Published Sep 24, 2026 by Xiph
Every collection was lawful. Every purpose was reasonable. The risk was never in any single feed — it is in what happens when they are joined.
Somewhere in the past month you agreed to a dozen small, sensible things. You gave a rental agent your date of birth. You drove under a camera. You handed a licence over to prove your age. You let a supermarket app watch a shop for four cents a litre. Each was disclosed, lawful and harmless.
None of them is the problem. The join is the problem.
Data fusion is the practice of taking records gathered separately — for different reasons, under different authorisations, by different organisations — and stitching them into a single searchable picture of one person. Nobody needs to break a law or breach a database to do it; the feeds already exist. Fusion needs only a shared key, and Australians hand out shared keys all day long.
What a join actually looks like
A key is any field two datasets have in common: a name and date of birth, a residential address, a driver licence number, a number plate, a mobile number, an email, a device identifier, a face.
The moment two datasets share a reliable key, they stop being two datasets. A rental bond record tells you almost nothing. A toll account tells you almost nothing. A plate read on a Tuesday afternoon tells you almost nothing. Joined on one address and one plate, they tell you where someone lives, what they drive, when they leave, and how that changed after March. Nothing in that picture was secret. It simply never existed in one place before, and nobody consented to it being assembled.
The government layer: routine, documented, and larger than most people think
Start with what is not in dispute, because the efficiency case here is genuinely strong.
The ATO runs dozens of standing data-matching programs, each published as a protocol and gazetted in the Federal Register of Legislation. Rental bond data reaching back to 1985. Property management software records. Lifestyle assets — boats, aircraft, artworks — obtained from insurers. Motor vehicle registries. Novated leases. Online selling. Ride-sourcing. Private health insurance. Much of it arrives under coercive powers in the Taxation Administration Act, meaning providers are compelled to hand it over.
And it works. The ATO reports that in one financial year the rental bond program, combined with other compliance strategies, identified roughly 5,600 taxpayers who had not treated property dealings correctly and raised about $23 million in additional revenue. If you pay your tax properly, you are entitled to be annoyed at people who do not.
Hold onto that, because the argument that follows is not that matching is illegitimate. It is that matching capability, once built, does not stay pointed where it started.
The front door almost nobody uses
Australia does have a purpose-built, safeguarded channel for this: the Data Availability and Transparency Act 2022. The DATA Scheme lets Commonwealth data go to accredited entities under a registered agreement, for three purposes only — government service delivery, policy and programs, and research. It expressly excludes law enforcement and national security, and created a National Data Commissioner to regulate it.
It is also barely used. As of March 2026, 41 entities were accredited: 18 Commonwealth bodies, 12 universities, 11 state and territory. The statutory review tabled that month found the Act had not been effective in achieving its objectives, that sharing had been limited, and recommended it be saved from its April 2027 sunset only with significant amendment.
That is the most useful finding here: the channel with the strictest transparency obligations and a dedicated regulator is the one hardly anybody bothers with. Fusion in Australia mostly happens elsewhere — bilateral agency matching, telecommunications metadata, identity verification services, commercially procured analytics. Watch the side doors, not the front one.

The private layer sitting on top
The Commonwealth's Document Verification Service was used more than 133 million times in 2024–25 by 2,228 organisations. Only 119 were government; the other 2,109 were private sector. The identity-checking plumbing built by government is now overwhelmingly operated by business — banks, telcos, age-gated platforms — each generating its own logs, each another joinable feed.
Around that sits a data broker industry the Privacy Act barely touches. APP 3.6 says organisations should collect information about you from you unless that is impracticable — honoured mostly in the breach. The exemption for turnover under $3 million leaves most Australian businesses outside the Act entirely, and reforms requiring brokers to register their holdings sit in a second tranche that has no bill and no commencement date.
The biometric layer just became easier too. In February 2026 the Administrative Review Tribunal found Bunnings could rely on a permitted general situation to collect facial images without consent, for the limited purpose of combating retail crime and protecting staff. It upheld the Privacy Commissioner's findings on notice and governance but set aside the core collection finding; the Commissioner did not appeal, and updated retail guidance followed in July. Facial recognition in Australian retail is now lawful with the right paperwork and a demonstrated justification. Defensible on the facts — and another permanent, high-quality identity feed.
Function creep you can watch happen
The clearest illustration is on the road. New South Wales switched on mobile phone detection cameras in December 2019: overhead cameras photograph the cabin of every passing vehicle, and AI reviews the images before a human confirms an offence. The network performs roughly 135 million vehicle checks a year.
Every vehicle is photographed. Not every suspected vehicle — every vehicle.
