The Australian Government’s proposed encryption legislation allows law enforcement and security agencies to target encrypted communications using a wide range of methods. These powers can require service providers to build new capabilities, run government software, or facilitate access to targeted devices.
An exposure draft of the legislation explicitly bans the use of “backdoors” or “systemic weaknesses or vulnerabilities” to access encrypted communications.
“The Australian government has no interest in undermining systems that protect the fundamental security of communications,” the draft states. “The new powers will have no effect to the extent that requirements would reasonably make electronic services, devices or software vulnerable to interference by malicious actors.”
The government also affirmed it will not stop tech providers from patching vulnerabilities that law enforcement agencies might otherwise exploit. Providers remain free—and are encouraged—to update their systems to ensure maximum user security.
Navigating Complex Tech Legislation & Compliance Skills
Implementing new compliance measures, building government-requested capabilities, and securing complex digital infrastructures require deep expertise in software engineering and cyber law. Whether you are managing software engineering teams or securing critical systems, partnering with specialists in IT recruitment helps organisations acquire talent capable of handling shifting legal and technical landscapes.
We connect top businesses and government suppliers with pre-vetted cybersecurity, software development, and network architecture specialists through our regional teams:
-
IT recruitment in Melbourne – Sourcing senior software engineers, system architects, and compliance leads.
-
IT recruitment in Sydney – Connecting organisations with cyber threat intelligence analysts and enterprise security specialists.
-
IT recruitment in Adelaide – Finding clearance-ready defence tech contractors, systems developers, and network engineers.
Three Forms of Technical Assistance Notices
Under a proposed new Part 15 of the Telecommunications Act, investigators can use a tiered framework depending on provider cooperation and technical capabilities:
1. Technical Assistance Request (TAR)
A voluntary request issued by select agencies asking a service provider to assist using their existing capabilities or to build a new one to help an investigation.
2. Technical Assistance Notice (TAN)
A compulsory notice issued where a provider already has the “existing means to decrypt” communications—such as holding the encryption key for non-end-to-end encrypted messaging. These can be requested by the head of ASIO or senior delegation officers in law enforcement.
3. Technical Capability Notice (TCN)
Reserved for the Attorney-General, this notice compels a provider to build a completely new technical capability to assist law enforcement. Providers receive 28 days to outline whether the requested build is technically feasible.
Note: These notices can be served for criminal and national security investigations, as well as matters relating to “protecting the public revenue”. In all instances, investigators still require an underlying warrant or authorisation to view content. Negotiated costs for assistance will be covered by the government rather than absorbed by the provider.
Section 317E: Scope of Technical Assistance
Section 317E outlines the specific actions agencies can require from non-voluntary providers. Expected forms of assistance include:
-
Removing Electronic Protections: Removing electronic protection measures applied by or on behalf of the provider.
-
Technical Information & Access: Providing technical specifications, facilitating access to facilities, services, equipment, or software.
-
Software Deployment: Installing, testing, maintaining, or using specialised software or equipment.
-
Capability & Service Modification: Modifying or substituting service characteristics, or assisting with technology development.
-
System Notifications: Notifying agencies of specific changes or technical developments affecting their services.
Who Fall Under the Legislation’s Scope?
The proposed laws cover a broad definition of “designated communications providers,” capturing almost every participant in the global communications supply chain operating in Australia:
-
Carriers, carriage service providers, and over-the-top (OTT) messaging services.
-
Telecommunications software suppliers, regardless of code size.
-
Facility builders, operators, hardware component manufacturers, and data centres housing points of presence (PoPs).
-
Manufacturers and installers of customer premises equipment (CPE) and data processing devices.
New Computer Access Warrants & Industry Reactions
A separate power inserted into the Surveillance Devices Act 2004 introduces computer access warrants. Approved by a judge or AAT member, these warrants allow agencies to covertly enter premises, access devices, copy data, and conceal their activities. They do not, however, permit altering or deleting data that would interfere with lawful computer usage.
Opposition Concerns
The legislation has faced opposition from privacy advocates and political leaders. Greens Senator Jordon Steele-John criticised the plan, stating it undermines end-to-end encryption principles:
“Installing malware on people’s devices to read encrypted data is not a solution to catching criminals, but it is weakening the defences of every single device that receives encrypted messages, therefore making it easier for criminals who want to steal data.”
https://www.itnews.com.au/news/govt-finally-reveals-how-it-plans-to-target-encryption-500156