Privacy Policy
Last Updated: July 2025
1. Introduction
Baker Merz Construction Lawyers ABN 40 650 782 317 (trading as Construction.Lawyer) is committed to protecting the privacy of all individuals whose personal information we collect in the course of our legal practice and the operation of our website at https://construction.lawyer.
This Privacy Policy sets out how we manage personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the European Union General Data Protection Regulation (GDPR) (EU) 2016/679, and the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). This policy also reflects adherence to the OECD Privacy Principles.
This policy applies to all clients, prospective clients, website visitors, referrers, expert witnesses, barristers and other third parties whose personal information comes into our possession. It applies to information collected through our website, during consultations, by telephone, by email and via any other means of communication.
Our legal bases for processing personal information include the performance of a contract, compliance with legal obligations (including under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)), protection of our legitimate interests, and your freely given consent where required.
2. Definitions
Personal Information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, as defined in section 6 of the Privacy Act 1988 (Cth). Under the GDPR, this is referred to as Personal Data (Article 4(1)).
Sensitive Information means personal information about an individual's racial or ethnic origin, political opinions, religious beliefs, criminal record, health information, or membership of professional associations, as defined in section 6 of the Privacy Act 1988 (Cth). We collect sensitive information only with your express consent or where authorised by law.
Cookies are small text files placed on your device by websites you visit. They store information about your browsing preferences and enable websites to recognise your device on subsequent visits.
Data Controller means the entity that determines the purposes and means of processing personal data (Article 4(7), GDPR). Baker Merz Construction Lawyers is the Data Controller for personal data of individuals in the European Union.
Data Processor means an entity that processes personal data on behalf of the Data Controller (Article 4(8), GDPR).
Data Subject means an identified or identifiable natural person whose personal data is processed (Article 4(1), GDPR).
Processing means any operation performed on personal data, including collection, storage, use, disclosure or destruction (Article 4(2), GDPR).
Consent means a freely given, specific, informed and unambiguous indication of a data subject's wishes signifying agreement to the processing of their personal data (Article 4(11), GDPR).
APPs means the Australian Privacy Principles in Schedule 1 of the Privacy Act 1988 (Cth).
GDPR means the General Data Protection Regulation (EU) 2016/679.
CCPA/CPRA means the California Consumer Privacy Act of 2018 and the California Privacy Rights Act of 2020.
3. Information We Collect
3.1 Personal Information You Provide
We collect personal information that you voluntarily provide when you engage our services, enquire about our services, subscribe to our publications, attend our events or otherwise interact with us. This includes your name, title, residential and business addresses, email addresses and telephone numbers. We also collect company or organisation details, including your position or role and Australian Business Number (ABN). Information relating to your legal matter is collected, including details of the construction project, dispute, contract or circumstances giving rise to your enquiry, and correspondence between you and our lawyers. Financial information necessary for billing and payment, including bank account details and payment history, is also collected. We collect identity verification documents required under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), including passport, driver's licence or other government-issued identification.
3.2 Automatically Collected Information
When you visit our website, certain information is collected automatically through cookies and tracking technologies. This includes your Internet Protocol (IP) address, browser type and version, operating system, device type and screen resolution. We also collect information about your browsing activity, including the pages you visit, time and date of your visit, time spent on each page, links clicked and referring website. We use Google Analytics for this purpose. Information generated by Google Analytics cookies is transmitted to and stored by Google on servers that may be located outside Australia.
3.3 Sensitive Information
In the course of providing legal services, we may collect sensitive information. This may include professional disciplinary history (particularly for Queensland Building and Construction Commission matters), health information where relevant to your legal matter (such as personal injury or workers compensation claims), and racial or ethnic origin where we undertake diversity monitoring, collected only with your explicit consent and anonymised where practicable. We collect sensitive information only where reasonably necessary for our functions and where you have consented or an exception applies under section 16A of the Privacy Act 1988 (Cth) or Article 9 of the GDPR.
