liber-net Submission on the Online Safety Amendment (Digital Duty of Care) Bill 2026
At vero eos et accusamus
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
The Australian government is proposing a bill that would put the design and operation of online platforms under direct supervision by the eSafety Commissioner. The stated intent protecting children online, but the legislation pairs it with broad and expandable definitions of “harm,” government-operated “sock puppet” accounts, and new powers to collect Australians’ personal information and share it across government. We believe this framework will push platforms to suppress lawful speech as the safe option.
Below is our submission on the exposure draft, lodged with the Department of Communications on 22 September 2026:
TO: Department of Infrastructure, Transport, Regional Development, Communications, Sport and the Arts
SUBMITTED TO: digitaldutyofcare@communications.gov.au
FROM: liber-net
CONTACT: Andrew Lowenthal, CEO
DATE: 22 September 2026
RE: Exposure Draft – Online Safety Amendment (Digital Duty of Care) Bill 2026
Dear Consultation Team,
liber-net welcomes the opportunity to comment on the exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026. We are a digital civil liberties initiative that combats digital authoritarianism and works to re-establish free speech as the norm for our networked age.
We recognise that children encounter inappropriate material online and that some of it has the potential to cause harm. We must also recognise that child safety is one of the doors through which controls on lawful speech and privacy can be introduced, and this Bill is a clear example of how that happens.
We support the measures in the Bill that give users greater control over their online experience. The intent to give users over 16 a choice over whether their feed is algorithmically personalised puts control back in the hands of Australian citizens, and we support measures of this kind.
Our concern is that the Bill aims to give users greater choice with one hand while taking far more control away with the other. It does this through broad categories of “harm” that could conceivably be used to restrict lawful speech, open-ended preventative obligations and a major expansion of eSafety’s mandate into the design of the systems that determine what information reaches Australians.The Bill also significantly expands eSafety’s information-gathering reach. This includes new powers to operate government “sock puppet” accounts under false identities, alongside broader compliance powers. Changes to the Privacy Act also allow eSafety to collect sensitive information without consent, while expanded information-sharing provisions allow it to share information across government. These changes raise serious privacy and civil-liberties concerns and represent a significant overreach of eSafety’s remit.
Below, we set out our core concerns and recommendations.
“Harm” risks becoming a parallel speech code. Protecting children from child sexual exploitation, grooming, pornography, credible threats, bullying and the promotion of suicide or self-harm involves relatively identifiable forms of harm. The draft moves beyond those categories into far more contestable territory.
Proposed section 25D, for example, includes material or conduct that “encourages or promotes hostile attitudes towards women or gender equality”. Neither “hostile attitudes” nor “gender equality” provides a clear boundary between harmful conduct and lawful disagreement.
The Minister can also expand categories of harmful material and design features through delegated legislation. This leaves the boundaries of what the state may treat as harmful to children open to future expansion, shifting control over lawful content away from parents and users and towards the government. If it is not illegal, then the government should not regulate it.
The enforcement architecture is more significant than its individual parts suggest. Schedule 2 item 63 designates the eSafety Commissioner an “enforcement body” under the Privacy Act. That status allows eSafety to collect sensitive information without consent and allows other entities to use or disclose personal information for “enforcement-related activities” conducted by or on behalf of eSafety. That term expressly includes “surveillance activities, intelligence gathering activities or monitoring activities”. This amounts to spying on everyday citizens.
Schedule 1 item 44 separately replaces the existing named recipients in section 212 with any “Commonwealth entity”, widening the range of government bodies that may receive information obtained by eSafety.
Taken together with eSafety’s compliance and investigative powers, these changes materially expand its ability to obtain private and sensitive information and circulate it across government. This poses an unacceptable threat to Australian internet users’ privacy.
The Bill gives eSafety government spy accounts. The draft expressly authorises the eSafety Commissioner and approved researchers to operate what the legislation calls “sock puppet identities”. These false identities can be used to create accounts, observe and record material and test services. The Commissioner can also interact through those accounts where necessary to maintain them.
