Anna Johnston, our founder and Principal, is one of Australia’s most respected experts in privacy law and practice.
With her qualifications in law, public policy and management, and over 25 years’ experience in legal, policy and research roles, Anna brings a breadth of perspectives and a wealth of experience to dealing with our clients’ privacy and data governance challenges.
Since establishing Salinger Privacy in 2004, Anna has conducted numerous Privacy Impact Assessments and privacy compliance reviews for our clients. Anna also authors most of our range of guidance publications, and writes regularly for the Salinger Privacy blog and publications ranging from tendaily to the Law Society Journal and Privacy Laws & Business.
As the former Deputy Privacy Commissioner for NSW, Anna also knows the regulator’s perspective. Since establishing Salinger Privacy, she has also been commissioned to write privacy guidance publications, and deliver presentations and training, on behalf of other regulators including the Australian, NSW and Victorian Privacy Commissioners.
Anna has been called upon to provide expert testimony before various Parliamentary inquiries and the Productivity Commission, spoken at numerous conferences, and is regularly asked to comment on privacy issues in the media. She is a lifetime member of the Australian Privacy Foundation, a member of the International Association of Privacy Professionals (IAPP) since 2008, and in 2019 was recognised as an industry veteran by the IAPP with the designation of Fellow of Information Privacy (FIP).
Anna’s pro bono advisory, advocacy, academic and editorial positions have included:
- Visiting Scholar at the Research Group on Law, Science, Technology and Society of the Faculty of Law and Criminology of the Vrije Universiteit Brussel (VUB), 2018
- Advisory Board Member for the EU’s STAR project, to develop training on behalf of European Data Protection Authorities, 2017 to date
- Member of the Asian Privacy Scholars Network (APSN), 2017 to date
- Editorial Board Member, Privacy Law Bulletin, 2010-16
- Advisory Committee Member, the Australian Law Reform Commission’s Inquiry into the Invasion of Privacy, 2013-14
- Board member, the International Association of Privacy Professionals, Australia & New Zealand, 2010-11
- Advisory Committee Member, the Australian Law Reform Commission’s expert advisory group on health privacy for the Review of the Privacy Act, 2006-08
- Project Team Member, University of New South Wales’ Interpreting Privacy Principles project, 2006-09
- Campaign Director, NoIDCard, the successful campaign against the proposed Access Card, 2006-07
- Chair of the Australian Privacy Foundation, 2005-06; Member of the International Committee 2018 to date
- Consumer Representative Member, National E-Health Transition Authority’s Consumer & Clinician Forum, 2005-06
- Primary Author, Australian country reports for Privacy International’s Privacy and Human Rights, 2005-06
- Editorial Board Member, Privacy Law & Policy Reporter, 2004-06
Anna holds a first class honours degree in Law, a Masters of Public Policy with honours, a Graduate Certificate in Management, a Graduate Diploma of Legal Practice, and a Bachelor of Arts. She is a Certified Information Privacy Professional, Europe (CIPP/E) and a Certified Information Privacy Manager (CIPM). She was admitted as a Solicitor of the Supreme Court of NSW in 1996. However since she no longer practices as a solicitor, she won’t mind your lawyer jokes at all.
Melanie Casley, our Senior Privacy Consultant, has deep experience in the application of privacy laws, having worked in the field since 2002, across both regulatory and advisory capacities.
At Salinger Privacy Melanie has led Privacy Impact Assessments into complex, multi-jurisdictional projects, such as a project to develop a real-time national information-sharing system for child protection, and data linkage and analytics projects in the health and disability sectors. She has recently developed a framework for privacy management for the Queensland Government’s Unify program, along with a series of seven PIAs on different aspects of the Unify program. The Unify program is a four-year project to replace legacy client-management systems and improve information sharing and collaboration across the social services and justice sectors, led by the Department of Child Safety, Youth and Women, in partnership with the Department of Youth Justice. Mel has also conducted privacy compliance reviews for clients needing a health check of their existing operations.
