These decisions are settled before a single system is designed: what stays inside your control, who signs before anything leaves, and the obligations each build is measured against.
Settled before anything is designed, so they are not traded away later when a deadline arrives.
A build reads from and writes back to the systems you already control, so no second copy of your client data lives anywhere else.
Each build carries a written rule for what is sent and what is withheld. Where a job does not need to know who the client is, it is not told.
Australian processing where your matters require it, settled and priced at the start. If a client contract, a government matter or your insurer imposes a location requirement, that requirement governs the build.
Every build stops and presents its work for approval. On screen, as a step that cannot be skipped.
Access is bounded by the user's existing permissions. It cannot open a matter they could not open themselves. Every action is logged with a time and a name against it.
Retention and destruction are decided in writing per build, because that is the half of the security obligation most often left undone.
Named plainly, because the wrong instrument is still in wide circulation and it changes the answer.
The plain-English version is on How we govern AI: what AI handles, what your people keep, and how every agent is tested to stop.
In a two-hour session we walk your own process step by step and score it the same way: what AI can take on, what a person must check, and what it should never go near. You leave with the one thing worth doing first, costed against your own numbers.
Book your AI ScanIt depends entirely on how the system is built. Six controls decide it: your existing systems stay the source of truth so no second copy of client data is created; only the minimum data needed leaves them; where processing happens is a design decision settled at the start; a named person approves anything before it reaches a client; the AI can only see what that user could already open; and retention and destruction are written down per build.
Any step where AI would perform an irreversible act itself, or make the final legal decision. Witnessing or signing a document, assessing testamentary capacity, authorising a release of trust funds, and the compliance sign-off itself. Every step of a process is scored before a build, and any step where AI would act irreversibly on its own is gated behind a named human who authorises each instance, or dropped from the build.
The 13 Australian Privacy Principles in Schedule 1 of the Privacy Act 1988 (Cth) are the live instrument, in force since 12 March 2014 and amended in December 2024. The older Information Privacy Principles and National Privacy Principles were repealed on that date, and the IPPs never applied to a private law firm at any point. Alongside the Act sit obligations it does not cover: the Solicitors' Conduct Rules, legal professional privilege, and the Notifiable Data Breaches scheme.
Australian processing where the firm's matters require it, settled and priced at the start rather than assumed afterwards. Where a client contract, a government or defence-linked matter, or the firm's insurer imposes a location requirement, that requirement governs the design. Where a job does not need to know who the client is, the data is de-identified before it leaves the firm's own systems.
No. The obligations attach to the firm, not to the supplier, and they depend on facts only the firm holds, annual turnover, the terms of its client engagements, its insurer's position and its own risk appetite. A supplier can describe its engineering controls and the reasoning behind them so the firm can form its own view. That is not legal advice and it is not a certification.