ntworld.ink
Part Five · Governance, law and proportionate response

Workplace surveillance laws by jurisdiction, and the public sector difference

A missing notice does not produce a technical non-compliance in New South Wales; a definition converts the monitoring into covert surveillance, which is an offence.

Part Five About 24 minutes

An organisation with staff in Darwin, Sydney and Melbourne decides to switch on endpoint monitoring. One configuration profile, one policy object, one deployment ring, one Monday morning.

In Melbourne there is no statute that speaks to it directly. In Darwin there is none either. In Sydney it is an offence, unless a written notice went out fourteen days ago, and a computer surveillance policy exists, and staff were told about that policy in a way that makes it reasonable to assume they understand it. Not a technical non-compliance. An offence, carrying fifty penalty units, because of a definition that turns a missing notice into something other than a missing notice.

Chapter 28 established which privacy regime an organisation is in. This chapter is about a separate body of law that most security teams do not know exists, because it is not privacy law, it is not in any product's documentation, and it does not appear in any vendor's compliance matrix. It regulates the act of watching rather than the handling of what is seen, and a control that satisfies every privacy principle can still be prohibited by it.

Two bodies of law, not one

There are two kinds of statute in play and confusing them is the most common error.

Workplace surveillance statutes regulate an employer watching employees. Their mechanism is notice and policy: the surveillance is permitted, provided the employer has told people about it in a prescribed way beforehand. Only New South Wales and the Australian Capital Territory have one of these covering computer surveillance.

Surveillance devices statutes regulate anyone using a defined class of device. Their mechanism is prohibition plus consent: using the device is an offence unless a party consents or an exception applies. Every jurisdiction has one. The question that decides whether monitoring software is caught is whether that jurisdiction's Act regulates a device that watches a computer, and the answers differ.

Sitting over both is the Commonwealth interception statute, which regulates a third thing again: reading a communication while it is in transit.

The New South Wales Act as the working model

The Workplace Surveillance Act 2005 (NSW) is the most developed scheme in the country and it is worth learning in detail, both because it applies to a large share of the Australian workforce and because it is the sensible national floor for reasons set out below.

Section 3 defines computer surveillance as surveillance by means of software or other equipment that monitors or records the information input or output, or other use, of a computer (high). There is no argument to be had about scope. An endpoint agent is caught. A browser extension that reports policy matches is caught. A data loss prevention policy that logs paste events is caught. So is a proxy log, if it monitors the use of a computer, which it does.

Section 10 sets the notice requirement. Surveillance must not commence without prior notice in writing to the employee, given at least fourteen days before it starts, though an employee may agree to a lesser period (high). Section 10(4) prescribes what the notice must state: the kind of surveillance, being camera, computer or tracking; how it will be carried out; when it will start; whether it is continuous or intermittent; and whether it is for a specified limited period or ongoing (high). Notice by email is notice in writing. Where an employee starts work after surveillance has commenced, or within the fourteen days, notice must be given before they start.

Section 12 adds two conditions that apply to computer surveillance specifically, and it is short enough to state in full in substance. Computer surveillance must not be carried out unless it is carried out in accordance with a policy of the employer on computer surveillance of employees at work, and the employee has been notified in advance of that policy in such a way that it is reasonable to assume the employee is aware of and understands it (high).

Read those two requirements as a design constraint rather than as paperwork. A policy has to exist, in writing, describing the surveillance. Staff have to have been told about it in a way that would survive someone asking whether they actually understood. An intranet page nobody has visited does not obviously meet the second limb; an induction module, a log-on notice or a targeted email might.

The trick in the definitions

Here is the part that changes how a defender should think about compliance, and it is not obvious from reading ss 10 and 12.

Neither s 10 nor s 12 carries a penalty. Look for one and there is none. That is not because breach is costless. It is because s 3 defines covert surveillance as surveillance of an employee while at work for an employer, carried out or caused to be carried out by the employer, and not carried out in compliance with the requirements of Part 2 (high).

