Privacy and Confidentiality

Your private information sits behind a law firm shield

Legal Consolidated is not a template reseller. You are instructing a national Australian law firm. Legal Consolidated authors your legal document and accepts responsibility for that work. Our law firm cover letter confirms this.

That difference matters.

Legal Consolidated owes the higher professional duties of a law firm. We owe duties of confidentiality. We manage conflicts of interest. We are subject to professional regulation and professional indemnity insurance. Qualifying confidential communications also attract legal professional privilege.

Privacy, confidentiality and privilege do different jobs:

Privacy

The Privacy Act 1988 (Cth) and the Australian Privacy Principles regulate how we collect, hold, use and disclose personal information.

Law firm confidentiality

Legal Consolidated must keep client information confidential, subject to the client’s authority and the law. A website that is not a law firm does not owe a solicitor’s professional duty of confidentiality.

Client Professional Privilege

Qualifying confidential communications between a client and Legal Consolidated are protected from compulsory disclosure. The privilege belongs to the client. It does not belong to the lawyer.

A non-law template seller cannot turn a privacy promise, password or encryption system into a solicitor’s professional duty or legal professional privilege.

These law firm standards govern the instructions used to build a 3-Generation Testamentary Trust Will, Family Trust deed, SMSF deed, Company Power of Attorney and every other Legal Consolidated document.

1. Who we are

Legal Consolidated Barristers & Solicitors is a national Australian law firm. We author online legal documents for clients in Western Australia, the Northern Territory, South Australia, Queensland, New South Wales, Victoria, Tasmania and the Australian Capital Territory.

In this policy, ‘Legal Consolidated’, ‘we’, ‘us’ and ‘our’ mean Legal Consolidated Barristers & Solicitors and, where the context permits, our principals, lawyers, employees, contractors and authorised representatives.

This policy explains how we collect, hold, use and disclose personal information when you use our website, create an account, build a legal document, communicate with us, deal with us through a lawyer, accountant, financial planner or other adviser, or otherwise interact with Legal Consolidated.

Read this policy with our Online Terms. The Online Terms govern the document-building service. This policy deals with privacy, confidentiality, legal professional privilege and data handling.

2. Our approach to privacy

We handle personal information under the Privacy Act 1988 (Cth), the Australian Privacy Principles, our professional obligations as an Australian law firm and other laws that apply to our legal document service.

Privacy is one part of a larger professional framework. Because Legal Consolidated is a law firm, confidentiality, legal professional privilege, duties to the court and conflict obligations sit beside privacy law.

For documents that are AML/CTF designated services, Australian law also requires customer due diligence, risk controls and record keeping. These obligations apply product by product. They do not automatically apply to every legal document. Read our Security, identity and AML/CTF controls.

Where another law requires or authorises collection, use, retention or disclosure, we comply with that law. This includes AML/CTF law, sanctions law, court orders and other professional or regulatory obligations.

3. Personal information

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether it is recorded in a material form or not.

The kinds of personal information we collect depend on how you deal with us and which document you build.

  • names, addresses, telephone numbers, email addresses, dates of birth and other contact details;
  • account details, login details, adviser details and firm or practice details;
  • information entered into our online document-building system;
  • answers to questions, document instructions, names of parties, capacities, relationships, entity details, trust details, company details, SMSF details, estate planning details, signing details and implementation details;
  • communications with us, including emails, online forms, website messages, telephone notes and support requests;
  • limited payment information provided by our merchant facility, such as payment amount, payment date, transaction reference, approval status, cardholder name and the last four digits of a card;
  • identity, authority, beneficial ownership, sanctions, AML/CTF, source of funds, source of wealth and risk information where required or appropriate;
  • technical information about use of our website, such as IP address, browser type, device information, cookies, analytics information and pages visited; and
  • other information you, your adviser or another authorised person provides to us.

4. Sensitive and highly confidential information

Some documents involve ‘sensitive information’ as defined by privacy law. This includes health information, racial or ethnic origin, religious beliefs, political opinions, sexual orientation, criminal records, professional or trade association membership and specified biometric information.

Documents also involve other highly confidential material. This includes family, financial, tax, estate planning and vulnerable-person information.

We collect sensitive information only where it is reasonably necessary for our functions or activities and the law permits the collection. This includes collection with consent and collection required or authorised for legal, regulatory, professional, AML/CTF, sanctions, identity, authority, risk, complaint, insurance or dispute purposes.

5. How we collect information

We collect personal information directly from you through our website, online forms, account system, document-building questions, email, telephone, document portals and other communications.

We also collect personal information from other sources where appropriate.

