Insight,

Digital Duty of Care: Australia's Latest Move on Online Safety

AU | EN
Current site :    AU   |   EN
Australia
Singapore

Tell me in a minute:

The Australian Government has released exposure draft legislation to introduce a new ‘digital duty of care’ requiring online service providers to take reasonable steps to deliver a safe online environment for their users.

Providers of online services will need to protect users from serious harmful content (such as child exploitation material and pro-terror content), with additional protections for children in relation to design features like recommender engines. Providers will also need to conduct comprehensive risk assessments, implement user empowerment tools as directed by the Minister, and meet new transparency reporting obligations. Penalties of up to A$109 million will apply for non-compliance. The new regime will replace the existing online content scheme (including existing industry codes and standards) along with the non-binding Basic Online Safety Expectations.

The breadth of the new duty of care may present concerns about the potential chilling effect on free expression and the practical challenges of age-based distinctions. Nonetheless, the Government intends to move at pace, with promises to introduce the legislation to Parliament later this year.

Consultation closes on 22 September 2026.


Continuing its recent flurry of tech-focused regulation – including world-first social media minimum age laws, a revised News Media Bargaining Incentive, and the long-awaited Phase 2 Privacy Act Reforms – the Australian Government has released the exposure draft that would legislate a new ‘digital duty of care’ into the Online Safety Act.

New digital duty of care

At its heart, the new duty would put an onus on online service providers to ensure a ‘safe online environment’ for their users to the extent ‘reasonably practicable’.

This will require service providers to:

  • protect all users from serious harmful material and conduct (eg child sexual exploitation or abuse, material that encourages self-harm or suicide, pro-terror material and abhorrent violence); and
  • protect children from:
    • material and conduct that is harmful to children (eg pornography, disordered eating content, material promoting hostility toward women or gender equality, glorification of crime or dangerous practices, and bullying); and
    • the impacts of certain ‘design features’ including recommender engines, endless content feeds, content feedback mechanisms and time-limited features. For social media services, there would be a requirement to ensure that these features are not provided to children under 16 years of age whether through an account or otherwise (doubling-down on existing age restrictions that apply to certain social media platforms when accessed through an account). Other online services – such as messaging apps, interactive online games and dating services - which fall outside the scope of the social media minimum age regime, will need to carefully consider how they may be impacted by the specific regulation of these design features for children under the duty of care framework.

While, in theory, an outcomes-focused approach may seem most effective in achieving online safety goals, it may not account for externalities beyond the service provider’s control such as user conduct, technical feasibility and security concerns affecting the relevant online environment. This will place significant pressure on the reasonableness qualification that applies to the duty.

Additionally, as part of the new duty of care, service providers will need to undertake comprehensive risk assessments for their services, update them on a regular basis and take steps to mitigate safety risks identified through the assessment process. The aim is to ensure that service providers take proactive and ongoing action to address the risk of harm before it occurs. However, the scope of the risk assessment is not limited to the digital duty of care and instead requires service providers to identify ‘all reasonably foreseeable risks, including those relevant to the provider’s digital duty of care’. This brings into question what risks, in addition to those required to protect children and protect persons from seriously harmful material, are meant to be assessed and addressed.

Expansive scope

Although the focus of recent media attention has predominantly been on social media platforms, the digital duty of care extends significantly further to capture a wide range of other online service providers including providers of designated internet services, relevant electronic services, internet carriage services, search engines, hosting services, app distribution services and even companies who manufacture, supply, maintain or install equipment in Australia in connection with social media services, designated internet services, relevant electronic services and internet carriage services.

Practically, this captures almost all aspects of the digital ecosystem in Australia, including:

  • companies who provide websites and apps in Australia;
  • companies that supply email services, IM services, SMS/MMS services, online games and online dating services;
  • telecommunications providers who provide underlying internet services; and
  • anyone that supports any of the above services.

The Minister has the ability to exempt services (or classes of services) that pose little risk to users in Australia or are used minimally in Australia. However, given the breadth of what is in scope, it is likely this exemption will need to do a lot of heavy lifting in order to avoid a disproportionate impact on services that have a naturally low risk profile (eg because they are provided exclusively or predominantly to enterprise users rather than consumers).

