About

Two people, onshore, doing the unbillable work.

ComplyHub is a Melbourne privacy compliance consultancy. We work with Australian professional services businesses that came into scope of the Privacy Act through the AML/CTF reforms, and with businesses that want their privacy program to survive contact with a regulator.

Why we started it

The advice exists. The implementation doesn't.

When Tranche 2 commenced on 1 July 2026, a lot of good legal commentary was published very quickly. What wasn't published was a way for a six-person conveyancing practice to actually get from that commentary to a data map, a defensible retention schedule and a staff that knows what to do when someone emails the wrong attachment.

Law firms will do it, at a rate that makes sense for them and not for you. Software vendors will sell you a dashboard that assumes the program already exists. In the middle there was nothing, and that gap is what ComplyHub does.

We deliberately stay narrow. Privacy, for Australian professional services, delivered onshore. We'd rather be the obvious choice for a small number of professions than a general compliance shop that's vaguely relevant to everyone.

Who you'll deal with

You'll speak to a founder, every time.

Compliance and delivery

Founder

Runs the client work: discovery, data mapping, gap assessment against the Australian Privacy Principles, and the documents. Holds and is completing certifications from the International Association of Privacy Professionals in privacy program management and AI governance, with privacy technology in progress.

If you engage us, this is the person in the room and the person who writes your program. Not a junior, not a subcontractor.

Technical and security

Founder

Comes from an eCommerce operations background — systems, integrations, and the practical reality of where data actually ends up when a business grows faster than its processes. Currently completing CompTIA Security+ and IAPP privacy technology certification.

Handles the technical side of assessments: access controls, third-party integrations, and the parts of a data map that live in software rather than in a filing cabinet.

We list certifications as held or in progress, and we update this page when that changes. If a credential matters to your decision, ask us on the call and we'll tell you exactly where it sits.

The line we don't cross

We are not a law firm, and we're specific about what that means.

Interpreting whether a particular service you provide is a designated service under the AML/CTF Act, advising on your liability, or telling you what a court would do — that is legal advice, and we don't give it. We say so in the engagement letter before you sign anything.

What we do is everything downstream of that: documenting where personal information lives, assessing your handling practices against the 13 Australian Privacy Principles, writing the operational documents your business runs on, training your staff, and keeping the whole thing current as the rules change.

In practice this comes up two or three times in a typical engagement. When it does, we flag it in writing and refer you on. We'd rather lose a small piece of scope than have you rely on us for something we're not qualified to give.

Our own house

The questions we ask you, asked of us.

A privacy consultancy with a weak privacy program isn't worth hiring, so here are ours, in the same terms we'd expect from you. Our client work is delivered from Australia. We maintain a data map and retention schedule for our own business. Our website uses privacy-respecting analytics that don't track you across sites, and enquiry data is stored onshore.

Our privacy policy and collection notice set out exactly what we collect, why, where it's held and how long we keep it. If you find a gap in them, tell us — we'll fix it and thank you publicly.

Talk to the people who'd do the work.

Twenty minutes, no obligation, and no sales engineer in between. Tell us what your business does and we'll tell you what applies to it.