Mel has previously served as Manager of the Information and Privacy Unit in the Victorian Department of Justice and Regulation, overseeing the compliance of both the Department, and statutory agencies within the Justice portfolio, in relation to privacy and related laws. She has also managed the secretariat functions for the Justice Human Research Ethics Committee, and coordinated a Whole of Victorian Government approach to privacy governance and policy. Prior to her role with the Victorian Department of Justice and Regulation, Mel performed a number of policy, training and compliance roles with the Office of the Victorian Privacy Commissioner.
Melanie holds a Bachelor of Laws, a Bachelor of Arts, and a Graduate Diploma of Educational Psychology. She is also an accredited mediator, a member of the IAPP, a Certified Information Privacy Manager (CIPM) and Certified Information Privacy Professional – Europe (CIPP/E).
Angie Barlow, our Senior Privacy Consultant, has over 14 years’ experience in the practical application of privacy and data security laws. She has extensive experience conducting privacy audits and PIAs, developing privacy policies, guidelines and checklists, and responding to privacy complaints and data breaches.
Prior to joining Salinger Privacy, Angie was the Privacy Officer for TAL Life Limited, a leading life insurer in Australia, protecting over 4.5 million customers and their families with products including life insurance, superannuation, investments and financial advisory services. As a result of more than a decade in that role, Angie has a comprehensive understanding of the expectations of customers, Federal and State regulators and the wider community in relation to privacy and data security. With deep operational experience regarding privacy and data breaches and remediation plans, Angie also has extensive knowledge of what ‘good’ privacy and data security looks like, and how to efficiently fix deficiencies within defined budgets.
Angie was also Chair of the Privacy Working Group of the Financial Services Council for more than a decade. This involved monitoring the extent and impact of privacy and data security legislative and regulatory reforms, drafting submissions to relevant Government agencies, and analysing publications from the OAIC, on behalf of financial services organisations and their customers.
Angie has qualifications and experience in law, risk and compliance. She holds a Bachelor of Laws, and was admitted as a solicitor in the UK.
Our Privacy & Technology Specialist, Samantha Floreani, has worked alongside clients during agile project design sprints, to offer advice on how best to implement ‘Privacy by Design’ principles to shape project design and outcomes. She also conducts privacy audits and PIAs for our clients, and wrote our guide Algorithms, AI, and Automated Decisions – A guide for privacy professionals.
Sam has previously worked as a senior policy analyst for the Office of the Victorian Information Commissioner (OVIC), and as State Director of Code Like A Girl. She has a particular commitment to ensuring fairness in technology, from gender equity in the tech industry to the ethical handling of personal information. At OVIC Sam conducted PIAs, as well as research and analysis on emerging technologies, in order to develop position papers for the Commissioner and guidance for the Victorian public sector. She has worked at the intersection of law, technology and ethics on topics including artificial intelligence, biometrics, de-identification, non-consensual sharing of intimate images and information sharing within government.
Sam has a Bachelor of Arts, a Diploma of Languages, an Honours degree in Politics and International Studies focussing on privacy and national security, and is currently completing a Graduate Diploma of Data Science. She is also a member of the IAPP, and is a Certified Information Privacy Manager (CIPM).
Andrea Calleia, our Director of Learning, has extensive experience in the learning and development field, and has specialised in privacy training since 2003 when she managed the privacy education program for the NSW Privacy Commissioner’s Office. Since joining Salinger Privacy in 2008 Andrea has managed our e-learning privacy training program, and delivers most of our face to face training. She has developed and delivered customised privacy training on behalf of clients including QANTAS, Sage Software, the Office of the Australian Information Commissioner, and PRAXIS Australia.
Andrea is consistently rated “5 out of 5” by our training participants and has been described as “excellent and engaging”, “enthusiastic, clear and effective”. She developed our Privacy Management in Practice workshop program, which has been described by participants as “top notch”, “practical and informative” and “effective for all participants coming from varied organisations”. Andrea also delivers our CIPM training on behalf of the International Association of Privacy Professionals (IAPP).
