Telco data retention — 2 years (Part 5-1A Telecommunications Act)
Carriers + CSPs must retain telco metadata for 2 years.
Who must comply
Carriers, internet service providers and providers of any service declared by the Minister, where the service carries communications by electromagnetic energy and the provider owns or operates infrastructure in Australia for its relevant services. Broadcasting services are excluded, and services provided only to an immediate circle or within a single area are excluded unless declared (s 187B).
What triggers it
Operating a relevant service under s 187A(3) that carries communications for customers.
When due
Ongoing. Subscriber and account information must be kept until 2 years after the account closes; all other required data for 2 years after it came into existence (s 187C).
Evidence required
Data retention design mapping each s 187AA data item to the systems that create and store it; retention schedules (2 years, or 2 years after account closure); encryption and access controls over retained data; any approved data retention implementation plan or Communications Access Coordinator exemption; Privacy Act handling procedures for retained data.
Max penalty
Section 187A(1), and the duty to comply with an approved implementation plan (s 187D(a)), are civil penalty provisions for the purposes of the Telecommunications Act 1997, whose Parts 31 and 31B provide for pecuniary penalties and infringement notices
Who must comply with this? The applicability test by industry, business structure and size.
Summary
Part 5-1A of the Telecommunications (Interception and Access) Act 1979 (s 187A) requires a service provider that operates a relevant service to keep specified telecommunications data about every communication carried by the service. The data set in s 187AA covers subscriber and account information, the source and destination of a communication, its date, time and duration, the type of communication and service, and the location of equipment at the start and end of the communication. Providers are not required to keep the content of communications, subscribers' web browsing history, or data about over-the-top services carried by another provider. Retained data must be encrypted and protected from unauthorised access (s 187BA), and the Privacy Act 1988 applies to retained data as if the provider were an organisation under that Act (s 187LA). A provider may operate under an approved data retention implementation plan or seek an exemption from a Communications Access Coordinator.
Enforced by
Source legislation
Industries
Topics
Related
- CWLTHComply with the Reducing Scam Calls and Scam SMs Industry CodeCSPs must implement controls to detect, trace and block scam calls and SMs, including SMS Sender ID Register.
- CWLTHComply with Telecommunications Consumer Protections (TCP) CodeTelcos must comply with the binding TCP Code covering credit assessment, billing, complaint handling and unwelcome contact.
- CWLTHComply with Customer Service Guarantee (CSG) for standard phone servicesTelstra + other carriers must meet CSG performance benchmarks for installations + faults.
- CWLTHCustomer Service Guarantee (CSG)Standard telephone service providers face CSG financial penalties for missed connection + repair timeframes.
Frequently asked questions
- Who must comply with Telco data retention — 2 years (Part 5-1A Telecommunications Act)?
- Carriers, internet service providers and providers of any service declared by the Minister, where the service carries communications by electromagnetic energy and the provider owns or operates infrastructure in Australia for its relevant services. Broadcasting services are excluded, and services provided only to an immediate circle or within a single area are excluded unless declared (s 187B).
- What triggers Telco data retention — 2 years (Part 5-1A Telecommunications Act)?
- Operating a relevant service under s 187A(3) that carries communications for customers.
- When is Telco data retention — 2 years (Part 5-1A Telecommunications Act) due?
- Ongoing. Subscriber and account information must be kept until 2 years after the account closes; all other required data for 2 years after it came into existence (s 187C).
- What is the maximum penalty for Telco data retention — 2 years (Part 5-1A Telecommunications Act)?
- Section 187A(1), and the duty to comply with an approved implementation plan (s 187D(a)), are civil penalty provisions for the purposes of the Telecommunications Act 1997, whose Parts 31 and 31B provide for pecuniary penalties and infringement notices
- What evidence is required for Telco data retention — 2 years (Part 5-1A Telecommunications Act)?
- Data retention design mapping each s 187AA data item to the systems that create and store it; retention schedules (2 years, or 2 years after account closure); encryption and access controls over retained data; any approved data retention implementation plan or Communications Access Coordinator exemption; Privacy Act handling procedures for retained data.
Source: https://www.homeaffairs.gov.au/about-us/our-portfolios/national-security/lawful-access-telecommunications. Rules Mate is not a law firm. Always verify against the live regulator source before acting.