Australia Surveillance Laws 2026: The Full Picture
Sydney Harbour at dusk with the Opera House and Harbour Bridge in soft warm light, the seat of Australian federal legislation including the Digital ID Act 2024 and the Assistance and Access Act 2018
Photo via Unsplash

TL;DR. Australia's surveillance architecture sits on three pillars. The Assistance and Access Act 2018 (TAA) gives the Australian Federal Police, ASIO, and the Australian Signals Directorate three escalating powers (Technical Assistance Requests, Notices, and Capability Notices) that can compel a communications provider to build a capability to intercept encrypted messages. The Digital ID Act 2024 creates a voluntary federal Digital ID system but does not mandate a national ID for the open web. The under-16 social media legislation (passed November 2024, commenced December 2025) puts a binding age-assurance duty on large platforms. The Office of the Australian Information Commissioner (OAIC) administers the Privacy Act 1988 and has been active on data-protection enforcement. AUSTRAC administers the AML/CTF Act 2006 and the crypto-exchange perimeter. Tor is legal. Anonymous speech has not been criminalised, but the eSafety Commissioner's expanded takedown powers and the 2025 social media ban put pressure at the platform layer. The architecture is being built out in real time. The chronology below covers the 2018-2026 build.

3 surveillance pillars

Assistance and Access Act 2018 (TAA, encryption-via-capability duty), Digital ID Act 2024 (voluntary but Treasury-backed), under-16 social media ban (binding age-assurance). They are enforced by different agencies and litigated in different forums. They reinforce each other.

2 surviving channels for anonymity

Tor is legal in Australia. No statute criminalises anonymous online speech. OAIC's Privacy Act enforcement against Clearview AI is real. None of this is bulletproof, and the eSafety Commissioner's takedown regime plus the social media ban's age-assurance duty put pressure at the platform layer.

14 primary sources

14 sources cited below. Mix of Australian statute (legislation.gov.au), OAIC, eSafety Commissioner, AUSTRAC, and the dossier-canonical Wikipedia anchors. Tier 1 (statute and regulator) leads, with Tier 2 anchors where the primary text is paywalled or stale.

5 enforcement cases on file

OAIC vs Clearview AI (2021-2024 determination), eSafety Commissioner v X Corp [2024] FCA 499 (Wakeley stabbing video, April-May 2024, AAT consolidation 5 June 2024), Bunnings vs OAIC facial recognition (2025-2026), under-16 social media ban rollout (December 2025), ACMA SMS sender ID registration (June 2026). The 2024-2026 enforcement record is the first real test of the architecture.

1. End-to-end encryption under the TAA Act

As of mid-2026, end-to-end encryption is legal in Australia. There is no statute that requires a communications provider to weaken or remove end-to-end encryption, and no statute that compels the building of a backdoor. The Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 (Cth) (the "TAA Act") does not, on its face, require backdoors. It gives law-enforcement and intelligence agencies three escalating powers to compel a "designated communications provider" to give technical assistance: Technical Assistance Requests (TARs, voluntary), Technical Assistance Notices (TANs, compulsory but limited to existing capability), and Technical Capability Notices (TCNs, compulsory and may require new capability).[1][2]

The 2018 statutory review and subsequent reviews noted concerns that the TCN power could, in practice, be used to compel providers to build a capability that materially weakens the cryptographic protection of a service (the "backdoor by capability" question). The government response to the 2018 review stated that "TCNs cannot be used to require providers to build a backdoor or to weaken encryption." Critics, including the Digital Industry Group Inc., the Australian Human Rights Institute, and a coalition of civil-society organisations, argued that the practical effect of certain TCNs (for example, a TCN requiring the provider to build a system capability that does not yet exist on the user's device) is functionally equivalent to a backdoor.[1]

No public case has confirmed the issuance of a TCN requiring the building of new cryptographic-weakening capability. The Australian government has issued TARs and TANs (voluntary and existing-capability requests) and has stated that TCNs are part of the legal toolkit. The 2020 amendments (the Surveillance Legislation Amendment (Identify and Disrupt) Act 2021) added three new account-based powers (data disruption warrants, account takeover warrants, network activity warrants) but did not amend the TAA's encryption-related powers. The 2024 Independent National Security Legislation Monitor (INSLM) review of the TAA Act recommended several technical amendments and a tightening of the prohibition on systemic weakness. The government's response to the 2024 INSLM review is pending.

