
"How exposed are Australians, really? A plain-English privacy audit of an ordinary life"
Not legal advice. We're writers, not lawyers — links to primary sources throughout.
How exposed are Australians, really?
Most privacy talk is either reassuring nonsense ("you have nothing to hide") or doom-posting with no detail. This article tries neither. Instead, we'll walk through one ordinary Australian day — wake up, phone, commute, buy something, go online, sleep — and count what the machinery around you records. The short answer: Australia is one of the most surveilled, least legally protected populations in the developed world. The long answer follows.
Layer 1: Your telco keeps a two-year map of your life
Since the Telecommunications (Interception and Access) Amendment (Data Retention) Act 2015 — the data retention scheme — every Australian telco and ISP must keep, for two years: who you called, texted or emailed (and who called you), when, for how long, and the cell tower your phone was attached to when you did it. Not the words you said — the shape of your life. Where you slept, when you woke, who you see on Sundays, which clinic you visited, how long you stayed.
That data isn't locked behind warrants for most agencies. Under the Telecommunications (Interception and Access) Act 1979, "enforcement agencies" can authorise their own access to stored metadata internally — no judge, no warrant. The OAIC's own submission to the parliamentary review recommended restricting the list of agencies and moving to a warrant scheme; the Australian Human Rights Commission went further, recommending the two-year period be significantly reduced. Neither happened in full. Australia remains one of a small number of jurisdictions with a two-year retention floor — the UK runs one year.
And access isn't theoretical. The scheme's oversight history includes agencies using metadata for everything from journalists' sources (which eventually got a special "journalist information warrant" after press-freedom outcry) through to local councils — in 2017 it emerged councils had been rorting the scheme for parking enforcement and dog registration disputes, prompting tightening. The plain-language version: your phone company holds a complete movement diary on you for two years, and dozens of agencies can request a look without a judge ever seeing the request. Our deep-dive on what telcos keep covers the record types in detail.
Layer 2: Your face is becoming a database key
In November 2024 the Privacy Commissioner made a landmark call: Bunnings breached Australians' privacy by scanning every customer's face across dozens of stores, without consent, without notification, and with no less-intrusive alternative considered. Commissioner Carly Kind put it bluntly: "We can't change our face." Bunnings has appealed; the fight continues, but the point stands — the country's biggest hardware chain ran biometric surveillance on shoppers who never agreed to it, and only stopped when the regulator intervened.
Retail is just the visible layer. The government layer is bigger: Services Australia and other agencies run face-matching services against driver licence and passport photo databases under the Intergovernmental Agreement on Identity Matching Services, with the parliamentary review of the Identity Matching Services Bill recording serious privacy concerns from the Human Rights Commission — including that the bill provided privacy safeguards only to some users of the system, not all. Meanwhile police in NSW and Queensland have trialled mobile facial recognition with no clear statutory basis, and the Digital ID app quietly re-centres your face in everyday government dealings.
Add the breaches and it gets worse: your face template, unlike a password, can't be rotated. When biometric databases leak — and they have, both in Australian mega-breaches and at casinos and retailers — you can't order a new face.
Layer 3: The commercial dragnet — you're tracked dozens of times a day
Online, the picture is industrial. The Consumer Policy Research Centre's landmark research found 91% of the top one million websites track their visitors, with data flowing to brokers who build behavioural profiles — and CPRC's consumer research (Not a Fair Trade) found Australians overwhelmingly want collection minimised, but have almost no practical control. Earlier CPRC analysis pegged the tracking count at up to dozens of data-collection events per person per day once apps, ad-tech and real-time bidding are counted.
Regulators know. The ACCC took Google to the Federal Court over misleading location-data settings and Google paid $60 million in penalties — 1.3 million Australian accounts had viewed the misleading screens. But a penalty years after the fact is not a shield. And the risk isn't just advertising: every Australian who has ever been touched by Optus, Medibank or Latitude-style breaches knows the collected data eventually leaks.
