Lizzie O'Shea 

Tech giants are trying to obliterate privacy. Australia has a rare chance to take back part of their power

‘Pervert glasses’ are selling out, tick-a-box consent is broken and the spectre of surveillance is invading all aspects of our lives
  
  

Mark Zuckerberg, the CEO of Meta, introduces the Oakley Vanguard AI glasses last year
Mark Zuckerberg, the CEO of Meta, introduces the Oakley Vanguard AI glasses last year. Lizzie O’Shea writes: ‘Granting strong legal protections over personal information is one of the most important ways to reshape technology in the interests of the many, not the few.’ Photograph: Bloomberg/Getty Images

A mere five years after the government first started talking about it, new changes have finally been proposed for the Privacy Act. They could not be more overdue and urgent. “Pervert glasses” are selling out at Kmart, facial recognition technology is proliferating in our everyday environments, and microtargeting for advertising has filled our algorithms with nonsense and toxic junk.

Privacy reform is hugely popular: 93% of Australians say protecting personal information is important to them, and 87% say they are more concerned about their privacy than they were five years ago. But it is practically impossible for us to take personal responsibility for our data footprint, especially in the age of AI. Tick-a-box consent is a broken model. Australians rate protecting our personal information as their number one priority for AI regulation.

Granting strong legal protections over personal information is one of the most important and impactful ways to reshape technology in the interests of the many, not the few. Data-extractive business models give rise to all sorts of negative downstream consequences, such as extremist and misleading content, addictive algorithms and careless product design. Privacy law has the capacity to target reform at the source of the problem – the collection, use and storage of personal information. This is far more effective than playing whack-a-mole with the latest exploitative or harmful product built by some avaricious tech bro who has been encouraged by our permissive regulatory environment.

Australia’s privacy laws remain woefully out of date, with the majority having been drafted four decades ago. This latest tranche of reform, if implemented, will be a highly significant improvement, bringing us closer to similar jurisdictions such as Europe and California. At the centre is a fair and reasonable test. This shifts the onus away from individuals to make impossible decisions about consenting to endless terms and conditions, instead posing the question to companies: are you collecting and using this information in a way that is fair and reasonable?

Sign up for the Breaking News Australia email

Interestingly, the government has also opted to introduce certain provisions around the right to erasure. Giving individuals the right to request that data be deleted is hugely important in a context where many people have experienced a data breach involving information they may have shared years before, including with companies they no longer use. It’s also important if you have a particular reason for wanting to delete: for example, you are managing a problem with gambling, and you don’t want that industry or marketing companies to know that about you. There are some carve-outs and limitations in the current proposal, but this next little while offers a great opportunity to convince the government to tighten these up.

While this exposure draft is a welcome step, the government needs to do more. Well-designed rules mean nothing if they are not enforced. The regulator, the Office of the Australian Information Commissioner, is under-resourced and outmatched in size compared to the corporations it supervises. The benefit of a flexible and technology-neutral rule such as the fair-and-reasonable test will include that it can adapt to community expectations over time and specific situations – but only if we allow people the right to enforce it directly in court. Courts have a really important role to play in interpreting and applying the rules: Meta’s recent US$17bn settlement serves as a case in point. Cases brought by people harmed by these companies allow evidence to come to light that can shape effective rule-making by our governments. Perhaps most importantly, they send a chill through boardrooms of companies that have to date banked on escaping the scrutiny of regulators.

This is a problem for another important policy: the digital duty of care. It’s a great idea but it also has to be enforced for it to be meaningful. At present, it would be very difficult for an Australian to sue Meta in the way that has been done in the US, even though the harms we experience are the same. It’s not even clear that the improvements Meta has committed to making as a result of that case will be also made to their Australian service. Such a perverse outcome can be addressed if the government makes it plain that both courts and regulators have a role to play in enforcing privacy rights and the digital duty of care.

The other key concern is the spectre of surveillance creeping into all aspects of our lives. Facial recognition technology is highly invasive and almost entirely unregulated in Australia and, while some aspects of these reforms might touch on this tech, we really need specific rules for such significant technologies. There are pre-existing proposals we could introduce immediately, which are in line with rules in other comparable countries.

Privacy reform may seem wonkish or a lost cause but, in reality, it’s one of the best tools we have to take back power from big tech and creepy companies. This proposal is a great first step but it can’t be the only one.

• Lizzie O’Shea is a lawyer and a founder and chair of Digital Rights Watch. She is the author of Future Histories

 

Leave a Comment

Required fields are marked *

*

*