Sections 10 and 12 are in Part 2. So monitoring that does not comply with them is not non-compliant monitoring; it is covert surveillance, by definition. And s 19 makes covert surveillance of an employee at work an offence unless authorised by a covert surveillance authority, with a maximum penalty of fifty penalty units (high). A covert surveillance authority is issued by a Magistrate under Part 4, on application by the employer under s 23, on grounds relating to suspected unlawful activity by named employees, and s 25 requires the Magistrate to be satisfied there are reasonable grounds to justify it. Section 29 limits the authority to thirty days (high).

The practical consequence is worth stating plainly. An organisation that deploys endpoint data loss prevention across a New South Wales workforce without a published computer surveillance policy has not committed an administrative oversight. It has, on the face of the Act, committed the offence of covert surveillance, and the remedy for covert surveillance is a warrant from a Magistrate, which it will not get for routine monitoring, because routine monitoring is not investigation of suspected unlawful activity by named individuals.

At $110 per penalty unit under s 17 of the Crimes (Sentencing Procedure) Act 1999 (NSW), fifty penalty units is $5,500 (high). The number is not the point. The characterisation is.

The rest of the New South Wales scheme

Four more provisions matter for this manual.

Section 15 prohibits surveillance of an employee in any change room, toilet facility, or shower or other bathing facility, at fifty penalty units (high). It is not directly relevant to AI monitoring and it is the provision most people have heard of, which is worth knowing when the Act comes up in a meeting.

Section 16 prohibits surveillance of an employee using a work surveillance device when the employee is not at work, with an express carve-out: the prohibition does not apply to computer surveillance of the employee's use of equipment or resources provided by or at the expense of the employer (high). That carve-out is what permits monitoring a corporate laptop used at home on a Sunday, provided Part 2 has been complied with. It does not extend to a personal device.

Section 18 restricts use and disclosure of surveillance records made through notified surveillance. The permitted purposes are a legitimate purpose related to employment or the employer's legitimate business activities, disclosure to law enforcement for the detection, investigation or prosecution of an offence, purposes related to civil or criminal proceedings, and averting an imminent threat of serious violence or substantial damage to property. Maximum penalty twenty penalty units (high). This is the provision that governs whether telemetry gathered for security may be handed to a disciplinary process, and Chapter 33 returns to it.

And section 17, which is the one that matters most for shadow AI, gets its own treatment below.

The Australian Capital Territory

The Workplace Privacy Act 2011 (ACT) covers similar ground with different drafting, and one detail of that drafting is worth borrowing.

Section 11 defines a data surveillance device as a device or program capable of being used to record or monitor the input of information into, or the output of information from, a computer (high). The word 'program' means monitoring software is named rather than inferred, which removes the argument that a piece of software is not a device. Listening devices are excluded and sit under separate territory legislation.

Section 13 requires written notice at least fourteen days before surveillance starts, or a shorter agreed period, and prescribes the notice contents including the permitted uses of surveillance records (high on the period; medium on the full content list). Section 16 adds the policy requirement for data surveillance specifically, and requires the policy to address permitted use of computer resources, access to logged information and monitoring methods, with 'computer resources' defined to include internet access and electronic communication applications (high). Sections 41 and 42 prohibit surveillance of private areas and of workers who are not at work.

The shape is the same as New South Wales: notice, policy, prohibited places, use limits, and a covert surveillance process for investigations.

Everywhere else

No other Australian jurisdiction has a dedicated workplace computer surveillance statute as at August 2026 (high).

Victoria has workplace-specific provisions in Part 2A of the Surveillance Devices Act 1999 (Vic), inserted in 2006, but they apply only to the use of surveillance devices in workplace toilets, washrooms, change rooms and lactation rooms (high). There is no Victorian notice requirement and no computer surveillance policy requirement.

