Skip to main content

Contemporary issue: technology and consumers: HSC Legal Studies

Syllabus dot point

“Contemporary issues concerning consumers: technology; identify and investigate this issue involving the protection of consumers and evaluate the effectiveness of legal and non-legal responses”

HSCLegal StudiesOption: Consumers15 min read

Quick answer

Technology has made buying easier and cheaper but has created new consumer risks: buying from overseas sellers, scams (Australians reported $2.18 billion in losses in 2025), data breaches (the 2022 Optus and Medibank breaches affected about 9.5 and 9.7 million people), manipulative online design, drip pricing and subscription traps. The ACL applies online, including to overseas businesses (ACCC v Valve, 2016), and the ACCC has pursued digital giants (Google, $60 million, 2022; its 2025 case against Microsoft). Newer, technology-specific laws include the Scams Prevention Framework Act 2025 (banks, telcos and digital platforms must prevent and respond to scams, with obligations phased in from 2026 and fully applying from 31 March 2027), the first Privacy Act civil penalty (Australian Clinical Labs, $5.8 million, October 2025), a statutory privacy tort (from 10 June 2025) and the unfair trading practices law (from 1 July 2027). Legal responses are improving but remain reactive, and offenders overseas are hard to reach.

Jump to a section
  1. What this dot point is asking
  2. The answer
  3. In one sentence
  4. Try this
  5. Exam-style questions

What this dot point is asking

Technology is one of the four contemporary issues that must be studied in the Consumers option of the Legal Studies Stage 6 Syllabus (2009). You must identify and investigate the issue and evaluate the effectiveness of legal and non-legal responses to it.

The 2009 syllabus was written when "technology" meant mainly online shopping and spam. In 2026 the issue is much broader: scams on an industrial scale, data breaches affecting millions, subscriptions that are easy to start and hard to cancel, and manipulative website design. The 2024 HSC paired technology with credit and asked how effective legal responses are; NESA wanted students to state the issues for consumers clearly and support a judgement with evidence. Marketing techniques that rely on technology, such as influencer marketing and drip pricing, are covered on marketing innovations.

The must-know spine

ACL applies online: ACCC v Valve Corporation (No 3) [2016] FCA 196 ($3 million). ACCC v Google (2022, $60 million, location data). ACCC v Microsoft (filed 27 October 2025; Copilot price rise; about 2.7 million subscribers). Scams: National Anti-Scam Centre (1 July 2023); Scamwatch; $2.18 billion lost in 2025 (Targeting Scams, March 2026); Scams Prevention Framework Act 2025 (from 21 February 2025), sectors designated May 2026, SPF Rules and AFCA membership from 1 September 2026, main obligations and AFCA complaints from 31 March 2027. Children's Online Privacy Code: exposure draft March 2026, must be registered by 10 December 2026. Privacy: Privacy Act 1988 (Cth); notifiable data breaches scheme; Optus (9.5 million) and Medibank (9.7 million) OAIC proceedings; Australian Clinical Labs $5.8 million (first Privacy Act penalty, October 2025); Privacy and Other Legislation Amendment Act 2024: statutory tort from 10 June 2025. Unfair trading practices law passed July 2026, from 1 July 2027. Spam Act 2003 (Cth); Do Not Call Register Act 2006 (Cth).

The answer

Identifying the issue

Technology affects consumers in five main ways:

  1. Online shopping and digital products. Consumers buy from businesses anywhere in the world, often without seeing the product, and buy digital goods (games, apps, streaming) whose "quality" is hard to define.
  2. Scams. Scammers use phone calls, text messages, social media, fake websites and investment platforms to steal money, and technology lets them operate at scale from overseas.
  3. Data and privacy. Every online transaction collects personal information. Large data breaches expose consumers to identity theft and further scams.
  4. Manipulative design. Websites and apps can use "dark patterns": hidden fees revealed at checkout (drip pricing), pre-ticked boxes, countdown timers, and subscriptions that are easy to start and hard to cancel.
  5. New technology in products. AI-enabled services, connected devices and algorithms that personalise prices raise new questions about quality, safety and fairness.

