Australia’s proposed Digital Duty of Care puts algorithms, recommender systems and online product design increasingly in the legal spotlight. (Photo by Sixteen Miles Out on Unsplash)
Children’s Privacy and Online Safety
Apps, websites, social media, online games and AI services face a rapidly changing mix of online safety, privacy and consumer laws. We look at what is changing in Australia — and what businesses should be thinking about now.
If your business operates an app, website, social media service, online game, marketplace, AI chatbot or other digital service, there is a new legal question worth asking:
Could the way your product has been designed create a legal risk?
Until relatively recently, online legal compliance tended to focus heavily on content.
What did somebody post? Should it be removed? Is it defamatory? Does it infringe copyright? What does the privacy policy say? Are the terms and conditions adequate?
Those questions have not disappeared.
But regulators are increasingly looking behind the screen.
How does the algorithm work?
Why does the feed show a user one thing rather than another?
Does the service use infinite scroll, autoplay, notifications, streaks, likes or personalised recommendations to keep people engaged?
Are children using it?
How does the business know their age?
What personal information is being collected to find out?
These questions are particularly timely following several major developments in Australia and overseas.
On 8 September 2026, the Australian Government released the exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026 (Cth).
Australia’s social media minimum-age regime is already operating under the Online Safety Act 2021 (Cth), following amendments made by the Online Safety Amendment (Social Media Minimum Age) Act 2024 (Cth).
Enforcement of that regime has just been strengthened by the Online Safety Amendment (Strengthening Enforcement for the Social Media Minimum Age) Act 2026 (Cth).
Meanwhile, the Office of the Australian Information Commissioner (OAIC) is finalising Australia’s new Children’s Online Privacy Code under the Privacy Act 1988 (Cth).
And overseas, the European Commission has preliminarily found Meta in breach of the European Union’s Digital Services Act in relation to what it describes as the “addictive design” of Facebook and Instagram.
Meta has also agreed to pay approximately US$18 billion over 10 years under an agreement with 52 US state and territory attorneys general concerning teen use of its platforms.
The common thread?
The law is becoming increasingly interested not merely in what an online service contains — but in how the service itself works.
What is Australia’s proposed Digital Duty of Care?
On 8 September 2026, the Australian Government released an exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026 (Cth).
At the time of writing, this is proposed legislation, not yet law.
The proposed legislation would significantly amend the Online Safety Act 2021 (Cth) and introduce a new Digital Duty of Care for online services.
The Government’s stated approach is essentially one of safety by design.
Rather than waiting for particular harmful material to appear and then asking whether it should have been removed, online services would be expected to identify and address relevant risks through their systems and processes.
That represents an important change in emphasis.
For businesses, legal compliance may increasingly begin before a feature is launched.
“My Feed, My Way”: when an algorithm becomes a legal issue
Another important part of the Government’s proposal is its “My Feed, My Way” initiative.
The proposal is intended to give Australians greater control over algorithmically recommended material.
That puts something traditionally regarded as a technical or commercial decision — how a feed is constructed — squarely into the regulatory conversation.
For businesses using recommendation engines and personalised feeds, that raises interesting questions.
What does the algorithm optimise for?
Time spent on the service?
Clicks?
Purchases?
Comments?
Shares?
Engagement?
Does the user understand why material is being recommended?
Can the user meaningfully change the way recommendations work?
And what happens when a business knows that particular design choices may create foreseeable risks?
The answers will depend upon the service and the final form of the legislation.
But these are increasingly questions on which product teams and lawyers may need to speak to each other.
Photo by Richard Williams on Unsplush
Social media minimum age laws in Australia
The Digital Duty of Care is not starting from a blank page.
Part 4A of the Online Safety Act 2021 (Cth), introduced by the Online Safety Amendment (Social Media Minimum Age) Act 2024 (Cth), already contains Australia’s social media minimum-age regime.
Under the regime, providers of age-restricted social media platforms must take reasonable steps to prevent Australian children under 16 from having accounts.
Importantly, the legal obligation is placed on covered platforms rather than on children or parents.
For businesses, one potentially difficult question is whether a particular service is actually caught.
Not every online business looks like Facebook or TikTok.
A service might combine messaging with gaming.
An app might contain a community feature.
A marketplace may allow interaction between users.
An AI product might include social functionality.
A platform may have changed considerably since it was first launched.
The legal characterisation of a service therefore matters.
Stronger enforcement powers arrived in September 2026
The regulatory position changed again this month.
The Online Safety Amendment (Strengthening Enforcement for the Social Media Minimum Age) Act 2026 (Cth) received assent on 11 September 2026.
