundering and counter-terrorism financing (AML/CTF) compliance obligations.

1. Scope

This Privacy Policy applies to personal information we collect about:

  • clients and prospective clients;
  • counterparties and their representatives;
  • witnesses and other individuals connected to matters we act in;
  • suppliers and service providers;
  • visitors to our website (if any); and
  • any other individuals we interact with in the course of providing legal and related services.

2. What is “personal information”?

Personal information has the meaning given in the Privacy Act 1988 (Cth) and includes information or an opinion about an identified individual, or an individual who is reasonably identifiable.

3. What personal information we collect

We may collect and hold personal information including (as relevant):

  • identification information (name, date of birth, address, signature);
  • contact details (email, phone number);
  • professional details (occupation, employer, role, business details);
  • financial information (bank details, payment details, transaction information);
  • information relevant to a legal matter (instructions, correspondence, documents, evidence);
  • website/technology information (IP address, device identifiers, cookies), if you use our website; and
  • AML/CTF-related information required to verify your identity and comply with AML/CTF laws (see section 6).

4. How we collect personal information

We collect personal information in a range of ways, including:

  • directly from you (in person, by phone, email, forms, portals or our website);
  • from your representatives (for example, your agent, accountant, broker or other adviser);
  • from other parties to a transaction or matter (and their advisers);
  • from publicly available sources (for example, ASIC registers, land titles, court lists);
  • from third-party verification providers and reference databases (where used); and
  • from other professional service providers engaged in connection with your matter.

If you do not provide requested information, we may be unable to provide services, progress a matter, or comply with our legal obligations.

5. Why we collect, hold, use and disclose personal information

We collect, hold, use and disclose personal information for purposes including:

  • providing legal and related services and managing client relationships;
  • verifying identity and conducting due diligence;
  • communicating with you and others about a matter;
  • preparing documents, advice, and representation;
  • billing, payments, accounting, and credit control;
  • managing risk, professional obligations, and insurance requirements;
  • maintaining internal records and file management;
  • responding to complaints and enquiries;
  • improving our systems, processes and services; and
  • complying with legal and regulatory obligations, including AML/CTF compliance.

6. AML/CTF compliance (integrated requirements)

6.1 AML/CTF compliance activities

We may collect, hold, use and disclose personal information to conduct AML/CTF compliance activities, which may include:

  • verifying your identity and, where applicable, the identity of beneficial owners and authorised representatives;
  • conducting ongoing due diligence and monitoring;
  • understanding the purpose and intended nature of business relationships and transactions;
  • conducting screening and checks against databases (where used);
  • assessing and managing AML/CTF risk; and
  • maintaining records required for compliance.

6.2 Types of AML/CTF personal information

For AML/CTF compliance, we may collect additional information such as:

  • copies of identification documents and numbers (for example, passport, driver’s licence);
  • residential address and proof of address documents;
  • company and trust information (including directors, shareholders, beneficiaries, trustees, controllers);
  • information about source of funds / source of wealth (where relevant); and
  • transaction and payment information relevant to the matter.

6.3 Use and disclosure for AML/CTF compliance

We may use and disclose AML/CTF-related personal information:

  • to comply with laws and regulatory requirements;
  • to our professional advisers, auditors, insurers, and service providers as reasonably necessary to support compliance;
  • to verification and screening service providers (where used); and
  • to government agencies and regulators, including AUSTRAC and law enforcement, where required or authorised by law.

6.4 Refusal or inability to complete AML/CTF checks

If you do not provide information required for AML/CTF compliance, or if we cannot reasonably complete required checks, we may be unable to act for you or continue to provide services (including where we must cease or decline to provide services to comply with law).

6.5 AML/CTF recordkeeping

We retain AML/CTF compliance records (including identity verification records and related compliance records) for at least 7 years, and otherwise in accordance with legal requirements and our record management practices.

7. Disclosure of personal information (general)

We may disclose personal information to third parties as required or reasonably necessary to provide our services, including:

  • barristers, experts, consultants, witnesses and other service providers engaged in a matter;
  • courts, tribunals, registries and government bodies (as required for a matter);
  • counterparties, their representatives and other stakeholders in a transaction or dispute;
  • our IT providers, cloud storage providers, practice management and communications providers;
  • financial institutions and payment processors (for billing and transactions);
  • our insurers and professional advisers; and
  • other parties with your consent or where required or authorised by law.

We do not sell personal information.

8. Overseas disclosure

We may disclose personal information to recipients located outside Australia, including where we use offshore or global technology service providers, or where a matter involves overseas parties.

Countries in which recipients may be located include:

  • United States
  • United Kingdom
  • Japan

Where practicable, we take reasonable steps to ensure overseas recipients handle personal information in a manner consistent with the APPs.

9. Security of personal information

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Measures may include:

  • access controls and authentication;
  • secure storage systems and encryption where appropriate;
  • staff training and confidentiality obligations; and
  • secure disposal and destruction processes.

No method of transmission or storage is completely secure. If we become aware of a data breach that is likely to result in serious harm, we will comply with the Notifiable Data Breaches scheme.

10. Retention and destruction (general)

We retain personal information for as long as reasonably necessary to:

  • provide services;
  • comply with legal and regulatory obligations (including AML/CTF obligations); and
  • manage our professional and business requirements.

When personal information is no longer required, we take reasonable steps to destroy or de-identify it (subject to legal retention obligations).

11. Access and correction

You may request access to personal information we hold about you and request correction if you believe it is inaccurate, out-of-date, incomplete, irrelevant or misleading.

We will respond to requests within a reasonable time and may need to verify your identity before providing access. In some circumstances, we may refuse access as permitted by law (for example, where providing access would disclose legal professional privilege or would be unlawful).

12. Complaints

If you have a complaint about how we have handled your personal information, please contact our Privacy Officer using the details in section 14.

We will acknowledge your complaint within 7 business days and aim to respond within a reasonable time.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC).

13. Website, cookies and analytics (if applicable)

If you use our website, we may collect information through cookies and similar technologies to help operate and improve the website and understand usage.

Cookies and similar technologies may include those used by Google and/or related services.

Further information about cookies and similar technologies is available at:
https://policies.google.com/technologies/cookies?hl=en-US

You can usually configure your browser to refuse cookies or delete existing cookies. If you do, some website functions may not work properly.

14. Contact us (Privacy Officer)

If you have questions, requests, or complaints about this Privacy Policy or our handling of personal information, contact:

Privacy Officer
Tri-meridian Corporate & Commercial Law Pty Ltd
Suite 2, 1 Markey Street
EASTWOOD SA 5063
Australia

Additional address: 29 Cadell Street, Goolwa SA 5214 Australia

Phone: 08 7120 9000
Email: gadams@tri-meridian.com

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The current version will apply from the date it is published or otherwise made available.

Effective date: 6 May 2026
Version: 1.1 | 25 Jun 2026