LEGAL

Privacy & Data Handling

How Transglobal Intel Net collects, uses, protects, and retains personal and client information across investigations, intelligence, risk advisory, due diligence, asset tracing, and lawful enforcement-support work.

DOCUMENT

Privacy & Data Handling

VERSION

1.0

STATUS

In force

EFFECTIVE

02 May 2026

1.0

Plain English summary. We collect, use, and store personal information so we can carry out investigations, intelligence, risk advisory, due diligence, asset tracing, and lawful enforcement-support work. We only collect what we need, only use it for the purpose it was given for, only share it with people who need it, and only keep it as long as is necessary. We follow the GDPR, the Australian Privacy Principles, and any other privacy law that applies. The detail below sets out exactly how.

Scope and applicability

1.1 This statement applies to personal information used by Transglobal Intel Net (the firm) in the course of investigations, intelligence, advisory, due diligence, asset tracing, and warrant, compliance, and enforcement-support work.

1.2 It applies whether information is provided directly by a client, lawfully obtained from third-party sources, generated by our own enquiries, or held in connection with prospective matters that do not proceed.

1.3 This statement is read alongside, and gives way to, the firm’s engagement letters, sponsored-engagement terms, and any applicable professional or regulatory obligations.

2.0

Lawful basis for processing

2.1 The firm processes personal information only where a lawful basis exists. The firm relies, as appropriate to the matter and jurisdiction, on: (a) the legitimate interests of the firm and its clients in conducting investigative, intelligence, and risk-advisory work; (b) the establishment, exercise, or defence of legal claims; (c) compliance with legal obligations; (d) the public interest in the prevention and detection of fraud, financial crime, and serious misconduct; and (e) consent, where consent is the appropriate basis.

2.2 For each engagement, the basis relied upon is recorded at intake under the firm’s permissible-purpose attestation procedure.

3.0

Categories of information processed

3.1 The firm may process: identity and contact information; corporate, beneficial-ownership, and registry data; transactional and financial information; litigation, regulatory, and enforcement records; sanctions and watchlist data; open-source and media information; structured data acquired under licence; observational information lawfully gathered in the field; and information provided by clients, counsel, and authorised counterparties.

3.2 Special-category information is processed only where strictly necessary to the matter and where an additional condition for processing is satisfied under applicable law.

4.0

Sources

4.1 Information is obtained from clients and their counsel; public registers and official sources; licensed commercial data providers; verified open-source channels; and the firm’s own lawful enquiries. The firm does not knowingly accept information sourced through unlawful means.

5.0

Storage, security, and access control

5.1 Client and matter information is held in controlled environments subject to access restriction on a strict need-to-know basis, multi-factor authentication, encryption in transit and at rest, and recorded access logging.

5.2 Physical material is held under equivalent controls. Removal of matter material from controlled premises is permitted only under recorded authorisation.

6.0

Cross-border transfer

6.1 The firm operates across multiple jurisdictions. Where personal information is transferred between jurisdictions, the transfer is conducted under an appropriate legal mechanism — including, as relevant, adequacy determinations, standard contractual clauses, intra-group transfer instruments, or binding obligations on counsel and counterparties.

7.0

Disclosure

7.1 Information is disclosed only: (a) to the client, on the matter to which it relates; (b) to counsel and authorised counterparties acting in the matter; (c) where required by law, court order, or binding regulatory direction; (d) where necessary for the establishment, exercise, or defence of legal claims; or (e) under explicit, recorded client instruction.

8.0

Retention

8.1 Matter information is retained for the period necessary to deliver the engagement, satisfy professional and regulatory obligations, and preserve evidentiary integrity. Default retention is seven years from matter closure unless a longer period is required by law, court order, or counsel direction. Records of permissible-purpose attestation are retained for the same period.

9.0

Rights of data subjects

9.1 Where applicable law affords data-subject rights — including rights of access, rectification, restriction, objection, and erasure — the firm honours those rights subject to the limitations recognised by that law. Limitations include the protection of legal privilege, the integrity of ongoing investigations, the rights and freedoms of others, and the firm’s obligations to clients, courts, and regulators.

10.0

Concerns and contact

10.1 Concerns regarding the firm’s handling of personal information may be raised in writing to the firm’s compliance address. Concerns engaging professional, regulatory, or ethical conduct may also be raised through the firm’s Confidential Reporting Channel.

Read in conjunction with: Standards & Governance · Terms of Engagement · Acceptable Use Policy.