Legislation passed in November 2023 extended those same cameras to seatbelt enforcement from 1 July 2024, and a March 2026 upgrade let them capture both directions of traffic. None of that is scandalous; the road safety case is real. It is the pattern in miniature. Infrastructure built for one narrow, well-argued purpose is the cheapest possible place to bolt on the next, because the cameras, storage and analytics are already paid for. Queensland's auditor found the state's equivalent program had skipped the ethical AI risk assessment its own policy required.
At the border the same logic runs nationally: SmartGates at Australia's international airports now use the traveller's face as the token, arriving and departing.
Robodebt: what fusion looks like when nobody checks
Between 2015 and 2019 the Commonwealth joined two accurate datasets. The ATO held annual PAYG income; Centrelink held fortnightly income declarations. The system averaged the annual figure across the year, compared each notional fortnight against what a recipient had declared, and raised a debt where they diverged.
Both inputs were correct. The join was not. Someone who worked intensively for three months and not at all for nine has no "average fortnight" — the number the system produced described a life nobody had lived. The onus was then reversed: prove you do not owe this, sometimes for years-old employment, sometimes with payslips from an employer that no longer exists.
About $751 million was recovered from roughly 381,000 people who did not owe it. The Royal Commission's 2023 report called the scheme crude and cruel, devised without regard to social security law. In July 2025 a second settlement of $548.5 million — including $475 million in compensation — became the largest class action settlement in Australian legal history, taking total redress past $2.4 billion.
The lesson is not that governments are malicious. It is narrower and more useful: fusion does not just aggregate accuracy, it can manufacture error — and automation then hands that error the authority of a decision. From 10 December 2026, Australian entities making substantially automated decisions that significantly affect people must disclose it in their privacy policies. Note what that is: a disclosure rule, not a prohibition.
The proportionality questions worth asking
When the next matching program, camera network or identity scheme is announced, assume good intent and ask about design instead:
-
What is the key? A program matching on a strong, permanent identifier — a licence number, a face — is categorically more powerful than one matching on a weak one.
-
Who else can query it? Not who is meant to. Who is technically able to, and under what other Act.
-
Does the purpose expire? If it can be widened by regulation without a fresh vote, the stated purpose is a starting position, not a limit.
-
Can the person see and correct the record? Robodebt's defining feature was that the individual carried the burden of disproving a machine.
The move that beats fusion outright
Every control above is someone else's to operate. There is one you own, and it is unglamorous: the data you never emit cannot be joined to anything.
For individuals: decouple identity from number with a private SIM — a mobile tied to your name is one of the strongest joining keys there is. Move sensitive conversations onto encrypted communications. Run a hardened handset that does not broadcast advertising and location identifiers by default. Leave optional fields blank — date of birth, address and mobile are precisely what makes records joinable. Fewer loyalty programs, fewer standing consents, fewer copies.
For businesses: treat collection as a liability, not an asset. Every field you retain is one you can be breached out of, compelled to produce, or asked to match. Shorten retention and enforce it. Map which identity data you hold and which third parties you feed. Work out whether anything you run counts as a substantially automated decision, because that disclosure obligation lands in December 2026. A risk audit or a virtual CISO costs a fraction of what this costs after an incident.
A final word
There is no villain in this story, which is precisely why it is difficult. Every program here was argued for on reasonable grounds and most of them work. But capability outlives justification. The camera bought for phones enforces seatbelts. The verification service built for government runs mostly in private hands. The averaging trick that raised revenue also invented debts.
You cannot un-build the fusion layer from your kitchen table. You can decide how much of yourself feeds it. At Xiph Cyber we have spent a decade building for exactly that position — hardened devices, private SIMs, encrypted communications, and the consulting to work out what your organisation should stop collecting. Get in touch at enquiries@xiphcyber.com.
Further reading
-
Statutory Review of the Data Availability and Transparency Act 2022, Final Report (March 2026) — https://www.finance.gov.au/sites/default/files/2026-03/statutory-review-of-data-availability-and-transparency-act-final-report.pdf
-
ATO, How we use data matching — https://www.ato.gov.au/about-ato/commitments-and-reporting/in-detail/privacy-and-information-gathering/how-we-use-data-matching
-
Royal Commission into the Robodebt Scheme, Report (July 2023) — https://robodebt.royalcommission.gov.au/publications/report
-
Attorney-General's Department, Identity Verification Services Act 2023 Annual Report 2024–25 — https://www.ag.gov.au/national-security/publications/identity-verification-services-act-2023-annual-report-2024-25
-
OAIC, statement on the Administrative Review Tribunal's Bunnings decision — https://www.oaic.gov.au/news/media-centre/privacy-commissioner-statement-on-administrative-review-tribunals-bunnings-decision
-
Transport for NSW, mobile phone and seatbelt detection cameras — https://www.transport.nsw.gov.au/roadsafety/topics-tips/seatbelts
Posted in: Security