Victoria is nevertheless the jurisdiction to watch. A Legislative Assembly committee inquiry into workplace surveillance was referred in May 2024 and reported in May 2025 with twenty-nine findings and eighteen recommendations. The government supported fifteen of the eighteen in principle, with three still under consideration (high on the inquiry and report; medium-high on the government response, which rests on a single commentary source). No Bill had been introduced as at August 2026, and the government had not settled whether reform would amend existing legislation or create a standalone Act.

Queensland has no workplace surveillance statute and no general surveillance devices Act. The Queensland Law Reform Commission recommended in 2020 that the Invasion of Privacy Act 1971 be replaced with a Surveillance Devices Act covering listening, optical, tracking and data surveillance devices. A government consultation closed in May 2023. Nothing had been enacted as at August 2026 (medium, being a negative finding from targeted searching).

The data surveillance question, jurisdiction by jurisdiction

This is the part most often missed, and it has one answer that matters.

Victoria's Surveillance Devices Act 1999 defines a data surveillance device in s 3 and then, in s 9, restricts the prohibition to law enforcement officers. A private employer is outside it (high on the restriction to law enforcement; medium-high on the s 3 wording). The Northern Territory's Surveillance Devices Act 2007 does the same thing: s 4 defines a data surveillance device as a device capable of being used to monitor or record information being put onto or retrieved from a computer, and s 14 prohibits its installation, use and maintenance by a law enforcement officer (high). Neither Act reaches an employer.

Western Australia, Tasmania and Queensland do not regulate data surveillance at all. The Western Australian Act covers listening, optical and tracking devices; the Tasmanian and Queensland Acts cover listening devices only (high).

South Australia is the exception, and it is the practically important finding of this section. The Surveillance Devices Act 2016 (SA) defines a surveillance device in s 3 to include a data surveillance device, and defines that as a program or device capable of being used to access, track, monitor or record the input of information into, or the output of information from, a computer (high). Section 8 then prohibits a person knowingly installing, using or maintaining a data surveillance device to do any of those things without the express or implied consent of the owner or the person with lawful control of the computer. The penalty is $15,000 or three years imprisonment for a natural person, and $75,000 for a body corporate (high).

Note that this prohibition is not limited to law enforcement and not limited to employers. It applies to everyone. Where the employer owns the device, the consent element is generally satisfied because the employer is the owner or the person with lawful control. Where the device belongs to the employee, under a bring-your-own-device arrangement, it is not, and a monitoring agent installed on that device is on the face of the section within the prohibition. No case applying s 8 to workplace monitoring was found, so treat this as a live risk rather than settled law, and treat it as a reason to get advice rather than a reason to guess (medium on the analysis; high on the statutory text).

The interception Act, and the public sector difference

Section 7(1) of the Telecommunications (Interception and Access) Act 1979 (Cth) prohibits a person from intercepting a communication passing over a telecommunications system, except as authorised by the Act (medium, verified only against secondary sources during this build).

The definition of interception in s 6(1) has two elements a defender should hold onto, because both are doing work.

The interception must occur while the communication is passing over the system. Reading content after it has arrived, or before it is sent, is not interception in passage; access to stored communications is dealt with separately. This is a large part of why the whole industry instruments at the user agent rather than in the network. A browser extension that inspects a prompt before the request is composed is not intercepting anything in transit; a proxy that decrypts and reads the request body is doing something much closer to it.

And the interception must be without the knowledge of the person making the communication. Notice defeats that element, at least as to the employee who is the sender. This is one of the places where the notice requirements of Chapter 29 and the interception question converge: the notice is not only a workplace surveillance obligation, it is also the thing that removes one of the two elements of the Commonwealth offence.

Then the public sector difference, which appears in a definition rather than in an operative section. Section 5 defines network protection duties in relation to a computer network as duties relating to the operation, protection or maintenance of the network, or, where the network is operated by or on behalf of a Commonwealth agency, security authority or eligible authority of a State, ensuring that the network is appropriately used by employees, office holders or contractors (high).

