Micron Document

Encryption Law by Country

Where strong encryption is a right, restricted, or compelled. National law and policy, mirrored per country.

Source: Global Partners Digital, World Map of Encryption, updated 2026-07-02. Full data at www.gp-digital.org/world-map-of-encryption

Encryption Law by Country (196)


General right to encryption
No known legislation or policies.

Mandatory minimum or maximum encryption strength
No known legislation or policies.

Licensing/registration requirements
No known legislation or policies.

Import/export controls
Export controls are set out in the Defence and Trade Controls Act 2012, which specifies that an individual must obtain a permit before exporting or supplying items on the Defence and Strategic Goods List (DSGL). Part 2, Category 5 of the Defence and Strategic Goods List 2021 includes certain forms of encryption such as quantum cryptography algorithms and associated software and technology, in addition to other information security devices and goods. However, the scope of encryption export controls are limited by a number of exemptions. These exclude all cryptographic goods being exported for the user’s personal use, all cryptographic software and technology in the public domain, all cryptographic software and technology that is considered basic scientific research, all cryptographic goods and software that is generally available to the public, and all cryptographic technology that is considered the minimum necessary information for a patent application. Therefore, most commonly used forms of encryption and cryptography tools, such as commercial or open-source hardware and software, are not subject to export controls. A copy of the Defence and Strategic Goods List 2021 can be found here . A copy of the Defence Trade Controls Act 2012 can be found here .

Other restrictions
No known legislation or policies.

Obligations on individuals to assist authorities
Under section 3LA of the Crimes Act 1914 (inserted by the Australian Cybercrime Act 2001 and amended by the Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018), a constable may apply to a magistrate for an order requiring a specified person to provide any information or assistance that is reasonable and necessary to allow the constable to do one or more things in relation to data held in, or accessible from, a computer or data storage device which has been seized, found on a person being searched or is on property being searched under a warrant. These are to be able to access the data, to copy the data; or to convert the data into documentary form or another form intelligible to the constable. In order to grant the order, the magistrate must be satisfied of three things. First, that there are reasonable grounds for suspecting that evidential material is held in, or is accessible from, the computer or data storage device. Second, that the specified person is reasonably suspected of having committed an offence, the owner or lessee of the computer or device (or an employee of them or a person engaged under a contract for services by them), a person who uses or has used that computer or device, or a person who is or was a system administrated for the system which includes the computer or device. Third, that the specified person has relevant knowledge of the computer or device or of measures applied to protect data held in, or accessible from, the computer or device. This could include knowledge of the password or other means by which the data has been encrypted and how it can be decrypted. Failure to comply with a requirement in such an order is a criminal offence, punishable by up to five years’ imprisonment or 300 penalty units (63,000 AUD) in ordinary cases, and by up to ten years’ imprisonment or 600 penalty units (124,000 AUD) where the order relates to a serious offence or a serious terrorism offence. The Crimes Act 1914 can be found here .

Obligations on providers to assist authorities
The Telecommunications Act 1997 (as amended by the Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018) provides for three types of requests and notices that the government and certain security and law enforcement agencies can issue to communications providers. Any request or notice must be reasonable and proportionate, and compliance must be practicable and technically feasible. The assessment of reasonableness and proportionality includes consideration of a number of specified factors, including whether the request or notice is “necessary” as well as “the legitimate expectations of the Australian community relating to privacy”. In relation to encryption, a request or notice must not have the effect of “requesting or requiring a designated communications provider to implement or build a systemic weakness, or a systemic vulnerability, into a form of electronic protection” or “preventing a designated communications provider from rectifying a systemic weakness, or a systemic vulnerability, in a form of electronic protection” (section 317ZG(1)). The Act explicitly states that such prohibited requests would include any which involve implementing or building new decryption capabilities in relation to a form of electronic protection as well as anything that would render systemic methods of authentication or encryption less effective (sections 317ZG(2) and (3)). Weaknesses and vulnerabilities are systemic if they affect “a whole class of technology” but are not if they are “selectively introduced to one or more target technologies that are connected with a particular person” (section 317B). Failure to comply with a technical assistance notice or a technical capability notice is an offence, punishable by up to 47,619 penalty units (AUD 9,999,990) if the provider is a body corporate and 238 penalty units (AUD 49,980) if it is not (section 317ZB). A copy of the Telecommunications Act 1997 can be found here .

Assessment Text Area
Australia’s legal framework contains some restrictions on encryption. These include export controls and obligations on providers and individuals to assist authorities. The export controls prohibit exporting, supplying or publishing certain forms of encryption software or technology unless authorisation is granted, but commonly used forms of encryption and cryptography tools are exempt. The legal framework also provides for three types of requests and notices that the government and certain security and law enforcement agencies can issue to communications providers. The legal framework provides constables with powers to require a specific person to provide access to encrypted data, subject to specific safeguards.

Active policy processes
No known active policy processes.




Murphy's Law