Helios Salinger

  • About
    • About Salinger Privacy – now Helios Salinger
    • Meet our team
    • Work with us
    • Videos, Podcasts and Media Mentions
    • Privacy Awareness Week
  • Consulting
    • Overview – Our Consulting Services
    • Privacy Impact Assessment
    • Privacy Maturity Assessment
    • Privacy by Design advice
    • Privacy Compliance and Gap Analysis
    • Algorithmic Impact Assessment
    • Re-identification Risk Assessment
    • Data ethics
    • Privacy Helpdesk
  • Training
    • Overview – Our Training Services
    • Privacy Compliance Training
    • Privacy Professionals Training
    • All Online Modules
    • Training Calendar
    • Public Courses and Workshops
    • In-house Privacy Training and Workshops
    • Webinars
    • IAPP Certifications
    • Training Advisory Services
    • Login
  • Resources
    • Overview – Our Resources
    • THE PRIVACY PULSE
    • Privacy Act Reforms
    • Compliance Kits
    • Resources on key privacy topics
    • Free Handbook
    • Newsletter
    • Login
  • Case Study
  • Blog
  • Calendar
  • Contact
  • Compliance Kits
    • For Business & Non-profits
    • For Peak Bodies
    • For Australian Government
    • For NSW Public Sector
    • For VIC Public Sector
    • For QLD Public Sector
    • For WA Public Sector
    • Login

Who We Are

Alex Kotova – Principal Consultant – Privacy

Alex has developed her privacy expertise through roles across multiple industries, including banking, retail, hospitality, gaming and health insurance.

At Salinger Privacy, Alex has led Privacy Impact Assessments and privacy compliance reviews with a special interest in sensitive information holdings, including biometric information, where she has delivered practical advice on privacy compliance and social licence considerations.

Alex has also advised on the drafting of internal policy and procedure documents, always ensuring she is up to date with regulatory expectations on the drafting of privacy governance documents and breach response plans.

Alex has particular expertise in applying privacy principles to the rapidly moving technology landscape, including the implementation, use and governance of expert systems (including artificial intelligence, machine learning, and algorithms) and other emerging technologies.  She has advised extensively on third-party software, complex data flows, and data sharing arrangements.  She has a special interest in the operation of data ecosystems, including AdTech and data brokerage.

With her extensive experience in in-house roles, Alex brings to her clients a solid understanding of how privacy risk fits into broader organisational risk profiles and project management activities, to ensure privacy risks are identified and mitigated without disrupting existing risk management processes.  She excels at developing a pragmatic understanding of our clients’ business operations and objectives to provide tailored and relevant advice on the practical application of privacy principles; the suitability and potential uplift of existing controls; and preparedness for upcoming regulatory changes.

Alex is able to offer advice at all stages of project delivery, including Privacy by Design at the inception of projects, and remediation advice for previously delivered initiatives, systems and processes.  She can also advise on the development of policies, procedures and frameworks to enable and support the privacy function, providing governance for its operation in a broader risk management context and uplifting compliance maturity.

In addition to offering clients practical advice, Alex has a keen interest in policy and research, particularly the future of privacy in Australia and its ever-growing intersection with technology.  Alex led Salinger Privacy’s response to the Privacy Act Review Final Report, and has presented at the OVIC Victorian Privacy Network Meeting to talk about what we can expect in 2024 in the privacy regulatory, legislative and technological space.

Alex holds a Bachelor of Laws / Bachelor of Arts, a Graduate Diploma of Legal Practice and was admitted as an Australian Lawyer in Victoria in 2015.  She is also a member of the IAPP, a Certified Information Privacy Manager (CIPM), and Certified Information Privacy Professional – Europe (CIPP/E).  In 2024 Alex was recognised as an industry veteran by the IAPP with the designation of Fellow of Information Privacy (FIP).

Andrea Calleia – Director, Learning – Privacy

Andrea has extensive experience in the learning and development field, and has specialised in privacy training since 2003 when she managed the privacy education program for the NSW Privacy Commissioner’s Office.  Since joining Salinger Privacy in 2008 Andrea has managed our e-learning privacy training program, and delivers most of our face to face training.  She has developed and delivered customised privacy training on behalf of clients including QANTAS, Sage Software, the Office of the Australian Information Commissioner, and PRAXIS Australia.  Andrea has also designed bespoke training solutions for professional bodies like the AMA and IAB Australia, for their members.

Andrea is consistently rated “5 out of 5” by our training participants and has been described as “excellent and engaging”, “enthusiastic, clear and effective”.  She developed our various small group programs such as Privacy Officer Essentials, which have been described by participants as “top notch”, “practical and informative” and “effective for all participants coming from varied organisations”.  Andrea also delivers our certification training programs such as AIGP and CIPM on behalf of the International Association of Privacy Professionals (IAPP).

