Assistance & Access Act 2018 (TOLA) — Anti-Encryption Powers
institutionIntelligence & Surveillance · Crypto & Digital ID · Darknet & Cyber
Australia passed a first-of-its-kind law that can compel tech companies to help crack their own encryption.
Who they are
The Assistance and Access Act of 2018 (TOLA), an Australian anti-encryption law.
What they do
It created an unprecedented regime letting the state issue escalating demands compelling communications providers to help access encrypted data.
How it works
Through three tiers of demands, it can require providers to assist; critics and GCHQ describe a 'ghost protocol' — silently adding a state key and hiding the notification — though the engine notes that's the critics' framing, not the actual statute, and the law does bar forcing a 'systemic vulnerability'; Apple, Google, and WhatsApp objected and Signal threatened to leave Australia.
Why it matters
The engine reads it as a case where state access is put ahead of the integrity of encryption itself, creating friction even with the US CLOUD Act.
The engine's record — word for word
Globally-unprecedented encryption-defeating regime: escalating TAR / TAN / TCN demands compelling communications providers to assist. The ''ghost protocol'' (silently injecting a state key + suppressing the new-participant notification) is the CRITICS'/GCHQ Levy-Robinson framing of what TOLA could compel — NOT statutory text (corrected). The Act bars requiring a 'systemic vulnerability'; Apple/Google/WhatsApp objected and Signal threatened to quit the Australian market. Created friction with the US CLOUD Act. Engine read: state access prioritized over cryptographic integrity. [verified/corrected] [Australia surveillance-state harvest — Aug 17 2026]
Follow the trail
Walk this on the live map →