Cybersecurity Policy Report, Guidance on Age Assurance, Privacy Protection Released in Australia, (Mar 17, 2026)
By Tony Foley
The Office of the Australian Information Commissioner (OAIC) has published new guidance on age assurance technologies to assist entities to ensure Australians’ privacy is protected when they encounter age checks online.
Three months after the inception of the country’s social media minimum age obligation, OAIC has observed significant growth in age checks taking place to give people access to online services. OAIC’s guidance helps entities work through the privacy issues associated with choosing and implementing age assurance methods.
“Age assurance solutions are in many cases fragmented across multiple providers. Entities need to stop and think about the goals of performing an age check, whether it is even necessary in the first place, and ensure strong governance across the ecosystem,” Privacy Commissioner Carly Kind said in a press release today. “Age assurance is not a blank cheque to use personal or sensitive information in all circumstances and must not erode Australians’ privacy rights.”
The guidance specifies that entities should do the following:
Establish whether age checks are needed and take a privacy-by-design approach;
Undertake due diligence to ensure the security of the entity’s age assurance ecosystem;
Assess risk and choose age assurance methods that are proportionate and minimize data collection;
Ensure clear consent requests are used for the collection of sensitive information like biometric templates or for secondary use or disclosure; and
Be transparent in privacy notices and ensure meaningful support is available to individuals at important moments, through a simple and easy-to-access complaint process.
OAIC warned that failure to meet these obligations may constitute “an interference with the privacy of an individual” under the Privacy Act 1988 and trigger compliance or enforcement action.
News: InternationalLegislation DataPrivacy