
Ironbridge Legal
Australia
Lawyers

Candy Lau
- Phone+61 (426) 373 988
- Email[email protected]
- Social
Position
Partner
Career
Candy is a multilingual lawyer with a strong cross-border and in-house informed practice in financial services regulatory compliance, corporate governance, privacy and the Security of Critical Infrastructure (SOCI) regime. She began her legal career at Deacons in Hong Kong before relocating to Sydney, where she practised at Henry Davis York and later Norton Rose Fulbright, where she was appointed Special Counsel. That background, together with her international experience and multiple in-house secondments, enables her to deliver commercially focused advice to senior stakeholders on legal, compliance, operational and reputational risk.
Candy advises global and major domestic financial institutions on regulatory compliance and reforms, regulator engagements, and complex review and remediation programs. Her practice includes advising on the design and distribution obligations regime, the reportable situations framework, and the Financial Accountability Regime, as well as its predecessor, the Banking Executive Accountability Regime. She has also supported a major Australian bank on systemic issues management and engagement with the Australian Financial Complaints Authority.
Her SOCI practice extends across multiple regulated sectors, including energy and infrastructure, data storage and processing, and financial services. She advises on the application of the regime to multi-jurisdictional operations, with a focus on risk management programs, supply chain and personnel risks, cyber security, and data governance obligations. She also regularly advises businesses on privacy obligations, including privacy framework uplift programs and statutory obligations arising from data breach incidents.
Languages
English