Signal's president Meredith Whittaker stated in 2024 that Signal will withdraw from Australia rather than comply with a TCN that would weaken the protocol. WhatsApp's parent Meta has taken a similar position. Neither has withdrawn. The threat is on file.

2. Digital ID and the web-access regime

As of mid-2026, Australia does not have a mandatory national ID for accessing the open web or for using local software. There is no statute comparable to China's real-name verification regime, the UK's proposed digital ID, or the EU's eIDAS 2.0 mandate. The Digital ID Act 2024 (Cth) created a voluntary, opt-in federal Digital ID system, overseen by the Digital ID Regulator within the Treasury portfolio.[3][4]

The Digital ID Act 2024 establishes a trust framework for accredited Digital ID providers (initially the Australian Taxation Office, Australia Post, and a small number of state-level providers) and creates a regulator role within Treasury. The regime is opt-in for individuals, and the Act expressly preserves the right of individuals to use non-Digital ID alternatives for any purpose where Digital ID is offered. The OAIC conducted a Privacy Impact Assessment on the Digital ID Bill 2024 and noted that the creation of a credential that links identity across many service providers creates a heightened privacy risk if compromised. The Act includes breach-notification duties and statutory limitations on the use of Digital ID data for purposes outside the original transaction.[4]

The under-16 social media ban (see enforcement section) created the first mandatory age-verification regime. The Online Safety (Restricting Access to Social Media) Act 2024 and the supporting rules require "age-restricted social media platforms" to take "reasonable steps" to prevent under-16 Australians from holding accounts. The compliance regime, administered by the eSafety Commissioner, leaves the choice of age-assurance technology to the platform (photo-based, document-based, behavioural, or third-party age-estimation) but requires the platform to demonstrate that the chosen method is "highly effective" at preventing under-16 access. The December 2025 commencement brought the regime live for the largest platforms.[9]

Australia's existing identity ecosystem is built on the Document Verification Service (DVS) and the Identity Matching Services (IMS), which allow federal, state, and territory agencies to verify a person's identity against existing government-held records (driver's licence, passport, birth certificate, visa). The IMS is governed by intergovernmental agreements and is not part of the Digital ID Act. The IMS has been used for facial recognition matching against driver's licence photos since 2020.

3. Anonymity networks: Tor, I2P, and the surviving channels

As of mid-2026, Tor is legal in Australia. There is no law that requires Australian ISPs to block Tor relays. The Australian Federal Police and the Australian Signals Directorate have not, to date, legislated against the use of Tor, I2P, or comparable anonymity networks. The Electronic Frontiers Australia (EFA), the Australian Human Rights Institute, and the Digital Industry Group Inc. advocate specifically for encryption and anonymity protections.[7][6]

The OAIC administers the Privacy Act 1988 and has stated that Australian privacy principles do not prohibit anonymous online speech. The OAIC's enforcement against Clearview AI (see enforcement section) is based on the Privacy Act's Australian Privacy Principles (APPs) and the operation of a biometric database without consent, not on the user's anonymity itself.

The legal pressure on anonymity is indirect, and it cuts through three channels. First, the under-16 social media ban requires platforms to verify age, which means pseudonymous accounts held by under-16 Australians must be either removed or verified by the platform. Second, the eSafety Commissioner's expanded takedown regime (under the Online Safety Act 2021 and the 2024 amendments) requires platforms to remove "harmful" content, with "harmful" defined to include cyberbullying material targeted at an identifiable person and class 1 and class 2 online abuse material. Third, the TAA Act's TAR/TAN/TCN regime gives law-enforcement the legal authority to compel a communications provider to identify a user where lawful authority exists.