  • lawyers, accountants, financial planners, tax advisers, SMSF advisers and other professional advisers;
  • employees, officers, trustees, directors, attorneys, agents, representatives, family members or other persons connected with a document;
  • identity verification providers, payment providers, technology providers and other service providers;
  • government registers, courts, tribunals, regulators, public databases and publicly available sources;
  • professional referrer certificates, AML/CTF checks, sanctions checks and beneficial ownership checks; and
  • website analytics, cookies, server logs and security systems.

If you provide us with personal information about another person, you must have authority to do so and, where reasonable, tell that person about this policy.

6. Why we collect, hold, use and disclose information

We collect, hold, use and disclose personal information for the purposes of operating Legal Consolidated and providing our online legal document service.

  • creating, administering and securing accounts;
  • building, delivering, updating and supporting online legal documents;
  • communicating with clients, users and professional advisers;
  • checking identity, authority, capacity, beneficial ownership, sanctions and AML/CTF matters;
  • assessing whether we provide, pause, refuse or stop a document build;
  • processing payments, refunds, receipts, tax invoices and reconciliation;
  • maintaining records, audit trails, version control and security logs;
  • responding to complaints, disputes, regulator enquiries, court orders and professional obligations;
  • maintaining insurance, professional indemnity, risk management and compliance records;
  • detecting, investigating and preventing fraud, misuse, cyber incidents, unauthorised access, unlawful activity and document tampering;
  • improving our website, document-building system, questions, hints, videos, logic and user experience;
  • sending service messages, legal updates, educational material or marketing communications where permitted; and
  • complying with law, including privacy, legal profession, tax, AML/CTF, sanctions, court, regulatory and record-keeping obligations.

7. If information is not provided

Complete and accurate information protects the integrity of the document build. Where information or verification is required, its absence stops us from creating an account, building or releasing a document, processing a refund, communicating with an adviser, completing an AML/CTF or sanctions check, responding to a request or continuing the online service.

We also pause, refuse or stop a build where the law, our professional obligations or our risk controls require that result.

8. Disclosure of information

We disclose personal information where reasonably necessary for the purposes described in this policy, where you consent, where the law requires or authorises disclosure, or where disclosure is consistent with our professional obligations.

Recipients include:

  • professional advisers, referrers, representatives or other persons you identify or authorise, or whom we are legally permitted to contact in connection with the document build;
  • technology, hosting, data storage, email, cyber security, document automation, payment, analytics and support providers;
  • identity verification, AML/CTF, sanctions, beneficial ownership, fraud prevention and risk screening providers;
  • insurers, professional advisers, auditors, consultants and contractors who assist Legal Consolidated;
  • courts, tribunals, regulators, law enforcement agencies, government agencies, professional bodies, AUSTRAC and other bodies where required or authorised by law;
  • third parties involved in a complaint, dispute, debt recovery, cyber incident, fraud investigation, regulatory enquiry or insurance matter; and
  • successors or proposed successors to Legal Consolidated’s business, subject to confidentiality and professional obligations.

We do not sell personal information.

9. Overseas disclosure and cloud services

We use online systems and service providers. Depending on the system and provider, personal information is stored, accessed, processed or backed up in Australia or overseas.

Where it is practicable to identify them, likely overseas locations include the United States, the United Kingdom, the European Union, New Zealand, Singapore and Canada. Provider infrastructure also operates in other locations.

Where privacy law requires it, we take reasonable steps in the circumstances to address cross-border disclosure of personal information.

10. Website, cookies and analytics

We use cookies, pixels, local storage, server logs, analytics tools and similar technologies to operate, secure, measure and improve our website and online document-building system.

These technologies remember preferences, maintain sessions, protect accounts, detect errors, prevent misuse, show us how the website is used and measure the performance of pages, hints, videos and document-building workflows.

You control cookies through your browser settings. Disabling cookies or similar technologies stops parts of the website or document-building system from working properly.

11. Credit card and payment information

Credit card payments are handled by our merchant facility through its secure payment gateway. Your card number, expiry date and CVV are entered into and processed by the merchant facility, not by Legal Consolidated, and cannot be viewed by us.

Your full credit card details do not pass through, and are not stored on, Legal Consolidated’s website, servers, database, email system or document-building system. This is standard merchant facility practice.

For administration, reconciliation, refunds, fraud prevention and record keeping, the merchant facility provides us with limited payment information. This includes the cardholder’s name, payment amount, payment date, transaction reference, approval status and the last four digits of the card.

12. Confidentiality

Legal Consolidated owes professional duties of confidentiality. We keep confidential information confidential in accordance with those duties.

Those duties are strong, but not absolute. We use or disclose information where the client permits it or the law requires or authorises it. This includes AML/CTF, sanctions, suspicious matter reporting, identity checks, court orders and regulatory enquiries.

We also use or disclose information where lawful and necessary to defend or enforce rights, manage professional indemnity, investigate complaints, complete audits or respond to cyber security incidents.

We use the expression ‘Client Professional Privilege’ because the privilege belongs to the client.