The amendments strengthen enforcement of the social media minimum-age regime and expand the eSafety Commissioner’s ability to obtain information relevant to compliance.
For businesses caught by the regime — and businesses supplying relevant services to them — that makes record keeping, internal decision-making and compliance evidence increasingly important.
It is one thing to say that reasonable steps were taken.
It may be quite another thing to demonstrate what those steps actually were.
Age assurance and the Privacy Act 1988 (Cth)
The minimum-age regime creates an obvious practical problem.
How does a business know how old somebody is?
Age assurance may require a business or its service providers to process information about users.
That can bring the Privacy Act 1988 (Cth) and the Australian Privacy Principles into consideration.
Questions may arise about what personal information is collected, why it is collected, how it is used, whether it is disclosed to third-party providers, how securely it is stored and how long it is retained.
There is a tension here that businesses should not overlook.
A service may need information about somebody in order to determine whether it should be collecting or using information about that person as a child.
Age assurance therefore should not automatically be treated as simply a technical exercise.
It can also be a privacy exercise.
Photo by Daria Nepriakhina on Unsplush
Australia’s Children’s Online Privacy Code
There is another major development approaching.
The Privacy and Other Legislation Amendment Act 2024 (Cth) required the OAIC to develop a Children’s Online Privacy Code under the Privacy Act 1988 (Cth).
The OAIC released an exposure draft of the Children’s Online Privacy Code on 31 March 2026.
The final Code is due to be registered by 10 December 2026.
The draft contains proposed protections concerning the handling of children’s personal information, including requirements directed at children’s best interests and proposed rules concerning targeted advertising and deletion of children’s personal information.
Importantly, businesses should not necessarily assume the Code is relevant only if they deliberately market a service to children.
The potential reach of children’s online privacy regulation makes the actual nature of the service, its users and its data practices important.
For some businesses, a critical question may therefore be:
We didn’t build this for children — but are children likely to use it?
What happened to Meta in the United States?
The international litigation provides some context for the direction of travel.
In August 2026, Meta announced an agreement with a bipartisan group of 52 attorneys general across US states, territories and the District of Columbia.
The agreement involves approximately US$18 billion in payments over 10 years.
But the interesting part for Australian online businesses is not simply the size of the cheque.
The agreement includes measures directed at how teenagers use Facebook and Instagram, including a default two-hour daily time limit, restrictions on access overnight, limits on notifications during school hours and additional age-assurance and parental-control measures.
Approximately US$5.3 billion of the payment is conditional upon specified measures also being adopted by TikTok and YouTube and corresponding payments being made.
The settlement is therefore concerned not simply with compensating for alleged past conduct.
It reaches into how digital products are designed and used.
Europe and “addictive design”
Europe has gone further again.
On 10 July 2026, the European Commission announced its preliminary finding that Meta had breached the European Union’s Digital Services Act in relation to the allegedly addictive design of Facebook and Instagram.
The features identified by the Commission include:
- infinite scroll;
- autoplay;
- push notifications; and
- highly personalised recommender systems.
The European Commission’s findings are preliminary and concern European, not Australian, law.
Nevertheless, they are highly relevant to the international regulatory direction.
Features that might once have been discussed only by UX designers and growth teams are now being discussed by legislators, regulators and litigators.
What about the Australian Consumer Law?
Online safety and privacy are not the only legal regimes businesses should have on their radar.
The Australian Consumer Law, contained in Schedule 2 to the Competition and Consumer Act 2010 (Cth), may also be relevant.
Section 18 prohibits misleading or deceptive conduct in trade or commerce.
Section 29 contains prohibitions concerning particular false or misleading representations.
Section 34 prohibits certain misleading conduct concerning the nature and characteristics of services.
Consider statements such as:
“Safe for children.”
“Parents are in control.”
“Turn this setting off and we stop tracking you.”
“We don’t use your information for advertising.”
“Your information is private.”
Those might appear to be ordinary marketing statements or interface copy.
But if they do not accurately reflect how the underlying product operates, Australian Consumer Law questions may arise.
Australian Competition and Consumer Commission v Google LLC (No 2) [2021] FCA 367
Google’s Australian location-data litigation provides an important example of why interface design and legal compliance can intersect.
In Australian Competition and Consumer Commission v Google LLC (No 2) [2021] FCA 367, the Federal Court considered representations made to Android users about Google’s collection and use of location data.
The case involved, among other things, the interaction between different account settings and what users were led to understand about the consequences of switching particular settings on or off.
The case was not about children’s online safety or addictive design.
Its relevance here is different.
