Privacy Policy

About this Policy

Penmans Lawyers Pty Ltd trading as Penmans (ABN 64 676 843 888) (Penmans, we, us or our) is committed to protecting the privacy and security of personal information. We are bound by the Privacy Act 1988 (Cth) (Privacy Act), including the Australian Privacy Principles (APPs).

This Privacy Policy explains how we collect, hold, use and disclose personal information, how you may access or correct personal information we hold about you, and how you may make a privacy complaint. This Policy applies to personal information collected in connection with our legal practice, our business activities and our website at penmans.com.au.


Personal Information We Collect and Hold

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable.

The types of personal information we collect and hold depend on our relationship with you and the nature of the legal services or other dealings involved.

Personal information we may collect and hold includes:

  • your name, date of birth and contact details;
  • identification information and information contained in identity documents;
  • information collected or generated as part of identity verification processes;
  • financial, banking and transaction information;
  • information about your employment, business, assets, liabilities and financial circumstances;
  • information relating to legal matters, transactions, disputes or proceedings;
  • information about your relationships with other individuals or organisations;
  • correspondence, instructions and other communications with us;
  • information required to comply with our legal, professional and regulatory obligations;
  • information about your interactions with our website and electronic systems; and
  • other personal information that you provide to us or that we lawfully collect in connection with our legal services or business activities.

     

Sensitive Information

In providing legal services, we may collect sensitive information where it is relevant to the services we provide. Depending on the circumstances, this may include information about a person’s health, racial or ethnic origin, religious beliefs, political opinions, sexual orientation, criminal record or other information classified as sensitive information under the Privacy Act.

We will only collect, use and disclose sensitive information where permitted by law.

 

How We Collect Personal Information

We generally collect personal information directly from you when you:

  • contact or engage us;
  • provide instructions, information or documents to us;
  • communicate with us by telephone, email, online forms or other means;
  • use our website;
  • attend our offices or meetings;
  • undertake an identification or identity verification process; or
  • otherwise interact with us.

We may also collect personal information about you from third parties where reasonably necessary for our functions or activities and where permitted by law.

Depending on the circumstances, these may include:

  • our clients and prospective clients;
  • other parties involved in legal matters;
  • lawyers and other professional advisers;
  • courts and tribunals;
  • government departments, agencies and regulatory authorities;
  • banks and financial institutions;
  • identity verification and information service providers;
  • search and information providers;
  • insurers;
  • publicly available records and databases; and
  • other service providers and third parties involved in providing or supporting our legal services.

In some matters, we may collect personal information about individuals who are not our clients because that information is relevant to the legal services we provide.

 

Why We Collect, Hold, Use and Disclose Personal Information

We collect, hold, use and disclose personal information where reasonably necessary for our functions and activities, including to:

  • provide legal services;
  • communicate with clients, prospective clients and other persons;
  • establish and manage our relationship with you;
  • verify identity and authority;
  • conduct conflict and other required checks;
  • open, administer and manage legal matters;
  • undertake searches, enquiries and investigations;
  • prepare, negotiate and complete legal documents and transactions;
  • conduct litigation and other dispute resolution processes;
  • process payments and manage accounts;
  • comply with our professional, legal and regulatory obligations;
  • prevent, detect and respond to fraud, cyber security threats and other unlawful activity;
  • manage our business, systems and records;
  • improve our services and business processes;
  • respond to enquiries, complaints and feedback; and
  • communicate with you about our services where permitted by law.

We may also use or disclose personal information for another purpose where you have consented to that use or disclosure or where it is otherwise permitted or required by law. 

 

Disclosure of Personal Information

In providing legal services and operating our business, we may disclose personal information to third parties where reasonably necessary or otherwise permitted or required by law.

Depending on the circumstances, these third parties may include:

  • barristers, solicitors and other professional advisers;
  • courts, tribunals and dispute resolution bodies;
  • government departments, agencies and regulatory authorities;
  • banks and financial institutions;
  • accountants, auditors and insurers;
  • experts, consultants and other professional service providers;
  • identity verification and information service providers;
  • electronic conveyancing and property information providers;
  • technology, software, cloud storage and communications providers;
  • document production, storage and destruction providers;
  • payment and debt recovery service providers;
  • other parties and their legal representatives in connection with a legal matter;
  • your authorised representatives; and
  • other persons or organisations where you have authorised the disclosure or the disclosure is permitted or required by law.

Where we engage third-party service providers, we take reasonable steps appropriate to the circumstances to protect personal information provided to them.

 

Overseas Disclosures

Some of the third-party service providers we use may involve personal information being accessed, processed or disclosed outside Australia. This may occur, for example, where a provider’s systems, support personnel or other operations are located overseas.

Where required by the Privacy Act, we take reasonable steps to ensure that an overseas recipient handles personal information in accordance with the applicable requirements of the Australian Privacy Principles.

The overseas recipients to whom we are likely to disclose personal information are currently located in New Zealand and United States of America.

