Lockton is committed to protecting the privacy of internet users who visit our websites.
Lockton Companies Australia Pty Ltd (Lockton) is committed to providing you with the highest levels of client service. We are bound by the Australian Privacy Act 1988 (Privacy Act) and Australian Privacy Principles (APPs). Our aim is to support you and to ensure that we comply with the Privacy Act and APPs in providing our services, and also with best practices set out in the EU and UK General Data Protection Regulations (GDPR) where applicable.
You can obtain further information about Australia’s privacy regime from the website of the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au
Lockton is subject to significant regulatory requirements including many that require us to collect personal information about you in order to provide our services. Lockton believes that this Privacy Policy discloses the purpose for which we collect personal information from clients, and how we and our representatives use, store, disclose or otherwise handle your personal information, including sensitive information.
You should read this Privacy Policy in conjunction with our separate Cookies Notice (opens a new window).
The primary purposes for which we collect personal information are to provide insurance broking, risk advisory, claims advocacy and related services, administer our relationship with you, and comply with our legal and regulatory obligations. The nature of the information we collect depends on the services we provide and the circumstances in which we deal with you.
If you provide us with information that we have not asked for and taken no active steps to collect, and which we determine it would not be lawful and reasonable for us to collect, we will destroy or de-identify that information as soon as practicable.
In some circumstances you can deal with us anonymously or use a pseudonym if you prefer, for example, to make a phone enquiry to check our contact details. However, if we are required by or under an Australian law or court or tribunal order to collect your details or it is impractical for us to deal with someone whose identity we do not know, we will not be able to provide our services to you.
Automated decision-making takes place when an electronic system uses personal information to make a decision, or something that is directly related to making a decision, without human intervention. In Australia, automated decision making is regulated under the APPs in certain circumstances. These are if:
The APP entity has arranged for a computer program to make, or do a thing that is substantially and directly related to making, a decision
Where that decision could reasonably be expected to significantly affect the rights or interests of an individual, and
Personal information about the individual is used in the operation of the computer program to make the decision or do the thing.
Currently, automated decision making is not in use at Lockton. If Lockton introduces automated decision making to its Australian operations, this policy will be updated to contain information about:
The kinds of personal information used in the operation of computer programs
The kinds of decisions made solely by the operation of computer programs, and
The kinds of decisions for which a thing, that is substantially and directly related to making the decision, is done by the operation of such computer programs
Note that ‘Making a decision’ includes refusing or failing to make a decision, and that we must tell you about our automated decision making whether decisions we make are beneficial or adverse to you.
Lockton generally collects personal information directly from you, from publicly available sources (such as LinkedIn) or if you provide authorisation, from third parties holding that information. You can refuse authorisation to collect from third parties. We may also collect your personal information without your agreement if required or authorised by or under an Australian law or court or tribunal order, or in limited circumstances if it would be unreasonable or impractical to collect it from you.
Our main use of your personal information is to provide our services to you. We may also use personal information for a secondary purpose that you would reasonably expect that is related to advising you, such as arranging, renewing or administering insurance policies on your behalf, liaising with insurers and other service providers, processing and managing claims, maintaining our client records, complying with our legal and regulatory obligations, and improving our products and services.
In some circumstances we are required by law to collect unique identifiers, such as your tax file number, but we do not adopt such numbers as our own identifier in respect of you and your file. We do not use or disclose that identifier except in circumstances permitted by the APPs, which include if use or disclosure of the identifier is reasonably necessary for us to verify your identity for our activities and functions.
Your personal information may also be used in relation to direct marketing. For more information about this see the Website and marketing section below.
To give you advice that is appropriate and in your best interests, we sometimes need to collect and use sensitive personal and other information about you. Without your consent or unless required to we will not collect information about you that reveals your racial or ethnic origin, political opinions, religious or philosophical beliefs or affiliations, membership of professional or trade associations, membership of a trade union, details of health, disability, sexual orientation or criminal record.
We may also need to use sensitive information in relation to permitted general situations, in particular, when the information is necessary for the establishment, exercise or defence of a legal claim.
Lockton’s employees are obliged to respect the confidentiality of the personal information it holds about its clients.
