Home / Privacy Policy

Privacy Policy

General

Jackson McDonald is committed to protecting the privacy and integrity of all personal information held by us. This policy explains how we collect, use, disclose and otherwise handle personal information, as well as the rights and choices available to you, in compliance with the Privacy Act 1988 (Cth) (including the Australian Privacy Principles) and the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act) (where we provide designated services). 

In this policy: 

  • “you” and “your” refers to you and any person whose personal information is collected by Jackson McDonald;
  • “Jackson McDonald”, “we”, “us” or “our” means Jackson McDonald (ABN 80 826 194 801) and its related entities of Level 17, 225 St Georges Tce, Perth WA 6000.

If you have any questions or comments about this policy or our privacy practices, please contact our Privacy Officer by: 

  • email at privacy@jacmac.com.au;
  • post addressed to Privacy Officer, Jackson McDonald, GPO Box M971, PERTH WA 6843; or
  • telephone on +61 8 9426 6611.

By using our services, websites or applications, or by otherwise providing us with your personal information, you consent to our collection, use, disclosure and handling of that information as outlined in this policy.  

If we are unable to collect, use, disclose or handle your personal information as described, we may not be able to provide you with access to our services, websites or applications.

We will update this policy from time to time to reflect changes to the way in which we use personal information. Please check our website regularly for any updates. 

This policy was last updated in June 2026.

What personal information do we collect and for what purposes?

We will only collect personal information where it is reasonably necessary for one or more of our functions and activities in the course of providing legal services and related functions. 

The types of personal information that we may collect, the individuals about whom we may collect that information and the purposes for which it is collected and used will depend on the nature of your relationship with us.  Generally, this includes information necessary to provide our services, perform contracts, comply with legal requirements or develop our business. 

Personal information: We collect, hold, use and disclose personal information for the purposes for which it was collected, related purposes, and other purposes including (without limitation):

  • providing the services that our clients have requested;
  • maintaining, managing and developing our relationship with clients and potential clients;
  • engaging and managing contractors;
  • carrying out research, planning, service development, security and risk management;
  • marketing our services, administering and operating our events and online publications;
  • assessing and considering applications from prospective employees, contractors and service providers;
  • developing and managing relationships with our employees;
  • managing insurance;
  • complying with our legal and regulatory obligations, including providing a safe workplace;
  • outsourcing our administrative and support functions; and
  • to otherwise carry out our functions as professional legal and other service providers.

Sensitive information: Where permitted by law, we may also collect sensitive information, such as racial or ethnic origin, political affiliation, memberships of a trade union or professional association, criminal record, or health information.  We will only collect sensitive information where it is reasonably necessary for us to carry out at least one of our functions or activities, or if the APPs otherwise permit such collection, including (without limitation):

  • for the purposes of providing legal advice;
  • in accordance with our equal employment opportunities policy;
  • for the purpose of assessing dietary requirements; 
  • another reason for which we have your consent and collection is necessary for that purpose; or
  • if it is required or authorised under an Australian law or court/ tribunal order. 

Credit information: Where permitted by law, we may collect credit information in connection with the supply of services. This includes information about your consumer credit liability, repayment history, default and other payment related information. We collect, hold, use and disclose credit information to assess credit worthiness, manage the collection of payments, identify fraudulent activity and participate in the credit reporting system.

References to personal information in this policy include sensitive information and credit information, unless specified otherwise.

For more detail of the types of personal information we may collect, and the purposes for which we may use it, are set out in Schedule 1 of this policy.

Are you required to provide personal information?

You are in control of who you share your personal information with. 

Upon request, we may give you the option of not identifying yourself, or of using a pseudonym, provided it is lawful and practicable to do so.  However, there are circumstances in which we cannot take action without certain personal information.  For example, where the information is required to process your instructions or orders, provide you with access to a service or to carry out a legally required compliance screening.

How do we collect personal information?

Generally, we collect personal information directly from the individual concerned, or the organisation of which that personal is an employee, director or principal.  Some of the situations where we collect personal information include when:

  • we take instructions to provide you with legal services or when you inquire about us providing you legal services.
  • you provide us, or one of our staff members, with your business card.
  • you attend an event that we organise.
  • you subscribe to receive our publications on our website.
  • you apply for a job with us or submit an expression of interest application to our HR team; or
  • you supply goods or services to us.

However, if direct collection is unreasonable or impracticable, we may collect personal information about individuals from third parties, including from publicly available sources.  If we do, we will take reasonable steps to ensure that the individuals concerned are made aware of the collection of their information.  Some examples of the typical third parties from which we may collect personal information are: 

  • our clients;
  • government agencies;
  • law enforcement bodies;
  • regulatory and licensing bodies;
  • publicly available records (including websites, social media platforms, public registries, court or tribunal records or ratings agencies);
  • service providers;
  • parties to whom you refer us, including previous employers and referees; or
  • recruitment agencies.

In some circumstances it may not be appropriate for us to provide the individuals concerned with a privacy notice that sets out how we use their personal information as doing so may breach client confidentiality or may risk contravening tipping-off laws.  Nevertheless, we will handle such personal information in accordance with applicable law.

