Serious Privacy
The PICCASO award winning Podcast, for those who are interested in the hottest field of human rights and laws on the digital frontier. Whether you are a professional who wants to learn more about privacy and privacy laws, data protection, GDPR or cyber law or someone who just finds this fascinating, we have topics for you from data management to cybersecurity, from social justice to data ethics and AI and digital identity protection. In-depth information on serious privacy topics including interviews with privacy leadership, privacy culture, serious discussions, and more.
This podcast, hosted by Dr. K Royal, Paul Breitbarth and Ralph O'Brien, features open, unscripted discussions with global privacy professionals (those kitchen table or back porch conversations) where you hear the opinions and thoughts of those who are on the front lines working on the newest issues in handling personal data. Real information on your schedule - because the world needs serious privacy.
Follow us on BlueSky (@seriousprivacy.eu) or LinkedIn
Serious Privacy
Privacy Down Under (with Commissioner Carly Kind)
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Welcome to the Serious Privacy podcast, where Paul Breitbarth and Ralph O'Brien speak with the Privacy Commissioner of Australia, Carly Kind, about the legislative developments in Australia, indigenous privacy, enforcement action on data breaches, and of course the U 16 social media ban.
If you have comments or questions, find us on LinkedIn and Instagram @seriousprivacy, and on BlueSky under @seriousprivacy.eu, @europaulb.seriousprivacy.eu, @heartofprivacy.bsky.app and @igrobrien.seriousprivacy.eu, and email podcast@seriousprivacy.eu. Rate and Review us!
Subscribe today HERE
From Season 6, our episodes are edited by Fey O'Brien. Our intro and exit music is Channel Intro 24 by Sascha Ende, licensed under CC BY 4.0. with the voiceover by Tim Foley.
You're listening to the award-winning Serious Privacy Podcast sponsored by TrustArc. Please welcome your hosts, Paul Breitbart, Ralph O'Brien, and Dr. Kay Royal.
PaulToday's episode is long overdue. You know that in this podcast we like to discuss what is happening in the privacy and data protection community around the globe, but if we are honest, the main focus tends to be on Europe and the United States. No wonder with the co-host from those regions. Today, however, we turn our lens in another direction and we go down under. Our guest today is none other than the Privacy Commissioner of Australia, Carly Kind, a role she has fulfilled for the past two and a half years. And before becoming Commissioner, Carly was the director of the UK-based Ada Laughless Institute, an independent research institute with a mission to ensure data and AI work for people and society. Before that, she had an extensive career as a digital and fundamental rights lawyer, mainly at international organizations and NGOs. My name is Paul Breitbart.
RalphAnd my name is Ralph O'Brien. And I get to say it today, welcome to Serious Privacy. First of all, thank you so much for joining us, Commissioner Carly Kind, which I've got to say is almost a superhero name.
SPEAKER_00Yes, I do try and get my children and family members to call me Commissioner when I can.
RalphIt does sound more formal, but it's also a very nice alliteration, right? Yeah, it's Peter Parker, Scott Summers. I very much, I very much appreciate it. Yeah. And we always start with an unexpected question. We say, are we ready for the unexpected question? But that's a really unfair thing to say. So I'll just jump in today. And my unexpected question today, because Kay isn't here, is what's your hot beverage of choice?
SPEAKER_01My hot beverage of choice is a large, long, black and taken dark black, usually, no milk added, because I have three little kids who still refuse to sleep through the night. So I wake up extremely tired and in need of caffeination every morning.
PaulFair enough. I remember those days well. Paul, mine would be a double espresso, especially this time of day, because we are not recording at our regular hour because of the time difference with Australia. Some double espresso are indeed needed to get up and running for the podcast.
RalphYeah, perhaps one of the reasons why we do sometimes end up being a little bit Europe and uh US focused is mainly for the time difference.
PaulRalph, what is your beverage of choice?
RalphLike most English people, I'm currently enjoying a cup of tea in the morning. Black or white? White, white. We have this expression in the military we call NATO standard, which is white with sugar, right? Disgusting. But I have swapped sugar for honey, because it's more uh more healthy. And in the evenings, I then tend to s to go to a red bush and at the weekend a chai latte. How's that for a full and comprehensive response? Very fancy. Commissioner Kind. We normally start by just giving, I know Paul gave a little bit of background shoe in the introduction, but we normally start by asking our guests to just give a short little biography of how you got here, how you got into this wonderful world that we like to call data protection and privacy.
