1. About this policy
East Coast Lawyers Pty Ltd ATF East Coast Lawyers Trust trading as East Coast Injury Lawyers and East Coast Lawyers (we, us, our, or East Coast Injury Lawyers) recognises and values the protection of your privacy. We recognise that in using our website(s) (including www.eastcoastinjurylawyers.com.au, www.ecil.com.au and www.goldcoastpersonalinjurylawyers.com.au) (the Website) and the services offered to you as listed on our Website (the Services), you are entrusting us with your personal information, so we understand that you want clarity about how we manage that information.
The Firm recognises the importance of protecting privacy. We are bound by the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs).
This policy explains how we collect, hold, use and disclose personal information, including sensitive information; how you may access or correct information; how to make a privacy complaint; whether information is likely to be disclosed overseas; and how we use artificial intelligence (AI) and automated decision-making technology (ADM).
This policy applies to clients, prospective clients, witnesses, service providers, website users, job applicants and other people whose personal information we handle. It should be read with any collection notice, costs agreement, terms of use or specific consent request we give you.
Through this Privacy Policy we have aimed to be as clear, open and transparent as possible about these matters, but if you have any questions, do not hesitate to contact us at info@eastcoastinjurylawyers.com.au.
Please note that this Privacy Policy forms part of the Terms of Use document, which is displayed at the footer of our Website.
2. What information we collect and hold
The information we collect depends on your dealings with us and the nature of the legal matter. It may include:
- identity and contact information, including name, date of birth, address, telephone number, email address and signature;
- matter, claim and incident information, including statements, photographs, recordings, correspondence, evidence, legal advice and litigation documents;
- health and sensitive information, including medical history, diagnoses, symptoms, treatment, disability, capacity for work, rehabilitation, psychological information and medico-legal reports;
- employment, income, taxation, banking, superannuation, insurance and financial information;
- government-related identifiers, such as Medicare, Centrelink, workers compensation, driver’s licence, passport and tax file details, where lawful and necessary;
- information about family members, dependents, witnesses, employers, health practitioners and other third parties; and
- website and technical information, including IP address, device, browser, cookies, analytics and enquiry data.
We generally collect sensitive information with consent where it is reasonably necessary for our functions or activities, unless another exception under the Privacy Act applies. We only adopt, use or disclose government-related identifiers where permitted by law.
3. How we collect information
We usually collect information directly from you, including through enquiries, interviews, telephone calls, meetings, forms, emails, our Website and documents you provide. We may also collect information from:
- your representatives, family members or support persons;
- health practitioners, hospitals, rehabilitation providers and experts;
- employers, insurers, brokers, accountants, funders and superannuation providers;
- courts, tribunals, commissions, regulators, police and government agencies, including Medicare, Centrelink, the ATO, the NDIA and workers’ compensation authorities;
- witnesses, other parties, their lawyers and publicly available sources; and
- providers of technology, identity-verification, analytics, marketing and other service providers.
If you provide personal information about another person, you should ensure you are authorised to do so and, where appropriate, make them aware of this policy. If we receive unsolicited personal information, we assess whether we could have collected it under the APPs and destroy or de-identify it where required.
4. Why we collect, use and disclose information
We collect, use and disclose personal information where reasonably necessary for our legal practice and related functions for purposes including:
- assessing enquiries and potential legal claims;
- conducting conflict, identity, fraud and compliance checks;
- providing legal advice and legal services;
- conducting, investigating, negotiating and resolving legal claims and proceedings;
- obtaining medical, expert and other evidence;
- communicating with clients and other persons involved in a matter;
- dealing with insurers, barristers, statutory bodies, courts, tribunals, experts and other legal practitioners;
- establishing, exercising or defending legal or equitable claims;
- managing client files and our legal practice;
- billing, accounting, auditing and trust accounting;
- complying with our professional, regulatory and legal obligations;
- managing complaints and enquiries;
- improving our services, systems and business processes;
- maintaining the security and functionality of our systems;
- staff training and quality assurance;
- communicating information about our services where permitted by law; and
- other purposes which are reasonably necessary for our business or which are required or authorised by law.
