Skip to content
MatterPath
How it worksLegal HelpFor law firmsAboutConsumer access
Law-firm sign inStart assessment →
Menu
How it worksLegal HelpFor law firmsAboutConsumer access
Law-firm sign inStart assessment →
  1. Home
  2. Legal Help Centre
  3. How MatterPath handles sensitive legal information

Privacy and trust

How MatterPath handles sensitive legal information

A practical explanation of how MatterPath limits collection, organises legal-matter information and gives consumers control before identifying details are disclosed to a selected firm.

Last reviewed
26 August 2026
Jurisdiction
Australia
Prepared by
MatterPath editorial team
Status
General information
General information only

MatterPath is not a law firm and does not provide legal advice. Using MatterPath does not create a lawyer-client relationship with MatterPath. Laws and procedures vary between Australian jurisdictions and may change. Speak with a qualified lawyer about your circumstances. Urgent deadlines may apply.

Information provided to MatterPath may not be protected by legal professional privilege.

Quick answer

The short version

MatterPath collects information needed to organise an assessment, produce a factual summary, support deterministic matching and operate the account. Legal-matter information can be sensitive, so the platform asks for separate active consent before collecting relevant sensitive information and again before identifying information is disclosed to a selected firm. Information entered into MatterPath is not automatically protected by legal professional privilege. MatterPath uses service providers and reasonable technical and organisational safeguards, but no online service can guarantee absolute security. Read the full Privacy Notice and current service-provider schedule for the legally operative detail.

Official context: Australian Privacy Principles

01

This guide explains the workflow, not the whole Privacy Notice

This guide is a plain-English overview of common privacy questions that arise when using MatterPath. It is not a replacement for the Privacy Notice, which explains the categories of information, purposes, disclosures, retention approach, privacy rights and complaint process in fuller detail. The service-provider schedule identifies current provider roles and any verified location information available to MatterPath.

Legal-matter information may reveal sensitive information, including health information, racial or ethnic origin, political or religious views, trade-union membership, sexual orientation or practices, biometric information used for identification, or a criminal record. It may also include personal information about children, witnesses, family members, opponents or professionals. The exact content depends on what the consumer chooses to enter.

MatterPath is operated by WD Ventures Pty Ltd and is not a law firm. Privacy obligations, confidentiality and legal professional privilege are different concepts. MatterPath applies its privacy controls to platform information, but using MatterPath does not itself create a lawyer-client relationship or make every communication privileged.

02

Collection and data minimisation

The Australian Privacy Principles require an organisation covered by the Privacy Act to collect personal information only where it is reasonably necessary for its functions or activities. Sensitive information generally requires consent unless a legal exception applies. OAIC guidance also treats proportionality and data minimisation as part of assessing what is reasonably necessary.

MatterPath's assessment asks structured questions to identify the legal category, jurisdiction, practical needs and matching preferences. A free-text answer should contain enough factual context to organise the matter, not every fact or document a future lawyer might eventually need. Avoid passport numbers, full account details, unnecessary health records, intimate material and unrelated third-party information.

A consumer can usually provide more detail directly to a selected firm after the firm has completed initial checks and provided a suitable channel. The fact that information is publicly available elsewhere does not mean MatterPath should collect it without regard to necessity, fairness and the person's reasonable expectations.

03

Separate consent for collection and disclosure

OAIC guidance says valid consent should be informed, voluntary, current and specific, and given by a person with capacity to understand and communicate it. Merely presenting a privacy notice does not necessarily establish consent to collect sensitive information. MatterPath therefore uses an active, separate consent step before relevant sensitive legal-matter information is collected through the assessment.

A second decision occurs before identifying information is sent to a firm. The consumer reviews the organised summary, chooses a firm and expressly authorises the identified disclosure. Consent is not bundled with starting the assessment, viewing a profile or receiving a suggestion. A firm does not receive identifying information merely because it participates or pays MatterPath.

The consent screen should identify what will be sent, to whom and for what purpose. Consumers should correct factual errors and remove unnecessary details where the workflow permits. If a person does not authorise disclosure, the identifying introduction payload should not be released through that workflow.

04

Summary, matching and consumer choice

Assessment answers are organised into a factual MatterPath summary. The consumer can review and correct context before matching. The summary is not legal advice, an assessment of merit or a prediction. Translation features are intended to assist understanding, but translated text should be checked against the English source where precise meaning matters.

Deterministic matching uses stated consumer requirements and verified professional-profile information. Relevant factors may include practice area, jurisdiction, service location, consultation mode, language and availability. Commercial payment must not override suitability. A recommendation reason should explain the matching factors without claiming that the firm is objectively best or that it will accept the matter.

