AML/CTF Privacy Policy and Collection Statement

This AML/CTF Privacy Policy and Collection Statement (AML/CTF Privacy Document) applies to our collection and use of personal information in connection with our obligations under the AntiMoney Laundering and CounterTerrorism Financing Act 2006 (Cth).

Our Privacy Statement, which is available at https://bluespacelegal.com/privacy-statement, applies more generally if you request legal and/or consulting services from us. If there is any inconsistency between this AML/ AML/CTF Privacy Document and our Privacy Statement, this AML/CTF Privacy Document prevails to the extent of any inconsistency.

AML/CTF Privacy Policy

Our commitment

We are committed to protecting your privacy. We collect, use, share, process, and manage Personal Information only as reasonably necessary for carrying out our functions and activities.

If we prepare to provide, provide you with, or reasonably anticipate that we may provide you with, any Designated Services, we will handle your Personal Information provided in relation to those services in an open and transparent way, subject to our legal obligations, in accordance with this Privacy Policy.

What does this Privacy Policy cover?

This policy applies only to Personal Information handled in connection with our AML/CTF obligations under the AML/CTF Framework. Other parts of our legal practice may be outside the Privacy Act. We still handle that information confidentially under the legal profession legislation (as defined in section 3A of the Legal Profession Uniform Law Application Act 2014 (NSW)), including the Legal Profession Uniform Law Australian Solicitors’ Conduct Rules 2015 (NSW).

Meaning of words used in this Privacy Policy

In this Privacy Policy the terms listed have the following meanings:

What privacy law applies to our relationship

We are a “small business operator” under s 6D of the Privacy Act and become subject to the Privacy Act, for the first time, only in relation to AML/CTF-related activities by operation of s 6E(1A) of that Act.

Accordingly, the Privacy Act,including the APPs, applies only to our collection, use, sharing, processing, and management of Personal Information required to comply with our obligations under the AML/CTF Framework.

Under APP 2 you may interact with us anonymously, or using a pseudonym, where lawful and practicable. However, interacting anonymously or using a pseudonym is not possible where we are required to verify identity under the AML/CTF Framework.

How do we collect Personal Information?

We collect Personal Information only by lawful and fair means.

We will collect Personal Information directly from the individual who is the subject of the information unless:

  • the individual has consented to collection of his or her Personal Information from a third party,

  • it is unreasonable or impractical to make a direct collection; and/or

  • we are required or authorised by law to collect his or her information from a third party.

We may collect Personal Information when you, your organisation, or those acting on your or your organisation’s behalf:

  • visit us or meet with our representatives;

  • communicate with us, including by physical post, email, social media, telephone or text message;

  • register to attend, present at or otherwise participate in a meeting, conference or event hosted or presented by us; and/or

  • engage us to provide services including when you supply KYC Information in response to our direct request.

If we use a credit reporting body for electronic identity verification, we will seek your express consent prior to doing so and offer an alternative means of verification (for example, certified copies of identification documents), as legally required.

Please refer to the attached AML/CTF Privacy Collection Notice which is required to be provided to you at or before the time we collect your Personal Information.

What Personal Information do we collect?

We are required by law under the AML/CTF Act to collect and verify certain Personal Information and may be prohibited from providing services if we cannot do so.

In particular, we collect KYC Information as required by the AML/CTF Act which may include names; addresses; location; contact details; job titles; and services and transactions obtained, offered and supplied including usage history and information about the time, place, and circumstances of our interactions with you.

We may infer information about you from your engagement with us and your activities. We may also collect Sensitive Information where required for compliance with the AML/CTF Framework or where otherwise permitted by law.

We may conduct ongoing monitoring of transactions and client information to comply with our AML/CTF obligations.

What happens if you don’t provide us with requested Personal Information?

If you do not provide requested Personal Information, we may be unable to provide Designated Services and/or comply with our legal obligations.

Purposes of collection of Personal Information

We collect and use Personal Information to carry out our activities and functions including providing you with Designated Services, complying with our regulatory obligations in relation to the delivery of those services, including adherence to the Legal Profession Uniform Law and its related rules and legislation, the Legal Profession Uniform Law Australian Solicitors’ Conduct Rules 2015 (NSW) and the Legal Profession Uniform General Rules2015 (NSW). Other relevant legislation which may require us to collect and use your Personal Information includes the Duties Act 1997 (NSW) and the Australian Registrars National Electronic Conveyancing Council’s Model Participation Rules.

