The Warrant Was the Part Doing the Work
On 6 August the NSW Government introduced the Crimes and Other Legislation Amendment (Further Organised Crimes Reforms) Bill 2026, which is still before Parliament. Most of the attention has gone to the measures that make good copy: unredacted toll camera images, NSW driver licence photos joining the Commonwealth’s face matching service, penalties for obstructing the Crime Commission doubling to ten years.
The provision that matters to your organisation attracted less. The bill extends Digital Evidence Access Orders — the regime that compels a person to supply the access information for a digital device — beyond the circumstances where that device has been seized under a search or crime scene warrant. The government’s release calls it an Australian-first and raises the penalty for non-compliance from five years to seven.
Some of the commentary has described this as warrantless phone surveillance. That is not quite right, and the imprecision is doing nobody any favours. A Digital Evidence Access Order is still an order, made by an issuing officer, on application, for prescribed serious offences connected to organised crime. What is being removed is the predicate — the requirement that the order attach to a device already seized under a warrant obtained for a specific search.
That is a narrower change than the headline, and it is the one with consequences for organisations that have never thought about this at all. The dramatic version of this story is about activists and dissidents. The mundane version is about a device that holds your data, in the hands of someone who is not you, subject to a lawful order you will never see.
Extraction Is Not a Search
Once access is compelled, the device is not searched. It is extracted. NSW Police use Cellebrite’s Universal Forensic Extraction Device, which does not go looking for the six messages relevant to an investigation. It takes what it can reach in a single pass, and the analysis happens afterwards, against a copy.
The volumes are public and they are not exceptional. A disclosure by the NSW Police Digital Forensics Unit records 30,794 extractions in the three financial years to June 2025 — 13,897 in 2022–23, 7,765 in 2023–24 and 9,132 in 2024–25 — performed across 160 Cellebrite kits deployed to police locations around the state. This is routine forensic practice operating at scale, not a capability held in reserve for extraordinary cases.
The same disclosure deserves reading precisely, because it undercuts the most alarming version of the story. Of those extractions, 20,553 were logical, 9,428 file system and 813 physical. Physical extraction is the bit-level image that recovers deleted material, and it accounts for under three per cent of the total. Two-thirds were logical — the shallower kind, taking what the operating system is willing to hand over.
That distinction matters a great deal to the civil liberties argument and almost nothing to yours. What an operating system willingly hands over is the mail client, the message history, contacts, calendar, photographs and documents. On a work-connected phone that means several years of correspondence cached locally. Chat history in Teams or Slack, which is where the candid version of most commercial discussions now lives. Files opened on the road and never cleared. Refresh tokens for half a dozen SaaS platforms. Photographs of whiteboards from planning sessions. Personal information about customers, patients or staff, in volumes nobody has ever counted because nobody has ever had cause to.
None of it is filtered out. The order concerns the device, not the ownership of the information on it.
The Order Is Served on a Person. The Exposure Sits With You.
Here is the part that should concentrate the mind at board level. The person subject to the order need not be under suspicion in any matter connected to your business. Their exposure can be entirely personal, entirely unrelated to work, and entirely their own affair.
Your data goes anyway.
If your fleet is bring-your-own-device — and for most Australian organisations outside the regulated sectors, some meaningful part of it is — then the container holding your commercial information is an asset you do not own, cannot inspect and have no standing to protect. Legal professional privilege, client confidentiality undertakings, material non-public information, personal information you hold under the Australian Privacy Principles: all of it is on the device, and none of it travels with a label.
There is also no mechanism by which anyone tells you. The order is served on the individual. They are under no obligation to inform their employer, and in the ordinary case they will be dealing with something distressing and will not think of it. Your organisation’s information can be copied to a third party, retained under a policy you have never read, and you will find out — if you find out — months later and by accident.
The Question Your Breach Process Cannot Answer
Somebody in your organisation should be able to say what happens next under the Notifiable Data Breaches scheme, and I would be surprised if anybody can.
The honest answer is that lawful access is not unauthorised access, and an extraction executed under a valid court order is unlikely to constitute an eligible data breach on its face. That is the probable position. It is not a settled one, and the reasoning has not been written down anywhere in your organisation.
Which is the actual problem. The scheme turns on unauthorised access to or disclosure of personal information the entity holds, assessed against a likelihood of serious harm. An organisation that has never considered the scenario has no assessment, no decision record and no reasoning to produce. “We had not thought about it” is a materially worse answer to a regulator than a documented conclusion that no notification was required and here is why. The second answer takes an afternoon. The first one takes an enforcement action.
This Belongs in the Management System, Not the Op-Ed Page
The instinct with a story like this is to argue about the legislation. That is a legitimate debate and it is not the one available to you, because whatever happens to this bill, the underlying capability has been in routine use since 2022 and the exposure predates the reform by years.
What is available to you is the control environment, and this is a gap with an unusually clear shape. Under ISO 27001 it lands squarely across user endpoint devices (A.8.1), security of assets off-premises (A.7.9), acceptable use (A.5.10) and the protection of personally identifiable information (A.5.34). If your Statement of Applicability claims those controls and your mobile device policy does not address compelled access, the claim is thinner than it reads.
The remedies are neither novel nor expensive. Containerise corporate data so it is separable from the device and remotely revocable. Stop local caching of mail and documents beyond a short window. Shorten token lifetimes so that a device image captures credentials that are already dead. Reduce what synchronises to mobile at all — most of the exposure is data nobody needed on a phone in the first place. Put a clause in the acceptable use policy requiring an employee to notify the organisation if a work-connected device is taken into custody, and make it clear that the obligation runs to the fact of it, not to the reason.
And be honest about the limits. Once a device is powered on and physically in someone else’s possession, remote wipe is not a plan. Prevention here means the data was never there.
The Takeaway
This is the domestic version of a problem this publication has already covered at the border, and it is harder precisely because it is duller. Border device searches at least come with a triggering event — someone booked a trip, and a travel policy could in principle catch it. This one has no trigger. There is no departure gate, no itinerary, no moment where the organisation could reasonably have been on notice.
The only place it can be caught is upstream, in the decision about what corporate information is permitted to sit on a device your organisation does not control. That is a governance decision, it costs a meeting, and the alternative is discovering the answer from somebody else’s court file.