Dodgy dark patterns
The OAIC is indeed drawing a sharper distinction between disclosure and consent, with revised APP 3 guidance explicitly stating that ‘Notice is not consent’. Compliance efforts for the traditional Spam Act might be visible and clear, but tracking technologies, inferences and opt-out functionality around such practices are not. The OAIC insists they become so.
On top of this, new terminology around what collecting by fair means is – and is not – is being introduced. APP 3 adopts the term ‘online choice architecture’ as a way of articulating how an individual’s choices may be distorted, manipulated or undermined digitally. It specifically references ‘harmful nudges’, ‘sludge’, ‘confirm shaming’, ‘biased framing’, ‘bundled consent’, and ‘default settings’ as practices at odds with privacy principles.
Several of these terms can already be found in Treasury’s draft laws proposal to amend the Australian Consumer Law and strengthen consumer protection against ‘manipulative’ offers, ‘distorted’ sales practices, subscription traps and drip pricing. The bill for an Act to Amend the Competition and Consumer Act 2010 against unfair trading practices was put up for consultation in February, and if passed, the laws will commence from 1 July 2027. Those laws have already gone through three readings in Parliament, with the Senate report due by 18 June.
Again, it’s a sign of growing regulatory scrutiny around how digital products shape user behaviour and ‘dark patterns’ are employed to gain personal data.
The OAIC has additionally reiterated the point that however fleeting data collection is, it still counts under privacy law. This was laid bare in the Bunnings facial recognition technology case earlier this year, where the Administrative Review Tribunal ruled personal information captured for just 4 seconds, processed automatically and with no human exposure, fit the definition of being ‘collected’ under Australia’s privacy law.
Notably, the APP 3 update also reflects the Privacy Commissioner, Carly Kind’s, other determinations on solicitation and use of personal information in practice. For example, in April, she ruled that the 2Apply rental technology platform, operated by InspectRealEstate (IRE), had collected “excessive personal information” via “unfair means” and therefore breached Privacy Law.
In that determination, IRE was found to have contravened Australia Privacy Principle 3.2 by collecting personal information that is not reasonably necessary for its functions or activities. The determination also concluded that 2Apply collected personal information by unfair means in contravention of APP 3.5, and in circumstances where individuals have a limited choice and there is a significant power imbalance between renters and real estate agents, property managers and landlords. The ruling is currently subject to appeal.
Contemporary use cases and enforcing existing powers
Speaking to Mi3, an OAIC spokesperson said its motivation was to keep guidelines up to date and “adapting in line with technical and market developments”.
“The updated APP 3 guidelines include consideration of contemporary technology use cases like artificial intelligence and facial recognition, as well as expanded and clarifying guidance around data minimisation, concepts like ‘reasonably necessary’ and ‘fair means’,” an OAIC spokesperson told Mi3. “Behaviours covered under APP 3, such as overcollection and collection by unfair means, create serious risks to the personal privacy and security of Australians.”
For OAIC, the hope is that organisations benefit from new guidance based on such contemporary use cases, “many of which are directly relevant to the marketing and data collection industry, helping to demonstrate compliance and non-compliance with APP 3”.
“There is expanded guidance on multiple existing requirements, such as the foundational requirement to only collect what personal information is ‘reasonably necessary’ for an entity’s functions and activities, the requirement to collect personal information by ‘fair means’, and clarifications on liability for where an entity engages a third party to collect personal information,” the spokesperson noted.
For industry commentators, privacy experts and lawyers Mi3 spoke to, the APP 3 update reflects all the ways Kind is wielding existing and expanded powers bestowed under Tranche 1 of Australia’s privacy law changes in one document. While the guidance does not itself create new law, it provides a strong indication of how the OAIC will pursue future investigations and enforcement.
Per Clayton Utz partner, Steven Klimt, APP 3 reflects Kind’s position that the Privacy Act is ‘principles-based’ regulation. “Its application can change as commercial practices and community standards change,” Klimt said.
“It has a potentially far-ranging impact in that many organisations may not have undertaken the rigorous analysis of their information collection practices the guidance requires … This may result in these matters being further tested in Courts and Tribunals.
“This may lead to some of the matters set out in the Guidance, which could be regarded as overreaches, being moderated.”
Leonard agrees. “Past interpretations of the Privacy Act, by both lawyers and regulators, are no longer a reliance guide to regulatory action in future,” he argues. “Commissioner Kind is testing the limits of the OAIC’s streamlined enforcement pathways and the capabilities of the Commissioner’s expanded enforcement team. Expect more penalties, more exacting enforceable undertakings, and active use of media naming and shaming, accompanied by new instructional material that will inform acceptable industry practice in Australia in adtech and martech activities.
Leonard positioned the APP 3 updates as the checklist for the Privacy Commissioner’s current year headline enforcement priorities: “Opaque adtech practices – that is, pixel tracking across third-party websites; other sharing of data between organisations that increases information imbalance between organisations and consumers; marketing to vulnerable groups – noting in particular, the expansive coverage of the draft Children’s Online Privacy Code to cover any online site which children are reasonably likely to view, regardless of whether that online site is designed to attract children or is directed at children.”
Leonard also re-emphasised the overarching point: That transparency and honesty are just the first necessary part of the fee when brands engage in data collection and handling activities, yet they’re ultimately “insufficient” on their own.