Australia's Privacy Reform: A Rare Chance to Rein in Big Tech
Australia's Privacy Reform: A Rare Chance to Rein in Big Tech

Five years after the government first began discussions, Australia has finally proposed significant changes to the Privacy Act. The reforms are urgently needed, as 'pervert glasses' sell out at Kmart, facial recognition technology becomes ubiquitous, and microtargeted advertising fills algorithms with toxic content.

Privacy Reform: A Popular and Necessary Step

Privacy reform enjoys overwhelming public support: 93% of Australians say protecting personal information is important to them, and 87% say they are more concerned about privacy than five years ago. However, individual responsibility for data footprints is practically impossible in the age of AI. The tick-a-box consent model is broken, and Australians rank protecting personal information as their top priority for AI regulation.

Lizzie O'Shea, a lawyer and founder of Digital Rights Watch, argues that granting strong legal protections over personal information is one of the most important ways to reshape technology in the interests of the many, not the few. Data-extractive business models lead to negative outcomes such as extremist content, addictive algorithms, and careless product design. Privacy law targets reform at the source – the collection, use, and storage of personal information – rather than playing whack-a-mole with harmful products.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

Key Reforms: Fair and Reasonable Test, Right to Erasure

Australia's privacy laws are woefully outdated, with most drafted four decades ago. The proposed reforms would bring Australia closer to jurisdictions like Europe and California. The centrepiece is a fair and reasonable test, shifting the onus from individuals making impossible consent decisions to companies, asking: is this collection and use of information fair and reasonable?

The government has also introduced provisions for the right to erasure, allowing individuals to request deletion of data. This is crucial for those affected by data breaches or managing problems like gambling, where they don't want industries to know about them. While there are carve-outs, the current proposal offers an opportunity to tighten these protections.

Enforcement Gaps and the Need for Stronger Action

O'Shea notes that well-designed rules mean nothing without enforcement. The Office of the Australian Information Commissioner is under-resourced and outmatched by the corporations it supervises. A flexible rule like the fair-and-reasonable test can adapt to community expectations, but only if individuals can enforce it directly in court. Courts play a vital role in interpreting rules, as seen in Meta's recent US$17bn settlement. Cases brought by harmed individuals bring evidence to light and shape effective rule-making.

This is also relevant to the digital duty of care policy. It must be enforced to be meaningful, but currently, Australians would find it difficult to sue Meta as in the US, despite experiencing similar harms. It's unclear if Meta's improvements from that case will apply to Australian services. The government should make clear that both courts and regulators have roles in enforcing privacy rights and the digital duty of care.

Facial Recognition and the Path Forward

Facial recognition technology remains highly invasive and almost entirely unregulated in Australia. While some reforms touch on this tech, specific rules are needed for such significant technologies. Pre-existing proposals align with rules in comparable countries and could be introduced immediately.

Privacy reform is one of the best tools to take back power from big tech and creepy companies. This proposal is a great first step, but it cannot be the only one.

Pickt after-article banner — collaborative shopping lists app with family illustration