My feed, my way - or the Minister’s way

A prominent feature of the Government’s announcement is the ‘My Feed, My Way’ initiative, which would give users the ability to turn off algorithmically-recommended content. The Government’s media release indicates that:

Social media platforms will be required to send a notification to new and existing users offering them a choice over their default feed. Users can choose to opt in to having their default feed include personalised content recommended by the algorithm. Alternatively, users can opt out of personally recommended content in their default feed and see the friends and creators they choose to follow.

However, the ‘My Feed, My Way’ initiative is not directly addressed in the exposure draft legislation itself. Rather, it appears this would be implemented using the Minister for Communications’ power to require service providers to provide specific ‘user empowerment tools’ - tools that give users control over the operation of certain design features. Other user empowerment tools that could be specified under this power include controls over the kind of content recommended for the user, the ability to turn off unwanted service features, or setting time limits on usage - though each would require a further ministerial determination to take effect.

No further details are available as far as we are aware. However, this clearly has the potential to materially alter the experience of many users on social media platforms where the content feed is a central service feature. It appears that users will effectively be forced to make a binary choice as to whether to accept personalised content recommendations or not. It is not clear whether more nuanced choices, such as giving users some ability to configure or ‘fine tune’ a recommendation algorithm to avoid certain types of recommendations without actually opting out altogether, would be acceptable.

Close attention will need to be paid to the wording of the instrument in which the Government’s signature policy is implemented.

eSafety guidance and complaint handling

eSafety may publish guidelines to assist service providers to comply with the duty of care, though compliance with the guidelines may not of itself guarantee compliance with the duty. In addition, there will be a mandatory requirement for service providers to provide complaint and dispute processes that comply with requirements determined by eSafety.

Replacing the existing framework

The new duty of care will effectively replace the existing online content scheme, and the complex series of industry codes and standards that have been developed under that scheme over the last few years. The existing scheme will remain in place until the duty of care commences, which is currently contemplated to be 12 months after the legislation receives Royal Assent. Given the significant time and effort invested in developing these codes and standards, and then building a compliance framework around them, some industry stakeholders may feel aggrieved at having to return to the drawing board quite so soon.

Enforcement and penalties

Despite its name, the ‘digital duty of care’ is not a private law duty but rather a regulatory obligation, enforceable by eSafety through an extensive suite of graduated enforcement powers. Penalties for failing to comply with the duty will be significant, with maximum fines of up to 60,000 penalty units (currently approximately A$109 million) depending on the seriousness of the contravention.

In addition, eSafety will have power to issue formal warnings (which can be published on eSafety’s website) and remedial directions requiring service providers to take specified action to address non-compliance, with failure to comply with a remedial direction itself attracting a maximum penalty of 60,000 penalty units.

eSafety will also have broad information-gathering and investigatory powers to support its compliance activities. Significantly, eSafety will be able to require service providers to produce their risk assessments on request (within 30 days), and may require persons to give information or evidence, produce documents, or answer questions relevant to an investigation or possible contravention of the Act. These powers can extend to summoning persons to attend before the Commissioner at a specified time and place.

Updated transparency reporting regime

Along with the digital duty of care, a new transparency framework will also be introduced, replacing the existing framework centred around the non-binding ‘Basic Online Safety Expectations’. This new framework would give eSafety broad powers to require online service providers to report on matters relating to online safety. eSafety would have specific powers to specify the contents and format of reports, and to publish reports in full (rather than simply on an aggregated or summary basis as is currently the case).

In addition to transparency reporting, eSafety would have the power to:

  • require online service providers to make certain information available to the public regarding the safety of their services, such as statistics around content moderation decisions, complaints handling, and actions taken to suspend or remove accounts for safety violations; and
  • give researchers approval to access data from online service providers to enable independent research into online safety matters. Subject to eSafety approval, researchers would also be able to use ‘sock puppet’ accounts (essentially accounts opened under a false or fictitious identity) to conduct covert research on platforms. eSafety itself would also have powers to assume sock puppet identities for the purposes of discharging its regulatory functions.