SPEAKER_01Yeah, absolutely. Thank you. I started out as a lawyer here in Australia, really interested in human rights law, and myself casting abroad out of frustration at the few opportunities there were to work in human rights law at the time in the early 2000s. Now Australia has a few more human rights legislative instruments, but at the time had none, including being the only Western democracy without uh human rights in the constitution or a bill of rights or a human rights act. Yes. I I moved to Europe and worked first in Geneva with the United Nations. I spent some time interning in London at the International Vir Association and started to build a career in human rights law. And then in 2012, I was excited to find an opportunity to segue into technology and human rights law by virtue of an opportunity to take up a role as head of international advocacy at Privacy International, which is a London-based NGO and campaign group, and really was very lucky to get that role at a time in which the organization was growing only from three to four people and was able to be part of that growth that PI went through over the next period of time, including as the issue of privacy really started to raise up the public agenda. So I cut my teeth in privacy law first as a campaigner advocate, later doing strategic litigation at Privacy International, and then went on to work really in an advisory space, both in terms of data protection, advisory for international organizations. So I spent some time, for example, advising UNHCR in West Africa on their data protection frameworks, but also in terms of technology policy, working with NGOs and other organizations, thinking through some of these tricky issues that arise at the issue of at the intersection of technology and human rights, like misinformation, censorship, surveillance and other privacy interferences. And then was really fortunate to get the opportunity to be the founding director of the Ada Lovelace Institute, which was being set up in 2019, to be, I think, what now looks like a very early thought leader on issues of AI and society and how to ensure that AI and its design and deployment serves humanity and not the other way around. And that occupied me for five years. And obviously that job wasn't quite done when I left it and still continues to really occupy my thoughts a lot. But I had the opportunity to take up this role as privacy commissioner, both an exciting personal and professional opportunity. I hadn't been back in Australia for 16 years. So I used the opportunity to move my family here for some time and get my young boys who all had Australian citizenship had but had never lived here, to experience life in Dan Undacks. But also I had been really for the five years that I was at the Ada Lovelace Institute, and even before, often regulation was posited as the answer to many of the rights, issues, and harms and vulnerabilities that we were identifying, including in the context of AI. And I was very intrigued to understand what is it to be on the other side of regulation and how do you make regulation work in a way that advocates such as myself had been anticipating or hoping that regulation would be effective in practice. So it was really about being on the other side of that and understanding how do you regulate in practice in a way that actually meets community expectations and really means something for people. And so that has been the wonderful experience I've been lucky to have since I took up this role.
PaulHow difficult is that reality?
SPEAKER_01A lot more difficult than I think I quite realized, or at least maybe difficult isn't the right word, but much more complex. I think the the architecture of regulation, the intersection of the laws that are on the books with the evidentiary and investigative challenges that exist to establish compliance or non-compliance, then cast against the people, the skills and capabilities you have in your hands and the constraints thereon, as well as the politics, which are also relevant to the work that we do, even as independent regulators. That is a really complex jigsaw puzzle. And it's not as straightforward as I perhaps naively thought from the outside, as saying if something's a law on the books, then it will certainly act as contributing that will be held accountable, they'll be held accountable in timely and effective ways. There's a lot that goes into thinking about how to regulate and when, how to use the resources you have with respect to which entities, with respect to which violation, and also how to have the outsized effect that you need to really have as a small regulator in the context of a global market, immense entities who have priced the cost of litigation into the cost of doing business, and really try to think about how to most effectively achieve your regulatory objectives using all the tools in your toolbox. So it's been a really hugely eye-opening experience. And I'm learning on the job every day, I would say.
RalphWe often hear commissioners say using all the tools in their toolbox. It's something we often hear from the regulators. But for those people who might not be familiar with the sort of Australian law and the Australian Privacy Framework, Privacy Act 88, the 13 apps, perhaps quickly you could tell us what tools you have available because the Australian law is very interesting, almost co-regulatory law. Which is very different from some of the laws we see elsewhere. And of course, and there's the federal nature as well. Some of our previous podcasts hope, people like Nalise and Alexandra have come down to Australia as sort of territory commissioners as well. So how does it all pull together?
