Security Information Policy

Purpose

Trust Law & More Limited is committed to protecting information belonging to the firm, its clients and third parties.

This policy sets out the principles Trust Law & More applies to the collection, use, storage, access, transmission and disposal of information and to the technology systems used in providing its services.

Trust Law & More recognises that, as a law practice, it holds information that may be personal, confidential, commercially sensitive or legally privileged. Appropriate information security is therefore an important part of both our professional obligations and the protection of our clients.

Scope

This policy applies to information held, accessed, transmitted, stored or processed by or on behalf of Trust Law & More, whether electronically, physically or through a third-party service provider.

It applies to all persons authorised to access Trust Law & More's information or information systems.

Information Security

Trust Law & More takes reasonable and proportionate steps to:

  • protect information against unauthorised access, disclosure, alteration, loss or misuse;

  • preserve the confidentiality and integrity of client and business information;

  • maintain appropriate availability of information and systems required for service delivery;

  • comply with applicable legal, regulatory, contractual and professional obligations;

  • maintain appropriate physical, electronic and communications security;

  • maintain appropriate backup, business continuity and recovery arrangements;

  • manage access to information according to the requirements of the person's role;

  • securely dispose of information when it is no longer required to be retained; and

  • identify, respond to and appropriately manage information-security and privacy incidents.

The security measures adopted will be appropriate to the nature and sensitivity of the information concerned and the risks reasonably associated with its loss, unauthorised access, disclosure or misuse.

Information Covered by this Policy

For the purposes of this policy, "information" includes:

  • client files and records;

  • personal information;

  • confidential and legally privileged information;

  • correspondence and communications;

  • financial and transaction information;

  • trust, estate and property records;

  • electronic documents and data;

  • paper-based records;

  • information contained in email, practice-management and other business systems;

  • information stored or processed using cloud-based services;

  • information accessed or processed through approved third-party technology providers;

  • audio, video and other electronic recordings; and

  • information generated, processed or assisted by approved artificial intelligence or automated technology.

This policy applies regardless of whether information is stored on systems owned by Trust Law & More or is hosted or processed by an approved third-party service provider.

Access and Authorised Use

Access to Trust Law & More's information and systems is restricted to authorised users.

Users are required to exercise reasonable care in accessing and using Trust Law & More's information and technology systems.

Where practicable, authorised users will have individual user credentials. Passwords, authentication credentials and security codes must not be disclosed to unauthorised persons.

Appropriate security measures, including multi-factor authentication where reasonably available and appropriate, are used to reduce the risk of unauthorised access.

Confidential, personal or privileged information must not be copied, transmitted or removed from an approved system without appropriate consideration of:

  • whether the use or disclosure is authorised;

  • the sensitivity of the information;

  • the risk of loss, unauthorised access or disclosure;

  • the security of the proposed method of transmission or storage; and

  • Trust Law & More's legal and professional obligations.

Cloud and Third-Party Technology Providers

Trust Law & More uses third-party technology and cloud service providers to support the operation of the practice and delivery of legal services.

Where client or business information is stored, transmitted or processed through a third-party provider, Trust Law & More takes reasonable steps, proportionate to the nature and sensitivity of the information involved, to consider the provider's privacy, confidentiality and information-security arrangements.

Third-party services must only be used for Trust Law & More information where their use has been approved by the firm.

Where information may be stored or processed outside New Zealand, Trust Law & More will have regard to its obligations under the Privacy Act 2020 and applicable professional obligations.

Artificial Intelligence and Automated Technology

Trust Law & More may use approved artificial intelligence-assisted and automated technology to support legal, research, drafting, administrative and business processes.

Use of artificial intelligence is subject to appropriate confidentiality, privacy, security and professional controls.

Trust Law & More considers the nature and sensitivity of information before providing information to an artificial intelligence or automated technology provider. Confidential, privileged or personal information must only be processed using technology approved by the firm and in circumstances consistent with Trust Law & More's legal and professional obligations.

Artificial intelligence-generated material is treated as an assistance tool rather than an authoritative source. Where appropriate, outputs are independently reviewed and verified before being relied upon or incorporated into legal work.

Responsibility for legal advice and legal services provided to clients remains with Trust Law & More.

More detailed requirements governing the use of artificial intelligence may be contained in Trust Law & More's internal policies and procedures.

Accuracy and Integrity

Trust Law & More takes reasonable steps to maintain the accuracy and integrity of information held within its systems.

Information relied upon for the provision of legal services will, where appropriate, be checked against authoritative records or source material.

Technology-assisted processing does not remove the requirement for appropriate professional judgement and review.

Information Storage, Backup and Recovery

Trust Law & More maintains appropriate systems and procedures intended to protect important business and client information against accidental loss or system failure.

Electronic information of continuing importance is stored or backed up in a manner appropriate to its significance and sensitivity.

Trust Law & More maintains reasonable arrangements for continuity of essential services and recovery of important information following technology failure, loss or other disruption.

Retention and Secure Disposal

Information is retained for as long as reasonably required for legal, professional, regulatory or business purposes.

When information is no longer required to be retained, Trust Law & More takes reasonable steps to dispose of it securely and in a manner appropriate to its sensitivity.

Information Security and Privacy Incidents

Any known or suspected loss, unauthorised access, disclosure, misuse or compromise of Trust Law & More information must be reported promptly to the person responsible for information security within the firm.

Trust Law & More will assess information-security and privacy incidents and take appropriate steps to contain, investigate and respond to them.

Where required, Trust Law & More will comply with applicable notification obligations, including those arising under the Privacy Act 2020.

Responsibility

Overall responsibility for information security within Trust Law & More rests with the firm's director or a person nominated by the director for that purpose.

Every person authorised to access Trust Law & More's information or systems is responsible for complying with this policy and for taking reasonable steps to protect information within their control.

Trust Law & More will periodically review its information-security arrangements, including the third-party technology services used by the practice, having regard to changes in technology, identified risks and applicable legal and professional requirements.

Questions or Concerns

If you have any concerns about the way Trust Law & More secures information, or have any questions about this Security Information Policy, please contact:

Deeanah Winders
Trust Law & More Limited
deeanah@trustlawmore.com
+64 9 875 7111

This Security Information Policy may be amended from time to time to reflect changes in Trust Law & More's practices, technology, legal requirements or information-security risks.

Last updated: August 2026