Australia's proposed 'Digital Duty of Care' for online services – filling some gaps in Australia's privacy protections
16 September 2026
On 8 September 2026, the Australian Government released an exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026 (the Digital Duty of Care Bill).
Communications Minister Anika Wells introduced the draft, describing it as extending basic safety-by-design standards to online products.
The Digital Duty of Care Bill proposes a number of changes to the Online Safety Act 2021 (Cth) (Online Safety Act). These changes, if the Digital Duty of Care Bill passes, include the following:
- The introduction of a digital duty of care, requiring persons responsible for online services[1] to ensure a safe online environment, including by undertaking risk assessments to identify reasonably foreseeable risks of harm to Australian users.
- Additional protections for children on social media — specified design features (including algorithmic recommender feeds, endless feeds and feedback features) should not operate for users under 16 years of age
- The creation of ‘user empowerment tools’, which will allow a user of an online service to manage the way design features of the relevant service operate for the user. This may include, for example, the option to view content in a non-algorithmically curated order. The intention is to use Ministerial legislative instruments to require specified online services to provide specified user empowerment tools (promoted by the Government under the slogan ‘My Feed, My Way’).
- Greater enforcement powers for the eSafety Commissioner.
- The creation of faster takedown mechanisms for harmful online content, as well as the introduction of new search engine ‘link deletion powers’.
The Digital Duty of Care Bill expands on the Online Safety Amendment (Digital Duty of Care) Bill 2024 that was introduced into Parliament in November 2024 but lapsed when Parliament dissolved in 2025.
Filling the gaps in the proposed Tranche 2 Privacy Act amendments
As noted in our previous article, a number of key recommendations that Government agreed to in its response to the Attorney-General’s Department’s Privacy Act Review Report of 2022 (2022 Review) are absent from the Tranche 2 Privacy Act amendments exposure draft (Privacy Act amendment exposure draft) released on 31 August 2026.
Notable omissions include:
- no requirement for all APP entities to conduct a Privacy Impact Assessment for high privacy risk projects; and
- no general right to erasure – the Privacy Act amendment exposure draft creates an individual right to erasure that only applies to large digital platforms, as defined in the exposure draft.
The Digital Duty of Care Bill, if passed by Parliament, will create further complementary protections for individuals in their dealings with providers of online services, and will address several of the gaps present in the Privacy Act amendment exposure draft, although only in relation to online service providers. These protections will also indirectly support the Government give effect to its obligations under Article 17 of the International Covenant on Civil and Political Rights.
New requirement for digital duty of care risk assessments
Through the creation of a ‘Digital duty of care’, and the creation of an onus on online services to provide a safe online environment (so far as is reasonably practicable), a person who provides an online service must conduct a written risk assessment identifying factors that include the following:
- all reasonably foreseeable risks, including those relevant to the provider’s digital duty of care
- the content that gives rise to those risks
- the design features of the service that give rise to those risks
- other systems or processes that give rise to those risks
- persons who may be affected by those risks
Assessments must assess the likelihood and potential severity of such reasonably foreseeable risks, as well as document the measures implemented to address them.
Providers must also record the expected effectiveness (and expected duration) of those measures, and meet any additional requirements determined by the eSafety Commissioner as to the manner, form, detail, standards or benchmarks applicable to the assessment.
Assessments must build in regular review and reassessment of the effectiveness of the measures adopted, be at least annual (or more frequent), be completed before any change that could introduce new risks, retained for six years and be made available to the eSafety Commissioner within 30 days on request.
While the Privacy Act amendment exposure draft does not universalise the requirement to undertake PIAs for high-risk privacy projects, the Digital Duty of Care Bill introduces a comparable risk-based assessment requirement, as outlined above.
We note that this obligation only applies to online service providers and is framed around ‘harm’ broadly and not specifically regarding privacy. However, it does appear that if there are reasonably foreseeable privacy risks to individuals then this would form part of the risk assessment required to be undertaken to comply with the Digital Duty of Care Bill’s new risk assessments. It therefore appears reasonable to say that the Digital Duty of Care Bill will create further privacy obligations for online service providers.
Enhanced content removal powers
Under the Privacy Act amendment exposure draft, the proposed new limited right to erasure (which provides individuals with a right to require large digital platforms to erase personal information that relates to the individual), applies only to large digital platforms.
Large digital platforms are defined in the Privacy Act amendment exposure draft as providers of a social media service, relevant electronic service or designated internet service (within the meaning of the Online Safety Act) with gross revenue of at least $500m, and/or an average of 2.5 million monthly Australian users or are prescribed by regulation. Accordingly, this right does not extend to all APP entities, contrary to the Government's earlier in-principle agreement to Proposal 18.3 of the 2022 Review.
While the Digital Duty of Care Bill does not create an expanded individual right to erasure, it does expand regulator-directed content removal powers including the following:
- a compressed 24-hour compliance window (down from 48 hours) for cyber-bullying, non-consensual intimate image and cyber-abuse removal notices, and
- new search-engine link-deletion notice powers across each of the cyber-bullying, intimate-image and cyber-abuse regimes.
The combination of the Privacy Act amendment exposure draft and the Digital Duty of Care Bill therefore further strengthen individual rights to have material containing their personal information, or material that is otherwise harassing them, to be removed.
Next steps
While it remains to be seen whether the Digital Duty of Care Bill will pass Parliament in its current form, entities who may be affected by the bill may wish to consider their existing risk assessment and content moderation processes. This bill further strengthens individual rights in relation to their interactions with online service providers and further has the effect of filling gaps in relation to privacy protections in Australia.
If you require advice on the Digital Duty of Care Bill, or otherwise require advice regarding your privacy obligations, please do not hesitate to contact Chantal Tipene or Kelly Matheson, and our team of privacy experts will be happy to assist you.
[1] ‘Online service’ will be defined broadly to include entities such as social media platforms, messaging apps, online games, dating services, certain general websites and apps, certain generative AI services, hosting services, internet service providers, search engines, app stores, and certain equipment and operating system providers.
