Skip to main content

Sources last verified on 17 August 2026. Methodology

Role guide

Legal and privacy counsel

Legal usually interprets the framework for the organisation and drafts what users see. The obligations still bind the organisation as a whole, and much of the delivery sits with other functions.

How to read this page. The obligations belong to your organisation, not to a role or a sector. Everything here is practical emphasis: which official duties this audience usually leads or feeds into, with links to the official text. Finishing one function's work never makes the company compliant by itself.

Work your function usually leads

  • Notice contentRule 3, official text →

    The notice must stand alone, itemise the personal data and purposes, and point to withdrawal, rights and the complaint channel.

  • Verifiable consent design for children and guardiansRule 10, official text →

    Choosing a lawful verification approach for parents and guardians is a legal design decision before it is a technical one.

  • Child data exemption analysisRule 12, official text →

    Whether a Fourth Schedule child data exemption applies is conditional and needs legal judgment.

  • Research and statistics exemptionRule 16, official text →

    Processing necessary for research, archiving or statistics can sit outside the Act when the Second Schedule standards are followed; deciding that is a legal call.

Work your function usually feeds into

  • Breach communicationsRule 7, official text →

    The intimation to affected individuals must be plain and complete; legal usually reviews what security drafts.

  • Cross border transfer requirementsRule 15, official text →

    Transfer restrictions depend on government orders that legal tracks.

Tools for this role