4. How We Collect Information
We collect personal information directly from you when you complete forms on our website, contact us by telephone, email or post, attend consultations, sign engagement letters or costs agreements, subscribe to our newsletters or legal updates, or register for our events and seminars.
We may also collect personal information from third parties where necessary to provide our legal services or where you have authorised us. This includes barristers, expert witnesses and other legal professionals involved in your matter; courts, tribunals and regulatory bodies including the Queensland Civil and Administrative Tribunal and the Australian Centre for International Commercial Arbitration; referrers including other law firms, accountants and insurance brokers; and publicly available sources such as ASIC registers, land title records and court databases.
Where we collect personal information from a third party, we will take reasonable steps to notify you as required under APP 5 of the Privacy Act 1988 (Cth).
5. Purpose of Collection
We collect, hold, use and disclose personal information for the following purposes.
Primary Purpose: To provide legal services, including advising on construction law matters, drafting and reviewing contracts, representing you in disputes, litigation and arbitration, and managing your legal matter. This purpose is linked to performance of a contract under Article 6(1)(b) of the GDPR.
Secondary Purposes: Billing, invoicing and debt recovery; compliance with professional obligations under the Legal Profession Act 2007 (Qld) and equivalent legislation in other jurisdictions; compliance with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth); quality assurance, file review and risk management; maintaining trust account and financial records in accordance with Queensland Law Society rules; and responding to complaints or legal claims against our firm. These purposes are linked to compliance with legal obligations under Article 6(1)(c) and legitimate interests under Article 6(1)(f) of the GDPR.
Marketing: With your express consent, we may send you legal updates, newsletters, seminar invitations and other marketing communications. You may opt out at any time by clicking the unsubscribe link or contacting privacy@bakermerz.com.au. The legal basis is your consent under Article 6(1)(a) of the GDPR.
Website Improvement: We use automatically collected information to analyse traffic and improve our website. The legal basis is our legitimate interest under Article 6(1)(f) of the GDPR.
Legal Obligations: We process personal information to comply with applicable laws, court orders, subpoenas and regulatory requirements.
6. Use and Disclosure
6.1 Internal Use
Your personal information is accessible only to our lawyers, paralegals, administrative staff and IT personnel who need access to perform their duties. All staff are bound by confidentiality obligations and our privacy policies.
6.2 Disclosure to Third Parties
We may disclose personal information where necessary for the provision of legal services or as required by law. This includes disclosure to barristers and other legal practitioners engaged in your matter; expert witnesses including quantity surveyors, engineers, architects and other construction industry professionals; courts, tribunals, arbitrators and regulatory bodies; your insurers or insurance brokers where your matter involves an insurance claim; opposing parties, their lawyers and mediators in dispute resolution or litigation; and government agencies where required by law, including the Australian Taxation Office and AUSTRAC.
6.3 Disclosure with Consent
We may disclose personal information to other third parties with your express consent or at your direction.
6.4 Disclosure Required by Law
We may disclose personal information without consent where required or authorised by Australian law, court order or subpoena, or where necessary to assist in the investigation of suspected unlawful activity.
6.5 Overseas Disclosure and Cross-Border Data Transfers
In the course of our international arbitration practice, personal information may be disclosed to parties outside Australia. This includes international arbitral institutions, foreign counsel and expert witnesses, and counterparties and tribunals in relevant jurisdictions.
Where we disclose personal information overseas, we take reasonable steps to ensure the overseas recipient does not breach the APPs, unless an exception applies under APP 8.2 of the Privacy Act 1988 (Cth). For EU data subjects, we ensure appropriate safeguards are in place in accordance with Chapter V of the GDPR, including Standard Contractual Clauses or other legally recognised transfer mechanisms.
We do not sell personal information. We do not share personal information for cross-context behavioural advertising.