The countries involved may change from time to time depending on the service providers we use.

 

Our Website

When you visit our website, certain information may be collected automatically. This may include your Internet Protocol (IP) address, browser and device information and information about how you use our website.

We may use this information to:

  • operate and maintain our website;
  • understand how visitors use our website;
  • improve our website and services;
  • maintain website security; and
  • detect and prevent misuse or fraudulent activity.

Cookies, Analytics and Online Tracking

Our website may use cookies, pixels, tags and similar technologies to collect information about how visitors interact with our website.

Depending on the technology used, the information collected may include your IP address, browser and device information, pages visited, links selected, the date and time of your visit, referring websites and other information about your interaction with our website.

We may use these technologies to:

  • operate and improve our website;
  • understand how visitors use our website;
  • measure website traffic and the effectiveness of our communications and advertising; and
  • where applicable, deliver or measure advertising that may be relevant to website visitors.

Some of these technologies may be provided by third-party analytics, advertising or other service providers. Information collected through these technologies may be disclosed to, or collected directly by, those providers and handled in accordance with their applicable privacy practices.

You can control or disable cookies through your browser settings. Where available, you may also manage advertising and tracking preferences through the relevant third-party platform or other controls made available on our website.

Disabling certain technologies may affect some website functionality.

 

Direct Marketing

We may use personal information to communicate with you about Penmans’ services, news or other information that we consider may be relevant to you where permitted by law.

We may send marketing communications by email, SMS or other means where permitted by law. You may opt out of receiving direct marketing communications from us at any time by using the unsubscribe facility provided in the communication or by contacting us.

We will not use sensitive information for direct marketing without your consent where consent is required by law.

 

Storage and Security

Penmans takes reasonable steps to protect personal information from misuse, interference and loss and from unauthorised access, modification or disclosure.

We use physical, technical and organisational safeguards  appropriate to the nature of the information we hold and the risks associated with it. These safeguards include appropriate access controls, security measures, policies, procedures and team member training.

Access to personal information is limited to team members and service providers who require access for legitimate purposes.

When personal information is no longer required to be retained, we take reasonable steps to securely destroy or de-identify it, subject to our legal, professional and record-retention obligations.

 

Access to Your Personal Information

You may request access to personal information that we hold about you.

Requests should be made to our Privacy Officer using the contact details below.

Before providing access to personal information, we may take reasonable steps to verify your identity or the authority of a person making a request on your behalf.

We will respond to access requests within a reasonable period and generally aim to do so within 30 days.

In some circumstances permitted by law, we may refuse access to some or all of the information requested.

Where we refuse access, we will provide written reasons where required by law and information about available complaint mechanisms.

We will not charge you for making an access request. We may, where permitted, charge a reasonable amount for costs associated with providing access.

 

Correction of Personal Information

We take reasonable steps to ensure that personal information we hold is accurate, up-to-date, complete, relevant and not misleading.

If you believe personal information we hold about you is inaccurate, out-of-date, incomplete, irrelevant or misleading, please contact us.

We will consider and respond to correction requests in accordance with the Privacy Act. 

If we refuse a request to correct personal information, we will provide written reasons where required by law and information about available complaint mechanisms.

Where applicable, you may request that we associate a statement with the information recording that you consider it to be inaccurate, out-of-date, incomplete, irrelevant or misleading.

 

Privacy Complaints

If you have a concern or complaint about how Penmans has handled your personal information or complied with its privacy obligations, please contact our Privacy Officer using the details below.

Please provide sufficient information for us to understand and investigate your concern.

We will:

  • acknowledge your complaint;
  • investigate the circumstances;
  • contact you if we require further information; and
  • provide you with our response following our investigation.

We aim to respond to privacy complaints within a reasonable period, generally within 30 days.

If you are not satisfied with our response, you may be entitled to lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

Information about making a privacy complaint is available at oaic.gov.au.

 

Data Breaches

Penmans maintains procedures for identifying, assessing and responding to actual or suspected data breaches.

Where a data breach is subject to the Notifiable Data Breaches scheme under the Privacy Act, we will comply with our obligations, including notifying affected individuals and the OAIC where required.

We may also take other steps considered appropriate to contain a breach, reduce potential harm and prevent recurrence.

 

Third-Party Websites

Our website may contain links to websites operated by third parties.

Penmans is not responsible for the privacy practices of third-party websites. We recommend reviewing the privacy policy of any third-party website you visit.

 

Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our practices, technology or legal and regulatory obligations.

The current version will be published on our website.

Last updated: 24 September 2026

 

Contact Us

If you have any questions about this Privacy Policy, wish to request access to or correction of your personal information, or wish to make a privacy complaint, please contact:

Privacy Officer
Penmans Lawyers
PO Box 6040
WEST GOSFORD NSW 2250
Email:
accounts@penmans.com.au
Telephone: 02 4324 1266

Further information about privacy rights and the Australian Privacy Principles is available from the Office of the Australian Information Commissioner at oaic.gov.au.