SPEAKER_01Yeah, absolutely. It is a complex regulatory landscape. I'd at a high level, the following things are true about the Australian system. It's heavily, it's obviously a common law system, and the contents of the act are very germane to common law systems in the sense that they're highly principles-based. They utilize a lot of concepts that are common in the common law, such as reasonableness, fairness, necessity, both kinds of concepts, which are really effective in making sure that the legislation is highly technology neutral and potentially quite flexible and applicable to different contexts, the downside of which is that it is remains quite high level. So, in terms of providing certainty to entities in terms of what compliance looks like, it's not necessarily clear on the face of the act itself. It requires a lot in the way of guidance and application into particular circumstances. There is also a long-running reform effort to update the act in various ways. But it is, it is, it is very different from the GDPR. And I I really came up with the GDPR as my first kind of data protection framework that I was familiar with. So it has required a shift in thinking and it's less, obviously less codified than the European approach. I think at first glance, I thought it was a lesser framework, but I've come to really appreciate its positives and advantages in terms of what it leaves open, particularly in countering the worst risks that arise in new technologies. But as you say, in addition to the main act, there's a range of other pieces of legislation. I think 39 other pieces of legislation that intersect with the Act. There are bespoke privacy regimes under certain legislative schemes in the fields of health, for example, taxation information, social media, which I know we're going to come to, digital identity and data portability. So there's separate legislative schemes there. Then in terms of jurisdiction, we have the entire private sector is within the remit of the federal act, albeit only those entities with an annual turnover of more than 3 million Australian dollars. So we don't capture small, small enterprises. We do have an extraterrestrial application of the Act. So there's a connection with Australia is required, but not domicile in Australia or anything like that. So we do have, for example, big tech companies within our jurisdiction. And then in terms of government actors, that's where the state territory commonwealth difference applies. So we only regulate federal government agencies. So that would include, for example, the Australian Federal Police or Home Affairs for Immigration, whereas the state and territory regulators regulate state and territory government agencies. And in Australia, those departments provide many of the main essential government services, such as health and education. So that that is the distinction. It is a complicated landscape. And we work pretty closely with our state and territory peers. Each of their separate pieces of legislation are, of course, different from each other and from the Federal Act as well. So it's a privacy professional's dream because there's endless advice to be provided to meets the requirement. But yes, from a compliance perspective, it is a relatively muddled picture at times. And the government's constantly looking for ways to streamline and simplify.
PaulKidding aside, there is also a lot of talk about legislative change. You've recently had a new law. Well, recently in 2024, I believe, a new legislative change come into effect, but there is talk about doing more. Is that to align Australia's legislation more to the trends that we see around the world, or is this really something that is required natively because of things that are happening in Australia or where you as office see that things are not good enough right now?
SPEAKER_01Yeah, it's a great question, Paul. And it's a very kind of storied history to Privacy Act reform, which was first initiated by the Australian Law Reform Commission in 2012, I believe. So we're going on almost 15 years since the concept of reforming the Privacy Act was first contemplated. And the government conducted a reform of a review of the Privacy Act in 2022, and that reported in 2023. So again, almost three years since that more comprehensive review was done. The inciting motivations behind, for example, that 2022 review, I think were twofold. One was around updating the act in light of the digital era, acknowledging that many of the technologies that now pose the largest privacy risks were not in contemplation at the time of the act's adoption in 1988. But I think a branch of the motivation also related to harmonization with other legal frameworks. And of course, at that time, GDPR was certainly one of those reference points. I think there's that Australia doesn't have an adequacy arrangement with the European Union. So that was no doubt a relevant factor. But also just being seen to keep up with the changes in kind of state-of-the-art privacy regulation. In time, in the recent years, I think there has been recognition of other objectives that can be achieved through Privacy Act reform and perhaps acknowledgement of the virtues of the Australian system that might allow it to take complementary but different approaches to the European approach. For example, really the flagship reform that is now under consideration and we expect will be taken forward by the government in the next couple of months is the introduction of a fair and reasonable test to all data processing. And the proposal is to essentially try to address the ineffective nature of current privacy