7. Cookies and Tracking Technologies
7.1 Types of Cookies
Our website uses cookies to enhance your browsing experience and analyse traffic. Essential Cookies are necessary for the proper functioning of our website and cannot be disabled. They enable core functionality such as page navigation. Analytics Cookies allow us to collect information about how visitors use our website, including which pages are visited and time spent. We use Google Analytics for this purpose. Marketing Cookies are not currently used, but if we implement them in future we will obtain your consent first.
7.2 Google Analytics
Our website uses Google Analytics, a web analytics service provided by Google LLC. Google Analytics uses cookies to help analyse how users interact with our website. Information collected (including your IP address) is transmitted to and stored by Google on servers in the United States. Google uses this information to evaluate website usage, compile reports and provide related services. Google may also transfer this information to third parties where required by law or where third parties process the information on Google's behalf.
7.3 Managing Cookies
Most web browsers allow you to control cookies through their settings. You can configure your browser to refuse all cookies or alert you when a cookie is placed. Disabling cookies may affect website functionality.
When you first visit our website, a cookie consent banner provides information about the cookies we use and allows you to accept or decline non-essential cookies.
7.4 Third-Party Cookies
Our website may contain embedded content from third parties. These third parties may place cookies that we do not control. We recommend reviewing the privacy and cookie policies of these third parties.
8. Data Security
8.1 Security Measures
We implement a range of physical, electronic and organisational measures to protect personal information from unauthorised access, modification, disclosure, misuse, loss or destruction.
Physical Security: Our offices are secured with access control systems. Physical files are stored in locked cabinets in secure areas accessible only to authorised personnel.
Electronic Security: Our IT infrastructure is protected by firewalls, intrusion detection systems and anti-malware software. Data transmitted between your device and our website is encrypted using Transport Layer Security (TLS). Our network is protected by multi-factor authentication. Laptop computers and mobile devices are encrypted and password-protected. Cloud-based systems are hosted by providers with SOC 2 Type II certification.
8.2 Staff Training and Confidentiality
All lawyers and staff undergo regular privacy and data security training. Every employee, contractor and consultant is required to sign a confidentiality agreement. Our information security policy is reviewed annually.
8.3 Data Breach Response
We have a Data Breach Response Plan in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth). In the event of an eligible data breach, we will take reasonable steps to contain the breach, notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable and within 72 hours, consistent with the requirements of both the NDB scheme and Article 33 of the GDPR.
9. Data Retention
We retain personal information for as long as necessary to fulfil the purposes for which it was collected, comply with legal and professional obligations, and protect our legal interests.
Legal Matter Files: Client files are retained for a minimum of seven years following completion of a matter, in accordance with Queensland Law Society guidelines and applicable limitation periods. Some files involving trusts, property transactions or matters concerning minors may be retained longer as required by law.
Financial Records: Billing and trust account records are retained for seven years in accordance with the Taxation Administration Act 1953 (Cth).
Website Data: Information collected through enquiry forms and newsletter subscriptions is retained as long as necessary to respond to your enquiry and maintain communications. Analytics data is retained in accordance with Google's policies.
Destruction: When personal information is no longer required, we take reasonable steps to destroy or de-identify it securely. Paper records are shredded via secure document destruction services. Electronic records are permanently deleted in accordance with our data destruction policy.
10. Your Rights
10.1 Australian Rights Under the APPs
Right of Access (APP 12): You have the right to request access to the personal information we hold about you. We will respond within 30 days. We may charge a reasonable fee for providing access. In certain circumstances permitted by APP 12, we may refuse access and will provide written reasons.
Right of Correction (APP 13): You have the right to request correction of personal information that is inaccurate, out of date, incomplete, irrelevant or misleading. We will take reasonable steps to correct information within 30 days. If we refuse, we will provide written reasons.
Right to Complain: If you believe we have breached the APPs, you may complain to us directly or lodge a complaint with the Office of the Australian Information Commissioner.
10.2 GDPR Rights for EU Data Subjects
Right to Access (Article 15): You have the right to obtain confirmation as to whether personal data concerning you is being processed, and access to that data and information about the processing.
Right to Rectification (Article 16): You have the right to obtain rectification of inaccurate personal data without undue delay, and to have incomplete personal data completed.
