Privacy Policy
Last updated: 6 July 2026
Russo Lawyers & Associates | ABN 98 858 479 737 | Level 19, 263 William Street, Melbourne VIC 3000 | samuel@russolaw.com.au | (03) 7040 9825
Russo Lawyers & Associates (we, us or our) is committed to protecting the privacy of individuals who visit our website, contact us or engage us for legal services. This Privacy Policy explains how we collect, hold, use and disclose personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) contained in Schedule 1 of that Act, the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act), the AML/CTF Rules and our professional obligations.
By using russolaw.com.au (Website) or by engaging us for legal services, you acknowledge that you have read and understood this Privacy Policy.
1. Application
This Privacy Policy applies to personal information we collect and handle in connection with our legal services, client onboarding and administration, conflict checking, AML/CTF compliance, recruitment, events, publications, website use and general practice operations.
We maintain practices, procedures and systems designed to support compliance with the APPs and the AML/CTF Act, including controls relating to confidentiality, information security, records management, direct marketing, access and correction requests and complaints handling.
2. What personal information we collect
The kinds of personal information we collect and hold depend on the nature of your relationship with us, including whether you are a client, prospective client, a person connected with a client matter, a supplier, service provider, job applicant, employee, contractor, subscriber, event attendee or website user. This may include:
- contact and identity information, including name, date of birth, address, phone number, email address and postal address;
- occupation, role, employer, business activity and professional information;
- identity documents and verification information, including document numbers, issuing authorities, expiry dates, photographs and signatures;
- government-related identifiers, where required or authorised by law;
- financial, banking, payment, transaction, source of funds, source of wealth and ownership information;
- matter information, including instructions, communications, evidence, documents and information about relationships between persons involved in a matter (such as the nature of charges or proceedings and court dates);
- information about companies, trusts, partnerships and other arrangements, including beneficial owners, controllers, directors, trustees, beneficiaries, shareholders and other connected persons;
- information relevant to politically exposed person status, sanctions screening, AML/CTF risk assessment and transaction monitoring;
- recruitment, employment and contractor information;
- event, subscription and marketing and communication preferences; and
- technical information, including IP address, browser type, pages visited on our Website and device information, collected automatically through server logs, cookies and analytics tools.
Sensitive information
Where you or another person voluntarily provide health information, criminal history or other sensitive information as part of your legal matter or our AML/CTF obligations, we collect and handle that information only where permitted by law, including where you consent and the information is reasonably necessary for our functions, where collection is required or authorised by law, or where necessary for legal claims or the provision of legal services.
3. How we collect personal information
We usually collect personal information directly from you when you instruct us, provide information or documents, communicate with us, complete a form or identity verification process, subscribe to our publications, register for an event, interact with our Website, or apply for employment or engagement with us.
We may also collect personal information from third parties where permitted by law, including clients, counterparties, witnesses, representatives, advisers, courts, tribunals, regulators, government bodies, public registers, commercial databases, identity verification providers, AML/CTF screening providers, financial institutions, recruitment agencies, referees, former employers and technology or analytics providers.
If you provide us with personal information about another individual, please take reasonable steps to ensure that person is aware their information has been provided to us and of this Privacy Policy. You should only provide sensitive information about another individual where you have their consent or authority to do so, or where otherwise permitted by law.
4. How we use personal information
We use personal information for purposes including:
- responding to your enquiry, providing legal services and carrying out your instructions;
- conflict checks, client onboarding and matter opening and administration;
- providing advice, conducting due diligence and managing transactions, litigation and dispute resolution;
- trust accounting, billing, debt recovery and practice management;
- complying with our professional, court, tribunal, regulatory and AML/CTF obligations, including customer due diligence, ongoing monitoring, sanctions and politically exposed person screening, risk assessment, reporting and record-keeping;
- responding to notices, audits, investigations and lawful requests from AUSTRAC, courts, regulators, law enforcement agencies and government bodies;
- risk management, insurance, complaints handling and professional indemnity matters;
- recruitment, employment, contractor and human resources administration;
- operating, securing and improving our Website and services, using de-identified or aggregated data where practicable; and
- sending you legal updates, publications and event invitations where permitted by law.
We do not use personal information to make decisions solely by automated means where that decision would significantly affect your rights or interests (see clause 7).
5. Disclosure of personal information
We may disclose personal information to:
- courts, tribunals, regulators, AUSTRAC and law enforcement agencies, in connection with legal proceedings, AML/CTF obligations or as required or authorised by law;
- opposing parties, prosecutors, expert witnesses, barristers and other professionals engaged in connection with your matter;
- financial institutions, insurers, identity verification providers and AML/CTF screening providers;
- service providers who assist us with practice management, document storage, file transfer, email, website hosting, recruitment, payment processing, analytics and similar functions, where those providers are bound by confidentiality and data-handling obligations;
- related or associated entities that support our practice for authorised business support functions; and
- any other person to whom you have authorised disclosure, or where disclosure is required or authorised by law.
We do not sell, rent or trade personal information to third parties for marketing purposes.
6. AML/CTF compliance
Where AML/CTF laws apply, we may be required to collect, verify, use, disclose and retain personal information about clients and other relevant persons before we provide a service and throughout a matter.
This may include information required to verify your identity, understand the nature and purpose of the service you have asked us to provide, identify beneficial owners (broadly, individuals with 25% or more ownership or control) or persons on whose behalf you act, verify your authority to act, establish source of funds or source of wealth, conduct sanctions and politically exposed person checks, assess risk and monitor transactions or behaviours on an ongoing basis.