Applying existing consumer law online

The ACL is technology neutral: the consumer guarantees and the prohibitions on misleading and unconscionable conduct apply to online transactions as they do in a shop.

  • ACCC v Valve Corporation (No 3) [2016] FCA 196. Valve, the US owner of the Steam gaming platform, told Australian consumers they had no right to refunds. The Federal Court held that the ACL applied to Valve because it carried on business in Australia, that the consumer guarantees applied to games, and ordered a $3 million penalty.
  • ACCC v Google (2022). The Federal Court ordered Google to pay $60 million for misleading Android users about the collection of their location data. The case linked consumer law and privacy: misleading consumers about data practices is misleading conduct.
  • ACCC v Microsoft (filed 27 October 2025). The ACCC alleges that when Microsoft integrated its Copilot AI assistant into Microsoft 365 Personal and Family plans and raised prices (the Personal plan from $109 to $159 a year), it told about 2.7 million subscribers that they had to accept the higher price or cancel, without disclosing a cheaper "Classic" plan without Copilot. Microsoft apologised and offered refunds to subscribers who moved to the Classic plan by 31 December 2025. These are allegations in a proceeding seeking penalties; check its outcome before treating it as a decided case.

Individual redress online. A consumer can take a claim against an Australian online retailer to NCAT, and against a business that trades in Australia through the ACCC or NSW Fair Trading. Enforcing an order against an overseas seller with no Australian presence is often impossible, so consumers rely on chargebacks through their bank or card provider and on platforms' own dispute processes.

Scams

The scale. The National Anti-Scam Centre's Targeting Scams report (March 2026) found that Australians made 481,523 scam reports in 2025, and that reported losses were $2.18 billion, up 7.8 per cent on 2024. Investment scams caused the largest losses ($837.7 million), followed by payment redirection, romance, phishing and remote access scams. Losses fell substantially from their 2022 peak after new measures were introduced, but rose again in 2025.

Legal responses.

  • The National Anti-Scam Centre, established within the ACCC on 1 July 2023, coordinates government, banks, telcos and platforms to share intelligence and disrupt scams (for example, taking down fake investment websites). It runs Scamwatch, which receives reports and publishes alerts.
  • Telecommunications rules: an industry code registered and enforced by ACMA requires telcos to identify, trace and block scam calls and texts.
  • The Scams Prevention Framework Act 2025 (Cth) inserted a Scams Prevention Framework into the Competition and Consumer Act 2010, commencing on 21 February 2025. It applies to sectors designated by the Minister. Banks, telecommunications providers and certain digital platforms (social media, instant messaging and internet search engine services) were designated in May 2026. Regulated businesses must comply with principles requiring them to govern, prevent, detect, report, disrupt and respond to scams, backed by civil penalties. The obligations are phased in: the SPF Rules commenced on 1 September 2026, when regulated businesses also had to join AFCA, and the main obligations apply from 31 March 2027. Mandatory sector codes, released in draft in May 2026, are to follow. AFCA is the single external dispute resolution scheme: for matters occurring from 31 March 2027, consumers can seek compensation from a business that failed to meet its obligations.

Evaluation. The framework is significant because it shifts responsibility from individual victims, who were usually told they had authorised the payment, to the businesses whose services scammers use. But it is being phased in, its main obligations do not apply until 31 March 2027, its codes were still in draft in mid-2026, and it does not reach scammers themselves, who are mostly offshore. Critics, including consumer groups, have argued that the UK's mandatory reimbursement model protects victims more directly.