consent processes and terms and condition processes, which put a lot of responsibility on individuals' shoulders and absolve entities themselves of having to do any of the hard work to think through costs and benefits and potential risks and harms to data subjects, but rather just allow individuals to consent away or click away some of the protections that they should otherwise deserve. And so the fair and reasonable test will say, in all the circumstances, in addition to being law, lawful, sorry, collection data collection use and disclosure will have to be fair and reasonable in the circumstances. And what is fair and reasonable will have a range of characteristics associated with it, including the whether the benefits to the individual are outweighed by any of the risks and harms, where the best interests of the child play in, what the individual's reasonable expectations were, et cetera. So I think that's actually, in a way, it's quite a novel way of starting to think about how to strengthen privacy law. And it, I think, what corresponds well with what we're seeing in data protection and privacy discourses, which is increasing appreciation of the intersection between privacy and data protection rights and consumer issues around fairness, around cost, cost of living, access to services, exploitation, predatory services online. I think lots of these are really starting to at least hit the Australian economy in ways that is really problematic and particularly targeting vulnerable communities. And I think by putting fairness right at the heart of privacy regulation, the government hopes, and I think it's the right aspiration to really be about creating a fairer playing field for consumers whose data is being treated like a commodity and who aren't necessarily getting the kind of dividends from that value exchange. It's in a way it's quite a radical change. And then I will stop in a second, appreciate I'm rattling on, but the some of the other changes are more technical or are more in line with that aspiration of aligning with, for example, the GDPR. So, for example, the definition of personal information under Australian law still uses a term which is about an individual rather than relates to the individual. So that will be changed to align with GDPR, for example.
PaulI really like the fairness part because fairness is, of course, also a principle in Article 5 of the GDPR of the UK Data Protection Act as well. But it's only very recently that it seems that data protection authorities really start to care about the fairness part of data processing. So to put it front and center in a legislative reform also really makes it clear to organizations operating in Australia that this is something that they should take into account and that not everything is just about the letter of the law. Ralph, you've been saying this on the podcast before, if you do assessment is not just about ticking the boxes and making sure that you address everything that is in the legislation, but also continuously asking the question, who are we doing this for? Is it what is the interest of the individual here?
RalphRecital one, personal data should be used to serve humankind, right? Yeah. We actually had a court case and I mentioned it on the podcast last week, which is one of the first court cases we've ever seen to actually actually use fairness. It's principle one in the GDPR and the UK GDPR, and fair, lawful, and transparent. But we often don't see fairness talked about enough. Lawful and transparent, sure, but not fairness. And actually I didn't even realise, so I've learned something today that was missing from the apps, the Australian privacy principles.
SPEAKER_01Fairness is there, but the means of collection have to be fair currently. So it's quite a kind of narrow. Yeah. Whereas this is very much going to put it right at the centre of collection and handling altogether.
PaulSo when you spoke about the legislative regime in Australia, for want of a better word, do you have any specific provisions also for the native people of Australia in your legislation? Do they have their own privacy approach maybe? We've spoken to people about Indigenous privacy before and know that Australia has a large Indigenous community. What's the approach there?
SPEAKER_01Yeah, so we don't have specific provisions around Indigenous data, but Indigenous data sovereignty is a very important concept that is and kind of policy and initiative that is well embedded in a range of Australian government departments and initiatives, and certainly something that we have reference to. We have a range of different ways in which we seek to serve Indigenous communities specifically. So, for example, we're currently in the process of ensuring our guidance is available in some Indigenous languages. We're also quite engaged in some of the work that's still being done in Australia about access to records pertaining to the stolen generation of Indigenous individuals in the 50s and 60s and probably as late as the 70s. One of the issues that continues to arise is that privacy protections are sometimes held out as ways of preventing Indigenous people from getting access to the information about their families and their heritage, et cetera. So it's there's kind of a kind of complex web of ways in which Indigenous data sovereignty and Indigenous data rights need to be given attention and really taken forward in Australia. And it's not necessarily through any particular legislative instrument, but rather through various initiatives that are scattered across government departments and within which our own agency participates.
