ntworld.ink
Part Five · Governance, law and proportionate response

Notice, consent and proportionality in monitoring program design

Lawfulness is a floor. Capability is not justification, consent in employment is not voluntary, and proportionality is a written argument rather than a score.

Part Five About 20 minutes

The capability is licensed. It is documented. There is a default policy that ships in audit mode, and a dropdown that changes audit to block. From the console, the whole thing is an afternoon's work.

That is the entire technical question, and it is the smaller half. The question underneath it has no dropdown. What harm is this control addressing, stated concretely enough that someone could show it was the wrong harm. Is this the least invasive control that materially reduces that harm. Whose personal information does it collect besides the employee's. And can the organisation write the reasoning down in a form that survives being read back by a privacy officer, a union delegate or a tribunal.

Chapters 28 and 29 established what the law requires. This chapter is about what the law leaves open, which is most of it. Several controls in Parts Three and Four are lawful in most Australian jurisdictions with notice and policy in place. Lawfulness is a floor. This chapter is the part of the manual that supplies the judgement, and it honours two things Part Four handed forward: the proportionality of risk-adaptive enforcement, from Chapter 25, and the point at which usage reporting becomes individual monitoring, from Chapter 26.

Necessity, and where proportionality actually lives

The operative phrase across Australian privacy law is 'reasonably necessary'. Collection is permitted where it is reasonably necessary for one or more of the entity's functions or activities. Everything else in the collection principle is elaboration on that phrase.

Two things about it are worth knowing precisely.

It is an objective test. The regulator's guidance puts it as whether a reasonable person who is properly informed would agree that the collection is necessary (high). Not whether the organisation thinks it is necessary, and not whether it would be useful. The burden of demonstrating necessity sits with the entity.

And the guidance now states directly that proportionality is implicit in the reasonably necessary requirement, and requires entities to take a data minimisation approach, with data collected being relevant, minimal and not excessive (high). That sentence, at paragraph 3.26 of the current guidelines, is the single most useful thing a defender can carry into a design meeting, because it converts proportionality from an ethical preference that can be traded away into a regulatory expectation attached to a statutory test.

The state and territory principles use the same structure. The Northern Territory's IPP 1.1 provides that a public sector organisation must not collect personal information unless the information is necessary for one or more of its functions or activities, and IPP 1.2 requires collection by lawful and fair means and not in an unreasonably intrusive way (high). 'Not in an unreasonably intrusive way' is a proportionality test in six words.

Why consent is the wrong instrument

Somebody in the meeting will say that staff consented to monitoring when they signed their contract. It is worth being precise about why that is not the answer, because the objection is not that consent is bad but that it is doing no work.

Consent, in Australian privacy law, must be voluntary, informed, specific, current, and given by a person with the capacity to give it. Employment defeats the first element in most cases. An employee who declines a condition of employment is not making a free choice in the sense the concept requires, and a consent that cannot be refused without consequence is not voluntary.

The structural evidence for this reading is in the surveillance statutes themselves. New South Wales does not ask an employee to agree to computer surveillance. Section 10 requires the employer to notify. Section 12 requires a policy and prior notification of it. The word 'consent' does not appear as the operative mechanism, and s 10(2) admits agreement only in the narrow sense that an employee may agree to a shorter notice period than fourteen days. The legislature designed the scheme around notice precisely because consent in employment does not bear weight.

A monitoring clause in a contract is not worthless. It is evidence that the employee was told, which goes to the notice question and, as Chapter 29 noted, to the knowledge element of the interception offence. It is simply not the legal basis on which the monitoring is permitted, and treating it as one is the most common error in this area.

One qualification, because the rule is not absolute. Where a genuinely optional programme exists, with a real alternative and no consequence for declining, consent can do real work. A pilot that staff volunteer for is a different proposition from a fleet deployment. Those conditions are rare in monitoring, and an organisation that thinks it has met them should check whether declining is genuinely free of consequence.