Data breaches and privacy

The issue. In September 2022 a cyberattack on Optus exposed the personal information of millions of customers, and in October 2022 a cyberattack on Medibank exposed health claims data, some of which criminals published online. The Australian Information Commissioner has brought civil penalty proceedings in the Federal Court alleging that Optus seriously interfered with the privacy of about 9.5 million Australians and Medibank with the privacy of about 9.7 million, by failing to take reasonable steps to protect their personal information. These are allegations; the proceedings were continuing in 2026.

Legal responses.

  • The Privacy Act 1988 (Cth) and its Australian Privacy Principles require businesses with a turnover above $3 million (and some smaller ones) to protect personal information (APP 11). The notifiable data breaches scheme requires them to notify affected individuals and the OAIC of an eligible data breach.
  • Higher penalties. After the 2022 breaches, Parliament raised the maximum penalty for serious or repeated interferences with privacy in late 2022, to the greater of $50 million, three times the benefit, or 30 per cent of adjusted turnover.
  • The first penalty. In October 2025 the Federal Court ordered Australian Clinical Labs to pay $5.8 million, the first civil penalties under the Privacy Act, after a February 2022 breach at its Medlab Pathology business exposed the information of more than 223,000 people. The penalty included $4.2 million for failing to take reasonable steps to secure personal information.
  • The Privacy and Other Legislation Amendment Act 2024 (Cth) created a statutory tort for serious invasions of privacy, which commenced on 10 June 2025. Individuals can sue for an intrusion into their seclusion or misuse of their information where they had a reasonable expectation of privacy; damages for emotional distress are available without proving other loss. The Act also gave the OAIC new enforcement tools and required it to make a Children's Online Privacy Code by 10 December 2026; the OAIC released an exposure draft of the code for consultation from 31 March to 5 June 2026.

Evaluation. Privacy law has moved from a weakly enforced, complaints-based regime to one with real penalties and a private right of action. But the law still responds after a breach. A second stage of reform, the exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 (which would, among other things, replace several obligations with a single "fair and reasonable" test for handling personal information), was released for consultation, with submissions closing on 18 September 2026; it was not law as at September 2026.

Manipulative design, drip pricing and subscription traps

The ACL's ban on misleading conduct struggles with practices that are not false but exploit behaviour: hiding the cancel button, making consumers click through multiple screens, revealing fees late, or using false urgency. In July 2026 Parliament passed the Competition and Consumer Amendment (Unfair Trading Practices) Bill 2026. From 1 July 2027 it will:

  • prohibit unfair trading practices that manipulate a consumer, or unreasonably distort the environment in which they make a decision, and cause them detriment;
  • require transaction-based fees to be displayed with the base price, to combat drip pricing; and
  • require businesses to provide an easy and straightforward way to cancel subscriptions, ending subscription traps.

Penalties will be the same as for other serious ACL breaches, up to $100 million for a corporation. The law responds to years of advocacy by CHOICE and consumer groups, and to evidence from the ACCC's digital platform services inquiries.

Non-legal responses

  • Awareness. Scamwatch alerts, bank and telco warnings, and campaigns such as "Stop. Check. Protect." teach consumers to recognise scams.
  • Industry action. Banks introduced confirmation of payee checks and delays on unusual payments; telcos block scam calls; platforms remove scam ads (often slowly).
  • NGOs. CHOICE investigates online practices and campaigned for the unfair trading practices law; IDCARE helps victims of identity theft; consumer legal centres assist scam victims with bank and AFCA disputes.
  • The media. Reporting of the Optus and Medibank breaches and of individual scam losses created pressure for the 2022 penalty increases, the 2024 privacy reforms and the scams framework.