The contractors and outsourcing companies that we use are also bound by obligations of confidentiality and must handle your personal information consistently with requirements of the Privacy Act and APPs. In line with modern business practices common to many financial institutions, and to meet your specific needs, we may disclose your personal information to the following types of entities:
insurance providers
compliance consultants
premium funders
temporary staff to handle workloads during peak periods
mailing houses
insurance reference bureaus and loss adjusters
your professional advisers, including your solicitor or accountant as authorised by you
your employer
information technology service providers (which may involve offshoring data when required)
government and regulatory authorities, as required or authorised by law, for example the Australian Securities and Investments Commission (ASIC)
another authorised representative of Lockton (if necessary)
a potential purchaser/organisation involved in the proposed sale of our business for the purpose of due diligence, corporate re-organisation and transfer for all or part of the assets of our business. Disclosure will be made in confidence and it will be a condition of that disclosure that no personal information will be used or disclosed by them
a new owner of our business that will require the transfer of your personal information
our financial and legal advisors (if necessary)
Some of our contractors and outsourcing companies may be located outside Australia, so we may transfer the personal information we collect about you to overseas jurisdictions. Those transfers are always made in compliance with APP requirements for cross-border disclosure of personal information. That is, before we disclose your personal information to overseas recipients, we will either take reasonable steps such as imposition of contractual obligations to ensure they do not breach the APPs (other than APP 1), or that they are bound by equivalent laws, or that you have given written consent and have been expressly informed of any resulting reduction in protections, or if required or authorised by law or in certain other permitted general situations.
Depending on the services being provided, we may disclose personal information to service providers and affiliated entities located in Australia, India, the United Kingdom, the United States, Singapore, New Zealand and other countries where our service providers operate. A current list of countries in which our overseas service providers are located is available on request.
We take seriously our obligation under APP 11 to take reasonable steps in all the circumstances to protect your personal information from misuse, interference and loss and from unauthorised access, modification or disclosure. These steps are both technical and organisational.
We store your personal information in your hard copy or electronic client files. Only authorised personnel who are subject to confidentiality requirements may access them. Lockton’s Information Security policy applies to everyone who works for Lockton and has access to our offices and systems. It contains detailed protocols and procedural requirements covering diverse areas involved in our business operations, such as email and mobile device security, internet security and credit card security.
We retain personal information only for as long as reasonably necessary and in accordance with our Information Security Policy. When we no longer need your personal information for any purpose for which we collected it, or the information is no longer required by any Australian law or court/tribunal order to be kept, we destroy it. Our Information Security Policy mandates specific retention periods for various categories of documents. Should you cease to be a Lockton client, we will securely maintain your personal information on-site or off-site for 10 years before it is destroyed.
We have put in place procedures including a Data Breach Response Process to deal with any actual or suspected data security breach, and we will notify you and applicable regulators or other entities of an actual or suspected breach where we are legally required to do so, including under the Privacy Act’s Notifiable Data Breaches scheme.
It is important to ensure that the personal information about you that we collect, use and disclose is accurate, up-to-date, complete and relevant. We take reasonable steps to ensure this, but your assistance is needed. Please update us with any changes to your personal information as soon as possible, and if you notice that some details we hold are incorrect, let us know. Changes should be communicated by contacting the Privacy Officer at compliance.au@lockton.com (opens a new window).
You can access your personal information that we hold, subject to certain exceptions permitted by law. We ask that you provide your access request in writing (for security reasons). We may need to ask you for specific information to help us confirm your identity before we respond. This is another appropriate security measure to ensure that your personal information is not disclosed to anyone who does not have the right to receive it.
Access to the requested personal information may include:
providing you with copies;
providing you with the opportunity for inspection; or
providing you with a summary.
If we need to apply charges in relation to providing access to you, we will disclose these charges to you prior to providing you with the information.
Exceptions that apply to our obligation to give you access on request are as follows:
if providing access would pose a serious threat to the life or health of a person;
if providing access would have an unreasonable impact on the privacy of others;
if the request for access is frivolous or vexatious;
if the information is related to existing or anticipated legal proceedings between us and would not be discoverable in those proceedings;
if providing access would reveal our intentions in relation to negotiations with you in such a way as to prejudice those negotiations;
if providing access would be unlawful;
if denying access is required or authorised by or under law;
if providing access would be likely to prejudice certain operations by or on behalf of an enforcement body or an enforcement body requests that access not be provided on the grounds of national security.
Should we refuse you access to your personal information, we will provide you with a written explanation for that refusal.
If we hold personal information about you, and you request correction of that information or we are satisfied that, in light of the purpose for which it is held, the information is inaccurate, out-of-date, incomplete, irrelevant or misleading, we must take reasonable steps to correct it and, on request, provide reasonable notification of the correction to any other APP entity to which the personal information was previously disclosed, unless impractical or unlawful to do so. If we refuse to correct your information and you request us to associate the information with notice that it is inaccurate, out-of-date, incomplete, irrelevant or misleading, we must take reasonable steps to make that notice apparent. We will not charge you in connection with correction of your personal information.
