Header illustration for "How exposed are Australians, really? A plain-English privacy audit of an ordinary life"

"How exposed are Australians, really? A plain-English privacy audit of an ordinary life"

Not legal advice. We're writers, not lawyers — links to primary sources throughout.

How exposed are Australians, really?

Most privacy talk is either reassuring nonsense ("you have nothing to hide") or doom-posting with no detail. This article tries neither. Instead, we'll walk through one ordinary Australian day — wake up, phone, commute, buy something, go online, sleep — and count what the machinery around you records. The short answer: Australia is one of the most surveilled, least legally protected populations in the developed world. The long answer follows.

Layer 1: Your telco keeps a two-year map of your life

Since the Telecommunications (Interception and Access) Amendment (Data Retention) Act 2015 — the data retention scheme — every Australian telco and ISP must keep, for two years: who you called, texted or emailed (and who called you), when, for how long, and the cell tower your phone was attached to when you did it. Not the words you said — the shape of your life. Where you slept, when you woke, who you see on Sundays, which clinic you visited, how long you stayed.

That data isn't locked behind warrants for most agencies. Under the Telecommunications (Interception and Access) Act 1979, "enforcement agencies" can authorise their own access to stored metadata internally — no judge, no warrant. The OAIC's own submission to the parliamentary review recommended restricting the list of agencies and moving to a warrant scheme; the Australian Human Rights Commission went further, recommending the two-year period be significantly reduced. Neither happened in full. Australia remains one of a small number of jurisdictions with a two-year retention floor — the UK runs one year.

And access isn't theoretical. The scheme's oversight history includes agencies using metadata for everything from journalists' sources (which eventually got a special "journalist information warrant" after press-freedom outcry) through to local councils — in 2017 it emerged councils had been rorting the scheme for parking enforcement and dog registration disputes, prompting tightening. The plain-language version: your phone company holds a complete movement diary on you for two years, and dozens of agencies can request a look without a judge ever seeing the request. Our deep-dive on what telcos keep covers the record types in detail.

Layer 2: Your face is becoming a database key

In November 2024 the Privacy Commissioner made a landmark call: Bunnings breached Australians' privacy by scanning every customer's face across dozens of stores, without consent, without notification, and with no less-intrusive alternative considered. Commissioner Carly Kind put it bluntly: "We can't change our face." Bunnings has appealed; the fight continues, but the point stands — the country's biggest hardware chain ran biometric surveillance on shoppers who never agreed to it, and only stopped when the regulator intervened.

Retail is just the visible layer. The government layer is bigger: Services Australia and other agencies run face-matching services against driver licence and passport photo databases under the Intergovernmental Agreement on Identity Matching Services, with the parliamentary review of the Identity Matching Services Bill recording serious privacy concerns from the Human Rights Commission — including that the bill provided privacy safeguards only to some users of the system, not all. Meanwhile police in NSW and Queensland have trialled mobile facial recognition with no clear statutory basis, and the Digital ID app quietly re-centres your face in everyday government dealings.

Add the breaches and it gets worse: your face template, unlike a password, can't be rotated. When biometric databases leak — and they have, both in Australian mega-breaches and at casinos and retailers — you can't order a new face.

Layer 3: The commercial dragnet — you're tracked dozens of times a day

Online, the picture is industrial. The Consumer Policy Research Centre's landmark research found 91% of the top one million websites track their visitors, with data flowing to brokers who build behavioural profiles — and CPRC's consumer research (Not a Fair Trade) found Australians overwhelmingly want collection minimised, but have almost no practical control. Earlier CPRC analysis pegged the tracking count at up to dozens of data-collection events per person per day once apps, ad-tech and real-time bidding are counted.

Regulators know. The ACCC took Google to the Federal Court over misleading location-data settings and Google paid $60 million in penalties — 1.3 million Australian accounts had viewed the misleading screens. But a penalty years after the fact is not a shield. And the risk isn't just advertising: every Australian who has ever been touched by Optus, Medibank or Latitude-style breaches knows the collected data eventually leaks.

Layer 4: The legal gap you're standing in

Here's the structural problem, in plain terms:

So the deepest vulnerability isn't technical — it's legal. Australians hold the fewest rights over their own data of almost any comparable country.

Layer 5: The breach ledger

The numbers are the grief made visible:

And the pace isn't slowing: the OAIC reported 1,205 notifiable data breaches in 2025 — the highest since the scheme began, with health providers the worst-hit sector. Services Australia now runs routine data-matching programs against breached organisations — the government itself assumes your breached data will be used against you.

What you can actually do

You can't fix the law from your couch this week. You can shrink your footprint. Honest priorities, roughly in order of value:

  1. Move off SMS to an E2EE messenger (Signal, or Matrix if you self-host). SMS is the worst channel in Australia — it's carrier-held and metadata-retention-covered.
  2. De-Google your phone if you can. A GrapheneOS or LineageOS device cuts the biggest single commercial tracking tap in your pocket. Our comparison guide covers the trade-offs.
  3. Understand what a VPN does and doesn't do. It hides your browsing from your ISP, but a VPN provider operating in Australia can itself be compelled under TOLA — offshore providers with audited no-logs are a different proposition. Details here.
  4. Carry radio silence when it matters. Faraday shielding for key fobs (relay-attack theft is now routine), phones and laptops: our tested guide covers what actually blocks what. Our faraday keyfob guard, phone pouch and laptop sleeve are stocked for exactly this (we run this store — affiliate disclosure: links to our own products).
  5. Block physical data siphons. A USB-C data blocker on rentals and public charging, webcam covers at home, and a FIDO2 hardware key so the next credential breach doesn't become your breach.
  6. Ask businesses why. Before handing over a driver's licence at reception, ask what it's for and how it's stored. Under the Privacy Act (where it applies) collection must be reasonably necessary. The question costs nothing and changes behaviour.
  7. Complain when it matters. The OAIC takes privacy complaints free of charge — the Bunnings determination started with exactly that kind of process.

The honest conclusion

An ordinary Australian in 2026 is recorded at the phone tower, at the checkout, in the supermarket aisle, by every website, by their government, and by whichever of the hundreds of databases holding their ID documents gets breached next. Most of this is lawful. Much of it would not be lawful in the EU. And the historical response — from the councils' metadata rorting to Bunnings' face scans — shows that without explicit prohibition, the data gets used.

Privacy here isn't something you're given. It's something you build. Start with the two-year map (messenger + phone), then the biometrics (refuse scans where you lawfully can), then the commercial layer (browser and DNS hygiene). You don't need to disappear — you need to stop being the easiest target in the room.

We sell privacy hardware at StealthOz; where we link our own products, that's the disclosure.

← All posts