Andrea served four years on the IAPP’s ANZ Advisory Board from 2020-2023, to promote and serve the privacy profession in Australia and New Zealand.

Andrea holds a Bachelor of Arts majoring in Education and Human Resources, and a Certificate IV in Training and Assessment.  As an alumni of the University of New South Wales, she is a Mentor for students specialising in the fields of Human Resources and Learning and Development.  Andrea is a Certified AI Governance Professional, a Certified Information Privacy Professional – Europe (CIPP/E), Certified Information Privacy Manager (CIPM), a Certified Information Privacy Technologist (CIPT), a Certified Practitioner of Human Resources with the Australian Human Resources Institute, a Fellow of the Australian Institute of Training and Development (AITD), a member of the IAPP, and a member of the Australian Privacy Foundation.  In 2021 Andrea was recognised as an industry veteran by the IAPP with the designation of Fellow of Information Privacy (FIP).

Joanne Funtanilla – Client Services Manager – Privacy

Joanne keeps Salinger Privacy running smoothly.  As well as book-keeping, Jo looks after our subscribers and suppliers, and makes sure our website and monthly newsletter look fabulous.

Melanie Casley – Principal Consultant – Privacy

Melanie has deep experience in the application of privacy laws, having worked in the field since 2002, across both regulatory and advisory capacities.

At Salinger Privacy Melanie has led Privacy Impact Assessments into complex, multi-jurisdictional projects, such as a project to develop a real-time national information-sharing system for child protection, and data linkage and analytics projects in the health and disability sectors.

Other notable engagements include Mel’s development of a framework for privacy management for the Queensland Government’s Unify program, along with a series of seven PIAs on different aspects of the Unify program.  The Unify program is a four-year project to replace legacy client-management systems and improve information sharing and collaboration across the social services and justice sectors, led by the Department of Child Safety, Youth and Women, in partnership with the Department of Youth Justice.

Mel has also conducted privacy compliance reviews for clients needing a health check of their existing operations, or PIAs of particular projects, across sectors as diverse as government service delivery, manufacturing, disability care and education services.

Mel has also been seconded to Rio Tinto’s Global Data Privacy Team to assist with the completion of PIAs and a range of data privacy advices spanning Rio Tinto’s world-wide operations.  At Rio Tinto, Mel worked closely with the existing Data Privacy Team, Rio Tinto’s Global Cyber Security Team, broader Information Security and Technology members and other key business operations including Procurement, Human Resources and Exploration operations based in Australia, New Zealand, Canada, Utah, France, Singapore, Serbia, Kazakhstan, India, Zambia and Mongolia.  Each of these PIAs required Melanie to use Rio Tinto’s existing risk management platform, Global Data Privacy Standard, local data privacy laws, and rely on local knowledge of Rio Tinto staff to develop her advice.

Mel has previously served as Manager of the Information and Privacy Unit in the Victorian Department of Justice and Regulation (now known as the Department of Justice and Community Safety), overseeing the compliance of both the Department, and statutory agencies within the Justice portfolio, in relation to privacy and related laws.  She has also managed the secretariat functions for the Justice Human Research Ethics Committee, and coordinated a Whole of Victorian Government approach to privacy governance and policy.  Prior to her role with the Victorian Department of Justice and Regulation, Mel performed a number of policy, training and compliance roles with the Office of the Victorian Privacy Commissioner (now known as OVIC).

Melanie is also the editor of the privacy law section of the Fitzroy Legal Service’s Law Handbook, and sits on a Human Research Ethics Committee for Macquarie University.

Melanie holds a Bachelor of Laws, a Bachelor of Arts, and a Graduate Diploma of Educational Psychology. She was admitted as a Solicitor of the Supreme Court of Victoria in 2001.

Mel is also an accredited mediator, a member of the IAPP, a Certified Information Privacy Manager (CIPM), Certified Information Privacy Technologist (CIPT) and Certified Information Privacy Professional – Europe (CIPP/E).  In 2022 Melanie was recognised as an industry veteran by the IAPP with the designation of Fellow of Information Privacy (FIP).

Justin Frank – Principal Consultant – Privacy

Justin is an experienced privacy advisor, with qualifications in both technology and law.

Justin has experience at a senior level, in ensuring compliance with State and Federal privacy laws and related statutory regimes, particularly in assisting stakeholders to understand and navigate their obligations.  Justin prides himself on taking a proactive and pragmatic approach to privacy, reflecting his belief that organisations are best served by implementing privacy solutions that are compliant and mirror best practice, with a view to the evolving regulatory environment.  Justin combines his past experience with technology and the law to provide understanding, practical advice, guidance and comprehensive solutions.