RalphYou mentioned the fact that the regime is somewhat complex. As it goes forward, you mentioned that the fairness change, you mentioned things like the penalty increase, you've mentioned things like looking at it in various tranches to add various sort of rights and freedoms as you've gone forwards. So then how is it regulated to you keep organizations up to date, keep organizations in a place where they can understand the changes and also individuals understanding their the their rights and freedoms? If you're if you've got this law that's constantly evolving, constantly changing, does there be any of you to looking at it wholesale? Get rid of the 88 Act and just bring something new in to consolidate everything? Or are we just going to see these more incremental changes and you updating organizations as as you go forwards?
SPEAKER_01Yeah, I think the the historical preference in Australian legislative history is this kind of updating, tinkering approach. And I'm not sure the Privacy Act gets a pass from that. So to my knowledge, there hasn't been any suggestion of a wholesale change. And that's maybe that's an interesting cultural or legal tradition issue that is different from European approaches, for example. Yeah, it's it is a challenge to say the act has in the last five years, for example, the act has been amended. Amended at least twice, once in 2024 to introduce new enforcement penalties, to introduce a mandate for us to develop a children's online privacy code, to introduce new obligations around disclosure of automated decision-making systems in privacy policies. And then prior to that, in 2022, to increase penalties. And then there are a range of, as I said, bespoke privacy schemes that have been specifically legislated. So the social media minimum age scheme, which you'll know as the social media ban, that legislative scheme, which is contained in the Online Safety Act, has it. Yeah. So look what the way we do it in practice is a set we try to use a kind of range of communications tools. Sometimes we'll use a block to explain a small change to the legislation. Sometimes we'll do bespoke guidance. So we did guidance, for example, on age assurance technologies, guidance on the social media ban. And we try to do things like webinars. We try to provide fact sheets. And where we can, we try to provide templates for collection notices or privacy policies, et cetera. So this year, for example, changes to the money laundering counterrorist financing law came into Australia to bring a range of small and median enterprises within the scope of the Privacy Act. Our jurisdiction expanded by 120,000 organizations overnight. And those organizations had particular needs because they had never had to comply with privacy law before. So we needed really easy, off-the-shelf ways to help them get to compliance. But at the end of the day, we are a small agency where fewer than 200 people, and we need to use our resources in the most efficient and effective way possible. So we do we basically take a risk-based approach to what needs guidance, what needs spelling out, what can be dealt with on an ad hoc basis or in blogs and other forms of guidance material.
RalphThose extra people, as I understand it, real estate professionals, lawyers, accountants, conveyancers, precious metals, stone. Very big in Australia, obviously. Yeah. And then you've got a core around C money and uh AML, CTF.
SPEAKER_01That's right. Exactly. So they now have Privacy Act obligations only insofar as it pertains to their compliance with AML-CTF regulation. But it's quite an important area of privacy regulation, as you'll know, because it traditionally involves the acquisition of identity documents. And what we see in particularly in our administration of the mandatory data breach notification scheme is that in every time there's a large data breach, every entity is sitting on top of copies of passports and ID documents that they do not need to have. And so what we're trying to achieve through that AML CTF regime, which is in one lens expanding obligations to cite identity documents and take copies of them, is to really make sure entities understand what the limits of those obligations are and what the retention requirements are as well.
PaulWell, speaking about data breaches, the Australian National Airline Qantas last year had a very big data break through a third-party platform used by the Contact Centre. And I saw in your recent press releases that you've just concluded the preliminary inquiry into that data breach. And surprisingly for me, you come to the conclusion we're not going to further investigate because basically there is no flesh to the bone here. This is a breach that could have happened to anyone. Nobody did anything particularly wrong. That is not something we hear a lot from data protection commissioners. So I was positively surprised. Let me be clear about that. But maybe you want to shed some more light on your decision there.