Unless you consent to us doing so otherwise, we will only use your Personal Information for the primary purpose for which it was collected, and for any secondary purpose if you would reasonably expect, and the purpose is related to, the primary purpose of collection. Examples of secondary purposes you might reasonably expect are listed in the previous paragraph.

In the case of Sensitive Information, any secondary purpose will be one that you would reasonably expect and directly related to the primary purpose of collection.

Disclosure of Personal Information

Third parties

Subject to legal requirements, we do not share your Personal Information with any third parties except:

  • with your express permission; and

  • to contracted service providers to organise or facilitate the efficient and effective administration, management or delivery of our services. This may include service providers that support our due diligence processes associated with complying with our AML/CTF obligations.

We will direct that such service providers comply with the Privacy Act in handling your Personal Information appropriately.

Legal requirements

We may use or disclose your Personal Information in circumstances where required by law and/or expressly permitted by the Privacy Act, including if:

  • it is not reasonable or practical to obtain consent and we reasonably believe use or disclosure is necessary to lessen or prevent a serious threat to life, health, or safety of any individual or public health and safety;

  • we have reason to suspect that unlawful activity or misconduct of a serious nature that relates to our activities or functions is being or has been engaged in, and we believe the collection, use or disclosure is necessary to take appropriate action in relation to the matter;

  • we reasonably believe that the collection, use or disclosure is reasonably necessary to assist with the location of a person reported missing; or

  • we are compelled by law including:

o by warrant or subpoena;

o where we are required by request under statute or lawful order of a government agency or authority including law enforcement, courts and tribunals and regulators; and/or

o to AUSTRAC and other government agencies without your knowledge or consent, including where we form a suspicion about a matter or transaction under the AML/CTF Framework.

Nothing in this Privacy Policy limits our obligations of confidentiality or client legal privilege. However, there may be circumstances where we are compelled to disclose confidential information to AUSTRAC under the AML/CTF Framework.

We are prohibited from notifying you of disclosures to AUSTRAC and may be prohibited from notifying you of disclosures to other government agencies or authorities.

Business transactions

If we are involved in a merger, acquisition or asset sale, your Personal Information may be disclosed in confidence as part of a due diligence process and may be transferred to the new owner. We will provide notice before your Personal Information is transferred and becomes subject to a different Privacy Policy.

How do we protect your information?

We hold Personal Information in hard copy and electronic formats. We take reasonable steps to prevent unauthorised access, disclosure, alteration, destruction or loss of Personal Information including by using a range of physical, operational and technological security measures to protect this information. These measures include organisational and technical measures such as:

  • administrative and technical controls to restrict access to Personal Information to only those people who need access;

  • staff policies and education; and

  • technological security measures, including firewalls, encryption and anti-virus software.

Where a data breach is likely to result in serious harm, we will comply with the Notifiable Data Breaches scheme in the Privacy Act, including notifying the OAIC and affected individuals, as required.

When we consider that Personal Information is no longer needed for any purpose for which the information may be used or disclosed in accordance with this Policy and that we are not required by law or court order to retain the Personal Information, we will take reasonable steps to destroy or de-identify the information. AML/CTF KYC Information and transaction records are kept for seven years after the business relationship ends or the transaction is completed, as required by the AML/CTF Framework.

Can your Personal Information be accessed offshore?

We maintain your Personal Information physically and electronically in Australia and in cloud servers, all of which may be securely accessed from outside of Australia. We may need to share your Personal Information with third parties outside of Australia (such as local law experts, consultants and/or your colleagues in another jurisdiction).

Some electronic services we use may process data offshore, such as cloud servers, bookkeeping services, Microsoft and AI tools, but those services are not entitled to access or use the Personal Information held by us except as required for delivery of the contracted service.

We take reasonable steps to ensure overseas recipients do not breach the APPs.