The consumer chooses whether to proceed and which firm may receive identifying information. A participating firm then independently considers conflicts, professional scope, capacity and engagement requirements. A suggestion or authorised introduction does not make the firm the consumer's lawyer.

05

Disclosure payloads and document sharing

A privacy-minimised preview can help a selected firm decide whether the matter appears within its general service scope without exposing unnecessary identity details. Identifying information should be limited to the authorised payload and released only after the consumer's active choice. The exact workflow and any exception must be described consistently in the current Privacy Notice.

Documents can contain hidden metadata, signatures, identity numbers, children's information or facts about other people. Do not upload an entire file merely because it may eventually be relevant. Keep originals secure, use working copies where appropriate, and follow the selected firm's instructions about secure transfer after conflict and engagement checks.

Once information is disclosed to a selected independent law firm, that firm handles it under its professional and privacy obligations. MatterPath's Privacy Notice should explain the boundary between MatterPath and independent recipients. Consumer authorisation does not guarantee that the firm will accept the matter or that privilege applies to every pre-engagement communication.

06

Service providers and overseas processing

MatterPath relies on service providers for functions such as hosting, database and authentication, email delivery, payments and controlled artificial-intelligence features. The current service-provider schedule should identify each provider's role and the categories of information involved. Providers should receive only the access needed for the contracted function.

An Australian organisation can have obligations when personal information is disclosed to an overseas recipient. OAIC guidance on APP 8 explains a reasonable-steps and accountability framework with legal exceptions. Hosting, support access and sub-processors can make location analysis more complex than the provider's headquarters or the selected cloud region.

MatterPath should not claim that all information remains in Australia unless the full provider configuration and sub-processing chain have been verified. Where countries or processing locations have not yet been confirmed, the service-provider schedule should say so plainly and be updated after verification rather than guessing.

07

Security, retention and deletion limits

OAIC guidance requires reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. What is reasonable depends on the information, organisation, risks and available measures. MatterPath uses technical and organisational safeguards appropriate to the service, but no website, database, email or third-party system can promise complete security.

Useful safeguards include role-based access, server-side authorisation, encryption in transit, controlled secrets, audit records that avoid legal detail, secure development practices and provider review. Public descriptions should remain at a level that helps users understand protection without exposing operational detail that could increase attack risk. Security claims should be accurate, testable and reviewed when systems change.

Personal information should not be kept indefinitely merely because storage is available. MatterPath's full Privacy Notice describes its documented retention approach, including account, matter, consent, matching, introduction, billing, security and legal records. A deletion request may not require immediate deletion of every record where retention is authorised or required, needed for security, necessary to establish or defend legal rights, or technically subject to a defined backup cycle.

08

Access, correction, withdrawal and complaints

A person can use MatterPath's privacy-request process to ask for access to, correction of or deletion of personal information. Identity verification may be necessary before information is released or changed. Access and deletion rights can have lawful exceptions, and the Privacy Notice explains how MatterPath responds and communicates any refusal where required.

Consent can be withdrawn for future handling covered by that consent. Withdrawal does not necessarily reverse a disclosure already authorised, erase a law firm's independent record, or require deletion of information that may lawfully be retained. MatterPath should explain the practical effect of withdrawal at the point it is requested rather than promising that every copy can be recalled.

Privacy concerns should first be raised with MatterPath using the contact and complaint process in the Privacy Notice. The Office of the Australian Information Commissioner generally expects a person to complain to the organisation first. If the response is delayed or unsatisfactory, the person may be able to lodge a complaint with the OAIC.

Before entering or sharing sensitive information

Use this check to reduce unnecessary collection and make an informed disclosure choice.

  • ✓Read the collection notice and the current Privacy Notice
  • ✓Describe the legal issue factually without including unnecessary identity numbers
  • ✓Avoid unrelated health, financial, intimate, child or third-party information
  • ✓Review the generated summary and correct errors before matching
  • ✓Check the selected firm's identity, service details and recommendation reason
  • ✓Read the disclosure payload and confirm exactly what will be sent
  • ✓Use the firm's secure channel for documents requested after initial checks
  • ✓Do not assume information entered into MatterPath is legally privileged
  • ✓Review the current service-provider schedule for processing information
  • ✓Use the privacy-request process for access, correction, withdrawal or complaints

Privacy controls at key MatterPath stages

StageMatterPath controlConsumer check
Start an assessmentActive consent before relevant sensitive information is collectedRead the collection notice and enter only information needed for the assessment
Create a summaryStructured factual organisation with a consumer review stepCorrect factual errors and remove unnecessary third-party or identity detail
Calculate matchesDeterministic criteria separate from commercial paymentReview the reason given and independently check the professional profile
Select a firmSeparate, specific authorisation for the stated disclosure payloadConfirm the recipient and exactly what identifying information will be sent
Continue with a firmThe firm makes its own conflict, capacity and engagement decisionAsk for the firm's privacy, secure-document and engagement information
Exercise a privacy choiceDocumented access, correction, withdrawal, deletion and complaint processUnderstand identity checks and any lawful retention or refusal reason

Common questions

Frequently asked questions

Is information I enter into MatterPath legally privileged?