We use or disclose information for the primary purpose for which it was collected. We may also use or disclose it for a related secondary purpose where you would reasonably expect this, with consent, or as otherwise required or authorised by law. We do not sell personal information.
5. Personal information via the Website
Most commercial websites use ‘cookies’, which are pieces of information that websites send to the browser and are stored in the computer hard-drive. Cookies make using the Website easier by storing information about matters such as your preferences on the Website. This allows the Website to be tailored to you for any of your return visits. Cookies will not be used to identify you personally.
If you would prefer not to receive cookies, you can alter your security settings on your web browser to disable cookies or to warn you when cookies are being used. However, by disabling the cookie function in your web browser you may impede your ability to use parts of the Website.
6. Your option not to provide your personal information
Providing us with your personal information is optional, but may be required for us to be able to provide you with the services we offer. When you provide us with your personal information, you are consenting to our storage, use and disclosure of that information as outlined in this Privacy Policy.
We may from time to time run competitions or offer additional benefits to you and we may ask you to provide us with your personal details for these purposes. Providing us with this information is optional to you. However, if you do not provide your personal information to us we may not be able to contact you or give you access to the additional benefits.
You may opt out of these additional communications at any time and can do so by emailing us at info@eastcoastinjurylawyers.com.au.
7. Who we may disclose information to
Where reasonably necessary or permitted by law, we may disclose personal and sensitive information to:
- insurers and claims managers;
- WorkCover and other statutory authorities;
- medical practitioners and health service providers;
- independent medical examiners;
- experts and consultants;
- employers;
- barristers and other legal practitioners;
- courts, tribunals and government agencies;
- process servers, investigators and other litigation service providers;
- accountants, banks, auditors and professional advisers;
- technology, telecommunications and information technology providers;
- cloud hosting and data storage providers;
- document management and practice management providers;
- telephone, call recording and transcription providers;
- artificial intelligence and automated technology providers and their approved subprocessors;
- cybersecurity providers and analytics providers;
- marketing and communications service providers;
- contractors and other service providers assisting us in operating our legal practice; and
- any other person or organisation where you have authorised the disclosure or the disclosure is required or permitted by law.
Information filed in court or used in a public hearing may become part of the public record. We take reasonable steps to require service providers to protect information and use it only for authorised purposes.
Under no circumstances will we sell, rent or licence your personal information onto any third parties for profiling or advertising purposes.
Should a third party approach East Coast Injury Lawyers with a demand to access your personal information, we will take reasonable steps to redirect the third party to request the information directly from you, wherever it is lawful and reasonable for us to do so.
If we are compelled to disclose your personal information to a third party we will take reasonable steps to notify you of this in advance, wherever it is lawful and reasonable for us to do so.
8. Artificial intelligence and automated technology
We use technology to assist us in providing legal services and operating our business. This may include cloud-based software, practice management systems, document management systems, electronic communications, telephone recording and transcription systems, videoconference recording and transcription systems, in-person recording and transcription systems, automated tools, automated decision making (ADM) technology and artificial intelligence (AI).
These technologies may be used to assist with activities such as:
- recording or transcribing communications;
- preparing file notes and summaries;
- reviewing, organising or processing documents and information;
- preparing or assisting with correspondence and other documents;
- legal and administrative research;
- managing workflows and tasks;
- improving administrative efficiency; and
- providing and administering legal services.
In personal injury matters, these tools may process health information, medical records, employment and financial information, claims records and other matter information. Information is used only for the relevant legal or administrative purpose. A responsible legal practitioner applies professional judgment and reviews material before it is relied on for legal advice.
Where personal information is processed using a third-party technology or AI provider, we take reasonable steps appropriate to the circumstances to protect that information and to ensure that our use of the technology is consistent with our privacy, confidentiality, professional and legal obligations.