It demonstrates that the gap between what an interface appears to tell users and what a digital system actually does can have legal consequences.
Fairfax Media Publications Pty Ltd v Voller; Nationwide News Pty Limited v Voller; Australian News Channel Pty Ltd v Voller [2021] HCA 27
Australian courts have also had to consider how responsibility operates when businesses facilitate interactions through online platforms.
In Fairfax Media Publications Pty Ltd v Voller; Nationwide News Pty Limited v Voller; Australian News Channel Pty Ltd v Voller [2021] HCA 27, the High Court considered whether media organisations that created and operated public Facebook pages were publishers of comments posted by third-party Facebook users.
The High Court held that the media organisations’ participation in facilitating the communication was sufficient for publication for the purposes of the case.
Again, this was a defamation case, not an online-safety case.
But it demonstrates why understanding how a platform actually operates can matter to the application of established legal principles.
Google LLC v Defteros [2022] HCA 27
The High Court returned to questions concerning online publication in Google LLC v Defteros [2022] HCA 27.
That case concerned Google search results containing a hyperlink to an allegedly defamatory newspaper article.
The High Court allowed Google’s appeal and held, in the circumstances of the case, that providing the search result did not amount to publication of the defamatory material in the linked article.
The contrast with Voller is useful.
The legal result may depend considerably upon what the technology does and the role the business actually plays in the communication.
That is another reason why generic assumptions about being “just a platform” or “just a technology provider” can be dangerous.
Privacy litigation has changed too
Since 10 June 2025, Australia has also had a statutory tort for serious invasions of privacy.
The cause of action is contained in Schedule 2 to the Privacy Act 1988 (Cth).
Subject to its statutory requirements, exemptions and defences, it provides a potential cause of action where there has been an invasion of privacy involving an intrusion upon seclusion or misuse of information and the other statutory elements are established.
Importantly, its potential operation is broader than the Australian Privacy Principles regime and may extend to defendants who are not themselves APP entities.
For digital businesses collecting, analysing and using substantial amounts of information about users, this adds another consideration to an already crowded legal landscape.
Which Australian businesses should be looking at this?
Not every law discussed above applies to every digital business.
That is precisely the point.
Depending upon their circumstances, businesses that may need to consider these developments include:
- social media platforms;
- apps;
- online games and gaming platforms;
- AI chatbots and generative AI services;
- dating apps;
- online marketplaces;
- messaging services;
- health and fitness apps;
- children’s and educational services;
- creator and content platforms;
- websites containing user communities or social features;
- businesses using recommendation engines or personalised feeds; and
- overseas digital businesses providing services to Australians.
A business does not necessarily need millions of Australian users before legal compliance matters.
Nor does it necessarily need to describe itself as a “social media platform”.
What the service actually does may matter more than the label attached to it.
Why use a lawyer for online safety and privacy compliance?
Because the difficult question is often not what a particular Act says in isolation.
It is which laws apply simultaneously — and how they interact with the particular product.
A new age-assurance feature might raise questions under the Online Safety Act 2021 (Cth) and the Privacy Act 1988 (Cth).
The way that feature is described to users may raise a separate issue under the Australian Consumer Law.
If children use the service, the Children’s Online Privacy Code may become relevant.
If an algorithm recommends material or is designed to maximise engagement, the proposed Digital Duty of Care may need to be considered.
If the business receives complaints suggesting that a feature is causing harm, internal documents about how those complaints were investigated may later become important.
And a business operating internationally may need to understand how Australian obligations fit with overseas regimes.
There may not be one compliance checklist that answers all of those questions.
What are the legal risks for online businesses?
Regulatory penalties are the most obvious risk, but they are not the only one.
Depending upon the business and circumstances, potential exposure may include:
- eSafety investigation and enforcement;
- privacy complaints and regulatory action;
- Australian Consumer Law claims;
- civil litigation;
- the statutory tort for serious invasions of privacy;
- contractual disputes;
- discovery and document-production obligations;
- reputational damage; and
- the commercial cost of redesigning a product after it has already launched.
Internal documentation can also become important.
What did the business know about the risk?
When did it know?
What testing was undertaken?
What did users complain about?
What did the algorithm optimise for?
Was a safer alternative considered?
Why was one default selected over another?
What did the business tell parents or users?
And does the product actually operate in the way its privacy policy, terms and marketing materials say it does?
These questions are much easier to consider before a regulator or litigant starts asking them.
How Sharon Givoni Consulting can assist online businesses
At Sharon Givoni Consulting, we advise businesses at the intersection of technology, intellectual property, privacy, consumer law and online regulation.
