Skip to content
Privacy

Privacy Policy

Effective date: 1 September 2026

Jocelen Griffiths Consulting is committed to respecting privacy and handling personal information responsibly, securely and with appropriate discretion.

This Privacy Policy explains how Jocelen Griffiths Consulting ("we", "us" or "our") collects, holds, uses and discloses personal information, and how individuals may contact us about their personal information or raise a privacy concern.

We seek to manage personal information consistently with applicable Australian privacy laws, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply to our activities.

1. About Jocelen Griffiths Consulting

Jocelen Griffiths Consulting is a principal-led strategic advisory practice providing strategic advice and support to executives, boards and organisations across areas including strategy, policy, stakeholder engagement, advocacy, communications, campaigns, organisational change and implementation.

In delivering this work, we may interact with clients, prospective clients, stakeholders, professional advisers, associates, contractors, suppliers and other individuals.

The nature of strategic advisory work means that some information entrusted to us may also be commercially sensitive or confidential. We treat those responsibilities seriously.

2. What personal information we may collect

The kinds of personal information we collect and hold will depend on the nature of our interaction with you and may include:

  • your name, email address, telephone number and other contact details;
  • your employer, organisation, position, professional responsibilities and business contact information;
  • information contained in enquiries, correspondence, meetings and other communications with us;
  • information about professional interests, responsibilities, stakeholder relationships or areas of expertise;
  • information relevant to an engagement, project, proposal or potential engagement;
  • records relating to events, meetings, consultations, stakeholder engagement or business development activities;
  • billing, payment and administrative information where relevant;
  • information about associates, contractors, suppliers and professional advisers;
  • information provided by applicants or prospective associates in connection with potential work opportunities;
  • information collected when you visit or interact with our website; and
  • other information that you choose to provide to us or that is reasonably necessary for our activities.

We do not seek to collect personal information that is unnecessary for our work.

3. Sensitive information

Some strategic advisory engagements may involve information that is regarded as sensitive information under Australian privacy law, including information about political opinions or associations, professional memberships or other matters afforded additional protection.

We will only collect sensitive information where it is reasonably necessary for our activities and where its collection is permitted by law, including where appropriate consent has been obtained.

The fact that our work may involve government, policy, advocacy or campaigns does not mean that we routinely collect sensitive information about individuals.

4. How we collect personal information

We may collect personal information:

  • directly from you through meetings, telephone calls, email, correspondence or other communications;
  • through our website, including information submitted through an enquiry or contact form;
  • in the course of providing advisory or consulting services;
  • through business development, stakeholder engagement, events and professional networking;
  • from a client or another organisation where the information is relevant to an engagement;
  • from referrals and professional contacts;
  • from associates, advisers, contractors or service providers;
  • from publicly available sources, including government publications, organisational websites, professional directories, media sources and professional networking platforms; and
  • where otherwise permitted or required by law.

Where practicable and appropriate, you may interact with us anonymously or using a pseudonym. In many professional and client-related dealings, however, it may not be practicable for us to work effectively without knowing your identity.

5. Why we collect, hold and use personal information

We may collect, hold and use personal information for purposes including:

  • responding to enquiries;
  • assessing and developing potential engagements;
  • providing strategic advisory and consulting services;
  • understanding client needs, operating environments and stakeholder landscapes;
  • undertaking research, analysis and strategic planning;
  • managing stakeholder engagement and professional relationships;
  • communicating with clients, stakeholders, associates and other professional contacts;
  • preparing proposals, reports, advice, briefings and other work products;
  • managing projects, meetings and engagements;
  • conducting legitimate business development activities;
  • maintaining professional contact and relationship information;
  • engaging and managing associates, contractors, advisers and suppliers;
  • administering our business, including invoicing, accounting, insurance and record keeping;
  • improving our services and business operations;
  • protecting our legal rights and managing risks;
  • meeting legal and regulatory requirements; and
  • other purposes reasonably related to the reason the information was collected.

Where appropriate, we may also use information for another purpose with your consent or where authorised or required by law.

6. Professional contacts and business development

As a professional advisory practice, we maintain relationships with clients, prospective clients, stakeholders and other professional contacts.

We may retain business contact information and information about professional roles, organisations, interests and previous interactions to help us manage those relationships and identify matters that may be relevant to our work.

We may occasionally contact professional contacts about our services, insights, events, developments or opportunities that we reasonably consider may be relevant to them.

Where applicable, direct marketing communications will provide an appropriate means to opt out of further marketing communications. We will respect requests not to receive such communications.

Electronic commercial communications will also be managed having regard to applicable requirements, including the Spam Act 2003 (Cth).

