Operators that would implement the proposed duty and respond to oversight
Covered online-service providers
Covered online-service providers are the regulated class contemplated by Australia's September 2026 digital-duty-of-care exposure draft. They would remain the day-to-day operators of their services while taking reasonably practicable steps to provide a safe online environment through assessment, design and effective risk-reduction measures.
Responsibilities and enforcement
Proposed sections 25H and 26–26A describe proportionate duties. The minister could specify exemptions and some user-empowerment requirements. Under section 26D, a reasonable belief in past or present noncompliance could lead eSafety to give written directions aimed at preventing future failures. Separate civil-penalty and infringement processes are contemplated. The draft also envisages scheme-governed research access, including tightly constrained test accounts; it does not establish a universal identity-collection requirement.
could obtain scheme-governed research access and test accounts
Sections205B-L: access depends on future rules and eligibility; fictitious accounts limited to authorized research, with interaction constraints and criminal-material exclusions. No actual transfer acquired.
Australian eSafety Commissioner → Covered online-service providers
would issue compliance directions on reasonable belief
Section26D PDF38-39: reasonable belief of past/present noncompliance triggers written future-prevention directions. Not unlimited orders. Civil penalties and infringement notices have distinct processes.
Australia digital duty of care — exposure draft → Covered online-service providers
would impose reasonably practicable safe-environment duty
Sections25H,26-26A PDF35-38: risk assessment, design and effective measures; proportionality rather than zero-harm guarantee. Proposed, not enacted or implemented.
Sections25H,26-26A PDF35-38: risk assessment, design and effective measures; proportionality rather than zero-harm guarantee. Proposed, not enacted or implemented.
Section26D PDF38-39: reasonable belief of past/present noncompliance triggers written future-prevention directions. Not unlimited orders. Civil penalties and infringement notices have distinct processes.
Sections205B-L: access depends on future rules and eligibility; fictitious accounts limited to authorized research, with interaction constraints and criminal-material exclusions. No actual transfer acquired.