A Quick Guide to Australia’s Data Retention Laws

Ajay Unni
Ajay Unni CEO,StickmanCyber
September 5, 2026 5 min read

Australia’s mandatory data retention regime applies to certain telecommunications providers, including carriers, carriage service providers and internet service providers that use telecommunications infrastructure in Australia. Providers covered by the regime must retain a prescribed data set and protect it under the Telecommunications (Interception and Access) Act 1979.

The regime concerns information about communications, rather than their content or substance. It requires covered providers to protect retained data through encryption and safeguards against unauthorised interference or access.

Why the law changed

Australia’s data retention regime is intended to ensure that a specified range of telecommunications data remains available for major investigations, including cybercrime, counter-terrorism and child-exploitation offences, rather than being deleted solely because it is no longer needed for ordinary business purposes.

Metadata you must collect

Covered providers must retain the telecommunications data specified in the Act. This includes information about a communication, such as its source, destination, date, time and duration, but not the content or substance of a phone call, email or other communication.

Examples include:

  • the source and destination of the communication
  • the date, time and duration of the communication
  • the type of service used
  • information about the location of equipment or the device used.

Some subscriber information must be retained for the life of the account and for a further two years after the account closes. Covered providers should consult the current statutory data set and official guidance for the services they operate.

Who can access the metadata?

Under the Act, ASIO and certain domestic law-enforcement agencies can authorise disclosure of telecommunications data in defined circumstances. Providers must comply with applicable disclosure and record-keeping requirements, and the Office of the Australian Information Commissioner monitors relevant privacy and disclosure-record obligations.

Where to go for help

For current obligations, exemptions, variations and industry guidance, consult the Attorney-General’s Department’s industry obligations guidance. It should be read with the current legislation and is not a substitute for legal advice.

How to simplify data protection

The regime creates two broad compliance priorities:

  1. collecting and retaining the required telecommunications data
  2. protecting the confidentiality of retained data.

A practical compliance programme can be organised into four phases:

  1. Define the scope of the data-retention requirements for your organisation.
  2. Plan implementation and assess the controls needed to meet those requirements.
  3. Execute the plan and document the operating procedures.
  4. Maintain and review the controls as obligations, services and risks change.

Relevant safeguards may include:

  • access control
  • multi-factor authentication
  • logging and auditing
  • high availability and resilience
  • scalability
  • secure implementation practices
  • privileged-user protection
  • application allow- and block-list controls
  • ongoing security monitoring.

If you would like support strengthening governance, risk and compliance controls around sensitive data, get in touch.

Source notes: The data-retention obligations, minimum two-year period, subscriber-information period and encryption requirements are summarised in the Attorney-General’s Department’s industry obligations guidance. The disclosure and privacy oversight information is summarised by the Office of the Australian Information Commissioner. Providers must keep certain disclosure records for three years under the Telecommunications Act record-keeping guidance.

Australia’s mandatory data retention regime applies to certain telecommunications providers, including carriers, carriage service providers and internet service providers that use telecommunications infrastructure in Australia. Providers covered by the regime must retain a prescribed data set and protect it under the Telecommunications (Interception and Access) Act 1979.

The regime concerns information about communications, rather than their content or substance. It requires covered providers to protect retained data through encryption and safeguards against unauthorised interference or access.

Why the law changed

Australia’s data retention regime is intended to ensure that a specified range of telecommunications data remains available for major investigations, including cybercrime, counter-terrorism and child-exploitation offences, rather than being deleted solely because it is no longer needed for ordinary business purposes.

Metadata you must collect

Covered providers must retain the telecommunications data specified in the Act. This includes information about a communication, such as its source, destination, date, time and duration, but not the content or substance of a phone call, email or other communication.

Examples include:

  • the source and destination of the communication
  • the date, time and duration of the communication
  • the type of service used
  • information about the location of equipment or the device used.

Some subscriber information must be retained for the life of the account and for a further two years after the account closes. Covered providers should consult the current statutory data set and official guidance for the services they operate.

Who can access the metadata?

Under the Act, ASIO and certain domestic law-enforcement agencies can authorise disclosure of telecommunications data in defined circumstances. Providers must comply with applicable disclosure and record-keeping requirements, and the Office of the Australian Information Commissioner monitors relevant privacy and disclosure-record obligations.

Where to go for help

For current obligations, exemptions, variations and industry guidance, consult the Attorney-General’s Department’s industry obligations guidance. It should be read with the current legislation and is not a substitute for legal advice.

How to simplify data protection

The regime creates two broad compliance priorities:

  1. collecting and retaining the required telecommunications data
  2. protecting the confidentiality of retained data.

A practical compliance programme can be organised into four phases:

  1. Define the scope of the data-retention requirements for your organisation.
  2. Plan implementation and assess the controls needed to meet those requirements.
  3. Execute the plan and document the operating procedures.
  4. Maintain and review the controls as obligations, services and risks change.

Relevant safeguards may include:

  • access control
  • multi-factor authentication
  • logging and auditing
  • high availability and resilience
  • scalability
  • secure implementation practices
  • privileged-user protection
  • application allow- and block-list controls
  • ongoing security monitoring.

If you would like support strengthening governance, risk and compliance controls around sensitive data, get in touch.

Source notes: The data-retention obligations, minimum two-year period, subscriber-information period and encryption requirements are summarised in the Attorney-General’s Department’s industry obligations guidance. The disclosure and privacy oversight information is summarised by the Office of the Australian Information Commissioner. Providers must keep certain disclosure records for three years under the Telecommunications Act record-keeping guidance.

Ajay Unni

Ajay Unni

CEO,StickmanCyber Ajay Unni is CEO of StickmanCyber, leading the team in delivering cybersecurity, risk, and compliance solutions. He holds a Master of IT and a Bachelor of Computer Science, is a PCI Qualified Security Assessor and Certified Information Systems Auditor, and has served as CREST Vice Chairman and a member of the NSW Government Cyber Security Taskforce. With over 25 years in the industry, Ajay is a sought-after voice on the Australian cyber threat landscape.

Master of IT B. Computer Science PCI Qualified Security Assessor Certified Information Systems Auditor (CISA) CREST Vice Chairman NSW Gov Cyber Security Taskforce

Cybersecurity As A Service for Australian Organisations

StickmanCyber helps mid-market businesses across Australia and New Zealand reduce cyber risk, strengthen compliance, and build security maturity without the cost and complexity of managing it all internally.

Combining experienced cybersecurity specialists with AI-powered delivery, StickmanCyber provides practical, Cyber Done support across risk assessments, compliance, remediation, and ongoing protection — acting as a trusted partner from strategy through to certification and beyond.

CREST Accredited PCI-DSS ISO 27001 Essential Eight Since 2006
Book a free consultation
Risk Assessment & Essential EightUnderstand your current maturity and gaps
Compliance & CertificationISO 27001, PCI DSS, SOC 2 and more
Penetration & VAPTFind gaps, strengthen controls, build resilience
24/7 Monitoring via StickSecureContinuous visibility across your environment

Recent Posts