7. Disclosure of personal information

We may disclose personal information where reasonably necessary to:

  • our associates, contractors and specialist advisers working on an engagement;
  • professional advisers, including lawyers, accountants, auditors and insurers;
  • technology, information-management, communications and other service providers;
  • organisations assisting us with administration, accounting, website hosting, email, data storage or other business functions;
  • clients where the information is appropriately connected with an engagement;
  • government agencies, regulators, courts or other parties where authorised or required by law; and
  • other parties with your consent or where disclosure would reasonably be expected having regard to the purpose for which the information was collected.

We do not sell personal information.

Where associates or specialist providers assist with an engagement, we seek to ensure that information is handled consistently with the confidentiality and privacy requirements appropriate to that work.

8. Confidential and client information

Privacy and confidentiality are related but distinct obligations.

Our work may involve commercially sensitive information, strategic advice, internal organisational information and other confidential material that may not necessarily constitute personal information.

We handle confidential information with appropriate discretion and in accordance with applicable contractual, professional and legal obligations.

Access to sensitive client and project information should be limited to people who reasonably require it for the relevant work.

9. How we hold and protect personal information

Personal information may be held electronically and, where necessary, in physical records.

We take reasonable steps appropriate to the nature of the information to protect it from misuse, interference, loss and unauthorised access, modification or disclosure.

Measures may include:

  • access controls and passwords;
  • appropriate device and account security;
  • secure cloud and information-management services;
  • limiting access to people who require information for legitimate business purposes;
  • appropriate confidentiality obligations for associates and service providers;
  • secure disposal or deletion of information when appropriate; and
  • reviewing information-handling practices as the business and its technology systems evolve.

No system of electronic transmission or storage can be guaranteed to be completely secure, and individuals should exercise appropriate care when transmitting particularly sensitive information electronically.

10. Third-party and cloud service providers

We use reputable third-party technology and professional service providers to operate our business, including Microsoft 365 for email, productivity and document services, Xero and related accounting services, website hosting providers and professional advisers.

Some of these providers may process or store personal information outside Australia or may use overseas service providers in delivering their services. Where it is practicable to identify the countries involved and Australian privacy law requires us to do so, we will provide that information.

We seek to use established providers with appropriate privacy and security arrangements and will review our service-provider arrangements as the business grows and changes.

11. Website information and cookies

When you visit our website, certain technical information may be generated automatically, such as:

  • IP address;
  • browser and device information;
  • pages accessed;
  • date and time of access; and
  • other technical information normally generated in operating a website.

Our website may use essential technical functions or cookies required for its operation.

If we introduce analytics, advertising technologies or other non-essential tracking in the future, we will review this Privacy Policy and any associated consent or notification requirements before doing so.

At the date of this Policy, this section should not be taken as a statement that we use particular analytics or advertising technologies unless they have actually been implemented.

12. Third-party websites

Our website may contain links to third-party websites or services.

We are not responsible for the privacy practices, security or content of third-party sites, and individuals should review the applicable privacy information provided by those organisations.

13. Accessing and correcting personal information

You may contact us to request access to personal information we hold about you or to ask us to correct information that you believe is inaccurate, out of date, incomplete, irrelevant or misleading.

We may need to verify your identity before responding.

There may be circumstances in which access cannot be provided or must be limited. Where applicable, we will deal with such requests in accordance with relevant legal requirements and will explain any refusal where required.

14. Retention and deletion

We retain personal information for as long as reasonably necessary for the purposes for which it was collected, for legitimate business and professional purposes, and to satisfy legal, contractual, insurance, taxation and record-keeping requirements.

Where information is no longer required, we will take reasonable steps to securely destroy or de-identify it where appropriate and where we are not required to retain it.

15. Privacy incidents and data breaches

We take suspected privacy and information-security incidents seriously.

If we become aware of a suspected loss of, unauthorised access to, or unauthorised disclosure of personal information, we will assess the circumstances and take appropriate steps to contain and respond to the incident.

Where applicable, this includes complying with requirements under the Notifiable Data Breaches scheme.

16. Privacy questions and complaints

If you have a question, concern or complaint about privacy or the way we have handled personal information, please contact:

Jocelen Griffiths Consulting
Email: jocelen@griffithsconsulting.com.au

We will consider privacy concerns promptly and seek to respond within a reasonable period.

Where the Privacy Act applies and you are not satisfied with our response, you may have the right to make a complaint to the Office of the Australian Information Commissioner (OAIC).

Information about the OAIC and its complaints process is available through the OAIC website.

17. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • changes to our business or services;
  • changes to how we handle information;
  • changes to our technology and service providers; or
  • legal or regulatory developments.

The current version will be published on our website with its effective date.

We encourage people who interact with us to review the Policy periodically.