AML/CTF Collection Notice for customer due diligence Gionis Legal & Advisory Pty Ltd collects personal information from clients and other individuals where required or reasonably necessary for our obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), associated rules and guidance, and other laws that apply to our legal practice. This notice explains why we collect this information, how we use and disclose it, and what may happen if it is not provided. Why we need to collect your personal information 1We collect your personal information to comply with the ‘Customer Due Diligence’ requirements in the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act). This includes to: - establish and verify your identity before providing certain services to you or the person you are acting on behalf of; - assess and manage potential money laundering, terrorism financing, proliferation financing risks or related compliance risks associated with the provision of our services; - make reports required by law under the AML/CTF Act; and meet record keeping obligations under the AML/CTF Act. What information we may collect 2 Depending on the matter and the applicable legal requirements, we may collect information such as: - name, date of birth, residential address, contact details and occupation; identity documents, such as a passport, driver licence, Medicare card or other identification document; - information about directors, shareholders, trustees, beneficiaries, beneficial owners or persons authorised to act; - information about source of funds and source of wealth; information about the nature, purpose and background of the transaction or matter; - information required for sanctions, politically exposed person or other risk screening; - biometric information, such as a facial image or liveness check, where electronic identity verification is used; - any other information reasonably required for AML/CTF compliance. How we collect information 3 We may collect personal information directly from you, from your organisation, from someone authorised to act on your behalf, from public registers or databases, from government or regulatory sources, or from third-party verification and due diligence providers. 4 We may use InfoTrack or another identity verification, due diligence or AML/CTF compliance provider to collect, verify, process and store information on our behalf. This may include electronic identity verification, document verification, facial image or liveness checks, sanctions and politically exposed person screening, and other due diligence checks. 5 If electronic identity verification involves a credit reporting body or other external data source, we will seek your consent where required by law and may offer an alternative verification process where legally required. Who we may share your information with 6We use personal information for the purposes described above and for related legal, professional, regulatory and administrative purposes. 7 We may disclose personal information to: - identity verification, due diligence and AML/CTF compliance providers, including InfoTrack; technology, cloud storage, practice management, document management, accounting, archival and professional service providers; banks, financial institutions, counterparties, advisers, experts, agents, courts, tribunals, registries, regulators and government authorities where reasonably required for the matter; - AUSTRAC and other government agencies where required or permitted by law; other persons where you consent or where disclosure is required or authorised by law. 8 In some circumstances, we may be required to disclose information to AUSTRAC or another authority without your knowledge or consent. We may also be prohibited by law from telling you that such a disclosure has been made. 9 Some of our service providers may process, store or access personal information outside Australia, including where cloud, technology, verification, support or subcontracting arrangements involve offshore infrastructure or personnel. 10 We may also disclose personal information to overseas recipients where this is reasonably necessary for the matter or service we are providing, or where you instruct or authorise us to do so. 11 Where required by the Privacy Act 1988 (Cth), we take reasonable steps to ensure appropriate privacy, confidentiality and security protections apply. What happens if we cannot collect your information 12 If you do not provide the personal information we request, we may be unable to verify your identity, complete required due diligence, act for you, continue acting for you, complete a transaction, or provide certain legal services. Your privacy rights and our privacy policy 13 Our Privacy Policy for AML/CTF obligations contains further information about how we will handle your personal information and how you can access and correct your personal information. It also outlines how to lodge a complaint and how that complaint will be managed if you are concerned about how we handled your information. Date reviewed: 29 June 2026