Jackson McDonald is committed to protecting the privacy and integrity of all personal information held by us. This policy explains how we collect, use, disclose and otherwise handle personal information, as well as the rights and choices available to you, in compliance with the Privacy Act 1988 (Cth) (including the Australian Privacy Principles) and the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act) (where we provide designated services).
In this policy:
If you have any questions or comments about this policy or our privacy practices, please contact our Privacy Officer by:
By using our services, websites or applications, or by otherwise providing us with your personal information, you consent to our collection, use, disclosure and handling of that information as outlined in this policy.
If we are unable to collect, use, disclose or handle your personal information as described, we may not be able to provide you with access to our services, websites or applications.
We will update this policy from time to time to reflect changes to the way in which we use personal information. Please check our website regularly for any updates.
This policy was last updated in June 2026.
We will only collect personal information where it is reasonably necessary for one or more of our functions and activities in the course of providing legal services and related functions.
The types of personal information that we may collect, the individuals about whom we may collect that information and the purposes for which it is collected and used will depend on the nature of your relationship with us. Generally, this includes information necessary to provide our services, perform contracts, comply with legal requirements or develop our business.
Personal information: We collect, hold, use and disclose personal information for the purposes for which it was collected, related purposes, and other purposes including (without limitation):
Sensitive information: Where permitted by law, we may also collect sensitive information, such as racial or ethnic origin, political affiliation, memberships of a trade union or professional association, criminal record, or health information. We will only collect sensitive information where it is reasonably necessary for us to carry out at least one of our functions or activities, or if the APPs otherwise permit such collection, including (without limitation):
Credit information: Where permitted by law, we may collect credit information in connection with the supply of services. This includes information about your consumer credit liability, repayment history, default and other payment related information. We collect, hold, use and disclose credit information to assess credit worthiness, manage the collection of payments, identify fraudulent activity and participate in the credit reporting system.
References to personal information in this policy include sensitive information and credit information, unless specified otherwise.
For more detail of the types of personal information we may collect, and the purposes for which we may use it, are set out in Schedule 1 of this policy.
You are in control of who you share your personal information with.
Upon request, we may give you the option of not identifying yourself, or of using a pseudonym, provided it is lawful and practicable to do so. However, there are circumstances in which we cannot take action without certain personal information. For example, where the information is required to process your instructions or orders, provide you with access to a service or to carry out a legally required compliance screening.
Generally, we collect personal information directly from the individual concerned, or the organisation of which that personal is an employee, director or principal. Some of the situations where we collect personal information include when:
However, if direct collection is unreasonable or impracticable, we may collect personal information about individuals from third parties, including from publicly available sources. If we do, we will take reasonable steps to ensure that the individuals concerned are made aware of the collection of their information. Some examples of the typical third parties from which we may collect personal information are:
In some circumstances it may not be appropriate for us to provide the individuals concerned with a privacy notice that sets out how we use their personal information as doing so may breach client confidentiality or may risk contravening tipping-off laws. Nevertheless, we will handle such personal information in accordance with applicable law.
We will only collect personal information if it is reasonably necessary for these purposes and we will not retain full copies of identity documents beyond what is permitted under applicable laws and guidance.
If we receive personal information that we did not take any active steps to collect, we will determine whether we would have been permitted to collect that information as part of pursuing our functions and activities. We will destroy or de-identify unsolicited personal information that we would not collect as part of our functions and activities if it is lawful to do so. If the information is of the type that we would collect to pursue our functions and activities, it will be handled in accordance with this policy.
If you provide us with personal information about another individual, we ask you to assist us by referring that individual to this policy.
We do not permit the personal information we hold to be used internally or disclosed to third parties unless:
Generally, we use or disclose personal information (including, in limited circumstances, your sensitive information) for the purposes for which it was collected and as otherwise permitted under applicable laws, including (without limitation) to:
In the course of our business, we will process personal information using a range of technologies, including cloud-based systems and artificial intelligence. We may use artificial intelligence technologies to enhance our services, our operations, and improve your experience with us. When processing your personal information, we ensure that all artificial intelligence applications comply with relevant data protection laws and regulations. However, we do not use personal information for any automated decision making processes.
Disclosures required or authorised by law: We may disclose your personal information without your consent where required or authorised by law. This may include disclosing personal information where reasonably necessary to:
In accordance with our AML/CTF obligations, we may use third party providers (such as First AML) to confirm and verify your identity.
In certain circumstances, we may be legally prohibited from informing you that such a disclosure has been made. For example, where we are authorised or required to disclose personal information where reasonably necessary the purpose of reporting suspicious matters to AUSTRAC in accordance with the AML/CTF Act and “tipping-off” provisions apply.
Disclosure to credit reporting bodies: We may disclose certain information about you to credit reporting bodies (CRBs), for example if you fail to meet payment obligations. The CRB may include such information in reports provided to credit providers to assist them in assessing your credit worthiness. We currently only disclose credit information to CreditorWatch.
You have the right to request CreditorWatch not to:
If you would like more information about how the above CRBs manage credit related information please contact them directly.
