Australia’s mandatory data retention regime applies to certain telecommunications providers, including carriers, carriage service providers and internet service providers that use telecommunications infrastructure in Australia. Providers covered by the regime must retain a prescribed data set and protect it under the Telecommunications (Interception and Access) Act 1979.
The regime concerns information about communications, rather than their content or substance. It requires covered providers to protect retained data through encryption and safeguards against unauthorised interference or access.
Why the law changed
Australia’s data retention regime is intended to ensure that a specified range of telecommunications data remains available for major investigations, including cybercrime, counter-terrorism and child-exploitation offences, rather than being deleted solely because it is no longer needed for ordinary business purposes.
Metadata you must collect
Covered providers must retain the telecommunications data specified in the Act. This includes information about a communication, such as its source, destination, date, time and duration, but not the content or substance of a phone call, email or other communication.
Examples include:
- the source and destination of the communication
- the date, time and duration of the communication
- the type of service used
- information about the location of equipment or the device used.
Some subscriber information must be retained for the life of the account and for a further two years after the account closes. Covered providers should consult the current statutory data set and official guidance for the services they operate.
Who can access the metadata?
Under the Act, ASIO and certain domestic law-enforcement agencies can authorise disclosure of telecommunications data in defined circumstances. Providers must comply with applicable disclosure and record-keeping requirements, and the Office of the Australian Information Commissioner monitors relevant privacy and disclosure-record obligations.
Where to go for help
For current obligations, exemptions, variations and industry guidance, consult the Attorney-General’s Department’s industry obligations guidance. It should be read with the current legislation and is not a substitute for legal advice.
How to simplify data protection
The regime creates two broad compliance priorities:
- collecting and retaining the required telecommunications data
- protecting the confidentiality of retained data.
A practical compliance programme can be organised into four phases:
- Define the scope of the data-retention requirements for your organisation.
- Plan implementation and assess the controls needed to meet those requirements.
- Execute the plan and document the operating procedures.
- Maintain and review the controls as obligations, services and risks change.
Relevant safeguards may include:
- access control
- multi-factor authentication
- logging and auditing
- high availability and resilience
- scalability
- secure implementation practices
- privileged-user protection
- application allow- and block-list controls
- ongoing security monitoring.
If you would like support strengthening governance, risk and compliance controls around sensitive data, get in touch.
Source notes: The data-retention obligations, minimum two-year period, subscriber-information period and encryption requirements are summarised in the Attorney-General’s Department’s industry obligations guidance. The disclosure and privacy oversight information is summarised by the Office of the Australian Information Commissioner. Providers must keep certain disclosure records for three years under the Telecommunications Act record-keeping guidance.
Australia’s mandatory data retention regime applies to certain telecommunications providers, including carriers, carriage service providers and internet service providers that use telecommunications infrastructure in Australia. Providers covered by the regime must retain a prescribed data set and protect it under the Telecommunications (Interception and Access) Act 1979.
The regime concerns information about communications, rather than their content or substance. It requires covered providers to protect retained data through encryption and safeguards against unauthorised interference or access.
Why the law changed
Australia’s data retention regime is intended to ensure that a specified range of telecommunications data remains available for major investigations, including cybercrime, counter-terrorism and child-exploitation offences, rather than being deleted solely because it is no longer needed for ordinary business purposes.
Metadata you must collect
Covered providers must retain the telecommunications data specified in the Act. This includes information about a communication, such as its source, destination, date, time and duration, but not the content or substance of a phone call, email or other communication.
Examples include:
- the source and destination of the communication
- the date, time and duration of the communication
- the type of service used
- information about the location of equipment or the device used.
Some subscriber information must be retained for the life of the account and for a further two years after the account closes. Covered providers should consult the current statutory data set and official guidance for the services they operate.
Who can access the metadata?
Under the Act, ASIO and certain domestic law-enforcement agencies can authorise disclosure of telecommunications data in defined circumstances. Providers must comply with applicable disclosure and record-keeping requirements, and the Office of the Australian Information Commissioner monitors relevant privacy and disclosure-record obligations.
Where to go for help
For current obligations, exemptions, variations and industry guidance, consult the Attorney-General’s Department’s industry obligations guidance. It should be read with the current legislation and is not a substitute for legal advice.
How to simplify data protection
The regime creates two broad compliance priorities:
- collecting and retaining the required telecommunications data
- protecting the confidentiality of retained data.
A practical compliance programme can be organised into four phases:
- Define the scope of the data-retention requirements for your organisation.
- Plan implementation and assess the controls needed to meet those requirements.
- Execute the plan and document the operating procedures.
- Maintain and review the controls as obligations, services and risks change.
Relevant safeguards may include:
- access control
- multi-factor authentication
- logging and auditing
- high availability and resilience
- scalability
- secure implementation practices
- privileged-user protection
- application allow- and block-list controls
- ongoing security monitoring.
If you would like support strengthening governance, risk and compliance controls around sensitive data, get in touch.
Source notes: The data-retention obligations, minimum two-year period, subscriber-information period and encryption requirements are summarised in the Attorney-General’s Department’s industry obligations guidance. The disclosure and privacy oversight information is summarised by the Office of the Australian Information Commissioner. Providers must keep certain disclosure records for three years under the Telecommunications Act record-keeping guidance.