Not automatically. MatterPath is not a law firm and using the platform does not itself create a lawyer-client relationship. Privilege can depend on the communication, purpose, recipient and circumstances.

Does a law firm see my identity as soon as it appears in a match?

No through the described consumer workflow. You review the summary, select a firm and expressly authorise the stated identifying disclosure. Read the consent screen to confirm the recipient and payload.

Does MatterPath guarantee that my information is completely secure?

No online service can guarantee absolute security. MatterPath uses reasonable technical and organisational safeguards and reviews its controls, while explaining material limitations in its Privacy Notice.

Is all MatterPath information stored only in Australia?

Do not assume that. MatterPath uses service providers, and hosting, support and sub-processing locations can vary. Review the current service-provider schedule and Privacy Notice for verified information.

Can I withdraw consent after authorising a disclosure?

You can request withdrawal for future handling covered by the consent. Withdrawal may not reverse a disclosure already made, remove an independent firm's record or require deletion of information lawfully retained. Contact MatterPath through the privacy-request process.

How do I correct information or make a privacy complaint?

Use MatterPath's privacy-request and complaint process described in the Privacy Notice. MatterPath may verify identity before providing access or making changes. If a privacy complaint is not resolved, the OAIC explains when and how a complaint may be lodged with it.

Verified references

Sources and official help

These official resources were checked on 26 August 2026. Use the linked service for its latest information.

  1. Australian Privacy PrinciplesOffice of the Australian Information Commissioner
  2. Chapter B: Key concepts, including consent and sensitive informationOffice of the Australian Information Commissioner
  3. APP 3: Collection of solicited personal informationOffice of the Australian Information Commissioner
  4. APP 8: Cross-border disclosure of personal informationOffice of the Australian Information Commissioner
  5. APP 11: Security of personal informationOffice of the Australian Information Commissioner
  6. Lodge a privacy complaint with usOffice of the Australian Information Commissioner
General information only

MatterPath is not a law firm and does not provide legal advice. Using MatterPath does not create a lawyer-client relationship with MatterPath. Laws and procedures vary between Australian jurisdictions and may change. Speak with a qualified lawyer about your circumstances. Urgent deadlines may apply.

Information provided to MatterPath may not be protected by legal professional privilege.

These guides cannot determine whether a matter has merit, predict an outcome or guarantee that a law firm will accept instructions.

On this page
  • This guide explains the workflow, not the whole Privacy Notice
  • Collection and data minimisation
  • Separate consent for collection and disclosure
  • Summary, matching and consumer choice
  • Disclosure payloads and document sharing
  • Service providers and overseas processing
  • Security, retention and deletion limits
  • Access, correction, withdrawal and complaints
On this page
  • This guide explains the workflow, not the whole Privacy Notice
  • Collection and data minimisation
  • Separate consent for collection and disclosure
  • Summary, matching and consumer choice
  • Disclosure payloads and document sharing
  • Service providers and overseas processing
  • Security, retention and deletion limits
  • Access, correction, withdrawal and complaints
Start assessment →Browse all legal guides

Continue reading

Related legal guides

Choosing and preparingWhat to prepare before speaking to a lawyerRead guide →Choosing and preparingHow to choose a lawyerRead guide →Getting startedWhat type of lawyer do I need?Read guide →

Organise your next step

Describe your matter in a guided assessment.

Review your factual summary and decide which participating law firm, if any, may receive your information.

Start your MatterPath assessment →
MatterPath

A clearer first step when you need legal help. Organise what happened, understand the matching process and keep control of who receives your details.

MatterPath is operated by WD Ventures Pty Ltd (ABN 36 701 566 421). MatterPath is not a law firm and does not provide legal advice.

Get legal help

Legal Help CentreStart assessmentHow it worksConsumer access

For law firms

For law firmsLaw-firm sign in

Company and legal

AboutContactPrivacyService providersLegal archiveTermsConsumer termsLaw-firm termsDisclaimerAccessibility
A WD Ventures company

© 2026

Built for clearer, more considered legal connections.