Australia’s mandatory data retention regime applies to certain telecommunications providers, including carriers, carriage service providers and internet service providers that use telecommunications infrastructure in Australia. Providers covered by the regime must retain a prescribed data set and protect it under the Telecommunications (Interception and Access) Act 1979.
The regime concerns information about communications, rather than their content or substance. It requires covered providers to protect retained data through encryption and safeguards against unauthorised interference or access.
Australia’s data retention regime is intended to ensure that a specified range of telecommunications data remains available for major investigations, including cybercrime, counter-terrorism and child-exploitation offences, rather than being deleted solely because it is no longer needed for ordinary business purposes.
Covered providers must retain the telecommunications data specified in the Act. This includes information about a communication, such as its source, destination, date, time and duration, but not the content or substance of a phone call, email or other communication.
Examples include:
Some subscriber information must be retained for the life of the account and for a further two years after the account closes. Covered providers should consult the current statutory data set and official guidance for the services they operate.
Under the Act, ASIO and certain domestic law-enforcement agencies can authorise disclosure of telecommunications data in defined circumstances. Providers must comply with applicable disclosure and record-keeping requirements, and the Office of the Australian Information Commissioner monitors relevant privacy and disclosure-record obligations.
For current obligations, exemptions, variations and industry guidance, consult the Attorney-General’s Department’s industry obligations guidance. It should be read with the current legislation and is not a substitute for legal advice.
The regime creates two broad compliance priorities:
A practical compliance programme can be organised into four phases:
Relevant safeguards may include:
If you would like support strengthening governance, risk and compliance controls around sensitive data, get in touch.
Source notes: The data-retention obligations, minimum two-year period, subscriber-information period and encryption requirements are summarised in the Attorney-General’s Department’s industry obligations guidance. The disclosure and privacy oversight information is summarised by the Office of the Australian Information Commissioner. Providers must keep certain disclosure records for three years under the Telecommunications Act record-keeping guidance.
Australia’s mandatory data retention regime applies to certain telecommunications providers, including carriers, carriage service providers and internet service providers that use telecommunications infrastructure in Australia. Providers covered by the regime must retain a prescribed data set and protect it under the Telecommunications (Interception and Access) Act 1979.
The regime concerns information about communications, rather than their content or substance. It requires covered providers to protect retained data through encryption and safeguards against unauthorised interference or access.
Australia’s data retention regime is intended to ensure that a specified range of telecommunications data remains available for major investigations, including cybercrime, counter-terrorism and child-exploitation offences, rather than being deleted solely because it is no longer needed for ordinary business purposes.
Covered providers must retain the telecommunications data specified in the Act. This includes information about a communication, such as its source, destination, date, time and duration, but not the content or substance of a phone call, email or other communication.
Examples include:
Some subscriber information must be retained for the life of the account and for a further two years after the account closes. Covered providers should consult the current statutory data set and official guidance for the services they operate.
Under the Act, ASIO and certain domestic law-enforcement agencies can authorise disclosure of telecommunications data in defined circumstances. Providers must comply with applicable disclosure and record-keeping requirements, and the Office of the Australian Information Commissioner monitors relevant privacy and disclosure-record obligations.
For current obligations, exemptions, variations and industry guidance, consult the Attorney-General’s Department’s industry obligations guidance. It should be read with the current legislation and is not a substitute for legal advice.
The regime creates two broad compliance priorities:
A practical compliance programme can be organised into four phases:
Relevant safeguards may include:
If you would like support strengthening governance, risk and compliance controls around sensitive data, get in touch.
Source notes: The data-retention obligations, minimum two-year period, subscriber-information period and encryption requirements are summarised in the Attorney-General’s Department’s industry obligations guidance. The disclosure and privacy oversight information is summarised by the Office of the Australian Information Commissioner. Providers must keep certain disclosure records for three years under the Telecommunications Act record-keeping guidance.