Evaluating the effectiveness of legal and non-legal responses

Issue Legal and non-legal responses Effectiveness
Online shopping ACL applies online (Valve, 2016); NCAT; chargebacks Effective against businesses in Australia; weak against overseas sellers
Scams National Anti-Scam Centre (2023); Scams Prevention Framework Act 2025; AFCA; Scamwatch Losses fell from their peak but rose 7.8 per cent in 2025; framework phased in from 2026, main obligations from 31 March 2027; offenders offshore
Data and privacy Notifiable data breaches; higher penalties (2022); first penalty (2025); statutory tort (2025) Improving; enforcement after the breach; Optus and Medibank proceedings unresolved
Manipulative design Misleading conduct cases (Google, 2022); unfair trading practices law (from 2027) A gap until 1 July 2027; depends on enforcement
Awareness and advocacy Scamwatch, bank warnings, CHOICE, media Essential for prevention and reform; no enforcement power

Judgement. Legal and non-legal responses to technology are effective to a moderate and increasing extent. The law has shifted from applying general rules online to building technology-specific regimes that place obligations on the businesses best placed to prevent harm: banks, telcos, platforms and data holders. But the pattern is reactive: the privacy reforms followed the 2022 breaches, the scams framework followed years of rising losses, and the unfair trading practices ban will not commence until 2027. The global and fast-changing nature of technology means Australian law will always struggle to reach offenders overseas, so prevention through awareness and industry obligations remains essential.

Common traps
Treating technology as only "online shopping"
In 2026 the strongest examples are scams, data breaches and manipulative design.
Stating the Optus and Medibank privacy cases as decided
They were OAIC civil penalty proceedings still before the Federal Court in 2026. The first Privacy Act penalty was Australian Clinical Labs (October 2025).
Saying the Scams Prevention Framework is fully in force
The Act commenced in February 2025, but sectors were designated in May 2026, the SPF Rules commenced on 1 September 2026, the main obligations and AFCA complaints start on 31 March 2027, and the codes follow later.
Saying drip pricing and subscription traps are already banned
The specific bans commence on 1 July 2027; until then, only misleading conduct rules apply.
Forgetting non-legal responses
Awareness, industry measures, NGOs and the media all matter, and the question may ask about them.

In one sentence

Technology has exposed consumers to overseas sellers, industrial-scale scams, massive data breaches and manipulative design, and although the ACL applies online and new laws on scams, privacy and unfair trading practices place real obligations on businesses, the law remains a step behind technology and struggles to reach offenders overseas.

Try this

Q1. Identify TWO issues for consumers arising from technology. (2 marks)

  • What the marker wants. Two clear issues, such as scams and data breaches.

Q2. Explain how the law responds to data breaches. (5 marks)

  • What the marker wants. The Privacy Act and notifiable data breaches, higher penalties, the Australian Clinical Labs penalty, the OAIC's Optus and Medibank proceedings, and the statutory tort.

Q3. To what extent do legal responses protect consumers from scams? (8 marks)

  • What the marker wants. The scale of losses, the National Anti-Scam Centre, the Scams Prevention Framework Act 2025 and its phasing, AFCA, limits such as offshore offenders, and a judgement.

Exam-style questions

Questions in the style of NESA exam questions on this dot point, each with a worked answer. They are written by ExamExplained unless tagged "Past paper"; the year shows the paper a question is modelled on.

