The compliance assumption most agencies are getting wrong
Cross-agency data sharing sits at the centre of most whole-of-government communications strategies issued over the past five years. The assumption embedded in those strategies — rarely examined, almost never formally tested — is that existing data-sharing agreements provide sufficient authorisation for paid-media activation. They do not, and the gap between what agencies believe is authorised and what is actually permitted is material, not procedural.
How data-sharing agreements were written — and for whom
Data-sharing agreements between Commonwealth agencies are typically drafted by legal teams advising on administrative law and service-delivery obligations. Their purpose is to enable one agency to provide data to another for a defined administrative function: income verification, eligibility assessment, fraud detection, service personalisation. The concept of using that data to construct audience segments for a demand-side platform, match those segments against commercial identity graphs, and pass them to an advertising exchange for programmatic bidding did not feature in the drafting instruction. It was not an oversight; it was simply not a foreseeable downstream application at the time most current agreements were executed.
The consequence is that communications directors and digital transformation leads reading those agreements today find general language about improving service outcomes, enhancing citizen experience, or supporting government communications — and interpret that language as covering paid-media activation. A careful reading of the Australian Government Agencies Privacy Code tells a different story.
Clause 10 of the Privacy Code and the reasonable-expectations standard
The Australian Government Agencies Privacy Code (2017), which binds all agencies subject to the Privacy Act 1988, sets out in clause 10 the conditions under which personal information collected for a primary service-delivery purpose may be used for a secondary purpose. The operative standard is whether the individual would reasonably expect the secondary use, or whether the secondary use is directly related to the primary purpose. Programmatic audience targeting — in which behavioural signals or enrolment attributes are matched against commercial identifiers and used to serve targeted advertising across third-party inventory — fails this standard on both counts for the overwhelming majority of data collected through service-delivery interactions. A citizen who provides income information to Services Australia for a welfare payment does not reasonably expect that information to inform a retargeting campaign on a social media platform or a programmatic display network.
The custodian gap: who carries the compliance risk
Because campaign procurement structures in Australian government separate the data-custodian function from the media-buying function, there is no formal mechanism by which compliance obligations transfer across the boundary between data release and data activation. The data-custodian agency — Services Australia, the Australian Taxation Office, a state revenue office — releases data under an agreement it believes covers the purpose. The communications team or panel media agency receives the data, constructs audience segments, and activates them in a demand-side platform. Neither party has formally assessed whether the activation step falls within the original authorisation. Per the structure of the Privacy Act 1988, the compliance risk defaults to the data-custodian agency, which is typically unaware that its data has entered a media-buying context at all. This is not a hypothetical risk profile; it is the operational default across a significant share of whole-of-government campaign activity.
What the Data Availability and Transparency Act 2022 actually authorises — and what it does not
The Data Availability and Transparency Act 2022 (Cth) represents the most significant reform to Commonwealth data governance in a generation. It is also, for the purposes of paid-media activation, largely irrelevant — and the gap between what the Act was designed to do and how it is being interpreted inside government communications functions is a primary driver of the compliance vacuum described in this piece.
The three permitted purposes and what they exclude
The DAT Act establishes an accredited data scheme under which Commonwealth data may be shared with accredited data users and data service providers for three permitted purposes: research and development, policy and program development, and delivery of services. As the Explanatory Memorandum to Part 2 of the Act makes explicit, these purposes were designed to support analytical and evidence-based functions — statistical analysis, program evaluation, service improvement modelling — within controlled data environments. The Explanatory Memorandum does not contemplate real-time commercial media activation as a permitted purpose, and the data code issued under the Act explicitly prohibits accredited users from applying Commonwealth data to downstream commercial uses.
The phrase "delivery of services" is the provision most commonly cited by communications teams seeking to argue that campaign targeting falls within the scheme. That reading is not supportable. The Explanatory Memorandum treats service delivery in the context of direct government-to-citizen service interactions, not as a category broad enough to encompass paid advertising as a delivery mechanism. Programmatic media buying is a commercial transaction between a government buyer and a private advertising exchange; it is not a service-delivery function in the sense the Act intends.