We do not authorise third-party technology or AI providers to use client confidential information to train publicly available AI models.
9. Decisions using automated technology
We may use ADM and AI technology in connection with client intake, conflict checks, identity and compliance checks, matter administration, document review, fraud or security monitoring and communications. Depending on the process, the information used may include identity and contact details, matter details, documents, financial information and health information.
Our current approved legal-assistance technology tools support staff rather than independently providing legal advice, deciding whether a client should be accepted or declined, deciding liability, assessing claim values or appropriate settlement amounts. A human remains responsible for all legal decisions. If we introduce technology that makes a decision solely by automated means or performs a function substantially and directly related to making a decision that could reasonably be expected to significantly affect a person’s rights or interests, this policy will describe the kinds of information used and the kinds of decisions involved.
Where ADM and AI technologies are used, we will ensure that:
- Adequate security measures are in force to protect your personal and sensitive information;
- Personal and sensitive information is accurate and complete;
- You are informed if significant decisions that have a material effect on your matter are made via automated processors;
- You are provided with the ability to request that a human review be conducted on significant decisions that have been made by ADM and AI technologies;
- Regular reviews of ADM and AI technologies are conducted to ensure that the processes and procedures in place do not have an adverse impact on your matter and to ensure that your data remains secure.
You may contact our Privacy Officer to ask how automated technology was used in a process affecting you or to request human review where applicable. Users must not prompt AI to diagnose or independently determine a person’s health condition, impairment, prognosis or capacity.
10. AI safeguards
We have implemented the following AI safeguards:
- approved business accounts and providers are used, rather than public consumer tools, for client information;
- access is limited according to role, matter permissions and need;
- personal information is minimised to what is reasonably necessary for the task;
- confidential or sensitive information is not sent through public web search features;
- available models and subprocessors are risk-assessed and access may be restricted;
- provider commitments concerning security, retention and model training are reviewed; and
- AI outputs are checked for accuracy, relevance, privilege, confidentiality and legal correctness.
11. Recording and transcription
We may record or transcribe telephone calls, videoconferences or in-person meetings for file-note, legal-service, quality, security or training purposes. Participants will be notified before or at the time recording starts, or as soon as practicable afterwards. Recordings and transcripts may contain sensitive and privileged information and are protected accordingly.
12. Overseas disclosure and processing
Some service providers, subprocessors, experts, funders or other recipients may be located outside Australia or may process or support information from overseas. Countries may vary and can include the United States, United Kingdom, European Union, Canada, New Zealand, Singapore and other locations notified to you or identified in relevant provider documentation.
Before disclosing personal and sensitive information overseas, we take reasonable steps required by APP 8, unless an exception applies. These steps may include conducting due diligence, reviewing contractual privacy and security obligations, restricting access, minimising data disclosed and review of storage, processing and support locations. Some technology data may be stored in Australia while real-time AI inference or technical support occurs overseas. We use providers who ensure that the data is encrypted during transit and is not used to train the underlying Large Language Models employed by them.
13. Direct marketing
We may use your contact details to send information about legal developments or services where permitted by law. You may opt out at any time by using an unsubscribe facility or contacting us. Opting out of marketing does not stop service, security, legal or matter-related communications.
14. Security, retention and destruction
In our business, personal information may be stored both electronically and in hard-copy form. We are committed to keeping your personal information secure regardless of the format in which we hold it and we take all reasonable steps to protect your information from misuse, interference, loss, and unauthorised access, modification or disclosure.
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss or unauthorised access, modification or disclosure. Measures may include access controls, multi-factor authentication, encryption, logging, backups, security monitoring, staff training, incident response, provider due diligence and physical security.
