31 August 2017
1. Purpose of policy
(a) CD+Co collects personal information from you in a number of different ways. We may collect personal information directly from you or in the course of our dealings with you, for example when you:
(i) provide personal information to us;
(ii) apply for a position of employment with us;
(iii) use our website or services (including via cookies); and
(iv) contact and correspond with us, for example to ask for information.
(b) We may also, if you consent, collect personal information about you from another CD+Co group entity, from publicly available sources of information or, in some cases, from third parties including recruitment agencies, previous employers, government departments and third party service providers which provide criminal, bankruptcy and other checks.
(c) The personal information we collect about you may include (but may not be limited to) your name, date and place of birth, contact details, Internet Protocol (IP) address, occupation and education/work history, financial or income information, employer, legal and industry areas of interest, passport details and information relating to your dealings with CD+Co and our clients.
(d) We may also collect sensitive information about you, including health information and criminal background checks.
(e) The purposes for which we collect your information may include:
(i) verifying your identity;
(ii) contacting you (including via electronic messaging such as SMS and email, mail, telephone or in any other lawful manner);
(iii) providing you with legal services or legal information;
(iv) undertaking conflict searches for our own purposes and the purpose of determining if we can represent a client or potential client;
(v) acting for a client when it acquires a business with employees;
(vi) acting for a client in litigation against a party;
(vii) acting for a client in a matter against a party (e.g. an employment matter); and
(viii) developing and improving our services and obtaining feedback.
(f) If we are not able to collect personal information about you, we may not be able to provide you with products, services and assistance to the extent that they require us to collect, use or disclose personal information.
3. Use and disclosure
(a) CD+Co may use or disclose your personal information for the purpose for which it was collected. We will also use and disclose your personal information for a secondary purpose that is related to a purpose for which we collected it, where you would reasonably expect us to use or disclose your personal information for that secondary purpose.
(b) Other instances when we may use and disclose your personal information include:
(i) where you have expressly or impliedly consented to the use or disclosure;
(ii) in confidence, to our advisors, consultants and insurers;
(iii) in confidence, to third parties to improve our services and obtain feedback; and
(iv) where the use or disclosure is authorised or required by or under an Australian law or court/tribunal order.
(c) We may also disclose your personal information to third parties, including:
(i) sharing your personal information among other CD+Co group entities, including CDPlus Corporate Services Pty Ltd (ACN 601 988 738) and Consolidated Law Group Pty Ltd (ACN 609 506 872); and
(ii) with third party service providers we use in conducting our business, subject to confidentiality provisions as we deem appropriate (including, without limitation, insurance brokers, banks, external photocopying providers, document production, legal outsourcing providers, legal contractors, billing or data storage services, email filtering, virus scanning and other technology services providers, and archival service providers).
(d) Some of the third parties to whom we disclose your personal information may be located outside Australia. For example, we may disclose your personal information to external national or overseas facilities in the course of conducting information and data processing, back up and scanning or for the purposes of obtaining administrative, outsourced or other services from third parties.
(e) The countries in which these third parties are located will depend on the circumstances. However, in the course of our ordinary business operations we commonly disclose personal information to third parties located in the following countries:
(i) the United States of America;
(iii) Hong Kong; and
(iv) the United Kingdom.
4. Information about events, our website and our services
We may contact you via email, SMS or other means to provide you with updated information relating to events or to provide you with other information about our services. If you do not wish to receive any such information, please contact us as set out below.
5. The information we keep about you
You have a right to request access to or correction of your personal information held by us. If you wish to access, correct or update any personal information we may hold about you, please contact us as set out below. However, we may charge for providing access to this information and we may refuse access where the Act allows us to do so.
6. Complaints process
(b) We will take any privacy complaint seriously. We will aim to resolve any such complaint in a timely and efficient manner, and our target response time is 30 days. We request that you cooperate with us during this process and provide us with any relevant information that we may require.
(c) We expect that our procedures will deal fairly and promptly with your complaint. However, if you remain dissatisfied, you can also make a formal complaint with the Office of the Australian Information Commissioner (which is the regulator responsible for privacy in Australia):
Office of the Australian Information Commissioner (OAIC)
Complaints must be made in writing via:
- Phone: 1300 363 992
- Mail: Director of Compliance, Office of the Australian Information Commissioner, GPO Box 5218, Sydney NSW 2001
- Website: www.oaic.gov.au
7. Storage and security of your personal information
(a) CD+Co will take reasonable steps to keep any personal information we hold about you secure. However, except to the extent liability cannot be excluded due to the operation of statute, CD+Co excludes all liability (including in negligence) for the consequences of any unauthorised access to your personal information. Please notify us immediately if you become aware of any breach of security.
(b) We may store your files in hard copy or electronically in our ordinary IT systems. These may include cloud servers based in Australia and / or the United States of America or the servers of third parties within Australia or our legal contractor in the Philippines.
(c) We implement a range of physical and electronic security measures to protect the personal information that we hold, including:
(i) key card-restricted access to our office;
(ii) mandatory password protection on all computers;
(iii) secure hard copy document, electronic storage media and hardware disposal procedures;
(iv) firewall and antivirus/malware software; and
(v) systems and application access controls implemented to restrict access to information (on a need to know basis).
(d) Staff receive periodic bulletins on security issues, to foster a security aware culture. We also have a regular review program to test the security measures in place and identify where changes may be necessary or desirable.