We will only collect personal information if it is reasonably necessary for these purposes and we will not retain full copies of identity documents beyond what is permitted under applicable laws and guidance.

What do we do on receipt of unsolicited personal information?

If we receive personal information that we did not take any active steps to collect, we will determine whether we would have been permitted to collect that information as part of pursuing our functions and activities.  We will destroy or de-identify unsolicited personal information that we would not collect as part of our functions and activities if it is lawful to do so.  If the information is of the type that we would collect to pursue our functions and activities, it will be handled in accordance with this policy.

If you provide us with personal information about another individual, we ask you to assist us by referring that individual to this policy.

What do we do with your personal information?

We do not permit the personal information we hold to be used internally or disclosed to third parties unless:

  • we consider it necessary to be used or disclosed in order that services we provide to you can be properly carried out;
  • you have consented or requested to the relevant use or disclosure of your personal information; or
  • we are required or permitted by law to use your personal information or disclosure it to a third party.

Generally, we use or disclose personal information (including, in limited circumstances, your sensitive information) for the purposes for which it was collected and as otherwise permitted under applicable laws, including (without limitation) to:

  • our employees, for business, administrative or service delivery purposes, except where confidentiality obligations prevent this;
  • external service providers who assist us in delivering our services, such as IT, data storage, cloud analytics and debt collection providers;
  • our professional advisers, auditors and insurers;
  • barristers, consultants, experts or other legal specialists engaged in your matter, or to foreign law firms when required;
  • regulatory authorities, government departments, 
  • courts, law enforcement, or other parties where required or authorised by law, or for the establishment, exercise, or defence of legal claims;
  • parties and their representatives with whom we are authorised or required to engage in relation to your matters;
  • any third party to whom we assign or novate our rights or obligations.

In the course of our business, we will process personal information using a range of technologies, including cloud-based systems and artificial intelligence. We may use artificial intelligence technologies to enhance our services, our operations, and improve your experience with us. When processing your personal information, we ensure that all artificial intelligence applications comply with relevant data protection laws and regulations. However, we do not use personal information for any automated decision making processes.

Disclosures required or authorised by law: We may disclose your personal information without your consent where required or authorised by law. This may include disclosing personal information where reasonably necessary to:

  • prevent or lessen a serious threat to life, health or safety;
  • protect our legal rights;
  • comply with our professional and regulatory obligations.

In accordance with our AML/CTF obligations, we may use third party providers (such as First AML) to confirm and verify your identity.

In certain circumstances, we may be legally prohibited from informing you that such a disclosure has been made.  For example, where we are authorised or required to disclose personal information where reasonably necessary the purpose of reporting suspicious matters to AUSTRAC in accordance with the AML/CTF Act and “tipping-off” provisions apply.

Disclosure to credit reporting bodies: We may disclose certain information about you to credit reporting bodies (CRBs), for example if you fail to meet payment obligations.  The CRB may include such information in reports provided to credit providers to assist them in assessing your credit worthiness.  We currently only disclose credit information to CreditorWatch.

You have the right to request CreditorWatch not to:

  • use credit reporting information for the purposes of pre‑screening of direct marketing by a credit provider; or
  • use or disclose credit reporting information if you believe on reasonable grounds that you have been, or are likely to be, a victim of fraud.

If you would like more information about how the above CRBs manage credit related information please contact them directly.

Do we use your personal information for direct marketing?

We may, from time to time, use or disclose your personal information (other than sensitive information or credit information) for the purpose of direct marketing. We may contact you by email, mail or telephone. However, you can let us know at any time if you no longer wish to receive these communications, by contacting us (using the contact details at the beginning of this policy) or using the opt-out/unsubscribe facility in our communications. 

Do we disclose personal information to overseas recipients?

Generally, we store the personal information that we collect in Australia. However, from time to time our IT suppliers and service providers may be required to access our server and the personal information that we hold on our server for assisting with resolving issues and maintenance. Our IT suppliers and service providers are located in Australia as well as the UK and the USA. Where we transfer your information internationally, we will take reasonable steps to ensure that your information is treated securely and the means of transfer provides adequate safeguards. 

Our arrangements with our IT suppliers and service providers:

  • ensure that at all time we maintain control of the information stored on our server; and
  • prohibit our IT suppliers and service providers from using or disclosing personal information for purposes other than providing services to us.

How do we store and protect your personal information?

We take reasonable steps to protect your personal information from misuse, interference, loss, unlawful access, modification and disclosure.

Our Information Security Management System is certified to ISO/IEC 27001, reflecting compliance with globally recognised, leading standards for the confidentiality, integrity, and availability of information assets.

Our premises are located in secure buildings with access restricted to authorised access card holders.  Our IT systems are protected against external threats through a range of security measures, including: 

  • strong password controls and multi-factor authentication for access to firm systems, remote platforms and client data;
  • regular audit, monitoring and data integrity checks to support the security and traceability of client and matter information;
  • current anti-malware, endpoint protection and software updates to reduce the risk of viruses, ransomware and other cyber threats;
  • role-based access controls, least-privilege permissions and encryption of confidential and privileged information both at rest and in transit;
  • secure document management and retention protocols, together with regular staff training on cyber security, phishing awareness and safe handling of client information;
  • tested backup and disaster recovery arrangements, supported by a documented incident response and data breach notification process aligned with legal, regulatory and client confidentiality obligations.