Layer 4: The legal gap you're standing in
Here's the structural problem, in plain terms:
- No general privacy right. Unlike the UK, NZ or Europe, Australian common law has no general cause of action for serious invasion of privacy. The Privacy and Other Legislation Amendment Act 2024 (No. 128 of 2024) finally introduced a statutory tort for serious invasions of privacy — a start, not a shield.
- The small business exemption. Businesses with turnover under $3 million are largely exempt from the Privacy Act. That's most cafés, tradies, gyms and salons — the places holding your ID scans, health forms and card records. The parliamentary briefing on the 2024 reform bill confirms the small business exemption was deliberately kept, over the Privacy Commissioner's objections.
- "Fair and reasonable" is coming slowly. The 2024 act introduces a fair-and-reasonable test for data handling, but phased in with weak resourcing behind it — the OAIC has been under-funded for years relative to its enforcement remit.
- Backdoor powers remain on the books. Technical Assistance/Technical Capability notices under the Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 can compel providers to build capabilities — the encryption wars aren't over (see our status piece).
- No GDPR-style deletion right. You can ask for correction in limited cases; there's no general right to have your data erased.
So the deepest vulnerability isn't technical — it's legal. Australians hold the fewest rights over their own data of almost any comparable country.
Layer 5: The breach ledger
The numbers are the grief made visible:
- Optus, 2022 — up to ~9.8 million current and former customers; licence and passport numbers for millions. The OAIC has now sued Optus in the Federal Court, alleging serious interference with privacy.
- Medibank, 2022 — ~9.7 million customers, including intimate health data dumped by the extortionists; OAIC civil penalty proceedings filed.
- Latitude, 2023 — ~14 million records, the largest by volume in Australian history, including 7.9 million driver's licence numbers.
- MediSecure, 2024 — ~12.9 million prescription records, from a company that had already lost its government contract and still held the data — the "data landfill" problem in its purest form.
And the pace isn't slowing: the OAIC reported 1,205 notifiable data breaches in 2025 — the highest since the scheme began, with health providers the worst-hit sector. Services Australia now runs routine data-matching programs against breached organisations — the government itself assumes your breached data will be used against you.
What you can actually do
You can't fix the law from your couch this week. You can shrink your footprint. Honest priorities, roughly in order of value:
- Move off SMS to an E2EE messenger (Signal, or Matrix if you self-host). SMS is the worst channel in Australia — it's carrier-held and metadata-retention-covered.
- De-Google your phone if you can. A GrapheneOS or LineageOS device cuts the biggest single commercial tracking tap in your pocket. Our comparison guide covers the trade-offs.
- Understand what a VPN does and doesn't do. It hides your browsing from your ISP, but a VPN provider operating in Australia can itself be compelled under TOLA — offshore providers with audited no-logs are a different proposition. Details here.
- Carry radio silence when it matters. Faraday shielding for key fobs (relay-attack theft is now routine), phones and laptops: our tested guide covers what actually blocks what. Our faraday keyfob guard, phone pouch and laptop sleeve are stocked for exactly this (we run this store — affiliate disclosure: links to our own products).
- Block physical data siphons. A USB-C data blocker on rentals and public charging, webcam covers at home, and a FIDO2 hardware key so the next credential breach doesn't become your breach.
- Ask businesses why. Before handing over a driver's licence at reception, ask what it's for and how it's stored. Under the Privacy Act (where it applies) collection must be reasonably necessary. The question costs nothing and changes behaviour.
- Complain when it matters. The OAIC takes privacy complaints free of charge — the Bunnings determination started with exactly that kind of process.
The honest conclusion
An ordinary Australian in 2026 is recorded at the phone tower, at the checkout, in the supermarket aisle, by every website, by their government, and by whichever of the hundreds of databases holding their ID documents gets breached next. Most of this is lawful. Much of it would not be lawful in the EU. And the historical response — from the councils' metadata rorting to Bunnings' face scans — shows that without explicit prohibition, the data gets used.
Privacy here isn't something you're given. It's something you build. Start with the two-year map (messenger + phone), then the biometrics (refuse scans where you lawfully can), then the commercial layer (browser and DNS hygiene). You don't need to disappear — you need to stop being the easiest target in the room.
We sell privacy hardware at StealthOz; where we link our own products, that's the disclosure.