Read the two limbs against each other. Everyone gets operation, protection and maintenance. Only government networks get 'ensuring appropriate use by employees'. A private employer monitoring staff to check whether they are using AI tools appropriately is not performing network protection duties as the Act defines them. A government agency doing the same thing is. That is a genuine and under-discussed asymmetry, and it runs in the opposite direction to the privacy position in Chapter 28, where the public sector body was the one without the exemption.

The provisions that use those definitions sit in Part 2-6 as ss 63C, 63D and 63E, dealing respectively with information for network protection purposes, information for disciplinary purposes, and communication of information to an agency (high on the section numbers and headings). Note what they are: rules about what may be done with intercepted information, not authorisations to intercept it. Finding a dealing provision that permits something is not the same as finding an interception exception.

Consultation

One more obligation, from a different Act again.

Section 205 of the Fair Work Act 2009 (Cth) requires an enterprise agreement to include a consultation term that requires the employer to consult employees about major workplace changes likely to have a significant effect on them, and allows for their representation in that consultation (high). Where an agreement does not contain a compliant term, the model term prescribed by reg 2.09 and set out in Schedule 2.3 of the Fair Work Regulations 2009 is taken to be a term of the agreement (high). The model term requires notification of a definite decision, the opportunity to appoint a representative, discussion of the change and its effects and of measures to mitigate adverse effects, written information, and genuine consideration of matters raised.

Whether introducing endpoint monitoring is a major change with a significant effect is a question of fact. The model term's definition of major change is framed around changes in production, program, organisation, structure or technology, which is broad enough to reach it. That is analysis rather than statutory text, and it is the analysis most higher education enterprise agreements proceed on in practice. Many such agreements also contain their own surveillance and monitoring clauses, which can be more restrictive than any statute, and which are the first document to read rather than the last.

The shadow AI lens

Blocking an AI site is itself regulated conduct in New South Wales. This is the finding that most surprises security teams, and it applies directly to the manual's standard first intervention.

Section 17 of the Workplace Surveillance Act provides that an employer must not prevent delivery of an email or access to a website unless the employer is acting in accordance with a policy on email and internet access that has been notified in advance in a way that it is reasonable to assume the employee is aware of and understands, and gives a prevented delivery notice as soon as practicable. Maximum penalty fifty penalty units (high). Section 17(2) provides exceptions where the email was blocked as spam or as containing malicious content, or where the email or website would be regarded by reasonable persons as menacing, harassing or offensive. Section 17(4) prohibits a policy that permits blocking merely because content concerns an industrial organisation of employees or an industrial matter (high).

Now apply it. Tagging a consumer AI service as unsanctioned so that the endpoint product pushes a block indicator prevents access to a website. A consumer AI service is not spam, is not malicious content, and is not menacing, harassing or offensive. So the s 17(2) exceptions do not obviously apply, and the block requires a notified internet access policy and a mechanism for issuing a notice to the affected employee. Nothing in any vendor's block workflow produces that notice. That is analysis rather than case law, and it follows directly from the text.

The multi-jurisdiction organisation. Run the three-city example to a conclusion. The conclusion is not that the organisation maintains three configurations. Jurisdictional carve-outs in a technical control are a maintenance liability, they fail silently when someone relocates, and they require the platform team to know where every staff member works, which it does not. The conclusion is that the organisation runs one configuration to the strictest applicable standard, because a policy and a notice cost nothing to extend to people who did not strictly need them.

What the floor requires, operationally. Four artefacts and one design constraint. A published computer surveillance policy describing what is monitored, by what means, and for what purpose. A written notice issued at least fourteen days before anything starts, containing the five matters in s 10(4). A separate policy covering blocking of websites, with a means of issuing a notice when a block is applied. Written use and disclosure limits, implemented as access control over who can query the telemetry and for what, not merely as a paragraph in a document. And the design constraint: no covert component, because the covert path requires a Magistrate and is available only for investigating suspected unlawful activity by identified individuals.