What accreditation does and does not confer
Accreditation under the DAT Act scheme grants an entity the right to access Commonwealth data within a controlled data facility or accredited environment for the permitted purposes above. It does not grant permission to onboard that data into a demand-side platform, match it against a third-party identity graph, pass audience segments to a data clean room operated by a commercial technology vendor, or otherwise introduce the data into an open programmatic stack. The Act's architecture assumes analytical closure: data enters a secure environment, analysis is conducted, outputs that do not re-identify individuals may be published or used to inform policy. The architecture of programmatic advertising inverts this model — audience segments defined by government data attributes are matched in real time against commercial identifiers held by advertising technology vendors, creating re-identification risk that the DAT Act's data code was explicitly designed to prevent.
"The DAT Act was built for analysts in secure facilities — not for audience segments being passed to a demand-side platform at two in the morning."
The clean-room misconception
A growing number of campaign briefs propose the use of data clean rooms — technologies offered by major advertising platforms that allow audience construction from first-party data without direct data transfer — as a mechanism that resolves the DAT Act constraint. This position has not been tested against the Act's data code or the Privacy Act, and there are strong grounds for concluding it does not resolve the constraint. A data clean room hosted by a commercial technology vendor is not a controlled data facility under the Act, the commercial vendor holds derived outputs from the matching process, and the contractual terms governing those outputs vary significantly across vendors. The clean-room model addresses the technical transfer problem; it does not address the authorisation problem, which precedes any technical implementation question.
Why the Privacy Act 1988 does not fill the gap the DAT Act leaves open
When the DAT Act is identified as insufficient authorisation for paid-media activation, the common fallback is the Privacy Act 1988 — specifically the argument that adequately de-identified data falls outside the Privacy Act's scope and may therefore be used without restriction. The Office of the Australian Information Commissioner's Privacy Act Review Report 2022 dismantles this argument with precision.
Chapter 6 and the limits of de-identification in programmatic contexts
Chapter 6 of the OAIC's Privacy Act Review Report 2022 addresses de-identification standards and their adequacy across different use contexts. The Report's central finding relevant to this discussion is that de-identification standards adequate for research publication — the removal of direct identifiers, the application of statistical disclosure controls — are materially inadequate in programmatic advertising contexts. The mechanism by which adequacy fails is cross-device matching and third-party data enrichment: audience segments that contain no direct personal identifiers can be re-identified with high probability through matching against commercial identity graphs that combine device signals, location data, and behavioural attributes. Per the Report, this re-identification pathway is not a theoretical risk; it is a standard feature of how demand-side platforms and data management platforms operate.
Australian Privacy Principle 6 and the secondary-use threshold
Australian Privacy Principle 6 permits secondary use of personal information in two relevant circumstances: where the individual would reasonably expect the use given the primary purpose of collection, or where the secondary purpose is directly related to the primary purpose. Cross-agency media targeting struggles to satisfy either limb. The first limb fails for the same reason identified under the Privacy Code's clause 10 analysis above: citizens engaging with government services do not form a reasonable expectation that their service-use behaviour will be used to target them with advertising. The second limb requires a direct relationship between service delivery and advertising activation — a relationship that is difficult to establish when the data has crossed an agency boundary and entered a commercial media-buying context.
Agencies sometimes argue that a public health campaign, a safety communications program, or an entitlements-awareness campaign represents a purpose so closely related to the original service-delivery interaction that the secondary use is directly related. That argument may hold in narrow circumstances — a Medicare enrolment reminder directed at the same cohort that submitted enrolment information — but it does not hold for broad audience-segment construction using behavioural signals from a multi-service platform like myGov, where the relationship between original collection purpose and advertising activation is attenuated across multiple service interactions and agency boundaries.
The reform gap: what has not yet been legislated
The OAIC's Review proposed a strengthened reasonable-expectations test, an expanded definition of personal information to cover de-identified but re-identifiable data, and a direct right of action for individuals where privacy obligations are breached. None of these reforms had been legislated at the time of publication. Agencies cannot rely on anticipated legislative reform to authorise current practice. The compliance environment applicable to campaigns being planned and executed today is the 1988 Act as amended, the 2017 Privacy Code, and the 2022 DAT Act — not the reform architecture recommended but not yet enacted.