SPEAKER_01Yeah, absolutely. So the obligation under Australian law with respect to security is to take reasonable steps in the circumstances to secure personal information. So that's a scalable obligation depending on all the circumstances of the entity. And reasonable steps is a kind of we're still in our in the nasancy of understanding judicial interpretation of reasonable steps in the context of cybersecurity in particular. We've had one case before the courts last year, which concluded we've got two more on foot with respect to the OPTIS data breach of 2022, which was a major data breach that affected many millions of Australians, and the Medibank data breach, which again affected more somewhere around 9 million Australians. So we're still working through some of the earliest cases in terms of what judicial interpretation requires of reasonable steps. But suffice it to say that it's it's not a kind of strict liability provision and it does require an analysis of what steps were taken, whether those steps adequately mitigated the risks. And the fact of having been subject to a data breach in and of itself does not make you run afoul of the law. And I think that's important to recognize that, particularly in this AI-driven era in which we know very well how many vulnerabilities are going, are now being exploited through advanced AI technologies, it may be that an entity takes all reasonable steps and yet is still subject to a cyber hack or attack that could not have been prevented or mitigated. So we wanted to, we obviously saw the immense regulatory need to investigate Qantas, but likewise, when we found ourselves relatively satisfied that they did take reasonable steps, and I'll talk about some of them in a second, we thought it was really important that we took the opportunity to spell out why we decided we're deciding to close down the investigation, chiefly to ensure confidence in our decision making. What we didn't want to happen is that to quietly close down an investigation and then to appear on the back foot when asked what's happening with Qantas. We wanted to be out in the open to spell out exactly how we make decisions about what to investigate and not what not to investigate. In this circumstance, there had been a social engineering attack on a third-party service provider that was based abroad. And so the obligation on Qantas was to manage how that third-party service provider was securing the personal information it held. And we found that Qantas did that relatively robustly, including through visiting on-site visits, the provision of training, the requirement for certain ISO standards to be met by that provider, contractual arrangements and the like. And while we didn't, our report didn't exonerate Qantas, we were able to conclude that in the present moment, the facts of the matter don't warrant our investigation in light of competing priorities and other issues. And of course, in light of the low evidence available to suggest there had been a contravention.
RalphThat's not to say that the Australian law is about teeth on the Australian clinical labs, 5.8 million Australian dollars, uh Meta, 50 million settlement, optus, civil proceedings, medium civil proceedings, clear view AI, determination. It's fair to say that you do have some level of enforcement if you choose to, but I appreciate we're only got a certain amount of time, so we do have to turn to the elephant in the room at some point. Or the rather baby elephant, I should call it, because you little trendsetters you, you have set the world on fire with the under 16 social media ban, which a lot of countries, including the UK, has then followed suit to consider. What's the commission's role in that? Where do you sit and how have you found that whole thing? Because there's some interesting reports coming out now on whether that's been effective or not. So yeah. Over two year commission.
SPEAKER_01It's a fa it's a fascinating case study on policy design, legislative design, and the effect of regulation on market incentives, all sorts of things. And obviously it's still really unfurling, I think, in its early stages. To cast back to the prior to the obligation being legislated, I was publicly speaking out against the notion of a social media ban, primarily for two primary reasons. One is because I didn't like the premise of a ban, which is that social media companies can't be forced to change their platforms into safe spaces, but also that it could catalyse a whole lot of personal information collection that would impact the privacy of every internet user, not only the privacy of children.
RalphYou won't find a disagreement from either.
SPEAKER_01Yeah, yeah, indeed. And I think that is still a really live risk. So I voice those opinions, but the legislation went ahead very rapidly, and I think that's really indicative of the kind of clear policy commitment that existed in the Australian government to get that over the line. And the OAIC became the co-regulator of that scheme alongside the e-Safety Commissioner. And the way that works is that the e-Safety Commissioner regulates the obligation to exclude children from platforms, and the OAIC regulates the privacy protections that are built into the legislation, which include, for example, that you have to immediately delete any personal information collected for the purposes of assuring age, unless you have the individual's consent to keep it. And so we have had very little role to date in actually responding to any complaints or issues that have arisen. We've had very few complaints relating to the privacy protections. And that could probably be attributed to a few factors. I think that's clear from the evidence so far that there's not yet been widespread compliance with the law, and you'll have the facts before you in a way that I don't, in terms of what the figures are suggesting, in terms of how many children are still on the platforms. Some of that I suspect is down to kind of recalcitrance of the platforms themselves to implement the obligation as required. Some of it is no doubt circumvention by children themselves. And some of it is probably due to the kind of technical implementation, which really is differing largely. We're seeing some use of third-party age assurance providers, which is on its face, seems to be highly privacy-preserving in some respects, in the sense that those third-party providers are almost universally doing a pretty good job on data minimization and deletion destruction. But of course, the fact of having to age assure in the first place, many do find to be affronting from a privacy perspective. There is there's also this question of how much age inference is being done or should being being, should be being done on certain platforms. And I think this is something that the age, the e-safety commissioner is really active in trying to understand more. Of course, we know many of these platforms have extensive information about every user and no doubt have the ability to ascertain with it a reasonably good level of accuracy how old a user is and the extent to which they are obliged to do that, and whether the extent to which privacy law prohibits them from doing that is a kind of emerging issue of compliance that is probably going to get more tricky in the coming months. I think we haven't seen widespread rollout of age assurance across the piece. As a user of many social media services here in Australia, I have not encountered any age assurance at any stage. So again, you can put that down to either non-compliance with the law or some kind of in the background age inference that's being done. The fact that I've held a Facebook profile for more than 20 years is likely a factor that means that they're assuring me on the back end and I'm not being made aware of it. But I think the the top-level takeaway is we don't we still don't have a lot of understanding about how entities purport to be complying with this law and whether or not they're doing everything they should be doing.
