Australian Human Rights Commission Human Rights in the Digital Age: Additional Material Submitted to the UN Global Digital Compact, 30 April 2023 Privacy Safety Regime which utilises concepts from product intervention powers and product safety interventions, proposing options that would allow governments and regulators to stop or limit obviously harmful uses of data as well as a process for regulators to proactively restrict and test new harmful practices as they evolve.14 29. While the Working Paper is specific to Australia, the Commission would call upon the Envoy to consider how similar models may be applicable, or could be adapted, to inform the better protection of data globally. Recommendation 1: Countries must consider models for protecting data and personal information online which do not place the primary onus on individuals to actively protect their personal information. 3.2 Review of existing legislative frameworks 30. In 2023, the Australian Government Attorney-General’s Department released the final report of its review of the Privacy Act 1988 (Cth) which considered whether Australia’s privacy legislation was fit for purpose. This review recognised that Australians now live much of their lives online, where their information is collected and used for a myriad of purposes in the digital economy. 31. The Privacy Act 1988 (Cth) (Privacy Act) is a key legislative protection of individuals’ personal information in Australia. The 13 Australian Privacy Principles (APPs) are structured to reflect privacy obligations across the information lifecycle, as entities collect, hold, use, disclose, and destroy or de-identify personal information. The APPs are legally binding principles, which provide entities with the flexibility to take a risk-based approach to compliance based on their particular circumstances, including size, resources and business model, while ensuring the protection of individuals’ privacy. 32. In considering how best to protect data, proactive reviews of key privacy legislation is essential. Countries must regularly review their key pieces of privacy legislation to ensure it is modern, fit for purpose and drafted in a technology neutral manner. Recommendation 2: Countries should regularly engage in consultative reviews of the legislation which regulates privacy and data. Such 7

Select target paragraph3