Original25 marks
Evaluate the effectiveness of legal and non-legal responses in protecting consumers from the risks of technology.
Show worked answer →
Thesis
Legal responses have moved from applying old rules online to building technology-specific regimes (scams, privacy, manipulative design), and they are now effective to a moderate and growing extent. Their limits are speed, cross-border offenders and reliance on enforcement after the harm.
The issues
Online shopping with overseas sellers; scams; data breaches and privacy; manipulative online design, drip pricing and subscription traps; AI-enabled products.
Online shopping
The ACL applies to businesses selling to Australians: ACCC v Valve (2016, $3 million). ACCC v Google (2022, $60 million, location data). The ACCC's case against Microsoft over Copilot price rises (filed October 2025).
Scams
$2.18 billion lost in 2025 (National Anti-Scam Centre). Scams Prevention Framework Act 2025 (from 21 February 2025): banks, telcos and digital platforms designated in May 2026, SPF Rules and AFCA membership from 1 September 2026, main obligations and AFCA complaints from 31 March 2027, sector codes still in draft. National Anti-Scam Centre (1 July 2023) and Scamwatch.
Privacy
Optus (about 9.5 million) and Medibank (9.7 million) breaches in 2022; OAIC penalty proceedings; Australian Clinical Labs $5.8 million (October 2025, the first Privacy Act civil penalty); statutory tort from 10 June 2025.
Manipulative design
Unfair trading practices law passed July 2026, commencing 1 July 2027.
Non-legal
Scamwatch alerts, bank warnings and CHOICE and media campaigns; education.
Judgement
Moderately effective and improving, but reactive and hard to enforce across borders.
Band guide (modelled on NESA Section III criteria)
21-25: extensive understanding, informed judgement, integrated legislation, cases, media and reports, sustained and cohesive. 16-20: sound judgement with relevant examples. 11-15: describes the law with some judgement. 6-10: descriptive. 1-5: general statements.
2024 HSC Q25 (b)Past paper25 marks
To what extent are legal responses effective in addressing the issues of credit and technology?
Show worked answer →

What the question demands. A judgement about legal responses to BOTH issues. NESA's feedback asked students to state the issues for consumers concerning credit and technology clearly and to support a judgement of the effectiveness of the legal responses with evidence; stronger responses referred to the ACL, NCAT and the ACCC.

Technology half of a plan. Issues: scams, data breaches, online shopping with overseas sellers, manipulative design. Legal responses: the ACL online (Valve, 2016; Google, 2022); the Scams Prevention Framework Act 2025; the Privacy Act 1988 and 2024 reforms (first civil penalty, October 2025; statutory tort from 10 June 2025); NCAT for individual online purchases; the 2026 unfair trading practices law. Judgement: legal responses are catching up but lag behind technology, and enforcement against overseas offenders is weak. Pair with the credit page.

Source: NESA, 2024 HSC Legal Studies examination, Section III, Question 25(b), and 2024 marking feedback.

Original6 marks
Explain how the Scams Prevention Framework Act 2025 (Cth) responds to scams.
Show worked answer →

The Act inserted a Scams Prevention Framework into the Competition and Consumer Act 2010 (Cth), commencing on 21 February 2025. It applies to sectors designated by the Minister: banks, telecommunications providers and certain digital platforms (social media, messaging and search) were designated in May 2026. Regulated entities must meet overarching principles to govern, prevent, detect, report, disrupt and respond to scams, backed by civil penalties. The SPF Rules commenced on 1 September 2026, when regulated businesses also had to join AFCA, but the main obligations apply from 31 March 2027, and mandatory sector codes (released in draft in May 2026) are to follow. From 31 March 2027 consumers can take complaints to AFCA and may be compensated where a business failed its obligations. It shifts responsibility from individual consumers to the businesses whose services scammers use, but its obligations are still being phased in.

Marking pattern (Original): 5-6 for the structure, sectors, obligations and redress with a limitation; 3-4 for a sound explanation; 1-2 for general points.

Original4 marks
Outline the significance of the Australian Clinical Labs case for consumer privacy.
Show worked answer →

In October 2025 the Federal Court ordered Australian Clinical Labs to pay $5.8 million after a February 2022 data breach at its Medlab Pathology business exposed the personal information of over 223,000 people. They were the first civil penalties ordered under the Privacy Act 1988 (Cth): $4.2 million for failing to take reasonable steps to secure information, and $800,000 each for failing to assess the breach and failing to notify it promptly. The case shows the regulator now enforces the Act through the courts, ahead of the larger Optus and Medibank proceedings.

Marking pattern (Original): 4 for the facts, penalty, first-ever status and significance; 2-3 for some; 1 for a general statement.

Practise this

Sources & how we know this

ExamExplained