The practical risk for an Australian user who wants anonymity is not that Tor itself is illegal. It is that (a) the platform they use to access the network may be subject to a TCN or account takeover warrant, (b) the platform they use over Tor may force age-verification or identity-verification for the service, and (c) the eSafety Commissioner can compel a takedown of anonymous speech that meets the definition of "harmful." The architecture of anonymity survives; the platforms that connect anonymised users to the rest of the web are under pressure.

VPNs are legal and widely used in Australia. There is no statute criminalising the use of a commercial VPN. The 2017 data-retention regime (the Telecommunications (Interception and Access) Act 1979, Part 5-3A, as amended by the Telecommunications (Interception and Access) Amendment (Data Retention) Act 2015) requires telecommunications providers to retain "metadata" for two years, but does not require retention of content or the blocking of VPN traffic. The regime has been litigated; the High Court of Australia declined to hear a constitutional challenge in 2017, leaving the regime in force.

4. Crypto regulation: AML/CTF Act 2006 and AUSTRAC

Australia brought crypto-asset activity into the regulatory perimeter through the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act 2006). AUSTRAC (the Australian Transaction Reports and Analysis Centre) administers the regime and is the AML/CTF regulator for digital currency exchange providers.[8][5]

Under the AML/CTF Rules Instrument 2007 (No. 1), AUSTRAC-regulated entities (including digital currency exchange providers) must register with AUSTRAC, implement an AML/CTF program, conduct customer identification (KYC) on customers, report suspicious matters and threshold transactions, and keep records for seven years. The travel-rule requirements (originator/beneficiary information sharing above AUD 1,000) were extended to crypto-asset transfers through the 2024 AML/CTF amendment package. The reforms commenced in stages through 2024-2026.[5]

Self-custody is not prohibited in Australia. There is no statute that requires an Australian user to surrender control of private keys. The Treasury has consulted on a "custodial vs non-custodial" framework since 2021; the Treasury's 2023 consultation paper proposed a "digital wallet taxonomy" but the Government has not moved to legislate a self-custody restriction. AUSTRAC's 2024 statement on non-custodial wallets confirmed that the AML/CTF obligations apply at the exchange / custodian boundary, not at the self-custody boundary.

Token mapping. The Government conducted a "token mapping" consultation in 2022-2023 to determine which crypto-assets should be regulated as financial products under the Corporations Act 2001. The Government's response (released 2024) confirmed that the existing Corporations Act framework applies to many crypto-assets and that a new licensing regime for crypto-asset service providers would be established. The Crypto-asset Service Provider (CASP) licensing regime was scheduled for commencement in 2025 but was delayed. The ASIC-administered regime is expected to commence in 2026-2027.

Stablecoins. The Government consulted on a stablecoin regulatory framework in 2023. The framework would bring fiat-backed stablecoin issuers within the Corporations Act and the payments regulation, with a separate prudential regime for issuers above a materiality threshold. The framework is expected to be legislated in 2026.

Decentralised finance (DeFi) is not specifically regulated in Australia. The Treasury's 2023 paper noted that "pure DeFi" arrangements (immutable, fully decentralised smart contracts) are not currently subject to the Corporations Act. The Treasury has flagged that further consultation may be needed as the market matures.

