Legal Firm Privacy Act IT Compliance Perth

What Perth law firms need to know about Privacy Act IT obligations, and the controls DM1 implements to help you meet them.

Talk to DM1 TodayView Our Services

Privacy Act Obligations for Perth Law Firms

Law firms in Western Australia handle sensitive personal and legal information subject to the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and professional conduct obligations. Legal practices have heightened obligations around confidentiality, access control, and breach notification.

A change lands on law firms from 1 July 2026. Anti money laundering obligations now extend to lawyers and conveyancers for certain services, with AUSTRAC enrolment open since 31 March 2026. Where a firm becomes a reporting entity, the Privacy Act applies to those activities regardless of the firm's turnover, so a small practice that previously sat under the exemption may no longer sit outside it entirely.

Firms also carry exposure through their suppliers. Practice management platforms, e-conveyancing services, outsourced typing and document services and cloud storage providers all hold client information, and an obligation to protect it is not discharged by handing it to somebody else. See third party and supplier risk for what the courts have said about relying on a third party.

DM1 is an IT provider, not a legal adviser. This page describes the IT controls Perth law firms should have in place. For guidance on legal and professional obligations, consult your legal practice's professional indemnity insurer or the Law Society of Western Australia.

IT Controls for Privacy Compliance in Legal Practices

"Client file access restricted to need-to-know"

Matter files in SharePoint should only be accessible to the fee earners and support staff working on that matter. DM1 configures SharePoint permissions and access controls for legal file management.

"Email encryption for sensitive client communications"

Client communications may contain privileged and commercially sensitive information. DM1 configures Microsoft Purview sensitivity labels and encryption for confidential email.

"MFA on all accounts, especially with remote access"

Law firm accounts are high-value targets. MFA is mandatory. DM1 enforces MFA across all Microsoft 365 accounts and blocks legacy authentication protocols.

"Secure external file sharing with clients and counsel"

Sharing documents externally should be controlled. DM1 configures SharePoint external sharing with expiring links, access restrictions, and audit trails for all external shares.

"Audit logging for all document access"

In the event of a breach or a dispute over access, you need to know who accessed what and when. DM1 enables Microsoft Purview audit logging with extended retention.

"Device encryption across all lawyer and staff devices"

Laptops leaving the office must be encrypted. BitLocker is configured and enforced by DM1 through Intune compliance policies.

How DM1 Helps Perth Law Firms Manage IT Compliance

1

IT Security Assessment

DM1 reviews your firm's current Microsoft 365 and device configuration against the controls expected for a legal practice.

2

Implement Priority Controls

DM1 deploys MFA, Conditional Access, document access controls, BitLocker encryption, and audit logging, in order of risk priority.

3

Ongoing Management and Reporting

DM1 maintains controls, monitors for anomalies, and provides documentation of your IT security posture for professional indemnity insurance requirements.

What DM1 Finds at Legal Practice Onboarding

DISCOVERED DURING DM1 NEW CLIENT ONBOARDING

Matter files accessible to all staff, no matter-level permissions

A Perth law firm's SharePoint had all matter files accessible to every staff member in the firm. DM1 restructured the SharePoint architecture with matter-specific permissions aligned to the fee earners assigned to each matter.

DISCOVERED DURING DM1 NEW CLIENT ONBOARDING

Client documents sent as unencrypted email attachments as standard practice

A Perth firm was routinely sending confidential client documents as standard unencrypted email attachments. DM1 configured Microsoft Purview sensitivity labels and trained staff on using secure sharing links instead.

DISCOVERED DURING DM1 NEW CLIENT ONBOARDING

Zero Conditional Access policies, entire tenant accessible from anywhere

A Perth law firm had no Conditional Access policies. Any lawyer's account, once compromised, gave full access to all client files from any device worldwide. DM1 applied a full Conditional Access baseline within the first session.

This page provides information about IT controls relevant to privacy compliance for law firms. It does not constitute legal advice. Law firms should consult qualified legal advisers and the Law Society of Western Australia for guidance on their specific obligations.

Get Your Law Firm IT Controls Right

DM1 implements IT security controls for Perth law firms. Call (08) 6202 6012 to discuss your current setup.

Contact DM1 Today(08) 6202 6012
Need IT help? Chat with us
DM1
DM1 Assistant
Perth IT Support Guide
Scroll to Top