At Salinger Privacy Justin has offered his expert advice to government and non-government clients, across sectors as diverse as medical research, local councils and law enforcement.  Justin holds current national security clearance, of value to our clients with particularly sensitive data holdings.

Justin has previously served as Associate Director in the Global Privacy Office of National Australia Bank (NAB), and as a privacy and FOI specialist lawyer with a Commonwealth regulatory agency.  Justin has also held numerous positions within the Victorian and Commonwealth public service and worked in technology roles in the retail and telecommunications sectors, including as a Senior Systems Engineer at Coles Myer.

Justin holds a Bachelor of Science, Bachelor of Laws with Honours, Master of Laws, and Graduate Diploma of Legal Practice.  Justin was admitted as an Australian Lawyer in Victoria in 2015.  He is a member of the IAPP.

Anna Johnston – Partner – Privacy

As our Founder and Principal, is one of Australia’s most respected experts in privacy law and practice.

With her qualifications in law, public policy and management, and over 30 years’ experience in legal, policy, research and consulting roles, Anna brings a breadth of perspectives and a wealth of experience to dealing with our clients’ privacy and data governance challenges.

Since establishing Salinger Privacy in 2004, Anna has provided advice on managing privacy risks to clients including tech start-ups, established businesses and government agencies.  She has conducted Privacy Impact Assessments on large and highly complex cross-jurisdictional projects for government including on the launch of the NDIS and the design of the My Health Record scheme.  Her private sector clients cross the economy, including the health, banking, human services, education, media, pharmaceutical, technology, insurance and professional services sectors.

Anna’s advice on data ethics and the application of privacy design strategies to complex data linkage projects has assisted clients including at the establishment of the NSW Centre for Education Statistics & Evaluation and the Victorian Centre for Data Insights.  She has also guided clients grappling with privacy and data management issues in the research and data analytics space across non-profit medical research institutes, for-profit data analytics companies, health service providers, universities and governments conducting multi-agency research and evaluation projects.

Anna’s influential and widely-read Salinger Privacy blogs have been quoted in the robodebt royal commission, prompted reforms to NSW privacy laws and a boycott of the 2016 Census, won awards for privacy writing, and introduced a new concept – individuation – into the privacy lexicon.  She also writes about privacy law and practice for publications including the Law Society Journal.  In 2022 Anna presented as a guest lecturer in Data Privacy Law for the Faculty of Law and Justice at UNSW, and was appointed to Xero’s Responsible Data Use Advisory Council.

As the former Deputy Privacy Commissioner for NSW, Anna also knows the regulator’s perspective.  Since establishing Salinger Privacy, she has also been commissioned to write privacy guidance publications, and deliver presentations and training, on behalf of other regulators including the Australian, NSW and Victorian Privacy Commissioners.  Given the depth of her experience in the sector, Anna is known as ‘the’ expert on NSW privacy laws.  She has read and annotated hundreds of NSW cases for our ‘PPIPA in Practice’ guide, and from 2001 to 2023 provided a pro bono caselaw update to NSW privacy practitioners at their quarterly meetings.  Anna also authors most of our range of guidance publications.

Anna has been called upon to provide expert testimony before various Parliamentary inquiries, the Productivity Commission and the European Commission, spoken at numerous conferences, and is regularly asked to comment on privacy issues in the media.  She is a lifetime member of the Australian Privacy Foundation, a member of the International Association of Privacy Professionals (IAPP) since 2008, and in 2019 was recognised as an industry veteran by the IAPP with the designation of Fellow of Information Privacy (FIP).  In 2024 Anna was appointed as a Westin Emeritus Fellow by the IAPP.

In 2024 Anna was appointed by the OECD to a global expert group on AI, Data and Privacy, to advise on using data protection law and privacy considerations to help build trustworthy AI.  In 2023, Anna was appointed a Senior Fellow, Global Privacy of the Future of Privacy Forum in Washington DC, in recognition of her “thought leadership and extraordinary ability to convey the state of play and foresight of data protection and privacy law developments in Australia”.

Anna has also been honoured for her ‘exceptional leadership, knowledge and creativity in privacy’ with the Vanguard Award, one of five privacy professionals recognised globally by the IAPP in 2022, whose pioneering work is helping to shape the future of privacy and data protection.  While her day-to-day work involves assisting clients to develop innovative approaches to privacy protection, the Vanguard award was bestowed in reflection of Anna’s contributions to the privacy profession, and to the protection of privacy for the benefit of all.  In particular, the award recognised Anna’s contributions in a voluntary capacity over 20 years, including both formal and informal advocacy on key issues, multiple pro bono advisory positions, and knowledge-sharing through speaking and writing about privacy.  Her passionate pursuit of law reform to improve protection against digital harms was called out in particular.