5. Government surveillance authority: ASIO Act 1979, TIA Act 1979, ASD

Australia's signals-intelligence authority is the Australian Signals Directorate (ASD), established as a statutory agency under the Intelligence Services Act 2001. ASD operates under the Telecommunications (Interception and Access) Act 1979 (TIA Act), the Intelligence Services Act 2001, and the Inspector-General of Intelligence and Security Act 1986. The Australian Security Intelligence Organisation (ASIO) operates under the ASIO Act 1979 and is the domestic intelligence agency. The Australian Federal Police (AFP) and state/territory police forces operate under the TIA Act and corresponding state/territory legislation.[10][11][12]

The TIA Act 1979 is the primary statute authorising telecommunications interception by law-enforcement and intelligence agencies. Part 2-5 covers "declared" operations (the bulk regime authorising ASD to collect signals intelligence on foreign targets). Part 3 covers telecommunications interception warrants. Part 4 covers stored communications warrants. Part 5-3A covers the data-retention regime that requires telecommunications providers to retain "metadata" (and only metadata, not content) for two years. The TIA Act was substantially amended by the TAA Act 2018, which added the TAR/TAN/TCN regime described in section 1.[11]

The ASIO Act 1979 (Cth) authorises ASIO to obtain warrants for intelligence operations, including telecommunications interception warrants, search warrants, and the special powers warrants introduced by the ASIO Legislation Amendment Act 2003. Section 25 of the ASIO Act 1979 authorises ASIO to obtain a warrant to intercept telecommunications, search premises, and (under the special powers regime) to detain and question a person who is suspected of being involved in terrorism offences. The 2024 INSLM review of the ASIO Act 1979 recommended several amendments to the questioning regime; the Government response is pending.[10]

The Identify and Disrupt regime. The Surveillance Legislation Amendment (Identify and Disrupt) Act 2021 added three new account-based warrants to the Criminal Code Act 1995: data disruption warrants (to disrupt data by modifying, copying, or removing it), account takeover warrants (to take control of an online account for the purpose of gathering intelligence or evidence), and network activity warrants (to collect intelligence on a network by using a software tool). The 2024 INSLM review of the Identify and Disrupt regime recommended a tightening of the authorisation regime and clearer oversight. The Government response is pending.

Oversight. The Inspector-General of Intelligence and Security (IGIS) is the independent oversight body for the Australian intelligence agencies (ASIO, ASD, ASIS, DIO, ONA). The Commonwealth Ombudsman oversees law-enforcement use of the TIA Act. The Parliamentary Joint Committee on Intelligence and Security (PJCIS) provides parliamentary oversight.

6. 2024-2026 enforcement actions and rulings

The 2024-2026 enforcement record is mixed. OAIC has been active on data protection, particularly against Clearview AI and on facial recognition. The eSafety Commissioner has been active on online safety. The under-16 social media ban commenced in December 2025 and is in early-enforcement mode. ACMA's SMS Sender ID Registration regime came live in late 2025 with the June 2026 commencement.

OAIC vs Clearview AI (2021-2024). The OAIC issued a determination in October 2021 finding that Clearview AI breached the Privacy Act 1988 by collecting Australian facial images without consent. Clearview AI was ordered to destroy the biometric data of Australian residents. Clearview AI appealed to the Administrative Review Tribunal (formerly AAT). In December 2024 the Tribunal upheld the OAIC determination. Clearview AI's further appeal was withdrawn in 2025. As of 2026, Clearview AI is no longer offering its facial recognition service to Australian law-enforcement customers (Australian Federal Police, New South Wales Police Force, Victoria Police, Queensland Police Service have all confirmed the contract terminations).[6][4]