Andrea has been appointed to the IAPP’s ANZ Advisory Board for 2020/2021, to promote and serve the privacy profession in Australia and New Zealand.
Andrea holds a Bachelor of Arts majoring in Education and Human Resources, and a Certificate IV in Training and Assessment. As an alumni of the University of New South Wales, she is a Mentor for students specialising in the fields of Human Resources and Learning and Development. Andrea is a Certified Information Privacy Professional – Europe (CIPP/E), Certified Information Privacy Manager (CIPM), a Certified Information Privacy Technologist (CIPT), a Certified Practitioner of Human Resources with the Australian Human Resources Institute, a Fellow of the Australian Institute of Training and Development (AITD), a member of the IAPP, and a member of the Australian Privacy Foundation. In 2021 Andrea was recognised as an industry veteran by the IAPP with the designation of Fellow of Information Privacy (FIP).
We often also collaborate with Stephen Wilson of Lockstep Consulting. Stephen is a leading international authority on digital identity and cyber security. His career spans more than 28 years in IT, software engineering and R&D management, in both Australia and the US, and since 1995 he has specialised in e-security. Stephen is Managing Director of ValidIDy and Lockstep Consulting, and has partnered with Salinger Privacy on a number of PIAs and other client engagements since 2005.
Stephen’s privacy experience is founded on many years working in the sensitive sectors of healthcare and government, and forged through highly original research into the complex interplay of privacy and security. He has pioneered privacy engineering and design techniques to tailor practical guidance for information architects, designers and project managers, to help build privacy controls into the formative stages of systems development. Stephen has helped organisations in government, health and finance throughout the Asia Pacific, with e-security strategy, policy, architecture, privacy, risk management, governance and technology selection.
Stephen has long been involved in public policy in privacy and security. He was a member of the ALRC’s Developing Technology Advisory Sub-committee (2007-08) and the Federal Privacy Commissioner’s PKI Reference Group (2000). He has served as Standards Australia’s Nominated Privacy Expert on the ISO Financial Services Security Technical Committee 68/SC 6. Stephen has authored numerous submissions to public inquiries into privacy, including the National Health Privacy Code (2003), the Privacy Act (2005), the Health & Welfare Access Card (2007), and Health Identifiers (2010).
Stephen holds an honours degree in Electrical Engineering, and a Bachelor of Science.
Depending on the nature of any given engagement, we may also bring on board Dr Chris Culnane of Castellate Consulting. Chris is an expert in cyber security and privacy, specialising in re-identification risk assessments. He has previously held academic posts at the University of Surrey and the University of Melbourne, where his research focus included the integrity of electronic voting, and the privacy and cyber security of open data releases.
Chris has partnered with Salinger Privacy on policy and research work in relation to online identifiers and developing law reform options. Chris also has a particular expertise in evaluating the privacy risks posed by large datasets, and has written extensively about de-identification and re-identification risks. His work led to the discovery of re-identification risks in the Federal MBS/PBS open data release, and more recently the Victorian government release of Myki data.
Whilst at the University of Melbourne Chris led consultancy contracts which undertook evaluations of privacy-preserving techniques, including for the Australian Bureau of Statistics and Transport for New South Wales. He was also the technical lead on the vVote project, which designed and implemented an end-to-end verifiable election system for the 2014 Victoria State Election, which at the time was the largest politically binding deployment of an end-to-end verifiable election.
In addition to his technical work, Chris has also led a number of consultation responses including in relation to Data Sharing and Release, and the Consumer Data Right, as well as appearing as a witness at both state and federal inquiries, including Electoral Matters Committees and the PJCIS inquiry into the Assistance and Access Bill (now TOLA).
Chris holds a first class honours Bachelor of Science in Computing, a Master of Science in Internet Computing, and a PhD in Computer and Information Systems Security.