Other strengthened safety protections

The new duty of care and transparency regime will be accompanied by various other strengthened safety measures, including:

  • new powers for eSafety to deal with apps and websites that are predominantly designed or used for the purposes of generating fake nude material – with these new powers, eSafety will be able to require app stores and internet search engines to remove access, links and advertising for such services;
  • measures to reduce the timeframe for complying with content removal notices from 48 hours to 24 hours;
  • greater flexibility for eSafety to intervene and issue removal notices even if there has been no prior complaint made to the service provider; and
  • extending the availability of link deletion notices to all complaints-based schemes so that internet search engine services can be required to remove links to identified harmful content (eg cyber-bullying material, an intimate image or adult cyber abuse material).

Walking a fine line between safety, freedom of expression and other interference

While few would dispute that society would benefit from a safer online environment, the measures proposed in the exposure draft legislation seek to walk a fine line. The new digital duty of care will put service providers under immense pressure to show that they are doing everything possible to eliminate potential safety risks. Given the threat of significant fines, regulatory action and the reputational damage that could ensue, it is possible that service providers will take an overly cautious or conservative approach and seek to eliminate or control content or behaviour that may not in practice result in the types of harm at which the legislation is targeted. The potential for overly restrictive content rules that will constrain freedom of expression is obvious.

Other aspects of the duty of care may also have a chilling effect on the online ecosystem. For example, the duty contemplates different levels of safety for adults, children under 18 and children under 16. While it may instinctively make sense to afford additional care to the younger members of the online community, these distinctions can only be applied in practice if service providers can reliably distinguish users based on age. It is not clear how that would be possible without introducing pervasive age verification or assurance mechanisms across all in-scope online services. Similarly, while the legislation expressly states that the duty of care will not require action to be taken in relation to ‘lawful communications occurring in private solely between consenting adults’, this raises the question of what action could be required where private communications involve a child or an adult who may not be consenting. Are service providers expected to be able to identify problematic exchanges and the ages of users in those instances and be able to intervene? If so, how would that be possible without intrusive content monitoring and age assurance across all in-scope communications services?

Reliance on delegated legislation

In addition, it is somewhat concerning that the proposed legislation makes extensive use of delegated legislation, with the Minister for Communications and eSafety each given broad powers to expand or adjust critical aspects of the duty of care regime. For example:

  • the Minister will have powers to determine additional material or conduct that is considered harmful either for all users or children and to require specified online services to provide specific types of user empowerment tools (including potentially to implement the ‘My Feed, My Way’ initiative as mentioned above, which has been presented as a feature-piece of the Government’s policy); and
  • eSafety will have powers to define required complaints handling processes, prescribe details of risk assessment processes and formats, impose expansive mandatory transparency reporting requirements, and set rules to allow researchers to require access to service data and to approve covert research activities.

While delegated legislation made by the Minister would be subject to disallowance by Parliament, and there would be a requirement for the Minister to seek advice from eSafety prior to exercising these powers, there is clearly a risk that these mechanisms could be used to further increase the reach of the duty of care without the same level of scrutiny that has accompanied its introduction.

Some may argue that a decision to extend the legislation to a new type of harm, not currently within contemplation, should be made by the Parliament following proper public consultation and debate, rather than by the Minister on their own. Importantly, there is no merits review available for the Ministerial determinations contemplated under the exposure draft - the only avenue for affected service providers would be judicial review for legal error - a narrow and technical avenue.

Next steps

The Government is seeking feedback from digital platforms, industry bodies, civil society organisations and advocates on the exposure draft legislation until 22 September 2026.

However, it is clear that the Government does not intend to wait around, with a public commitment to introduce the legislation to Parliament in 2026.

Latest Thinking
Insight
Yesterday the Federal government released its long-awaited draft legislation to ban the use of post-employment non-compete clauses for workers earning below the “high income threshold” and non-poaching clauses for all employees, together with extending the existing cartel framework to cover no-poach and wage-fixing arrangements between entities.

08 September 2026

Insight
We examine the ACCC’s response to CHOICE’s designated complaint and its call for stronger product safety rules, including for online marketplaces.

07 September 2026

Insight
On 3 September 2026, Federal Treasury published exposure draft legislation to implement the 30 per cent minimum tax on certain discretionary trusts, a measure which was announced in the 2026-27 Federal Budget and will apply from 1 July 2028.

04 September 2026