Notice, and the fact that there are two of them

An organisation that has written one notice has usually written half of what it needs, because two different instruments require two different documents with different contents and different triggers.

The collection notice comes from the privacy principles. Under APP 5.2 the matters are the entity's identity and contact details; the fact and circumstances of collection where the individual may not be aware; whether the collection is required or authorised by law; the purposes of collection; the main consequences if the information is not collected; the entities to which the information is usually disclosed; that the privacy policy explains access and correction; that it explains complaints; and whether the information is likely to be disclosed overseas and where (high). The Northern Territory's IPP 1.3 lists six equivalent matters, and the state variants are close (high). The trigger is collection, and the timing is at or before collection where practicable.

The surveillance notice comes from the workplace surveillance statute. Under s 10(4) of the New South Wales Act the matters are the kind of surveillance, how it will be carried out, when it will start, whether it is continuous or intermittent, and whether it is for a limited period or ongoing (high). The trigger is the commencement of surveillance, and the timing is at least fourteen days before.

They overlap and they are not the same. The collection notice explains what happens to the information; the surveillance notice explains what the watching consists of. An organisation with a privacy collection statement and no surveillance notice has satisfied one statute and not the other. Write both, publish both, date both, and re-issue when the control changes.

The invasiveness ladder

It helps to have a shared vocabulary for how far a proposed control goes, so that a design conversation can be about levels rather than products. Five levels, from least to most invasive, described here as a way of naming a proposal rather than as a maturity model to be climbed.

Aggregate metadata, with no user attribution at the point of reporting. Which applications are in use, by how many people, at what volume. This answers the question a governance committee is actually asking, which is about scale and category.

User-attributed application and site telemetry. That a named account reached a named service at a time, uploaded a file, or pasted content. The subject becomes a person rather than a population.

Sensitive information matching with metadata logging. That a named account submitted content matching a sensitive information type to a named service, recorded without capturing the content itself. This is where Microsoft's default policies sit, and the default is well chosen.

Prompt content capture, or inline content inspection. The text itself, retained or scanned in real time.

Continuous behavioural analytics, screen capture and keystroke logging. A model of the individual, maintained over time.

The argument, stated plainly. The first three levels are ordinarily defensible in an Australian public sector organisation that has done the notice and policy work. The fourth needs a specific justification, a narrow scope and role-based access to the results, and for free consumer services it should generally be refused for the reasons below. The fifth is not appropriate outside an authorised investigation, and an organisation that finds itself discussing it should first ask what question it is trying to answer.

The rule underneath the ladder is one sentence: capability is not justification. That a control is included in the entitlement, is recommended by a posture dashboard, and can be enabled with one click, contributes nothing to the question of whether it should be.

When reporting becomes monitoring

Chapter 26 left this open and it belongs here.

Aggregate usage reporting and individual monitoring are frequently the same telemetry with a different query. A dashboard that shows two hundred staff reached a service last month is built from records that each name one person. Nothing technical separates the aggregate from the individual; the aggregate is a group-by.

So the distinction cannot be a property of the data pipeline. It has to be a property of who can run which query, against which population, for what purpose, with what approval, and with what record of having done so. That makes the control an access control over analysts and an audit trail over queries, not a configuration setting on a collector. An organisation that says it only does aggregate reporting, and gives twelve people unrestricted query access to the underlying table, is not doing aggregate reporting. It is doing individual monitoring that nobody has asked for yet.

Behavioural baselining is the sharpest version of the problem. A baseline is a model of an individual's normal conduct, built in order to detect departures from it. Building one is a decision about a person, taken before any suspicion exists, and the fact that it is described as anomaly detection does not change what it is. It can be justified. It should be justified explicitly, and not arrive as a consequence of enabling a product feature.

A proportionality test that can be written down

Proportionality is often invoked as a sentiment. It is more useful as a short list of questions with written answers, because the written answers are the artefact that survives.