To respond to your access or correction request, we may need to ask you for specific information to help us confirm your identity and ensure your right to access or correct the information. This is another appropriate security measure to ensure that your personal information is not disclosed to any person who has no right to receive it.
When you visit our website, we may collect internet traffic data such as IP addresses from providers of tracking services. We do not use this tracking to directly identify you and we comply with the global Transparency and Consent Framework (TCF V2.2).
Lockton’s website uses cookies to provide you with a better user experience. Cookies also allow us to identify your browser while you are using our site – they do not identify you. For more information about cookies, view our Cookies Notice (opens a new window). If you do not wish to receive cookies, you can instruct your web browser to refuse them.
Our website may also provide links to third-party websites that collect your information. The use of your information by these third-party sites is outside Lockton’s control and we cannot accept responsibility for the conduct of these third-party organisations. Other websites are not subject to our privacy standards, so you should assess the privacy policies these websites display.
If any of our website content or marketing communications (see below) are suitable only for adults, we take reasonable steps to ensure that this content is available or provided only to recipients who are legally entitled to use or participate in the relevant product, service or event.
You may register with us via our website, through LinkedIn or during events to receive newsletters and other information. This information may be either factual or marketing in nature. By registering, you enable us to collect your name and email address and store it on our database. We take care to ensure that the personal information you give us via our website or LinkedIn or at events is kept secure. Security systems that protect your information include the use of firewalls and data encryption.
If you wish to update your registration details, please email your request to us at lockton.au@lockton.com (opens a new window). We will endeavour to meet your request within a reasonable period after the request is made. If you do not wish to receive any further information from us, you can unsubscribe.
Direct marketing is regulated in Australia by not only the Privacy Act and APP 7 but also by the Spam Act 2003 (Cth) (Spam Act) which regulates direct marketing using a ‘commercial electronic message’ such as an email, instant message, SMS or MMS. Voice calls by telephone are covered separately by the Do Not Call Register Act 2006 (Cth).
We will only send you commercial electronic messages with your express or implied consent. These messages will identify the Lockton team member or division that has sent you the message.
We also comply with the Spam Act and abide by the Spam Regulations 2021 (Cth) in relation to the unsubscribe facility that must be included in commercial electronic messages. If you want to use the unsubscribe facility that we provide, you are not required to:
Provide personal information in addition to the electronic address to which the message was sent; or
Log into an existing account or create a new one.
You may also withdraw any marketing consent previously provided to us at any time.
Lockton may operate closed circuit television (CCTV) cameras in the reception and entry areas of certain offices for security, safety and access control purposes. CCTV is not generally used in areas where visitors would reasonably expect a higher level of privacy. The presence of CCTV surveillance will be notified through signage where required by law.
When you visit our premises, CCTV may collect and record images of you and your activities in monitored areas. Depending on the circumstances, CCTV footage may constitute personal information under the Privacy Act.
We collect and use CCTV footage for purposes such as:
maintaining the security of our clients, employees, contractors, visitors and other individuals attending our premises;
protecting Lockton's premises, systems, information and property;
monitoring access to and from Lockton offices; and
preventing, deterring, identifying and investigating unlawful activity, misconduct, security incidents or safety incidents.
We may disclose CCTV footage to building managers, security providers, professional advisers, insurers, law enforcement agencies, regulators or other third parties where reasonably necessary for the purposes described above, where authorised or consented to by you, or where required or permitted by law.
CCTV footage is protected by appropriate technical and organisational security measures and access is restricted to authorised personnel and service providers who require access for legitimate business, security, legal or regulatory purposes. CCTV footage will be retained only for as long as reasonably necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law, or the footage is required in connection with an investigation, complaint, legal proceeding or regulatory inquiry.
If you have a complaint about our handling of your personal information, please contact our Privacy Officer:
Privacy Officer
Lockton Companies Australia Pty Ltd
Level 18, 45 Clarence Street Sydney NSW 2000, Australia
Email: compliance.au@lockton.com
We will acknowledge your complaint and aim to respond to it promptly and within a reasonable period. You also have the right to make a complaint at any time to the Office of the Australian Information Commissioner (OAIC), Australia’s privacy regulator.
OAIC contact details
For a phone enquiry:
1300 363 992
Monday to Thursday 10 am to 4 pm (AEST/AEDT)
For an online enquiry:
Submit an Enquiry form (opens a new window)
Post:
GPO
Sydney NSW 2001
Fax:
+61 2 6123 5145
This Privacy Policy is current as at September 2026 and is updated from time to time. Please check our website for updated versions.