Skip to main content
Rules Mate

Telco data retention — 2 years (Part 5-1A Telecommunications Act)

Carriers + CSPs must retain telco metadata for 2 years.

highcurrentongoingCriminal liability

Who must comply

Carriers, internet service providers and providers of any service declared by the Minister, where the service carries communications by electromagnetic energy and the provider owns or operates infrastructure in Australia for its relevant services. Broadcasting services are excluded, and services provided only to an immediate circle or within a single area are excluded unless declared (s 187B).

What triggers it

Operating a relevant service under s 187A(3) that carries communications for customers.

When due

Ongoing. Subscriber and account information must be kept until 2 years after the account closes; all other required data for 2 years after it came into existence (s 187C).

Evidence required

Data retention design mapping each s 187AA data item to the systems that create and store it; retention schedules (2 years, or 2 years after account closure); encryption and access controls over retained data; any approved data retention implementation plan or Communications Access Coordinator exemption; Privacy Act handling procedures for retained data.

Max penalty

Section 187A(1), and the duty to comply with an approved implementation plan (s 187D(a)), are civil penalty provisions for the purposes of the Telecommunications Act 1997, whose Parts 31 and 31B provide for pecuniary penalties and infringement notices

Who must comply with this? The applicability test by industry, business structure and size.

Summary

Part 5-1A of the Telecommunications (Interception and Access) Act 1979 (s 187A) requires a service provider that operates a relevant service to keep specified telecommunications data about every communication carried by the service. The data set in s 187AA covers subscriber and account information, the source and destination of a communication, its date, time and duration, the type of communication and service, and the location of equipment at the start and end of the communication. Providers are not required to keep the content of communications, subscribers' web browsing history, or data about over-the-top services carried by another provider. Retained data must be encrypted and protected from unauthorised access (s 187BA), and the Privacy Act 1988 applies to retained data as if the provider were an organisation under that Act (s 187LA). A provider may operate under an approved data retention implementation plan or seek an exemption from a Communications Access Coordinator.

Enforced by

Source legislation

Industries

Topics

telecommunicationsdata-retentionmetadata

Related

Frequently asked questions

Who must comply with Telco data retention — 2 years (Part 5-1A Telecommunications Act)?
Carriers, internet service providers and providers of any service declared by the Minister, where the service carries communications by electromagnetic energy and the provider owns or operates infrastructure in Australia for its relevant services. Broadcasting services are excluded, and services provided only to an immediate circle or within a single area are excluded unless declared (s 187B).
What triggers Telco data retention — 2 years (Part 5-1A Telecommunications Act)?
Operating a relevant service under s 187A(3) that carries communications for customers.
When is Telco data retention — 2 years (Part 5-1A Telecommunications Act) due?
Ongoing. Subscriber and account information must be kept until 2 years after the account closes; all other required data for 2 years after it came into existence (s 187C).
What is the maximum penalty for Telco data retention — 2 years (Part 5-1A Telecommunications Act)?
Section 187A(1), and the duty to comply with an approved implementation plan (s 187D(a)), are civil penalty provisions for the purposes of the Telecommunications Act 1997, whose Parts 31 and 31B provide for pecuniary penalties and infringement notices
What evidence is required for Telco data retention — 2 years (Part 5-1A Telecommunications Act)?
Data retention design mapping each s 187AA data item to the systems that create and store it; retention schedules (2 years, or 2 years after account closure); encryption and access controls over retained data; any approved data retention implementation plan or Communications Access Coordinator exemption; Privacy Act handling procedures for retained data.

Source: https://www.homeaffairs.gov.au/about-us/our-portfolios/national-security/lawful-access-telecommunications. Rules Mate is not a law firm. Always verify against the live regulator source before acting.