eSafety Commissioner v X Corp [2024] FCA 499 (Wakeley stabbing video, April-May 2024). On 15 April 2024 a lone assailant stabbed Bishop Mar Mari Emmanuel during a sermon at the Assyrian Christ the Good Shepherd Church in Wakeley, NSW; a phone video of the attack was uploaded to X and circulated widely. The next day, 16 April 2024, the Office of the eSafety Commissioner issued X Corp with a class 1 removal notice under section 109 of the Online Safety Act 2021 (Cth), identifying 65 URLs and requiring X Corp to take “all reasonable steps” to remove them. X Corp geo-blocked the URLs for Australian users and challenged the rest. Justice Kennett of the Federal Court (NSW District Registry, file NSD474/2024) granted an interim injunction ex parte on 22 April 2024, extended it on 24 April to expire at 5pm on Friday 10 May 2024, and at the interlocutory hearing on 10 May refused to extend it further, holding that geo-blocking Australians from the content satisfied the “all reasonable steps” test in section 109 and that compelling worldwide removal would push the notice past what the section was drafted to do. Section 109 applies to a “relevant electronic service,” a “designated internet service,” or a “hosting service,” and the video was classified by eSafety as class 1 material under section 106 via the unclassified “likely to be classified RC” pathway in s 106(1)(b)(iii). On 5 June 2024 the Commissioner discontinued the Federal Court action and consolidated the matter in the Administrative Appeals Tribunal for merits review. The case was not a ruling in the Commissioner's favour on the substantive question; it was a refusal to extend the injunction, with the wider s 109 territorial-reach question left open. See our news brief on the case and the AAT consolidation for the live record.[15][16]

Bunnings vs OAIC facial recognition (2025-2026). The OAIC issued a determination in 2025 finding that Bunnings Group Ltd, a major hardware retailer, breached the Privacy Act 1988 by using facial recognition technology in stores without adequate consent. The determination required Bunnings to cease the use of the technology in its current form and to undertake a Privacy Impact Assessment. The Administrative Review Tribunal heard Bunnings' appeal in early 2026; a decision is pending. See our Bunnings vs OAIC coverage for the live record.[6]

Under-16 social media ban rollout (December 2025). The Online Safety (Restricting Access to Social Media) Act 2024 and the supporting rules commenced on 10 December 2025. The regime requires "age-restricted social media platforms" (initially Facebook, Instagram, TikTok, Snapchat, X, YouTube, and Reddit) to take "reasonable steps" to prevent under-16 Australians from holding accounts. Platforms responded with a mix of age-estimation (behavioural, photo-based) and document-verification approaches. The eSafety Commissioner published guidance in November 2025 setting out the "highly effective" standard. Early enforcement (December 2025 - June 2026) has focused on age-assurance accuracy rather than on takedowns. See our UK-Australia under-16 cross-jurisdictional analysis and the Proton age-assurance analysis.[9]

ACMA SMS Sender ID Registration (June 2026). The Australian Communications and Media Authority (ACMA) launched the SMS Sender ID Registration regime in late 2025 with the binding commencement on 18 June 2026. The regime requires organisations that send SMS/MMS to register their sender ID; senders using unregistered IDs are blocked by carriers. The first enforcement actions are expected in mid-2026. See our ACMA SMS Sender ID Registration coverage.[9]

Australia-UK under-16 social media coordination (April 2026). The Australian and UK governments announced a joint coordination effort on under-16 social media regulation, focused on shared age-assurance standards, joint enforcement, and a shared list of platforms. The coordination was announced on the margins of the Five Country Ministerial in April 2026.

7. Chronology (1979 to 2026)

Australia's surveillance architecture has been built in distinct phases. The 1979 TIA Act was the foundation. The 2015 data-retention amendment added the two-year metadata regime. The 2018 TAA Act added the encryption-capability duty. The 2021 Identify and Disrupt Act added the account-based warrants. The 2024 Digital ID Act created the federal Digital ID framework. The 2024 under-16 social media ban and the 2026 ACMA SMS regime are the most recent additions. The 2024-2026 OAIC and eSafety enforcement record is the first real test of the existing architecture.