The DAT Act was built for analysts in secure facilities — not for audience segments being passed to a demand-side platform at two in the morning.
The architecture of the compliance vacuum: where custodianship ends and activation begins
Understanding why this compliance gap persists — despite senior legal and privacy officers inside most major agencies — requires examining the structural conditions that produced it. The gap is not primarily a product of negligence or deliberate risk-taking; it is a product of institutional architecture that places data custody and data activation in separate organisational silos with no formal handover mechanism between them.
The structural separation of custodian and activator
In the Commonwealth architecture and its state equivalents, data custodians — Services Australia, the ATO, state revenue offices, health departments — hold the authorisation framework. They are responsible for compliance with the Privacy Act, the Privacy Code, and any agency-specific legislation governing the data in their custody. Media-buying functions sit in a separate part of the organisation: a central communications branch, a campaign team, or more commonly a panel media agency contracted under a whole-of-government procurement arrangement. The panel agency receives a campaign brief that may specify target audiences derived from government data holdings. The agency constructs audience segments, activates them in a demand-side platform, and reports on campaign performance. At no point in this workflow does a formal mechanism exist to transfer or verify compliance obligations across the custodian-to-activator boundary.
What Services Australia's data-sharing framework does and does not permit
Services Australia's published data-sharing framework, which governs downstream uses of Medicare, Centrelink, and myGov data assets, delineates permitted uses in terms of service improvement, research collaboration with accredited entities, and fraud and compliance functions. The framework contains no provision — explicit or implied — for the construction of media-buying audiences from Medicare enrolment cohorts, myGov behavioural signals, or Centrelink service-interaction data. Yet according to documented campaign planning discussions in the public record, these data assets are informally referenced in campaign targeting conversations as inputs for audience definition. The informal reference does not trigger a compliance review because the formal handover mechanism that would initiate such a review does not exist.
Why the policy architects did not model this use case
The compliance vacuum is not merely a procedural oversight that a revised standard operating procedure can resolve. It reflects a structural absence in how whole-of-government data governance has been designed. The architects of the DAT Act, the Privacy Code, and the data-sharing frameworks that preceded them were modelling data flows between government entities for administrative and analytical purposes. Paid-media activation as a downstream application of government data — a use case that became technically and commercially feasible only with the maturation of programmatic advertising infrastructure after 2015 — was not in scope for those design exercises. The governance architecture was not built to accommodate this use case because no one building it anticipated the use case would arise. That explanation is historically accurate; it is not a defence for agencies operating in the current environment.
| Framework | Designed purpose | Covers paid-media activation? | Key limiting provision |
|---|---|---|---|
| Data Availability and Transparency Act 2022 | Research, policy, service delivery (analytical) | No — explicitly excluded | Explanatory Memorandum, Part 2; data code prohibition on downstream commercial use |
| Privacy Act 1988 / APP 6 | General personal information handling | Not adequately — secondary use threshold rarely met | APP 6 reasonable-expectations test; OAIC Review Report Ch. 6 de-identification limits |
| Australian Government Agencies Privacy Code (2017) | Agency-specific privacy obligations | No — clause 10 secondary use prohibition | Clause 10: secondary use requires reasonable expectation at collection |
| Services Australia data-sharing framework | Service improvement, research, fraud | No — no media-buying provision | Permitted uses enumerated; media activation absent |
| Agency-level data-sharing agreements | Administrative and service-delivery functions | Typically no — drafted before activation use case arose | Purpose limitation clauses drafted for administrative contexts |
How GDS UK built a legal gateway model to separate data custodians from delivery agencies
The compliance vacuum described in this piece is not unique to Australia's federal architecture. The UK Government Digital Service encountered structurally identical problems as it scaled cross-departmental data use for public services and communications functions, and it developed a formal architectural response. That response — the legal gateway model — provides the closest available international precedent for resolving the custodian-to-activator gap in the Australian context.