What specific harm is this addressing? Described concretely enough that it could be shown to be the wrong harm. 'Data leakage' is not concrete. 'A staff member pasting identifiable client information into a service the organisation has no agreement with, where it may be retained and may inform outputs to other users' is.

What is the least invasive control that materially reduces that harm? Note the two words doing work. 'Least invasive' points down the ladder. 'Materially' rules out the control that reduces the harm by an amount nobody could measure.

What does the next level up add? Expressed as a difference in outcome, not a difference in capability. Content capture adds the ability to see the text. What decision would the organisation make differently, having seen it, that it would not make having seen only that a match occurred?

Whose personal information does this collect besides the employee's? Chapter 28 established why this question matters and it is the one most often skipped.

What is the retention period, who can query it, and what is logged when they do?

And the last one, which is not a legal test and changes more answers than the other five combined: what would the organisation say if this control were described accurately in a newspaper, or in a union bulletin, or by a staff member to a journalist? If the answer requires the control to be described inaccurately, the analysis has already produced its result.

There is no score at the end of this. It produces a written argument, which is what a regulator, a tribunal or a consultative committee actually wants, and which a committee that wanted a number will find unsatisfying.

Privacy impact assessments

A privacy impact assessment is the standard vehicle for that written argument.

The obligation is narrow. Section 12 of the Privacy (Australian Government Agencies — Governance) APP Code 2017 requires an agency to conduct a PIA for all high privacy risk projects, and the Code binds agencies as defined in s 6(1) of the Privacy Act, which means Commonwealth agencies (high). It does not bind a State university, which is not an agency, and it does not bind private sector organisations, for whom a PIA is good practice rather than a statutory requirement (high).

Do one anyway. Not because of the obligation, but because the artefact is the reasoning, and the alternative to writing the reasoning down before deployment is reconstructing it afterwards, under time pressure, in front of someone who is unhappy. The regulator's own AI guidance recommends assessments before deploying AI systems, and the same logic applies to deploying a system that monitors AI use.

The shadow AI lens

Designing at the first three levels. Work through what each buys for a shadow AI programme specifically.

Aggregate discovery answers the governance question. Which categories of AI application are in use, at what scale, and is the trend moving. No user attribution is required for any of that, and the committee paper is better without it.

User attribution becomes necessary when the question changes shape: not who is doing this, but whether a particular unit or role has a workflow problem that the organisation is failing to meet. That is a legitimate question, and it is worth noticing that the answer to it is usually a service design change rather than an enforcement action.

Sensitive information matching with metadata logging tells the organisation that a match occurred, against which policy, by which account, to which service, without capturing what the content was. It supports a conversation with the individual, it supports a trend line, and it does not create a store of the organisation's most sensitive material in a security tool. This is the design the default policies adopt and it is the right default.

Why content capture for free consumer services is the level to refuse. Three arguments converge on the same conclusion, which is a comfortable position and worth noticing when it happens.

The legal argument, from Chapter 28. A prompt routinely contains personal information about people who are not the employee: students, patients, applicants, members of the public. Capturing prompt content collects information about all of them, and no employee records exemption could reach it even in a jurisdiction where the exemption is available. The organisation would be creating a new holding of third-party personal information as a side effect of supervising its own staff.

The security argument. Doing content inspection at the network layer requires breaking transport security across the fleet, which manufactures a high-value target out of the inspection point and captures banking, health, legal and government traffic that has nothing to do with the question being asked. The volume and sensitivity of personal information the organisation holds goes up, and with it the obligation to protect it.

And the technical argument, from Part Four. For free consumer tiers it mostly does not work anyway. Prompt and response retention is supported for enterprise services connected through the identity layer or a named integration, and for a restricted set of consumer services in the managed browser with a collection policy configured to capture content. The general case is not available. An organisation can spend a great deal of proportionality capital acquiring a capability it will not get.

Adaptive enforcement as an automated decision about a person. Risk-adaptive controls scale enforcement by a computed risk level: audit for most users, warn for some, block with override for those the system has classified as elevated risk. That is a decision about an individual, made by a program, using personal information, with an effect on how they work.