Depending upon the particular service, this may involve advice concerning:
- the Online Safety Act 2021 (Cth);
- Australia’s social media minimum-age requirements;
- the proposed Online Safety Amendment (Digital Duty of Care) Bill 2026 (Cth);
- the Privacy Act 1988 (Cth) and Australian Privacy Principles;
- the Children’s Online Privacy Code;
- age assurance and children’s data;
- privacy policies and collection notices;
- terms and conditions;
- AI and chatbot services;
- platform and product design;
- Australian Consumer Law representations;
- online marketplaces and user-generated content;
- internal risk and governance documentation; and
- responding to regulatory or legal complaints.
The starting point is often not simply reading the business’s terms and privacy policy.
It is understanding what the product actually does.
Because Australia’s digital laws are increasingly looking behind the screen.
Interesting facts: online safety, algorithms and children’s privacy
Under 16: Australia’s social media minimum-age regime applies to Australian children who have not reached 16, with the compliance obligation imposed on covered platforms rather than children themselves.
Under 18: Australia’s proposed Children’s Online Privacy Code concerns the privacy of children and young people under 18.
10 December 2026: the OAIC is required to have Australia’s Children’s Online Privacy Code ready for registration by this date.
US$18 billion: the approximate value of Meta’s 10-year agreement with 52 US attorneys general.
US$5.3 billion: approximately 30% of Meta’s payment is conditional upon specified action by YouTube and TikTok, including teen protections and matching payments.
2 hours: Meta’s US agreement includes a default two-hour daily limit for teenagers across Facebook and Instagram, which can only be switched off with parental permission.
Midnight to 6 am: Meta’s agreement provides for default overnight blocking of teen access to parts of Facebook and Instagram.
Infinite scroll is now a legal issue: the European Commission has expressly identified infinite scroll, autoplay, push notifications and highly personalised recommender systems in its preliminary Digital Services Act findings concerning Meta’s allegedly addictive design.
A privacy policy may not be enough: increasingly, regulators and courts can be interested in whether what a business tells users matches what its technology actually does.
The law is looking under the bonnet: product design, algorithms, defaults, data collection and engagement features are increasingly moving from the product team’s desk to the lawyer’s.
Further Reading
Australian Government — Exposure Draft: Online Safety Amendment (Digital Duty of Care) Bill 2026
8 September 2026
https://www.infrastructure.gov.au/department/media/publications/exposure-draft-online-safety-amendment-digital-duty-care-bill-2026
Australian Government — Online Safety Act 2021 (Cth)
https://www.legislation.gov.au/C2021A00076/latest/text
Australian Government — Online Safety Amendment (Social Media Minimum Age) Act 2024 (Cth)
https://www.legislation.gov.au/C2024A00127/latest/text
Australian Government — Online Safety Amendment (Strengthening Enforcement for the Social Media Minimum Age) Act 2026 (Cth)
https://www.legislation.gov.au/C2026A00083/asmade
Office of the Australian Information Commissioner — Children’s Online Privacy Code
https://www.oaic.gov.au/privacy/privacy-for-kids/privacy-for-kids-childrens-online-privacy-code
Office of the Australian Information Commissioner — Statutory tort for serious invasions of privacy
https://www.oaic.gov.au/privacy/your-privacy-rights/more-privacy-rights/statutory-tort-for-serious-invasions-of-privacy
European Commission — “Commission preliminarily finds the addictive design of Instagram and Facebook in breach of the Digital Services Act”
10 July 2026
https://digital-strategy.ec.europa.eu/en/news/commission-preliminarily-finds-addictive-design-instagram-and-facebook-breach-digital-services-act
Meta — “Our Agreement With Bipartisan Attorneys General: Calling on TikTok and YouTube to Join Us in Supporting Teens”
August 2026
https://about.fb.com/news/2026/08/agreement-with-state-attorneys-general-supporting-teens/
Cases
Australian Competition and Consumer Commission v Google LLC (No 2) [2021] FCA 367
Fairfax Media Publications Pty Ltd v Voller; Nationwide News Pty Limited v Voller; Australian News Channel Pty Ltd v Voller [2021] HCA 27
https://www.hcourt.gov.au/cases-and-judgments/judgments/judgments-1998-current/fairfax-media-publications-pty-ltd-v-voller
Google LLC v Defteros [2022] HCA 27
https://www.hcourt.gov.au/cases-and-judgments/judgments/judgments-1998-current/google-llc-v-defteros
Please note the above article is general in nature and does not constitute legal advice.
Please email us info@iplegal.com.au if you need legal advice about your brand or another legal matter in this area generally.