If you do not provide the information we request, we may be unable to provide the requested service, or may need to pause, limit or terminate our work, subject to our professional obligations and applicable law.
We may be required to disclose information to AUSTRAC or another authority where required or authorised by AML/CTF laws. Those laws restrict what we can tell you about certain reports, notices, investigations, requests or disclosures (see clause 8).
7. Automated decision-making and tools
We use technology, including automated and computer-assisted tools, for functions such as identity verification, document verification, sanctions and politically exposed person screening, transaction monitoring, risk assessment and conflict checking.
We do not use these tools to make solely automated decisions that significantly affect an individual's rights or interests. Automated outputs may inform decisions made by appropriately trained personnel, including whether we can act for you, whether enhanced customer due diligence is required, or whether AML/CTF or other legal steps are required.
8. Legal professional privilege and confidentiality
Our duties of confidentiality and legal professional privilege remain important and are not displaced by this Privacy Policy. Some laws, including the AML/CTF Act, may require or authorise us to collect, use, disclose or retain personal information despite those duties. Where privilege may apply to information or documents requested under AML/CTF laws or other laws, we assess and manage privilege claims in accordance with applicable legal requirements.
Where we form a suspicion that must be reported to AUSTRAC, the law may prohibit us from telling you, or anyone else, that a report has been made or is proposed to be made (this is known as tipping off). Separately, if the sole basis for a suspicious matter report is privileged information, we are not required to make that report and we will only ever disclose non-privileged information where privilege applies to part of our reasons for suspicion.
We do not adopt a government-related identifier as our own identifier of an individual unless permitted by law. We may collect, use or disclose government-related identifiers where reasonably necessary for identity verification, legal services, AML/CTF compliance, court or tribunal processes, regulatory compliance, or where otherwise required or authorised by law.
9. Direct marketing
Where we are permitted by law to do so, we may use your contact details to send you marketing communications, legal updates, publications and event invitations about our services. Marketing communications sent by electronic means are sent in accordance with the Spam Act 2003 (Cth) and only to recipients who have consented, expressly or by inference, to receive them.
Each electronic marketing message will identify us as the sender and include a functional unsubscribe facility. You can opt out at any time by using the unsubscribe link, replying STOP to an SMS, or contacting Samuel Russo using the details in clause 17. We do not use sensitive information for direct marketing without your consent.
10. Cross-border disclosure
Some of our service providers (for example, cloud hosting, email, practice management and AML/CTF screening providers) may store or process personal information outside Australia. We may also disclose personal information overseas where necessary for your legal services, where you have consented, or where a matter involves an overseas party, transaction, court, tribunal, regulator, registry or authority.
The countries in which overseas recipients are located will depend on the particular matter, service provider or technology used. Before we disclose personal information overseas, we take the reasonable steps required by APP 8 to ensure the overseas recipient handles your personal information in a way that is consistent with the APPs, unless an exception applies.
11. Storage, security and retention
We take reasonable steps to ensure the personal information we collect, use and disclose is accurate, up to date, complete and relevant and to protect it from misuse, interference, loss, unauthorised access, modification and disclosure, as required by APP 11. Those steps include physical, technical and administrative safeguards, such as access controls, password protection, secure cloud services, staff training and confidentiality obligations on our staff and contractors.
We retain personal information only for as long as we reasonably need it for the purposes set out in this Privacy Policy, or as otherwise required or permitted by law, including legal profession record-keeping obligations, tax and audit requirements, professional indemnity insurance arrangements and AML/CTF compliance. Records required under AML/CTF laws may need to be retained for a prescribed period of at least 7 years.
When we no longer need personal information for a lawful purpose, we will take reasonable steps to destroy it or de-identify it, subject to these retention requirements.
12. Notifiable data breaches
We have a data breach response plan. If we have reasonable grounds to believe that an eligible data breach has occurred, in line with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act, we will notify the Office of the Australian Information Commissioner (OAIC) and any affected individuals as soon as practicable.
13. Accessing and correcting your personal information
You have the right to ask for access to personal information we hold about you and to ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.
To make a request, please contact Samuel Russo, Principal Lawyer, using the details in clause 17. We will respond within a reasonable period (usually within 30 days) and we may need to verify your identity before providing access. We will tell you if there is a reason we are unable to provide access or make a correction.
14. Complaints
If you believe we have handled your personal information in a way that does not comply with the APPs or this Privacy Policy, please contact Samuel Russo to make a complaint. We will respond within a reasonable period (usually within 30 days). If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner:
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5288, Sydney NSW 2001
15. Cookies and analytics
Our Website may use cookies, pixels, analytics tools and similar technologies to enable functionality, understand website usage, improve our services and support communications. Analytics data is collected in aggregated and de-identified form where practicable.
Most internet browsers allow you to delete or block cookies, or to receive a warning before a cookie is stored. If you disable cookies, some parts of the Website may not function as intended.
16. Changes to this policy
We may update this Privacy Policy from time to time. The current version will always be available at russolaw.com.au/privacy.
17. Contact us
If you have any questions about this Privacy Policy or wish to exercise any of your rights, please contact us via the contact details set out on this Website.
This Privacy Policy does not form part of any client engagement agreement. For information about how we handle client confidentiality and legal professional privilege, see your costs agreement or engagement letter.
Contact: Samuel Russo | samuel@russolaw.com.au | (03) 7040 9825