The Commonwealth automated decision-making transparency clauses at APP 1.7 and 1.8 commence on 10 December 2026 and require an entity's privacy policy to describe the kinds of personal information used in such programs and the kinds of decisions they make (high). They bind APP entities, so a State university is outside them. The design expectation they express is reasonable to adopt regardless: if the organisation runs a system that classifies staff by risk, say so, in the policy, in plain terms, along with what happens at each level and how a person finds out they have been classified.

A worked contested case. Australian regulatory practice has one clear application of a necessity and proportionality analysis to a technology deployment, and it is worth telling with both halves.

In November 2024 the Australian Information Commissioner determined that a retailer's use of facial recognition contravened the Privacy Act. The reasoning is the part to learn: an entity must assess whether it is reasonably necessary to collect the information in order to carry out its functions and activities, must not deploy a technology merely because it is available, convenient or desirable, and must weigh whether the benefits gained outweigh the privacy interference caused (high).

In March 2026 the Administrative Review Tribunal's Guidance and Appeals Panel substantially overturned that outcome, upholding the use of the technology for the limited purpose of combating retail crime and protecting staff and customers, while not disturbing the findings about inadequate notification and insufficient governing policies (high on the outcome, from the Commissioner's own statement; low on the tribunal's neutral citation, which was not confirmed).

Both halves belong in any honest treatment. The proportionality analysis is genuinely contestable, and a defender who presents it as settled will be embarrassed. The notification and governance failures were contested by nobody. The lesson for a shadow AI programme is that the arguable part is whether the control is proportionate, and the unarguable part is whether people were told and whether a policy existed. Get the unarguable part right first.

Where this breaks down

Proportionality is not a defence to a specific statutory prohibition. An excellent assessment does not make a South Australian data surveillance program lawful without consent, and does not cure a missing New South Wales notice. The analysis operates in the space the statutes leave open, and where a statute closes the space, the analysis is irrelevant.

A privacy impact assessment is a document. It creates no control, prevents nothing, and an organisation can produce a thorough one and deploy the thing anyway. Its value is that it makes the decision visible and attributable, which is not the same as making it good.

Notice fatigue is real. A notice that nobody reads satisfies the statute and fails the purpose, and the response is fewer and clearer notices rather than more.

The analysis has to be redone when the control changes, and vendor defaults change without asking. A policy that was audit-only when it was assessed and is block-with-override two releases later is a different control with a different proportionality position, and nobody sends an email about it.

The six questions produce an argument, not a score. A committee that wants a risk rating will not be satisfied, and inventing one to satisfy them converts a defensible piece of reasoning into an indefensible number.

And the honest limit of the whole chapter: proportionality reasoning is easiest to apply to the controls that reach the fewest people, and hardest to apply where it matters most. Nobody argues about aggregate discovery. The arguments happen at the level where the organisation is deciding what to do about a specific person, and at that point the process discipline described here is what stands between a defensible decision and an improvised one.

Check your understanding
  1. Explain in two sentences why a monitoring clause in an employment contract is not the legal basis for monitoring, and say what the clause is actually good for.
  2. Take a control your organisation already runs, place it on the invasiveness ladder, and state what the next level up would add expressed as a difference in outcome.
  3. A manager asks to see one named staff member's AI usage. Write the two-sentence reply, and name the thing you would need to have in place before the answer could be yes.
  4. Identify whose personal information other than the employee's is collected by prompt content capture, and say which exemption would not reach it.
  5. State which of the six proportionality questions your organisation would answer worst, and why.