We retain information for as long as required for legal, professional, insurance, taxation, limitation, dispute and business purposes. Client files are generally retained for at least seven years after a matter closes, and longer where required or appropriate, including for children, persons under a legal disability, trust records, deeds, wills, litigation or continuing obligations. When information is no longer required and no law or order requires retention, we take reasonable steps to destroy or de-identify it. Where deletion from backups is not immediately practicable, access is restricted and the information is put beyond ordinary use until deletion occurs.
No system is completely secure. If an eligible data breach occurs, we will assess and respond in accordance with the Notifiable Data Breaches scheme, including notifying affected individuals and the OAIC where required.
15. Data quality
The accuracy of the personal information we have requested from you is important to us. Should you suspect, or become aware of, that personal information we hold as a result of having requested it from you is inaccurate, out of date, incomplete or misleading, please contact our Privacy Officer at info@eastcoastinjurylawyers.com.au.
We will deal with all requests for correction of personal information as quickly as possible. Requests relating to a large amount of information, or information which is not currently in use, may require further time before a response can be given.
If we refuse to change the personal information as you request, we will provide you with reasons for our refusal, unless doing so would be unreasonable in the circumstances. We will also provide details of how you may make a complaint about our decision.
In the event that we agree to correct personal information about you, you may request that we take reasonable steps to give notice of the correction to any third party to whom we have disclosed the inaccurate, out of date, incomplete or misleading personal information.
16. Access and correction
In some cases, we will refuse to give you access to personal information we hold about you. This includes, but is not limited to, circumstances where giving you access would: be unlawful; have an unreasonable impact on other people’s privacy; prejudice an investigation of unlawful activity; reveal our intentions in relation to negotiations with you so as to prejudice those negotiations; prejudice enforcement related activities conducted by, or on behalf of, an enforcement body; reveal evaluative information generated within the East Coast Injury Lawyers organisation in connection with a commercially sensitive decision-making process.
We will also refuse access where the personal information relates to existing or anticipated legal proceedings and the information would not be accessible by the process of discovery in those proceedings. Further, we will refuse access where your request is frivolous or vexatious and where we reasonably believe that: giving access would pose a serious threat to the life, health or safety of any individual, or to public health or public safety; unlawful activity, or misconduct of a serious nature, is being or may be engaged in against East Coast Injury Lawyers and giving access would be likely to prejudice the taking of appropriate action in relation to that matter.
If we refuse to give you access we will provide you with reasons for our refusal, unless doing so would be unreasonable in the circumstances. We will also take reasonable steps to give you access in a way that meets your needs without giving rise to the reasons of our refusal. Further, we will provide details of how you may make a complaint about our decision.
17. Privacy complaints
If you believe we have mishandled personal information, please send a written complaint to our Privacy Officer with your contact details and a description of the issue. We will acknowledge the complaint, investigate it and respond within a reasonable period. We may ask for further information and will explain any outcome or proposed resolution.
If you are dissatisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or telephone 1300 363 992. Other external review rights may also apply.
18. Disposal of personal information no longer required
If we hold personal information about you and we no longer need that information for any purpose for which the information may be used or disclosed, we will take reasonable steps to destroy or de-identify that information unless we are prevented from doing so by law.
19. Contact us
If you have any concerns, complaints or questions about our Privacy Policy, or our privacy practises, please contact our Privacy Officer at info@eastcoastinjurylawyers.com.au.
20. Changes to this policy
We reserve the right to modify or amend this Privacy Policy at any time to reflect changes to law, technology or our practises. Should any significant amendments occur, notification will be provided by publication on the Website 14 days prior to the changes being implemented (the Notice Period) unless the circumstances of the amendments make it unreasonable to provide such a Notice Period. Your continued use after the Notice Period has lapsed indicates your consent to be bound by the modified and/or amended Privacy Policy.
For further information about privacy in general, please refer to the Office of the Australian Information Commissioner’s website http://www.oaic.gov.au.
Privacy Policy last updated on 14 September 2026.

Enter your details below and one of our specialists will contact you as soon as possible for a free, no obligation case review.