Data is central to how organisations grow, compete and engage with customers. Used well, it can deliver sharper insights, better services and new commercial opportunities. Used poorly, it can quickly create privacy, cyber, compliance and reputational risk.
Our privacy team is passionate about supporting clients to use data confidently, unlocking its value while managing the legal, regulatory and stakeholder expectations that come with it.
Led by four partners with deep privacy expertise and experience, our team spots issues, designs and embeds privacy compliance frameworks, and supports major incident and regulatory action responses. We make the complex straightforward, and deliver clear advice that legal and commercial teams can action with confidence.
Our expertise
Our work spans proactive privacy enablement and reactive response, including:
Responding to incidents, requests, complaints, and regulatory investigations
- data breaches
- NDB assessments
- OAIC engagement, complaints, access/correction requests, communications and lessons learned
- ACMA engagement (investigations, complaints, representation and negotiation)
Contracting, data sharing and third parties
- SaaS
- outsourcing
- data sharing
- vendor due diligence
- privacy/security terms and risk allocation
Privacy strategy, governance and uplift
- privacy audits
- governance frameworks, policies, training, maturity reviews
- remediation roadmaps.
Privacy by design and data use
- privacy by design
- PIAs
- data mapping
- consent, transparency, analytics, AI and emerging data uses
Communications and marketing
- privacy notices
- collection statements
- direct marketing
- marketing consents
- Spam Act compliance
- preference management
- fair data use
Privacy strategy, governance and uplift
- privacy audits
- governance frameworks, policies, training, maturity reviews
- remediation roadmaps.
Privacy by design and data use
- privacy by design
- PIAs
- data mapping
- consent, transparency, analytics, AI and emerging data uses
Communications and marketing
- privacy notices
- collection statements
- direct marketing
- marketing consents
- Spam Act compliance
- preference management
- fair data use
Contracting, data sharing and third parties
- SaaS
- outsourcing
- data sharing
- vendor due diligence
- privacy/security terms and risk allocation
Responding to incidents, requests, complaints, and regulatory investigations
- data breaches
- NDB assessments
- OAIC engagement, complaints, access/correction requests, communications and lessons learned
- ACMA engagement (investigations, complaints, representation and negotiation)