Originally published on LinkedIn in response to the ACS Information Age report Australians to gain ‘right to erasure’ under privacy reforms.
This is one of the more important elements of Australia’s proposed privacy reforms.
The right to erasure, or more plainly, the right to delete, is something I strongly support.
For me, this is not an abstract privacy debate.
When Optus was breached, my information was caught up in it. I had been an Optus customer for about six months, roughly ten years earlier. I had provided information for a specific purpose, to obtain a telecommunications service. That relationship had ended years before, yet my information remained.
That experience crystallised something I have spoken about for years through my work with the ACS Data Sharing Committee and in a podcast with David Cook: collecting information is only one part of the data lifecycle.
What happens afterwards matters just as much.
Why was the information collected?
What is it being used for?
Who can access it?
How long is it retained?
And, critically, when the purpose has ended, why is it still there?
We have become extraordinarily good at collecting data and comparatively poor at letting it go.
A right to delete begins to rebalance that relationship. It gives an individual some agency after information has left their hands. It is also good security practice. Personal information that an organisation no longer holds cannot subsequently be exposed in its next data breach.
I do think the proposal should ultimately go further.
The current reform targets large digital platforms. The underlying principle is much broader. We give identifying and sensitive information to telecommunications companies, banks, real estate agents, hotels, health providers, retailers and countless other organisations as part of ordinary life.
Deletion should not simply become another compliance process where individuals need to remember every organisation they have dealt with and submit requests one by one.
Responsible data governance should mean collecting only what is necessary, using it only for legitimate purposes, retaining it only for as long as there is a legitimate reason, and destroying it when that reason disappears.
The current debate about AI, biometrics and smart glasses makes all of this more urgent, but the underlying problem is not a particular piece of technology. It is control.
I have said before that I want my son’s generation to be able to see a doctor, obtain a phone or rent a home without unnecessarily surrendering control of their identity and personal information.
Technology should serve us, not the other way around.
The right to delete is an important step towards making that principle real.
Perhaps the question we should be asking organisations is very simple: If you no longer need my information for the reason I gave it to you, why are you still holding it?