Right to Erasure (Article 17): You have the right to obtain erasure of personal data without undue delay where specified grounds apply, including where the data is no longer necessary or you have withdrawn consent.
Right to Restrict Processing (Article 18): You have the right to obtain restriction of processing where you contest accuracy, where processing is unlawful, or where you have objected to processing.
Right to Data Portability (Article 20): You have the right to receive personal data concerning you in a structured, commonly used and machine-readable format, and to transmit it to another controller.
Right to Object (Article 21): You have the right to object to processing based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
10.3 CCPA/CPRA Rights for California Residents
Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information collected, sources of collection, business purposes and categories of third parties with whom we share it.
Right to Know if Personal Information is Sold or Shared: You have the right to know whether we have sold or shared your personal information. We do not sell or share personal information.
Right to Opt-Out of Sale or Sharing: You have the right to opt-out of the sale or sharing of personal information. As we do not sell or share personal information, no opt-out is currently required.
Right to Delete: You have the right to request deletion of personal information, subject to exceptions permitted by law.
Right to Correct: You have the right to request correction of inaccurate personal information.
Right to Limit Use of Sensitive Personal Information: You have the right to request that we limit use and disclosure of sensitive personal information to that necessary to perform services.
Right to Non-Discrimination: You have the right not to receive discriminatory treatment for exercising your CCPA/CPRA rights.
11. How to Exercise Your Rights
To exercise any rights described in this policy, please contact our Privacy Officer using the details in Section 15.
Response Timeframes: For APP requests, we respond within 30 days. For GDPR requests, we respond within 30 days (extendable by two months for complex requests). For CCPA/CPRA requests, we respond within 45 days (extendable by 45 days where necessary).
Verification: Before acting on your request, we will verify your identity by asking you to provide information matching what we have on file. If an agent exercises your rights, we require evidence of their authority.
Complaints: If dissatisfied with our response, you may escalate to the Office of the Australian Information Commissioner (www.oaic.gov.au), the supervisory authority in your EU Member State, or the California Attorney General (oag.ca.gov).
12. Third-Party Links
Our website may contain links to third-party websites, including courts, tribunals, regulatory bodies and industry organisations. These links are provided for your convenience. We do not control and are not responsible for the content, privacy practices or security of third-party websites. The inclusion of a link does not imply our endorsement. We encourage you to review the privacy policy of each website you visit before providing personal information.
13. Children's Privacy
Our website and legal services are not directed at children under 16, and we do not knowingly collect personal information from children under 16. If you are under 16, please do not provide personal information without a parent or guardian's involvement. If we become aware that we have collected personal information from a child under 16 without verified parental consent, we will delete that information immediately. If you believe we may have inadvertently collected such information, please contact privacy@bakermerz.com.au immediately.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the law, or our services. Changes will be posted on this page with an updated "Last Updated" date. Material changes will be notified by email (where you have consented to communications) or by a prominent notice on our website. Your continued use of our website and services after changes constitutes acceptance. If you do not agree with the updated policy, discontinue use and contact us to discuss your concerns.
15. Contact Us
If you have questions, concerns or complaints about this Privacy Policy or our privacy practices, please contact our Privacy Officer.
Privacy Officer
Baker Merz Construction Lawyers ABN 40 650 782 317
Trading as: Construction.Lawyer
Email: privacy@bakermerz.com.au
Telephone: 1300 710 864
Postal Address: Suite 140, 167 Eagle Street, Brisbane QLD 4000, Australia
Office Locations: We also operate from Sydney, Melbourne, Perth and Darwin.
If you are not satisfied with our handling of your privacy concern, you may lodge a complaint with the Office of the Australian Information Commissioner:
Office of the Australian Information Commissioner (OAIC)
GPO Box 5218, Sydney NSW 2001
Telephone: 1300 363 992
Website: www.oaic.gov.au
This Privacy Policy was last updated in July 2025 and supersedes all previous versions.