This moves a civil online-safety regulator further into techniques normally associated with covert investigation. In isolation, that would warrant scrutiny. Combined with expanded compliance duties, information-sharing pathways and Privacy Act enforcement status, it becomes part of a much broader increase in the regulator’s investigative reach.
The Bill leaves its boundaries open to future expansion. The Minister can use legislative instruments to add new categories of harmful material, conduct and design features, expanding the practical reach of the regime without new primary legislation.
Greens Senator David Shoebridge recently argued that messages from Pauline Hanson and the Coalition that he regarded as harmful should not be amplified to children under a Digital Duty of Care. His comments show the concern is not hypothetical and that there is already a political appetite to use “harm” as a basis for deciding which lawful political messages can reach an audience. If a government on the other side of politics is elected in the future, it could use the same tools against Shoebridge’s legal political messages, potentially limiting the reach of climate or LGBT advocacy.
Research access risks creating a government-approved knowledge loop. The draft allows data-access schemes for approved researchers, but defines those researchers as employees of Australian universities, excluding suitably qualified independents.
This risks concentrating research authority within a narrow institutional circle. University ethics approval does not eliminate ideological bias, while independent researchers may lack access to the data needed to test or challenge resulting claims. liber-net has documented a similar dynamic in the United States, where government funding helped build an expert-led content-moderation field with significant institutional bias.
See https://liber-net.org/federal-awards-project/.
Stronger and faster enforcement is arriving with fewer safeguards. The Bill removes statutory consultation requirements attached to the codes and standards framework, cuts several removal-notice periods from 48 hours to 24 hours and places broad preventative obligations on platforms. Where classifications are contestable, services face substantial penalties and shorter decision windows, but no equivalent penalty for unnecessarily suppressing lawful material. The commercial incentive is to block, demote or remove borderlinecontent before a complaint or regulatory finding. The predictable result is rushed, risk-averse decision-making and over-removal.
Recommendations
1. Keep lawful expression outside the Duty’s content-control powers. Remove vague categories that bring otherwise lawful political, religious or social expression within the regulatory regime, including “hostile attitudes towards women or gender equality”. This is thought policing. Do not permit new categories affecting lawful expression to be added through open-ended delegated powers. Platforms remain free to offer voluntary user-controlled filters and safety tools.
2. Preserve genuine user control of feeds. Retain the principle behind “My Feed, My Way” and extend it consistently. Expressly protect chronological feeds, friends and following feeds, subscriptions, search and other genuinely user-directed ways of accessing content. Neither eSafety nor the Minister should determine what lawful material a replacement feed carries or how it is ranked.
3. Do not expand eSafety into a broader enforcement and surveillance role. Remove its express designation as an “enforcement body” under the Privacy Act, do not extend compulsory powers into general Duty of Care compliance, and retain the existing limits on which government bodies may receive information obtained by eSafety.
4. Remove false-identity powers and open research access to independents. Delete the provisions authorising eSafety to operate false-identity accounts. If compulsory researcher access to platform data is retained, eligibility should extend to suitably qualified independent researchers under transparent, objective and viewpoint-neutral privacy and security requirements.
5. Restore due process and public scrutiny. Retain meaningful consultation requirements for major changes to online-safety regulation. Rapid removal periods should apply only to clearly unlawful material, while contestable cases should receive adequate time and meaningful review before penalties attach. Major changes affecting speech, privacy or platform architecture should be made transparently and subject to proper parliamentary and public scrutiny.
6. Remove the Minister’s power to expand the regime through legislative instruments. Every regulated harm, design feature and service category must be clearly and exhaustively defined in the Act. Any future expansion should require an amending Bill and full parliamentary debate. This is too much power over lawful online expression to leave to ministerial discretion.
Conclusion
The Bill contains worthwhile measures that can give Australians greater control over their online experience, but its treatment of online harms needs far more consideration and much clearer definition. As drafted, too much of the regime effectively asks the public to grant broad powers now and trust that they will be used wisely. That is not good enough in a relatively new and particularly fraught area of regulation.
liber-net urges the Government to preserve the user-empowerment measures while removing the provisions that expand regulatory control over lawful expression, surveillance and information-sharing.
Submitted by liber-net