We may, from time to time, use or disclose your personal information (other than sensitive information or credit information) for the purpose of direct marketing. We may contact you by email, mail or telephone. However, you can let us know at any time if you no longer wish to receive these communications, by contacting us (using the contact details at the beginning of this policy) or using the opt-out/unsubscribe facility in our communications.
Generally, we store the personal information that we collect in Australia. However, from time to time our IT suppliers and service providers may be required to access our server and the personal information that we hold on our server for assisting with resolving issues and maintenance. Our IT suppliers and service providers are located in Australia as well as the UK and the USA. Where we transfer your information internationally, we will take reasonable steps to ensure that your information is treated securely and the means of transfer provides adequate safeguards.
Our arrangements with our IT suppliers and service providers:
We take reasonable steps to protect your personal information from misuse, interference, loss, unlawful access, modification and disclosure.
Our Information Security Management System is certified to ISO/IEC 27001, reflecting compliance with globally recognised, leading standards for the confidentiality, integrity, and availability of information assets.
Our premises are located in secure buildings with access restricted to authorised access card holders. Our IT systems are protected against external threats through a range of security measures, including:
Some personal information may be stored in offsite archival facilities as part of our records management and retention practices. We take reasonable steps to ensure that those archival arrangements are secure and subject to appropriate security measures. Access to archived records is restricted to authorised personnel and managed in accordance with our confidentiality obligations, data retention requirements and applicable privacy laws.
In addition, all our employees are required, as a condition of employment, to treat personal information held by Jackson McDonald as confidential.
Personal information will be retained in accordance with our data retention procedures which categorises all of the information held by us and specifies the appropriate retention period for each category of information. Those periods are based on the requirements of applicable laws and the purpose for which the information is collected and used, taking into account legal and regulatory requirements to retain the information for a minimum period, limitation periods for taking legal action, good practice, and our business purposes.
We do not retain unnecessary copies of full identification documents where not required.
We endeavour to take reasonable steps to ensure that the personal information that we collect is accurate, up-to-date and complete by, for example conducting annual audits of the personal information that we hold.
If you think that the personal information we hold about you might be out of date and needs to be corrected please contact us.
Application of European privacy laws
If you are an individual in a country in the European Economic Area (EEA), we may be required to comply with the EU General Data Protection Regulation 2016/679 (GDPR) which applies to us when processing the personal information of individuals (data subjects) who are in countries in the EEA in relation to offering you our products or services or if we monitor any of your behaviour when in those countries.
You have the right to request access to the personal information we hold about you and to ask for it to be corrected if you believe it is inaccurate, incomplete or out-of-date.
To request access to or correction of your personal information, please send a written request specifying the information you wish to access or amend to our Privacy Officer using contact details at the beginning of this policy.
To process your request, we may ask you to verify your identity. There is no charge for making a request for access to or correction of your personal information. However, you may be required to pay any reasonable costs incurred by us in providing you with access (e.g. staff time collating the information, photocopying costs, postage costs). We will let you know the likely cost in advance.
We will endeavour to respond to your request within a reasonable time.
For access requests: We will provide you with access to your personal information unless we are legally permitted or required to refuse your request (in whole or part). For example, we are required to refuse access to documents that are subject to legal professional privilege. If we refuse your request, we will provide you with a written notice explaining the reasons for the refusal and details on how you can make a complaint about our decision.
For correction requests: If we agree that the information we hold is incorrect, we will update our records promptly. If we do not agree that the information is incorrect, we will notify you in writing of our decision. You can then ask us to attach a statement to your record indicating that you believe the information is inaccurate.
If you have a complaint about the way in which we have handled your personal information, please let us know by contacting Jackson McDonald’s Privacy Officer using the contact details at the beginning of this policy.
All complaints will be reviewed and, where appropriate, investigated by our Privacy Officer. We will notify you of the outcome as soon as reasonably practicable, typically within 30 days of receiving your complaint (or such other time as agreed) and in the manner you have requested that we communicate with you.
If we are unable to resolve your concerns to your satisfaction, you may make to the Office of the Australian Information Commissioner. The Office of the Australian Information Commissioner can be contacted by:
A number of facilities on our website and applications invite you to provide us with personal information, such as the job application facility in the “Careers” section of our website and our email queries facilities. The purpose of these facilities is apparent at the point that you provide your personal information, and we only use that information for those purposes.
Our website also uses ‘cookies’ and similar technologies (via Google Analytics) to collect information about your device, browsing activity and usage patterns (including your IP address). The information generated by the cookie about your use of our website will be transmitted to and stored by Google on servers in the United States. Google uses this information to evaluate website use, compile reports on website activity for website operators and provide other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf. Google does not associate your IP address with any other data held by Google.
You may refuse the use of cookies by selecting the appropriate settings on your browser. However, please note that if you do this you may not be able to use the full functionality of our website. By using our website, you consent to the processing of data about you by Google in the manner and for the purposes set out above.
Third party sites: Our website may contain links to other sites which are controlled by third parties. Visitors should consult these other sites’ privacy policies and please be aware that we do not accept responsibility for their use of information about you.
Children’s privacy on the websites: Our website and applications are not intended for use by children under the age of 18. We do not knowingly collect personal information from anyone under 18 years of age through the website.