The gateway determination as a procurement precondition
The UK GDS documented its legal gateway architecture in its 2023 guidance on using data to improve government services. The gateway model requires a data-custodian department to issue a formal gateway determination before any data sharing proceeds. The determination specifies: the permitted uses of the data; the permitted recipients; the prohibited downstream applications; the minimum necessary data attributes to be shared; and the conditions under which the determination lapses or must be renewed. Under GDS guidance, media buying is classified as a prohibited downstream application absent explicit ministerial direction — a classification that reflects deliberate policy judgment rather than technical incapacity.
The critical operational feature of the gateway model is temporal: the determination must be obtained before a campaign brief is issued, not after. This shifts compliance responsibility upstream, making it a precondition of procurement rather than a post-hoc review triggered by a legal query. In practice, this means a delivery agency — a central communications function, a health department running a public awareness campaign — cannot issue a targeting brief to a media agency until the custodian department has issued a gateway determination that explicitly addresses the proposed activation purpose. If the determination cannot be obtained, the targeting approach must be revised. The compliance burden does not migrate silently across an organisational boundary; it is resolved at source.
Data minimisation at the gateway stage
The GDS model also mandates a data minimisation protocol as a component of the gateway determination. Audience segments passed to media activation must be constructed from the minimum necessary attributes — attributes sufficient to reach the intended audience, and no more. The gateway determination specifies which attributes are permitted, and the media agency or delivery agency cannot enrich those segments with additional data from commercial third-party sources. This contractual prohibition on downstream enrichment addresses the re-identification risk identified in the OAIC's Privacy Act Review Report: by preventing the receiving agency and its contracted media buyers from augmenting government-derived segments with commercial identity data, the model maintains the de-identification integrity that the DAT Act and Privacy Act require.
Australian government communications functions currently have no equivalent mechanism. Panel media agency contracts under the Government Digital Advertising arrangement do not contain explicit prohibitions on downstream data enrichment. This absence is a specific and addressable gap in panel specifications.
Applicability to the Australian context
The GDS legal gateway model is not directly transposable to Australia's federal constitutional structure, which distributes data custodianship across Commonwealth and state entities in ways that the UK's more centralised system does not replicate. However, the model's core principle — that a formal, documented determination from the data custodian must precede activation by a delivery agency, and that the determination must explicitly address the proposed downstream use — is structurally applicable. The National Data Commissioner's function, established under the DAT Act, provides a natural locus for developing Australian-specific gateway guidance. The OAIC's role in Privacy Impact Assessment provides a complementary mechanism. What is required is the political and administrative will to treat gateway determination as a campaign procurement precondition rather than an optional governance enhancement.
How the US Digital Service addressed the consent-layer problem in Login.gov
The United States Digital Service and the General Services Administration confronted a related but distinct problem in designing the Login.gov federated identity platform: how to build a cross-agency authentication infrastructure that could not, by design, leak service-use data into commercial advertising stacks. The architectural solution they developed — a consent-layer model with technical and contractual isolation from advertising technology — offers instructive contrast with the myGov platform's current constraint set.
Architectural isolation as a governance instrument
The Login.gov privacy framework, published by USDS and GSA, describes a federated identity architecture in which authentication signals and service-use patterns are held in an environment that is technically isolated from any commercial data environment. The isolation is enforced at two levels simultaneously: contractual prohibition prevents Login.gov operators and their technology contractors from licensing, transferring, or making data available to third-party advertising technology vendors; and technical access controls prevent the advertising stack from querying or receiving data from the authentication environment regardless of contractual arrangements. The combination of contractual and technical controls means the isolation is robust to organisational changes, contractor substitutions, and commercial pressure from advertising technology vendors seeking to incorporate government authentication signals into identity graphs.
The framework's key design principle, as stated in the USDS documentation, is that the value of a federated government identity platform depends on citizens trusting that authentication signals will not be monetised or used to target advertising at them. If that trust is compromised — by a data leak, a contractual arrangement that allows indirect data use, or a policy change that permits advertising activation — the platform's utility as a cross-government service infrastructure is materially diminished. The design choices reflect that judgment directly.
