Header illustration for "Metadata retention in Australia 2026: what your telco keeps, what a VPN changes"

"Metadata retention in Australia 2026: what your telco keeps, what a VPN changes"

Metadata retention in Australia 2026: what your telco keeps, what a VPN changes

A decade after it passed, Australia's mandatory data retention scheme is still the quiet backbone of Australian surveillance law. Almost every internet user generates records under it every day, and most people still don't know exactly what's being collected, who can look at it, or what a VPN actually does about it. Here's the state of play as of October 2026.

What the scheme requires

Part 5-1A of the Telecommunications (Interception and Access) Act 1979 (TIA Act), introduced by the 2015 Data Retention Act, obliges every carrier and carriage service provider to retain a defined dataset for two years. The categories are set out in s 187A: subscriber details, the source and destination of a communication, the date, time and duration of a communication, device identifiers, and the location of the equipment used. Content is not retained, and neither is browsing history — the 2015 scheme deliberately excluded the specific web address accessed. (TIA Act, Part 5-1A, Telecommunications (Interception and Access) Amendment (Data Retention) Act 2015, Home Affairs data retention guideline)

Retained, reviewed, retained again

The scheme was meant to be reviewed continuously, and it has been. The Parliamentary Joint Committee on Intelligence and Security (PJCIS) reviewed the mandatory data retention regime in the last parliament and the committee's report came down on the side of retaining the scheme while tightening oversight — and the government response accepted that the review would recur. A further review of the regime is before the PJCIS in the current parliament, so the "repeal or retain" question is genuinely still live in Canberra rather than settled. (PJCIS review of the mandatory data retention regime, Government response to the PJCIS)

Separately, the Telecommunications and Other Legislation Amendment Act 2025 (assented 4 November 2025) changed how retained-adjacent information flows: protected network activity warrant information can now be used for prosecution decisions and disclosure in criminal proceedings, and prescribed agencies get limited access to stored communications for interception-capability development and testing. Industry body the Internet Association of Australia described parts of the bill as "function creep" and asked for it to be withdrawn and redrafted with full consultation. (Bills Digest No. 17, 2025-26, TOLAOLA Act 2025)

Who enforces it

The ACMA polices the industry obligations. Its recent record is mixed but real: Telstra paid a $2.5 million penalty for large-scale failures relating to customer data handling in the silent and unlisted number database, and Aussie Broadband paid $213,120 for record-keeping failures affecting an emergency and law-enforcement directory. In 2026 Telstra paid a further $277,200 over skipped identity checks on unauthorised SIM swaps. ACMA also reports annually on telco costs and compliance with Part 5-1A itself. (iTnews, TechPartner, ACMA Telcos and law enforcement report 2023-24)

What a VPN does — and doesn't do

A VPN shifts the point where your traffic meets the internet. Your ISP sees only an encrypted tunnel to the VPN server, so the destination-server IPs you visit aren't in your ISP's retained dataset. That's the honest core of the "VPN defeats metadata retention" pitch.

But three caveats matter. First, your telco still retains your subscriber records, billing, device identifiers, cell-tower location data and the fact and timing of your connections — none of that disappears behind a VPN. Second, a VPN moves your metadata to the VPN provider; if that provider logs (or sits in a jurisdiction that compels logging), you've changed who holds the data, not whether it exists. Third, application-level data — email headers, DNS handled outside the tunnel, messaging-app accounts — can still identify what you did. A VPN is a useful tool for one specific slice of the retained dataset, not an exemption from the scheme.

Practical takeaways

This article is general information, not legal advice.


Further reading in this series: Australia's encryption wars in 2026 covers the TOLA powers that govern access to communications, and our threat model guide explains how to reason about what you actually need to protect.

← All posts