Australia's digital regulation landscape is evolving rapidly, with major reforms across privacy, artificial intelligence (AI), online safety, cybersecurity, children's rights, automated decision-making and digital duty of care obligations. Understanding how these regulations intersect is critical for organisations managing digital risk, compliance and technology governance.
While each reform has its own scope and implementation timetable, they are increasingly interconnected. Organisations must look beyond individual compliance obligations and understand where regulatory requirements overlap, converge and create new risks. A coordinated approach to digital regulation and compliance can help organisations manage regulatory change, strengthen governance frameworks and prepare for future technology regulation in Australia.
Australia's Privacy Act reform process has reached a critical milestone after more than three years of review, consultation, and incremental legislative action.
Read More
Automated decision-making: preparing for the new transparency obligation
With transparency obligations set to commence on 10 December 2026 and broader reforms on the horizon, organisations captured by the Privacy Act and the Australian Privacy Principles need to understand where automation influences key decisions and ensure they are ready to comply.
Read More
OAIC's Children's Online Privacy exposure draft: from consultation to code
Proposed Privacy (Children's Online Privacy) Code 2026 would represent a significant shift in the Australian regulatory landscape for any organisation whose digital products and services involve the collection, use or disclosure of children’s personal information.
Read More
Social media use in Australia to be restricted for under 16s
Australia has introduced a world-first social media ban for under 16-year olds. Certain social media platforms are required to take reasonable steps to prevent Australian children under the age of 16 from having accounts on their platform.
Read More
The new statutory tort for serious invasions of privacy
The proposed statutory tort, part of the federal government’s Privacy Act reforms, brings with it new risks for businesses, who may be liable directly, or in certain circumstances vicariously liable through the conduct of their employees or agents.
Read More
Privacy Act reforms: work to be done, but more to come
The first tranche of the Privacy Act reforms included the introduction of a Children’s Online Privacy Code and a statutory tort for serious invasions of privacy, as well as the creation of new penalties for less serious infringements of the Privacy Act.
Read More
Data and Privacy
We are engaged by some of the world’s leading technology companies to assist with their data governance requirements, including application of the GDPR to Australian companies, Australian privacy law compliance, regulatory investigations, arrangements with data processors and marketing activities.
View capability