The recognised legal expressions are ‘legal professional privilege’ and ‘client legal privilege’. This protection is one of the most valuable differences between instructing a law firm and buying a template from a website that is not a law firm.

Legal professional privilege protects confidential communications made for the dominant purpose of:

  • obtaining or giving legal advice; or
  • use in existing or reasonably anticipated litigation.

The privilege provides immunity from compulsory disclosure in court proceedings, regulatory investigations and other compulsory processes, subject to the governing law. The client controls the privilege.

Legal Consolidated’s document-building system records instructions given to the law firm for the purpose of building a legal document. Our cover letter confirms that Legal Consolidated authored the document and accepted responsibility for its work. This provides evidence of the lawyer–client relationship and the purpose of the instructions.

However, privilege is not automatic merely because information is entered on a law firm’s website. The dominant-purpose test still applies. Not every answer, document or communication is privileged.

Privilege is also lost or waived through inconsistent disclosure. It does not protect communications made to further fraud, crime or another improper purpose. It does not override legislation that clearly removes or limits the privilege.

Even where privilege does not attach, Legal Consolidated’s professional duties of confidentiality continue to apply, subject to the client’s authority and the law.

14. Artificial intelligence and automation

We use technology, automation, document assembly systems, expert systems and approved artificial intelligence tools to build, test, improve, review, validate and deliver online legal documents and website content.

Our document-building system uses the personal information, answers and document instructions that the user enters. It applies logic, selects clauses, builds the document and identifies when a build stops or requires further information. Those automated steps affect the clauses produced and whether the online build proceeds. They do not determine a court, tribunal, regulator or third party’s view of the person’s legal rights.

We do not enter or upload confidential client information into publicly available artificial intelligence systems. Approved internal or controlled tools remain subject to our confidentiality controls and professional duties. Their use is not permission for public disclosure and does not waive privilege.

The user remains responsible for selecting the document, entering complete and accurate data, checking that data and confirming the answers before Lock & Build.

15. Security

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, unauthorised modification and unauthorised disclosure.

Security measures include secure website connections, password controls, access controls, logging, backups, cyber security tools, staff confidentiality obligations, service provider controls, document version control and other administrative, technical and physical safeguards.

No online service is risk-free. You are responsible for keeping your account credentials secure, logging out of shared devices, checking suspicious emails or payment requests by telephone, and telling us promptly if you suspect unauthorised access or misuse. Read our Security, identity and AML/CTF controls.

16. Data breaches

If we become aware of a data breach, we assess it and respond in accordance with our legal and professional obligations.

Where the Notifiable Data Breaches scheme applies and a data breach is likely to result in serious harm, we notify affected individuals and the Office of the Australian Information Commissioner as required by law.

17. Retention and destruction

We retain personal information for as long as reasonably necessary for the purposes for which it was collected, for our legal and professional obligations, for record keeping, for insurance and risk management, for complaints and disputes, for cyber security, and where required or permitted by law.

Retention periods differ. AML/CTF, tax, legal profession, limitation period, insurance, audit, complaint and dispute requirements set or justify longer retention periods.

When information is no longer required and no law or professional obligation requires retention, we take reasonable steps to delete, de-identify or securely destroy it. Records retained for legal or professional reasons are archived or otherwise controlled.

18. Access and correction

You have the right to ask for access to personal information we hold about you and to ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.

We verify your identity where needed before responding. We refuse access or correction where the law permits, including where access affects another person’s privacy, breaches confidentiality, prejudices legal proceedings, reveals commercially sensitive information, undermines security, interferes with AML/CTF or sanctions obligations, or is otherwise unlawful or inappropriate.

If we refuse a request, we will explain the reason where it is reasonable and lawful to do so.

19. Direct marketing and legal updates

We send legal updates, educational material, service messages, website information and marketing communications where permitted by law.

Opt out of marketing communications through the unsubscribe function or by contacting us. We still send service, account, document, compliance, security and legal notices that are not marketing.

20. Complaints

If you have a privacy complaint, contact Legal Consolidated first using the contact details below and mark the communication ‘Privacy Complaint’. Please provide enough detail for us to understand and investigate the issue.

We will consider the complaint and respond within a reasonable time.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.

21. Changes to this policy

We update this policy by publishing a replacement on our website or otherwise making it available.

The current version published or made available by Legal Consolidated applies from the time it is published or made available, unless we state otherwise.

22. Contact

Legal Consolidated Barristers & Solicitors
ABN 94 936 003 432

Website: legalconsolidated.com.au
Privacy and legal document enquiries: lawyer@legalconsolidated.com.au
Account and login help: admin@legalconsolidated.com.au
Telephone: 1800 141 612

Postal: Post Office Box 5169, Dalkeith, WA 6009
Head office: 18 Stirling Highway, Nedlands, WA 6009