PaulI'm hearing some investigations on the horizon.
SPEAKER_01Yes, yeah. Hopefully, I'm sure that's right. And and there's a kind of slight lacuna in terms of powers that the e-safety commissioner is trying to address at the moment. I don't necessarily think she had all of the enforcement and investigation powers she needed to have in order to understand compliance. But I I the other thing I'd just observe is I think com you know, community attitudes to privacy in Australia aren't weakening in any way. We see that people are more concerned about their privacy today than they were five years ago, are highly engaged in privacy issues at a kind of community level in Australia. We survey the community every three years that we've just put out our most recent survey, and people care, they care a lot. So I don't think there's an apathy emerging with respect to privacy, even despite things like this. So I think that's important and good to know. I think one of the risks around widespread age assurance is that people have become veneured or used to being asked to identify themselves all the time and stop caring about things like anonymity and privacy, which would be really concerning. So that's positive. And the other positive I would say is I do think that there's a kind of interesting social, cultural impact of the ban that means people are having different conversations at home, things are starting to move in terms of social acceptability, et cetera. But that's obviously a long game. And I think we could also ask whether that's the an appropriate objective for legislation to catalyze cultural change. Maybe it isn't, but it's an interesting aspect of the debate.
PaulI'm hopeful that it would also come at some point with some form of education for minors on on how to deal with social media, especially if they now come of social media age and are allowed to create accounts that because they are so eager to try it, that they don't do so unthinkingly or with without thinking, but have some conscience on do's and don'ts that are also provided to them through their parents, through education, maybe even through the responsibility of the platforms themselves.
SPEAKER_01I think that that's right. The other thing it's worth noting is that we are currently developing the children's online privacy code, which will be brought into effect by December this year. And that we hope will be really complementary to the ban in the sense that it will cover a far greater set of online services. It will extend to gaming, streaming platforms, etc., and will really be about making sure that when children do go online, that they are afforded much higher privacy protections than they have been historically. And indeed than adults are under the current Privacy Act. And I think it's important that, as you say, as children start to come online, they also do, they benefit from that education awareness, but also those protections. It shouldn't just be a free-for-all after they turn 16.
RalphAs we would fall in love, just had a both looked at each other, expecting each other to speak, which I don't think we've ever done on the podcast before. We'd always just jump in. But I was going to say, I think that's probably a perfect place to wrap things up. It's sad that Kay could not join us today.
PaulIn all fairness, it's between 2 and 3 a.m. in the morning now that we're recording for her.
RalphSo it is between 2 and 3 in the morning for us. The love go could goes out to Kay, but in the meantime, it just remains for me to say thank you to Commissioner Carly Kind. And and very much uh appreciated that you've come on and all the best for the way that the complicated web that is Australian data protection law, which must be quite a difficult job to regulate, comes out. Until then, it's goodbye from me.
PaulThank you very much. Goodbye from me as well. We hope to see you in Brussels at the GPA.
SPEAKER_01Absolutely. Look forward to it. Thanks again for having me.
TimSee you next week. Goodbye. Now that was serious privacy. Please subscribe on your favorite podcast app and leave us a review. You can find us on LinkedIn, Instagram, and Blue Sky at Sirious Privacy. Feel free to drop us a question or a comment. We'd love to hear from you.