Anna’s pro bono advisory, advocacy, academic and editorial positions have included:

  • Member of the OECD.AI global expert group on AI, Data and Privacy, 2024 to date
  • Westin Emeritus Fellow at the IAPP, 2024 to date
  • Senior Fellow, Global Privacy at the Future of Privacy Forum, 2023 to date
  • Member of the Responsible Data Use Advisory Council, Xero, 2022-2023
  • Visiting Scholar at the Research Group on Law, Science, Technology and Society of the Faculty of Law and Criminology of the Vrije Universiteit Brussel (VUB), 2018
  • Advisory Board Member for the EU’s STAR project, to develop training on behalf of European Data Protection Authorities, 2017 to date
  • Member of the Asian Privacy Scholars Network (APSN), 2017 to date
  • Editorial Board Member, Privacy Law Bulletin, 2010-16
  • Advisory Committee Member, the Australian Law Reform Commission’s Inquiry into the Invasion of Privacy, 2013-14
  • Board member, the International Association of Privacy Professionals, Australia & New Zealand, 2010-11
  • Advisory Committee Member, the Australian Law Reform Commission’s expert advisory group on health privacy for the Review of the Privacy Act, 2006-08
  • Project Team Member, University of New South Wales’ Interpreting Privacy Principles project, 2006-09
  • Campaign Director, NoIDCard, the successful campaign against the proposed Access Card, 2006-07
  • Chair of the Australian Privacy Foundation, 2005-06; Member of the International Committee 2018 to date
  • Consumer Representative Member, National E-Health Transition Authority’s Consumer & Clinician Forum, 2005-06
  • Primary Author, Australian country reports for Privacy International’s Privacy and Human Rights, 2005-06
  • Editorial Board Member, Privacy Law & Policy Reporter, 2004-06

Anna holds a first class honours degree in Law, a Masters of Public Policy with honours, a Graduate Certificate in Management, a Graduate Diploma of Legal Practice, and a Bachelor of Arts.  She is a Certified Information Privacy Professional, Europe (CIPP/E) and a Certified Information Privacy Manager (CIPM).  She was admitted as a Solicitor of the Supreme Court of NSW in 1996. Anna is a member of the IAPP.

Emily McGufficke – Director of Advisory

Emily brings an extensive background in privacy compliance and risk management to her client engagements.

At Salinger Privacy Emily has led complex engagements, such as a Privacy Impact Assessment into a novel application of artificial intelligence in healthcare, including advice on ensuring the lawful authority to proceed with multiple use cases, managing vendor risk, and testing for re-identification risk.  She has developed in consultation with stakeholders a data sharing assessment protocol for a strategic alliance of three organisations, to traverse legal, ethical and safety concerns.  Emily has also reviewed the operations of programs involving secondary use of health data and transborder data flows.

Drawing from her experience working in health, legal and financial sectors as well as regulatory roles, Emily can articulate for our clients how privacy obligations apply to their operations, the material privacy risks associated with their business activities, and the appropriateness of the controls and compliance arrangements in place.

Before joining Salinger Privacy, Emily held in-house privacy roles across both government and for-profit organisations.  Most recently as Privacy Compliance Manager at the Commonwealth Bank, Emily assisted business units and Line 1 risk teams to identify and mitigate privacy risks in projects ranging from handling personal information about individuals experiencing vulnerability, through to implementing high privacy risk technology such as biometric identification and use of AI.  She also supported privacy compliance and risk management for start-ups and new digital solutions via x15ventures, CBA’s venture scaler and innovation arm.

Emily also has a deep appreciation for the expectations of a privacy regulator, having worked in the OAIC, where she investigated and conciliated complaints, and conducted privacy audits and data-matching inspections on behalf of the Privacy Commissioner.

Emily holds a Bachelor of Laws with Honours, a Bachelor of Arts, and a Graduate Diploma of Legal Practice.  Emily was admitted as a Lawyer of the Supreme Court of NSW in 2010.  She is a member of the IAPP.

Helios Salinger can help you navigate the complexity of the regulatory environment, and ensure the trust of your customers.

CONTACT US

T: 02 9043 2632
Level 37, 180 George Street
Sydney NSW 2000
Email Enquiry

© Helios Salinger Pty Ltd
ACN 655 748 593
ABN 59 655 748 593

Our Privacy Policy

Terms of Engagement

Subscribe to our newsletter.

These details will be added to our mailing list to receive the Helios Salinger eNews and Product News newsletters. You can unsubscribe or adjust your preferences at any time, from the bottom of any newsletter.