Behind the curtain of legal professional privilege: lessons from Medibank v McClune

30/04/2026 Legal professional privilege (LPP) protects confidential information, documents and communications, between a lawyer and a client made for the purpose of providing legal advice or services. Issues surrounding LPP arise when documents address a wider-range of topics beyond just providing legal advice or services. This is the core issue in the recent case of …
Read more

RentTech on notice: OAIC determination signals tougher scrutiny for “excessive” renter data collection

30/04/2026 The Office of the Australian Information Commissioner (OAIC) has issued a landmark determination against a major rental technology (RentTech) platform, sending a clear message that is it is not acceptable to collect as much information as possible without a clear reason for doing so. OAIC found that the “2Apply” platform, a popular tool used …
Read more

Risks in broad FOI disclosure exemptions

23/04/2026 In the recent case of Bachelard v Australian Federal Police [2025] FCAFC 5, the Federal Court of Australia has reinforced the core principle of the act: the Australian right to access government documents under the Freedom of Information Act 1982 (Cth) (FOI Act) Background Journalist Michael Bachelard sought access to documents held by the …
Read more

How new AUSTRAC anti-money laundering obligations will impact our clients

21/04/2026 Australian law firms, including Grifin Legal, will be subject to mandatory anti-money laundering (AML) and counter-terrorism financing (CTF) obligations from 1 July 2026, marking a significant expansion of the country’s financial crime prevention regime. The new laws bring legal practitioners into line with banks and financial institutions that have long operated under similar requirements. …
Read more

Administrative Review Tribunal decision on Bunnings use of facial recognition technology

25/02/2026 A recent Administrative Review Tribunal (ART) decision on Bunnings Group Limited’s (Bunnings) use of facial recognition technology (FRT) has overturned some of the Privacy Commissioner’s findings in relation to the contravention of the Australian Privacy Principles (APP).   Departing from the Commissioner’s findings, the ART found that Bunnings lawfully collected the sensitive information of individuals entering its stores via FRT in accordance with APP 3.3 as …
Read more

AI and Employee Rights: what the recent agreement between Microsoft and Unions can tell us

06/02/2026 As workplaces continue to grapple with the emergence and implications of AI, Microsoft has announced a landmark Framework Agreement with the Australian Council of Trade Unions (ACTU), to ensure workers have a voice in how AI and other emerging technologies are implemented in Australian workplaces. The continuing improvements in AI capabilities has caused increased …
Read more

Don’t get swept away: Are you prepared for the OAIC compliance sweep?

12/01/2026 In December 2025, the Office of the Australian Information Commissioner (OAIC) announced plans to conduct its first-ever compliance sweep in January 2026. Australia’s privacy regulator will kick off the new year with a targeted review of businesses privacy policies to ensure that entities are meeting their obligations under Australian Privacy Principle 1 (APP 1). …
Read more

New AI Plan for the Australian Public Service

12/12/2025 On 12 November 2025, the Australian Government released the AI Plan for the Australian Public Service. The Plan aims to improve efficiency and productivity in the APS by substantially increasing its use of AI in the next 18 months. It includes 15 initiatives under 3 mutually reinforcing pillars (Trust, People, and Tools) which aim …
Read more

Breach of Australian Privacy Principle 11 in use of cloud-based database by wine wholesaler

10/11/2025 Recently, the Privacy Commissioner, Carly Kind found that Vinomofo Pty Ltd, an online wine wholesaler, interfered with the privacy of individuals whose personal information it held in its database. In December 2018, Vinomofo commenced a data migration project to update its system for managing customer data, which included migrating customers’ personal information to a …
Read more