Law & Policy

Australia's Assistance and Access Act, Explained

August 7, 2026 8 min read Haven Team

In December 2018, Australia passed a law that lets law enforcement and intelligence agencies compel technology companies to help them access data, including by building capabilities that do not yet exist. It stops short of ordering a decryption backdoor in so many words, and critics argue the gap between what it forbids and what it allows is where the real risk lives.


The formal name is the Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018, usually shortened to TOLA or just the Assistance and Access Act. It was drafted and passed quickly in the final sitting weeks of the year, and it remains one of the most consequential encryption laws in a democracy because of what it permits agencies to demand from the companies that build communication tools.

To understand the debate you have to understand the three instruments the law creates, because they escalate from asking to ordering to compelling something new.

The three notices

The Act lets designated agencies serve one of three instruments on what it calls a designated communications provider, a category broad enough to cover carriers, device makers, app developers, and website operators with any connection to Australia.

Instrument What it does Voluntary?
TAR
Technical Assistance Request
Asks a provider to help using capabilities it already has Voluntary
TAN
Technical Assistance Notice
Compels a provider to use a capability it already has Mandatory
TCN
Technical Capability Notice
Compels a provider to build a new capability to assist Mandatory

The TCN is the one that draws the most attention. A Technical Capability Notice can require a company to develop something it does not currently possess in order to make future assistance possible. That is a meaningful step past traditional lawful-intercept orders, which generally compel the use of access a provider already built for its own operations.

Why it worries engineers

A law that can order a company to build a new access mechanism is a law that can, in principle, ask for capabilities the company deliberately chose not to have. The design decision to hold no keys stops being a permanent guarantee and becomes a state the law can ask you to leave.

The systemic weakness line

The Act does contain a limit. It says a notice cannot require a provider to implement or build a systemic weakness or systemic vulnerability, and cannot prevent a provider from fixing one. On its face, this is the clause meant to rule out a universal backdoor.

The problem is definitional. The law's own definitions of those terms are narrow and contested. A weakness aimed at a particular person's device or account can be argued to fall outside a "systemic" weakness that affects a whole class of technology, even though the technique used to build it might be reusable. Security researchers and industry groups argued during and after passage that the line is drawn in a place engineers cannot reliably interpret, because a capability built once rarely stays confined to a single target in practice.

There is no cryptographic mechanism that weakens security for one person and no one else. A capability that can be pointed at a target can usually be pointed at anyone who fits the target's profile.

This is the same objection that recurs whenever a government proposes conditional access. It appears in the debates over the UK Online Safety Act, the EU's Chat Control proposal, and every round of encryption backdoor proposals. The technical community's position has been consistent: exceptional access is a property of a system, not of a warrant, and you cannot scope it to a single lawful request.

Secrecy and its chilling effect

Notices under the Act come with strict non-disclosure provisions. A company that receives one can be barred from revealing its existence, and unauthorized disclosure carries criminal penalties. This secrecy is what makes the law hard to observe from the outside. Unlike a court proceeding, a TAN or TCN can operate entirely in private, which limits public accountability and complicates the reporting that transparency reports and warrant canaries were built to surface.

For an individual user, the practical consequence is a trust question rather than an immediate technical one. If a provider can be secretly compelled to assist, and cannot tell you, then the only providers you can fully reason about are the ones structurally unable to comply, because they hold no keys and can reach no plaintext to hand over.

The Five Eyes context

Australia does not operate alone here. It is a member of the Five Eyes intelligence-sharing arrangement alongside the United States, United Kingdom, Canada, and New Zealand, and those governments have issued joint statements calling for lawful access to encrypted content. Analysts have noted that a capability compelled in one member state can benefit the alliance broadly through intelligence sharing. A law passed in Canberra is therefore relevant well beyond Australian borders.

The Act has been reviewed repeatedly since passage, including by the Independent National Security Legislation Monitor and the Parliamentary Joint Committee on Intelligence and Security, both of which recommended amendments to tighten definitions and oversight. Reform has been slow, and the core powers remain in force.

What it means for how you choose tools

The lesson of the Assistance and Access Act is not that any one provider is compromised. It is that a legal power to compel new capabilities changes what a promise is worth. A company that can access your data can be required to, quietly. A design that removes the company's ability to access your data removes the thing a notice would demand.

That is why architecture matters more than policy for a threat model that includes legal compulsion. Client-side end-to-end encryption, keys that never leave your device, and open code an outsider can inspect are not marketing features in this frame. They are the difference between a provider that could be compelled to hand over your content and one that has nothing to hand over. The reasoning is the same one we walk through for key disclosure laws: the strongest protection is the plaintext the operator never had.

Try Haven free for 15 days

Encrypted email and chat in one app. No credit card required.

Get Started →