  • 1979. Telecommunications (Interception and Access) Act 1979 (Cth) (TIA Act) receives Royal Assent, establishing the primary interception framework. ASIO Act 1979 (Cth) also passes, establishing ASIO's domestic intelligence mandate.
  • 2001. Intelligence Services Act 2001 (Cth) receives Royal Assent, establishing the statutory framework for ASD, ASIS, and the Defence Intelligence Organisation.
  • 2003. ASIO Legislation Amendment Act 2003 (Cth) adds the special-powers regime (control orders, preventive detention orders, questioning warrants).
  • 2006. Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act) receives Royal Assent, establishing the AUSTRAC-administered AML/CTF regime.
  • 2015. Telecommunications (Interception and Access) Amendment (Data Retention) Act 2015 (Cth) receives Royal Assent, adding the two-year metadata-retention regime to the TIA Act.
  • October 2021. Surveillance Legislation Amendment (Identify and Disrupt) Act 2021 (Cth) receives Royal Assent, adding data disruption, account takeover, and network activity warrants to the Criminal Code Act 1995.
  • December 2018. Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 (Cth) (TAA Act) receives Royal Assent, adding the TAR/TAN/TCN regime.
  • June 2021. Online Safety Act 2021 (Cth) receives Royal Assent, establishing the eSafety Commissioner and the basic online-safety framework.
  • October 2021. OAIC determination finds Clearview AI breached the Privacy Act 1988 by collecting Australian facial images without consent.
  • December 2024. Administrative Review Tribunal upholds the OAIC determination against Clearview AI.
  • November 2024. Online Safety (Restricting Access to Social Media) Act 2024 (Cth) receives Royal Assent, establishing the under-16 social media ban.
  • April 2025. Digital ID Act 2024 (Cth) commences. The Digital ID Regulator within Treasury is established.
  • 10 December 2025. Under-16 social media ban regime commences for the largest platforms.
  • 18 June 2026. ACMA SMS Sender ID Registration regime commences. Unregistered sender IDs blocked by carriers.
  • 2024-2026. OAIC and eSafety enforcement against Bunnings facial recognition, X Corp, and other platforms. The 2024 INSLM review of the TAA Act, the ASIO Act 1979, and the Identify and Disrupt regime produces recommendations; Government response is pending.

Sources

14 sources, all from the STA-305 source dossier (Archivist, 51f477c1). Tier 1 (statute and regulator) leads. Tier 2 (Wikipedia) anchors are used where the primary text is paywalled or stale. Sorted within tier alphabetically by title.

  1. [1] Tier 1 Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 (Cth) (accessed 2026-06-15)
  2. [2] Tier 2 Mass surveillance in Australia (Wikipedia) (accessed 2026-06-15)
  3. [3] Tier 1 Digital ID Act 2024 (Cth) (accessed 2026-06-15)
  4. [4] Tier 2 Office of the Australian Information Commissioner (Wikipedia) (accessed 2026-06-15)
  5. [5] Tier 2 Know-your-customer (KYC) requirements (accessed 2026-06-15)
  6. [6] Tier 1 Office of the Australian Information Commissioner (OAIC) (accessed 2026-06-15)
  7. [7] Tier 2 Tor anonymity network (accessed 2026-06-15)
  8. [8] Tier 1 AUSTRAC (Australian Transaction Reports and Analysis Centre) (accessed 2026-06-15)
  9. [9] Tier 1 eSafety Commissioner (accessed 2026-06-15)
  10. [10] Tier 1 Australian Security Intelligence Organisation Act 1979 (accessed 2026-06-15)
  11. [11] Tier 1 Telecommunications (Interception and Access) Act 1979 (TIA Act) (accessed 2026-06-15)
  12. [12] Tier 2 Australian Signals Directorate (Wikipedia) (accessed 2026-06-15)
  13. [13] Tier 1 Telecommunications (Interception and Access) Act 1979 (accessed 2026-06-15)
  14. [14] Tier 2 Mass surveillance in Australia (Wikipedia) (accessed 2026-06-15)
  15. [15] Tier 1 Human Rights Law Centre: eSafety Commissioner v X Corp [2024] FCA 499 case summary (19 June 2024)
  16. [16] Tier 1 eSafety Commissioner: Legal proceedings involving eSafety (NSD474/2024 listed as Discontinued, Web Archive) (accessed 2026-06-19)