Bring your own device. Two provisions converge on the same answer from different directions. Section 16 of the New South Wales Act permits out-of-hours computer surveillance only of employer-provided equipment. Section 8 of the South Australian Act prohibits a data surveillance program without the consent of the person with lawful control of the computer. Both point at the same conclusion the technical chapters reached independently: monitoring software on a personal device is a different proposition from monitoring software on a corporate one, and the difference is not only technical.

Where this breaks down

Territorial reach is unresolved. The New South Wales Act contains no express extraterritoriality provision, and whether it binds a New South Wales employer in respect of an employee who works entirely in another state was not resolved by any source found. The definitions borrow from the state's industrial relations legislation, which suggests the connection that matters is the employment and the place of work rather than the employer's registered office, but that is inference and should not be stated as settled (low).

Whether a private organisation's internal network is a 'telecommunications system' for interception purposes is unresolved, and no authority was found either way. The consequence is not that the risk is low; it is that the risk is unquantified, which is a worse position for a governance paper to be in.

The exceptions in s 7(2) of the interception Act were not verified at paragraph level during this build, so a specific paragraph should not be cited without checking, and the provision that authorises interception for network protection, as distinct from the provisions that permit dealing with the results, was not located.

Enterprise agreement clauses vary and were not reviewed. In the higher education sector they routinely address surveillance directly, and several are more restrictive than the statutes described here.

Reform is pending in Victoria and recommended in Queensland. A jurisdictional map drawn in August 2026 has a short useful life, and the Victorian government response makes change there likely rather than speculative.

And the underlying limit of the whole chapter: these statutes regulate what an employer may do. They say nothing at all about what a staff member may do on their own device with their own account, which remains, as it has been since Chapter 3, the part of the problem that no instrument reaches.

Check your understanding
  1. A colleague says the fourteen-day notice was missed but it is only a technical breach and can be fixed by issuing it now. Correct them in two sentences, naming what the monitoring became in the meantime.
  2. State which of the jurisdictions your organisation operates in has a surveillance devices Act that reaches a private employer using monitoring software, and what the consent element requires.
  3. Explain why notice matters to the Commonwealth interception question and not only to the workplace surveillance question.
  4. Identify the provision that regulates blocking a website in New South Wales, and state the two things an employer must have in place before applying a block.
  5. Explain the difference between what a private employer and a Commonwealth agency may treat as network protection, and say which of the two your employer is.

Glossary terms used in this chapter

computer surveillance · consultation term · covert surveillance · data surveillance device · device onboarding · endpoint DLP · enterprise agreement · interception · Microsoft Compliance Extension · network protection duties · penalty unit · prevented delivery notice · surveillance record · unsanctioned application · workplace surveillance

Sources

Legislation was checked against the jurisdictional legislation services and, for New South Wales, against the Bill as passed by both Houses and the New South Wales Judicial Commission Bench Book, on 9 August 2026. Two preferred primary hosts were unreachable during the build, which is why the New South Wales sourcing takes the form it does.

