Steven acts for businesses, non-profits and government agencies on technology contracts, outsourcing, cybersecurity, cyber risk preparedness and incident response, data privacy and ICT procurement. Clients value Steven's risk-informed, outcomes-focused approach to complex matters.
Biography
Steven acts for businesses, non-profits and government agencies in the technology and digital economy sector. His clients include technology-forward buyers and sellers, and organisations requiring cyber risk, data privacy and technology contracting advice.
He is a member of the Queensland Law Society's Cybersecurity Working Group and a strategic advisor to the board of the Project Management Institute Queensland Australia Chapter.
Steven advises on cyber risk and cybersecurity, data privacy and commercialisation, cyber and data incident response, technology contracts, outsourcing, SaaS and cloud services, software development agreements, telecommunications arrangements, ICT procurement, and IP licensing and commercialisation.
Steven's practice spans complex technology contracts and multi-jurisdictional regulatory matters. He has advised Trapeze Group on a major Transport for New South Wales ticketing contract, icetana.ai on AI regulation across six international markets, and Nextracker on Australia's evolving critical infrastructure cybersecurity regime. His work regularly involves navigating overlapping federal, state and international regulatory frameworks, including privacy, surveillance, AI compliance and the Security of Critical Infrastructure Act.
Steven's combined commercial and legal background and Project Management Professional credential give him an outcomes-focused understanding of technology projects and their delivery pressures. His Queensland Law Society Cybersecurity Working Group membership reflects active engagement in cybersecurity practice development.
Credentials
Academic qualifications:
- Juris Doctor (with Distinction) (Bond University)
- Bachelor of Business Administration (Honours) (Wilfrid Laurier University)
Certifications:
- Project Management Professional (PMP)
Memberships:
- Australian Information Security Association (AISA)
- Queensland Law Society Cybersecurity Working Group
Steven's experience
Trapeze Group
Advised Trapeze Group on its successful tender responses and contract negotiations to supply Transport for New South Wales with the Bus Solution component of the Opal Next Generation ticketing system. The engagement spanned departures from proposed terms for the multi-year hardware, software and services contract, leading contract negotiations to align commercial and risk management positions, securing internal and group legal approvals, and negotiating with supply partners and subcontractors to align subcontract arrangements with whole-of-project terms.
icetana.ai: AI regulatory framework across 6+ jurisdictions
Leading advice to icetana.ai, an Australian AI surveillance and analytics company, on the legal and regulatory treatment of AI and AI-based technologies across Australia, Asia Pacific, the United States, the United Kingdom, Europe and selected Middle Eastern countries, covering data privacy, biometric technologies, automated decision-making and AI compliance to support its market expansion strategy.
Aged care, ministry and support services provider in Queensland
Leading advice to Churches of Christ Queensland, an provider of retirement & aged care, foster and kinship services, youth support, housing services and churches, in developing a comprehensive suite of policies, consents and procedures for the lawful installation, management, and use of safety & surveillance equipment (including CCTV) in residential care homes and home/community settings across Queensland and Victoria.
The assignment involved careful synthesis of cross-jurisdictional privacy and surveillance legislation, preparing detailed consent and notification templates for residents, and providing an accessible compliance roadmap for staff and board members.
Contracted service provider's data privacy responsibilities
Acting for medical devices maker Stryker Australia in connection with the rollout of its software as a service delivered on behalf of public health agencies and out-of-hospital care providers. Advising the supplier in relation to its responsibilities under federal and state privacy laws, and application of exemptions from the Privacy Act 1988 (Cth) where Stryker delivers services for a State authority and has compliance obligations under State privacy laws.
We delivered strategic and practical advice on: the application and interaction of federal and state privacy laws for contracted service providers; analysis of statutory exemptions; clarification of the supplier's status as a contracted service provider and associated obligations; recommended practical measures for data retention and documentation; and recommended tailoring product communications to Australian legal requirements as opposed to international standards.
Data breach incident response
Assisting organisations to respond to actual or suspected cyber incidents end-to-end, from initial assessment through response strategy, data reviews, regulator and individual notification, stakeholder communication and post-incident review.
Critical infrastructure and device cybersecurity
Advising international device manufacturer Nextracker on its compliance with Australia’s Security of Critical Infrastructure Act 2018 and Cyber Security Act 2024, focusing on their solar tracking technologies, cross-border operations, and emerging requirements for smart device cybersecurity and ransomware reporting.