Some personal information may be stored in offsite archival facilities as part of our records management and retention practices. We take reasonable steps to ensure that those archival arrangements are secure and subject to appropriate security measures.  Access to archived records is restricted to authorised personnel and managed in accordance with our confidentiality obligations, data retention requirements and applicable privacy laws.

In addition, all our employees are required, as a condition of employment, to treat personal information held by Jackson McDonald as confidential.

How long do we keep personal information?

Personal information will be retained in accordance with our data retention procedures which categorises all of the information held by us and specifies the appropriate retention period for each category of information. Those periods are based on the requirements of applicable laws and the purpose for which the information is collected and used, taking into account legal and regulatory requirements to retain the information for a minimum period, limitation periods for taking legal action, good practice, and our business purposes.

We do not retain unnecessary copies of full identification documents where not required. 

How do we maintain the quality of personal information?

We endeavour to take reasonable steps to ensure that the personal information that we collect is accurate, up-to-date and complete by, for example conducting annual audits of the personal information that we hold.

If you think that the personal information we hold about you might be out of date and needs to be corrected please contact us.

Application of European privacy laws

If you are an individual in a country in the European Economic Area (EEA), we may be required to comply with the EU General Data Protection Regulation 2016/679 (GDPR) which applies to us when processing the personal information of individuals (data subjects) who are in countries in the EEA in relation to offering you our products or services or if we monitor any of your behaviour when in those countries. 

How can you ask us to correct or access the personal information we hold about you?

You have the right to request access to the personal information we hold about you and to ask for it to be corrected if you believe it is inaccurate, incomplete or out-of-date.

To request access to or correction of your personal information, please send a written request specifying the information you wish to access or amend to our Privacy Officer using contact details at the beginning of this policy.

To process your request, we may ask you to verify your identity. There is no charge for making a request for access to or correction of your personal information. However, you may be required to pay any reasonable costs incurred by us in providing you with access (e.g. staff time collating the information, photocopying costs, postage costs). We will let you know the likely cost in advance.

We will endeavour to respond to your request within a reasonable time.

For access requests: We will provide you with access to your personal information unless we are legally permitted or required to refuse your request (in whole or part).  For example, we are required to refuse access to documents that are subject to legal professional privilege.  If we refuse your request, we will provide you with a written notice explaining the reasons for the refusal and details on how you can make a complaint about our decision. 

For correction requests: If we agree that the information we hold is incorrect, we will update our records promptly.  If we do not agree that the information is incorrect, we will notify you in writing of our decision.  You can then ask us to attach a statement to your record indicating that you believe the information is inaccurate.

How can you tell us about a problem or make a complaint relating to our privacy practices?

If you have a complaint about the way in which we have handled your personal information, please let us know by contacting Jackson McDonald’s Privacy Officer using the contact details at the beginning of this policy.

All complaints will be reviewed and, where appropriate, investigated by our Privacy Officer.  We will notify you of the outcome as soon as reasonably practicable, typically within 30 days of receiving your complaint (or such other time as agreed) and in the manner you have requested that we communicate with you.

If we are unable to resolve your concerns to your satisfaction, you may make to the Office of the Australian Information Commissioner. The Office of the Australian Information Commissioner can be contacted by: 

  • email at enquiries@oaic.gov.au
  • post addressed to Office of the Australian Information Commissioner, GPO Box 5218, Sydney NSW 2001; 
  • telephone on 1300 363 992
  • online form available at: www.oaic.gov.au/privacy/privacy-complaints. 

Our website

A number of facilities on our website and applications invite you to provide us with personal information, such as the job application facility in the “Careers” section of our website and our email queries facilities. The purpose of these facilities is apparent at the point that you provide your personal information, and we only use that information for those purposes.

Our website also uses ‘cookies’ and similar technologies (via Google Analytics) to collect information about your device, browsing activity and usage patterns (including your IP address).  The information generated by the cookie about your use of our website will be transmitted to and stored by Google on servers in the United States. Google uses this information to evaluate website use, compile reports on website activity for website operators and provide other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf. Google does not associate your IP address with any other data held by Google. 

You may refuse the use of cookies by selecting the appropriate settings on your browser. However, please note that if you do this you may not be able to use the full functionality of our website. By using our website, you consent to the processing of data about you by Google in the manner and for the purposes set out above.

Third party sites: Our website may contain links to other sites which are controlled by third parties. Visitors should consult these other sites’ privacy policies and please be aware that we do not accept responsibility for their use of information about you.

Children’s privacy on the websites: Our website and applications are not intended for use by children under the age of 18. We do not knowingly collect personal information from anyone under 18 years of age through the website. 

Download Schedule 1

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Stay up-to-date and subscribe to receive our latest news and insights