  1. Workplace Surveillance Act 2005 (NSW), Act No 47 of 2005. Text verified against the Bill as passed by both Houses. parliament.nsw.gov.au The source for the s 3 definitions of surveillance, computer surveillance and covert surveillance, and for ss 10, 12, 15, 16, 17, 18, 19, 23, 25 and 29. Last checked 9 August 2026; (high).
  2. Judicial Commission of New South Wales, Local Court Bench Book, 'Workplace Surveillance Act 2005'. judcom.nsw.gov.au Currency as amended to the Industrial Relations Amendment Act 2023, commenced 1 July 2024. Used as an independent cross-check on section numbers and penalties, and the source for the fifty and twenty penalty unit maxima. Last checked 9 August 2026; (high).
  3. Judicial Commission of New South Wales, Sentencing Bench Book, 'Fines'. judcom.nsw.gov.au The source for the New South Wales penalty unit value of $110 under s 17 of the Crimes (Sentencing Procedure) Act 1999 (NSW). Last checked 9 August 2026; (high).
  4. Workplace Privacy Act 2011 (ACT), republication R6. legislation.act.gov.au The source for the s 11 definition of a data surveillance device including a program, the s 13 notice period, the s 16 policy requirement, and ss 41 and 42. Last checked 9 August 2026; (high).
  5. Surveillance Devices Act 2016 (SA), authorised version. legislation.sa.gov.au The source for the s 3 definition of a data surveillance device as including a program, and the s 8 prohibition and penalties. Last checked 9 August 2026; (high).
  6. Surveillance Devices Act 1999 (Vic), and Surveillance Devices Act 2007 (NT). legislation.vic.gov.au and legislation.nt.gov.au The source for the restriction of the data surveillance device prohibitions to law enforcement officers in s 9 and s 14 respectively, and for the Victorian Part 2A workplace privacy provisions covering toilets, washrooms, change rooms and lactation rooms. Last checked 9 August 2026; (medium-high).
  7. Australian Law Reform Commission, Serious Invasions of Privacy in the Digital Era, Report 123, chapter 14, 'Surveillance Devices'. alrc.gov.au Published 2014. Used for the cross-jurisdictional comparison of surveillance devices legislation. Note that it predates the South Australian Act of 2016 and is out of date for that jurisdiction. Last checked 9 August 2026; (medium).
  8. Telecommunications (Interception and Access) Act 1979 (Cth), Federal Register of Legislation, compilation current at 4 June 2026. legislation.gov.au The source for the s 5 definitions of network protection duties and responsible person for a computer network, and for the location of ss 63C, 63D and 63E in Part 2-6. The wording of ss 6(1) and 7(1) is reported here from secondary sources and should be verified against the compilation before quotation. Last checked 9 August 2026; (medium).
  9. Fair Work Commission, 'Consultation term', and Fair Work Regulations 2009 (Cth) reg 2.09 and Schedule 2.3. fwc.gov.au The source for s 205 of the Fair Work Act 2009 (Cth) and the contents of the model consultation term. Last checked 9 August 2026; (high).
  10. Parliament of Victoria, Legislative Assembly Economy and Infrastructure Committee, Inquiry into Workplace Surveillance, and the Office of the Victorian Information Commissioner news item of 11 June 2025. parliament.vic.gov.au and ovic.vic.gov.au The source for the referral in May 2024, the final report in May 2025, and its twenty-nine findings and eighteen recommendations. Last checked 9 August 2026; (high).
  11. Queensland Law Reform Commission, Report 77, and the Queensland Department of Justice civil surveillance reforms consultation page. qlrc.qld.gov.au and justice.qld.gov.au The source for the 2020 recommendation of a Queensland Surveillance Devices Act and the consultation that closed in May 2023. Last checked 9 August 2026; (medium).

Open questions

Whether the Workplace Surveillance Act 2005 (NSW) binds a New South Wales employer in respect of employees working entirely outside the state is unresolved. No primary source or case law was found (low).

Whether a private organisation's internal network is a telecommunications system for the purposes of the Telecommunications (Interception and Access) Act 1979 (Cth) is unresolved, and no authority was found either way (low).

The paragraph lettering of the exceptions in s 7(2) of the interception Act, and the location of the interception-side network protection exception as distinct from the dealing provisions in Part 2-6, were not confirmed (low).

The amendment history of the Workplace Surveillance Act between 2020 and August 2026 was verified against the as-passed Bill and the New South Wales Judicial Commission Bench Book rather than against the consolidated Act's historical notes. One consequential amendment was identified, commencing 1 July 2024. Confirm there is nothing further before relying on the section numbers in a document that matters (medium).

Whether Queensland has enacted a surveillance devices Act since the 2023 consultation is a negative finding based on absence of search results rather than an authoritative statement (medium).

Last updated 9 August 2026