Monday, 08 July 2019 07:53

Encryption law: 'Misunderstanding leading to IT industry concerns' Featured

Encryption law: 'Misunderstanding leading to IT industry concerns' Image by mohamed Hassan from Pixabay

The Department of Home Affairs says it is creating documentation to clarify the intended operation of the encryption law which was passed in December 2018, claiming that companies are concerned about it because they do not have a clear idea of their obligations under the law.

In a 57-page submission to an inquiry into the Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018, Home Affairs said some in the IT industry were also claiming that, due to these concerns, investors had been reluctant to invest in the domestic communications and tech markets.

The department said its communications materials would:

  • "accurately communicate the intended purpose and effect of the legislation;
  • "address the core concerns of industry and investors; and
  • "provide practical examples for how the key measures and safeguards will operate, and the potential impact on different stakeholders."

It also claimed that the new law did not impose any standing obligations on industry or require changes in business practices or product development.

"[The law does not] undermine the security of devices or networks, allow for the construction of decryption capabilities or so-called ‘backdoors’, require companies to jeopardise information security for innocent users or require employees of companies to work in secret without their employer’s knowledge," the submission said.

A review of the encryption law was begun by the Parliamentary Joint Committee on Intelligence and Security as soon as it was passed, on 6 December 2018, with a reporting date of 3 April. It was expected to provide some solace to the technology industry.

But the PJCIS kicked the issue down the road, asking the Independent National Security Legislation Monitor, Dr James Renwick, to review the law and report back by 1 March 2020. The PJCIS will then submit a report to Parliament by 13 April 2020.

The Commonwealth Ombudsman has recommended that the power given to Home Affairs Minister Peter Dutton to redact its reports on the law be removed, but the Home Affair submission defended this by saying it had been created to protect "sensitive information" provided by industry from public disclosure.

"The AFP has raised concerns regarding the need to continue to protect sensitive information from public disclosure in the event of a legislative amendment to remove this power. The Department understands an alternative to the Minister’s redaction power may be to undertake conditional vetting between the Ombudsman and agencies prior to publication. This will leverage the constructive relationships shared by law enforcement agencies and the Ombudsman," the submission said.

It brushed aside the numerous concerns expressed by both Australian and foreign individuals and entities, saying, "International companies and investors looking to engage in the domestic market should have confidence that the legislation establishes no standing obligations on industry, and does not, or indeed cannot, undermine the security of products and devices."

It claimed the law was "supported by strong safeguards and oversight measures that protect business interests and the privacy of Australians, maintains the security of the digital ecosystem and ensure the powers are exercised responsibly".

And it concluded that, "The operation of the Assistance and Access Act to date indicates that overall, the current key settings afford an appropriate balance between the operational needs of agencies, the protection of civil liberties and the interests of providers."


26-27 February 2020 | Hilton Brisbane

Connecting the region’s leading data analytics professionals to drive and inspire your future strategy

Leading the data analytics division has never been easy, but now the challenge is on to remain ahead of the competition and reap the massive rewards as a strategic executive.

Do you want to leverage data governance as an enabler?Are you working at driving AI/ML implementation?

Want to stay abreast of data privacy and AI ethics requirements? Are you working hard to push predictive analytics to the limits?

With so much to keep on top of in such a rapidly changing technology space, collaboration is key to success. You don't need to struggle alone, network and share your struggles as well as your tips for success at CDAO Brisbane.

Discover how your peers have tackled the very same issues you face daily. Network with over 140 of your peers and hear from the leading professionals in your industry. Leverage this community of data and analytics enthusiasts to advance your strategy to the next level.

Download the Agenda to find out more


Sam Varghese

website statistics

Sam Varghese has been writing for iTWire since 2006, a year after the site came into existence. For nearly a decade thereafter, he wrote mostly about free and open source software, based on his own use of this genre of software. Since May 2016, he has been writing across many areas of technology. He has been a journalist for nearly 40 years in India (Indian Express and Deccan Herald), the UAE (Khaleej Times) and Australia (Daily Commercial News (now defunct) and The Age). His personal blog is titled Irregular Expression.



Recent Comments