• Home
  • /
  • Privacy & security

|

Privacy advice that protects without paralysing – from advice and assessments through to clauses, statements, and tools.

Public and private sector agencies that handle personal have a lot to manage: privacy law, security requirements, breach prevention, and the readiness to respond when something goes wrong. Day to day, the questions tend to be specific: can we process this, do we need an MOU, is our privacy statement still right, do our contracts protect us, do we understand the information laws that actually apply, are we taking a privacy-centric approach?

In situations like these, an experienced and pragmatic privacy lawyer helps you protect people's privacy, comply with the law, safeguard your reputation and, sometimes, sleep better at night.

01 – CAPABILITIES

How I can help.

Three pillars covering privacy and security from understanding where you stand, through documenting how you operate, to responding when things change or go wrong.


PILLAR 01

Assessment & maturity

  • Privacy maturity stocktakes
  • Threshold and full privacy impact assessments
  • Compliance reviews against the IPPs or HIPRs
  • Compiling the information-related legislation that applies to your agency

PILLAR 02

Docs & frameworks

  • Privacy statements, guides, policies and training material
  • Privacy and security clauses for contracts
  • Information sharing MOUs and AISAs
  • Frameworks for assessing privacy, human rights, and ethics impacts

PILLAR 03

Operations & response

  • Ad hoc advice on issues as they arise 
  • Access and correction requests 
  • Privacy breaches and complaint responses
  • Public sector security obligations

02 – EXPERIENCE

Selected experience.

A handful of representative projects, anonymised as appropriate, many with a technology or digital government dimension.


CASE 01

PMAF

MATURITY

Privacy maturity assessment - PMAF

Conducted a privacy maturity assessment for a government department – surveying staff, reviewing policies, and producing recommendations to lift IPP compliance.


Role: External counsel, assessment lead

CASE 03

PRIVACY FRAMEWORK

HUMAN RIGHTS & ETHICS

Privacy framework for service design

Provided wide-ranging advice for a framework that assesses the privacy, human rights and ethics implications of proposed services and processes.


Role: External counsel

CASE 02

GOVERNMENT POLICY

PRIVACY

Policy on data protection and use

Provided substantial privacy law advice and drafting inputs for a government policy on data protection and use, in close consultation with internal team.


Role: External counsel, privacy law advisor

CASE 04

COPILOT

PIA

Copilot privacy impact assessment

Undertook a privacy impact assessment on an agency's proposed deployment of Microsoft 365 Copilot - surfacing risks and making recommendations to mitigate them.


Role: PIA lead

SEE MORE EXAMPLES ↓

ASSESSMENTS, MATURITY, AND ADVICE


  • Reviewed organisational privacy policies and agency compliance with the Privacy Act's information privacy principles
  • Reviewed, contributed to, and drafted privacy impact assessments
  • Assessed the privacy implications of generative AI
  • Advised on the privacy implications of machine-to-machine processing of personal information
  • Advised on whether technical changes to  government systems had privacy implications
  • Provided detailed advice on policy initiatives involving the collection and sharing of personal information for beneficial outcomes

POLICIES, PRIVACY STATEMENTS, GUIDES, AND TRAINING


  • Reviewed and updated a Crown entity's privacy statement and some of its internal privacy policies and processes
  • Prepared privacy guides for both public sector agencies and regulatory organisations
  • Prepared guidance for staff on the use and disclosure of student-related personal information
  • Drafted and amended privacy statements for multiple government and corporate websites
  • Delivered training for a Crown entity on Privacy Act 2020 implications
  • Delivered training for a government department on the Data Protection and Use Policy 

INFORMATION SHARING AND CONTRACTS


  • Advised on approved information sharing agreements under the Privacy Act and their associated processes and privacy impact assessments
  • Advised on and drafting privacy-centric contractual provisions
  • Negotiated contracts for an online consultation service to ensure Privacy Act compliance
  • Developed open data principles that recognise the importance of personal privacy and the potential risks of aggregating seemingly anonymised datasets
  • Developed and automated information sharing MOU templates

OTHER STATUTES AND INTERNATIONAL REGULATION


  • Collected, collated, and summarised statutory provisions enabling the collection, use, and sharing of personal information
  • Advised on relevant aspects of previous statistics legislation
  • Reviewed and redrafted agreements and privacy statements for GDPR compliance

I’ve worked with Richard a few times over the years … . He is outstanding in his understanding of personal information collection, use and sharing. This includes not only a superb grasp of privacy law, but also extends into the forest of overlapping laws and codes that modify or impact on the Privacy Act’s various elements.

DPUP Engagement Lead

SOCIAL WELLBEING AGENCY

03 – TOOLS I BUILT

Tools that speed up the work.

Two decades of privacy work, packaged into tools that handle the repeatable parts, increasing efficiency and enabling focus on the more complex elements. 


StopLookGo Privacy

Guidance on the Act, a library of specific legislative authorities, a range of assessment tools, and the ability to build the documents agencies need such as privacy statements, information-sharing MOUs, and data licence agreements.


"Richard’s ... StopLookGo [Privacy] produced a helpful preliminary report for us on some privacy issues we required advice on. It was an effective way for us to understand which areas needed priority, so we could make the best use of our time in the next steps.” 

PRIVATE SECTOR CLIENT, AGRICULTURE SECTOR 


Guides

Assessment tools

Document automation

Privacy automations in Contract Foundry

The Contract Foundry includes builders specifically for privacy statements, privacy clauses, information sharing MOUs, and other privacy-adjacent agreements. Same drafting standards I'd produce manually, generated in a fraction of the time it would otherwise take.


"With the information sharing MOU builder, I was able to build an MOU between a government department and a professional regulatory body rapidly, keeping costs down.” 


Privacy clauses

Privacy statements

Info sharing MOUs

Have a privacy matter on your mind?

Happy to jump on Teams or Zoom to talk it through. Just a 15-min chat to see if I'm the right fit.