The myGov contrast: ambiguity where architecture should resolve
The myGov platform operates under a related but weaker constraint set. Services Australia's published framework prohibits the direct sale of myGov data to third parties, and the Privacy Act's APP 6 secondary-use provisions apply. However, the framework does not explicitly prohibit the construction of lookalike audiences from myGov behavioural signals for use in paid-media campaigns — a use case that does not require direct data transfer but achieves similar targeting outcomes through statistical modelling. Under the Login.gov model, this ambiguity would be resolved by architectural design: the system would be built in a way that makes lookalike audience construction from platform behavioural signals technically impossible, not merely contractually prohibited.
"Over-caution and non-compliance are symmetric governance failures; both require the same structural remedy."
The practical implication for Australian agencies is that reliance on policy guidance and contractual prohibition to govern myGov data use in campaign contexts is a weaker governance position than the Login.gov model demonstrates is achievable. The DTA's ongoing myGov development program provides an opportunity to incorporate architectural isolation controls analogous to the Login.gov model. Whether that opportunity is taken depends on whether data governance in the advertising activation context is treated as a platform design requirement or a policy afterthought.
Over-caution and non-compliance are symmetric governance failures; both require the same structural remedy.
Over-caution is not a safe harbour: the cost of compliance paralysis to public communications
The compliance gap described throughout this piece generates two distinct failure modes, not one. The first — agencies activating cross-agency data without adequate authorisation — receives most of the attention in privacy and governance discussions. The second — agencies prohibiting all cross-agency data use in campaign targeting because no resolution framework exists — receives far less attention but carries comparable systemic cost. Both are governance failures; neither is a satisfactory outcome.
How blanket prohibition becomes the default response
When legal teams inside agencies identify the compliance gap — typically when a campaign brief arrives and someone asks whether the proposed targeting approach is consistent with the Privacy Act — the common response in the absence of a resolution framework is blanket prohibition. No cross-agency data may be used in campaign targeting; all audience construction must rely on commercially available third-party data or platform-native audiences. This position is operationally defensible in the sense that it eliminates the specific compliance risk identified. It is not, however, a governance position. It is the absence of governance translated into an operational instruction, and it has material consequences for the effectiveness and efficiency of public communications programs.
The DTA's investment in whole-of-government data infrastructure — the National Data Commissioner function, the DAT Act accreditation regime, the myGov platform's data integration capabilities — was premised on a social return from improved government services and communications. That return includes the capacity to reach citizens with relevant public information more efficiently, to reduce wastage in public communications spend, and to improve the measurability of campaign outcomes. Compliance paralysis in the media-activation layer forfeits that return. It does not improve individual privacy outcomes, because the data assets remain held by custodian agencies under existing frameworks. It simply removes the social return without removing the cost of maintaining the data infrastructure.
The symmetric risk framework
Senior public servants responsible for data governance and communications functions should treat over-caution and non-compliance as symmetric risks within a single governance framework, not as a binary choice between safety and utility. The National Audit Office's published guidance on digital program governance and the DTA's own investment framework both treat compliance failures and capability failures as equivalent impairments to program value. A campaign targeting approach that exposes an agency to Privacy Act liability is a governance failure. A campaign targeting approach that prohibits legitimate and properly authorised data use because a determination framework has not been developed is an equally significant governance failure — it simply expresses as forgone benefit rather than direct liability.
The remedy for both failure modes is the same: a formal determination framework that precedes campaign planning rather than responding to it. Agencies that invest in developing that framework — by adapting the GDS gateway model, by engaging the OAIC on a privacy impact assessment methodology specific to paid-media activation, by revising panel media agency contract specifications to require documented cross-agency data obligation processes — create the conditions under which cross-agency data sharing can be activated compliantly and efficiently. Agencies that do not invest in that framework will oscillate between non-compliant activation and compliance paralysis, with neither outcome serving citizens or the public interest.
A defensible framework: what must be in place before a cross-agency campaign brief is issued
The analysis in this piece points toward a specific set of structural requirements. The following framework does not constitute legal advice and cannot substitute for agency-specific legal review. It represents a minimum viable governance architecture derived from the legislative framework, international precedent, and the structural analysis of the compliance vacuum set out above. Agencies operating in this space should treat these components as necessary conditions, not as a sufficient checklist.