Glossary terms used in this chapter

adaptive protection · collection notice · collection policy · consent · data minimisation · endpoint DLP · Insider Risk Management · invasiveness ladder · privacy impact assessment · proportionality · sensitive information type · sensitivity label · workplace surveillance

Sources

  1. Office of the Australian Information Commissioner, 'Australian Privacy Principles guidelines, chapter 3: APP 3 Collection of solicited personal information', version 1.2, updated 13 May 2026. oaic.gov.au The source for the objective 'reasonably necessary' test at paragraph 3.25 and for the proportionality and data minimisation statement at paragraph 3.26. Last checked 9 August 2026; (high).
  2. Office of the Australian Information Commissioner, 'Australian Privacy Principles guidelines, chapter 5: APP 5 Notification of the collection of personal information'. oaic.gov.au Last updated 12 October 2023. The source for the ten matters in APP 5.2. Last checked 9 August 2026; (high).
  3. Northern Territory Information Commissioner, text of the Information Privacy Principles. infocomm.nt.gov.au The source for IPP 1.1, IPP 1.2 and the six collection notice elements in IPP 1.3. Last checked 9 August 2026; (high).
  4. Workplace Surveillance Act 2005 (NSW), s 10. Text verified against the Bill as passed by both Houses. parliament.nsw.gov.au The source for the five matters a surveillance notice must state, and for the point that the scheme is built on notice rather than consent. Last checked 9 August 2026; (high).
  5. Privacy (Australian Government Agencies — Governance) APP Code 2017 (Cth), ss 5, 7 and 12. legislation.gov.au The source for the requirement that an agency conduct a privacy impact assessment for all high privacy risk projects, and for the limitation of that obligation to agencies. Last checked 9 August 2026; (high).
  6. Privacy and Other Legislation Amendment Act 2024 (Cth), Schedule 1 Part 15, as made. legislation.gov.au The source for the automated decision-making transparency clauses at APP 1.7 and 1.8 and their commencement on 10 December 2026. Last checked 9 August 2026; (high).
  7. Office of the Australian Information Commissioner, 'Guidance on privacy and the use of commercially available AI products'. oaic.gov.au Published 21 October 2024, last updated 17 January 2025. Supports the treatment of reasonable alternatives as bearing on necessity, and the recommendation to conduct assessments before deployment. Last checked 9 August 2026; (high).
  8. Office of the Australian Information Commissioner, 'GenAI tools in the workplace: balancing protection of personal information and business efficiency', blog by Natalie Le, 4 December 2025. oaic.gov.au The regulator's own graduated position, placing policy, training and technical measures on a scale rather than defaulting to prohibition. Last checked 9 August 2026; (high).
  9. Office of the Australian Information Commissioner, 'Facial recognition technology in retail settings after the Bunnings decision'. oaic.gov.au The source for the reasoning in the determination of 19 November 2024, including that an entity must not deploy a technology merely because it is available, convenient or desirable. Last checked 9 August 2026; (high).
  10. Office of the Australian Information Commissioner, 'Privacy Commissioner statement on Administrative Review Tribunal's Bunnings decision', 5 March 2026. oaic.gov.au The source for the outcome of the review, including that the notification and governing policy findings were not disturbed. The tribunal's own citation was not obtained. Last checked 9 August 2026; (medium).
  11. Telemetry and Control Options for Shadow AI in an Australian University (this project's internal source report), section 6. The origin of the five-level invasiveness ladder rendered here as prose, and of the position that levels one to three are the defensible default for a public sector organisation.

Open questions

The neutral citation and exact date of the Administrative Review Tribunal decision reviewing the November 2024 facial recognition determination were not confirmed during this build. The outcome is confirmed from the Commissioner's statement of 5 March 2026. Retrieve the citation before quoting the decision (low).

The proportionality and data minimisation language at paragraph 3.26 of the APP Guidelines chapter 3 appears in the version updated 13 May 2026 and may be new or strengthened relative to earlier versions. That comparison was inferred rather than verified by reading the archived versions side by side (medium).

Whether any Australian tribunal or court has applied the statutory tort of serious invasion of privacy to workplace monitoring is not known. The tort commenced on 10 June 2025 and no such case was found (medium).

Last updated 9 August 2026