How you can access and correct your Personal Information

We will respond to inquiries from an individual regarding whether we hold any Personal Information relating to that individual and will allow access to and correction of any such Personal Information subject to our contractual arrangements where Personal Information is held by a third party, and the conditions and limitations set out in the Privacy Act, including:

  • if we reasonably believe that giving access would pose a serious threat to the life, health or safety of any individual, or to public health or public safety;

  • giving access would have an unreasonable impact on the privacy of other individuals;

  • the request for access is frivolous or vexatious;

  • the information relates to existing or anticipated legal proceedings between the organisation and the individual, and would not be accessible by the process of discovery in those proceedings;

  • giving access would reveal the intentions of the organisation in relation to negotiations with the individual in such a way as to prejudice those negotiations;

  • giving access would be unlawful;

  • denying access is required or authorised by or under an Australian law or a court/tribunal order;

  • the organisation has reason to suspect that unlawful activity, or misconduct of a serious nature, that relates to the organisation’s functions or activities has been, is being or may be engaged in and giving access would be likely to prejudice the taking of appropriate action in relation to the matter;

  • giving access would be likely to prejudice one or more enforcement related activities conducted by, or on behalf of, an enforcement body; or

  • giving access would reveal evaluative information generated within the organisation in connection with a commercially sensitive decision‑making process.

If you believe that the Personal Information we, or our contracted third party, hold about you is inaccurate, out-of-date, incomplete, irrelevant, or misleading, you may request that we correct it by contacting our Privacy Officer. We may ask you to verify your identity before giving you access or making corrections, and we may charge a reasonable fee for providing access (but not for making a correction).

You can contact our Privacy Officer at the following link.

We will take reasonable steps to correct your information to ensure it is accurate, complete, and up-to-date within a reasonable period (usually within 30 days) of receiving your request.

How you can complain about our information handling practices

All privacy-related inquiries and complaints are handled by our Privacy Officer. If you have any concerns regarding our management of your Personal Information, or if you believe we have breached the APP/s, please contact our Privacy Officer in writing setting out the details of your complaint.

We are committed to achieving a fair and equitable resolution of any privacy concerns. When you lodge a complaint, we will follow this internal review process:

  1. We will acknowledge receipt of your written complaint within a reasonable time (usually within seven days).

  2. Our Privacy Officer will conduct an internal investigation into your complaint. This will involve reviewing the circumstances of the collection, use, or disclosure of your information and assessing our compliance with our internal procedures and the Privacy Act. We may contact you to request further information to assist with our investigation.

  3. We will endeavour to complete our investigation and provide you with a written response outlining the outcome of our review, our decision, and any corrective actions we propose to take within 30 days of receiving your complaint.

If you are not satisfied with our response, or if we do not resolve your complaint within 30 days, you are entitled to escalate your complaint by lodging a complaint with the Office of the Australian Privacy Commissioner at this link.

If you require a copy of this Privacy Policy in a particular form (e.g. large print) please contact our Privacy Officer.

Dated July 2026

AML/CTF Collection Statement

This privacy collection notice from Blue Space Legal Group Pty Ltd (ACN 613 763 429) outlines why we collect your personal information, what we collect, how we collect it and who we share it with.‍ ‍

Why we need to collect your information

‍We collect your personal information to comply with the ‘Customer Due Diligence’ requirements in the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act). This includes to: ‍

  • establish and verify your identity before providing certain services to you or the person you are acting on behalf of;

  • assess and manage potential money laundering, terrorism financing, proliferation financing risks or related compliance risks associated with the provision of our services;

  • make reports required by law under the AML/CTF Act; and

  • meet record keeping obligations under the AML/CTF Act

What personal information we collect

We collect the following types of personal information: ‍

  • your full name, date of birth, residential address; and

  • photo ID and unique identifier, such as a passport or driver’s licence number.

‍We also collect the following sensitive information: ‍

  • whether you are a member of any political associations, professional or trade associations may be used to verify your occupation or determine whether you are a politically exposed person

How we collect your information

We will generally collect your personal information directly from you. However, we may collect your personal information from third parties including a service provider such as another law firm which you have engaged in another jurisdiction, a colleague who is authorised to provide this information to us such as a personal assistant, or from public records including online searches.

Who we may share your information with

We may share your personal information with AUSTRAC or other government agencies to meet our legal and regulatory obligations including under the AML/CTF Act or the AML/CTF Rules.

What happens if we cannot collect your information

If you do not provide us with your personal information, we may not be able to verify your identity and provide you (or the person you are acting on behalf of) with the services you have requested.

Your privacy rights and our privacy policy

Our attached AML/CTF Privacy Policy contains further information about how we will handle your personal information and how you can access and correct your personal information. It also outlines how to lodge a complaint and how that complaint will be managed if you are concerned about how we handled your information.

How to contact us about your privacy

Dated July 2026