The four minimum components of a compliant activation architecture
A minimum viable governance architecture for cross-agency paid-media activation requires four components to be present simultaneously before a brief is issued:
- A formal data-sharing agreement that explicitly names media activation as a permitted purpose. General language about improving communications outcomes or supporting service delivery is not sufficient. The agreement must specifically contemplate the construction of audience segments for use in paid-media campaigns, identify the platforms and technologies through which activation will occur, and specify the data attributes that may be used for audience construction. Existing agreements drafted for administrative purposes must be reviewed and, where necessary, renegotiated to include this provision.
- A legal gateway determination from the data-custodian agency. Modelled on the GDS gateway framework, this determination must specify: the permitted activation purpose; the permitted recipient (communications team or named panel agency); prohibited downstream applications including third-party data enrichment; the minimum necessary data attributes for the proposed audience segment; and the lapse conditions for the determination. The determination must be issued before the campaign brief is issued to the media agency, not after.
- A data minimisation protocol reviewed by the OAIC or an agency privacy officer with equivalent authority. The protocol must specify how audience segments will be constructed to minimise the personal information used, how the de-identification standard will be maintained through the activation process, and how the risk of re-identification through cross-device matching or third-party enrichment will be technically and contractually prevented. Where a Privacy Impact Assessment has not been conducted for the specific campaign targeting approach, one must be completed at this stage.
- A contractual prohibition on downstream data enrichment binding the panel media agency. The media agency's contract must explicitly prohibit the use of government-derived audience segments as seeds for lookalike modelling against commercial third-party data, the onboarding of government-derived segments into vendor-operated data clean rooms without explicit gateway authorisation, and the retention of segment data beyond the campaign period. This prohibition must be enforceable, not merely advisory.
Changes required to panel procurement specifications
The Government Digital Advertising panel and equivalent state government media procurement panels currently do not require media agencies to demonstrate a documented process for identifying when a campaign targeting brief triggers cross-agency data obligations. This is a specific and correctable gap in panel specifications. Panel administrators — the DTA at Commonwealth level, equivalent central agencies at state level — should amend panel specifications at the next review cycle to require that panel-holding agencies:
- maintain a documented procedure for identifying cross-agency data obligations at brief intake;
- nominate a designated privacy compliance contact for government account work;
- demonstrate familiarity with the DAT Act accreditation scheme, APP 6 secondary-use provisions, and the Privacy Code's clause 10 requirements; and
- agree contractually to the downstream data enrichment prohibition described above.
These specifications do not impose a disproportionate burden on panel agencies. They bring the media-buying function into the compliance architecture rather than leaving it outside it, which benefits both agencies and their government clients by clarifying responsibility and reducing the default-to-custodian risk profile described earlier in this piece.
The role of the National Data Commissioner and the OAIC
The National Data Commissioner, the OAIC, and relevant departmental privacy officers should jointly develop guidance specific to paid-media activation use cases. That guidance should be analogous in structure and purpose to the GDS legal gateway model: it should provide a template gateway determination, specify the privacy impact assessment methodology applicable to programmatic audience targeting, and address the specific re-identification risks that the OAIC's Privacy Act Review Report identified in programmatic advertising contexts. The current situation — in which each agency constructs ad hoc interpretations of frameworks that were never designed for this purpose — produces neither consistent compliance nor consistent capability. Sector-wide guidance does not require legislative reform; it requires administrative coordination among existing regulators and framework owners, and it is the most direct path from the current compliance vacuum to a defensible operating environment.
Agencies seeking to move toward a compliant framework before sector-wide guidance is available can engage with government digital advertising specialists who understand both the media-buying architecture and the data governance obligations that govern it, and who can map specific campaign data flows against the DAT Act and Privacy Act frameworks before a brief reaches the activation stage. Documented examples of how other agencies have approached this mapping are available in published case studies. The contact page provides the appropriate starting point for agencies seeking a governance readiness review.
SoudCoh works with government communications teams to map their campaign data flows against DAT Act and Privacy Act obligations before a brief reaches the media-buying stage — contact the team to commission a governance readiness review.

