Freedom of information documents obtained by The Guardian and reported in July 2026 show the eSafety Commissioner expects online services to treat VPN detection as part of their compliance with Australia’s online safety codes.
VPNs remain legal in Australia. The obligation created by the codes sits with platforms — not with VPN providers, and not with the people who use them.
What has gone largely unexamined is the second-order effect: detection built to identify one group of users registers the same signal from everything else that runs over an encrypted tunnel, starting with the remote access Australian organisations rely on every day.
What the FOI Documents Say
The documents record the eSafety Commissioner’s position that “service providers must take reasonable steps to prevent workarounds like VPNs so eSafety will look at this when considering compliance with codes.”
The same reasoning has already been applied once. Under the social media minimum age obligations, eSafety treats VPN detection as a reasonable step for platforms to prevent underage account holders. The July documents extend that expectation to services covered by the Phase 2 codes.
| Date | What Happened |
| December 2025 | Social media minimum age obligations commence; eSafety treats VPN detection as a reasonable step for platforms |
| March 2026 | Phase 2 Online Safety Codes commence, covering services that provide access to age-restricted material |
| April 2026 | eSafety publishes its Online Safety Codes and Standards Regulatory Guidance |
| July 2026 | FOI documents show eSafety expects platforms to detect VPN use when assessing code compliance |
Are VPNs Legal in Australia?
Yes. Using a VPN in Australia is lawful, and the online safety codes do not change that. No Australian legislation restricts VPNs as a category, and none has been introduced. Conduct that is unlawful remains unlawful whether or not a VPN is involved — the tool does not alter the status of the act.
The legal position is identical for a paid subscription and for a free VPN. What separates them is transparency, not legality: whether the provider publishes a no-logs policy, whether that policy has been independently audited, where connection data is stored, and whether it is shared.
The Australian Cyber Security Centre applies the same test in its own guidance, which tells users to check a provider’s privacy policy and independent reviews before installing anything.
Business use of VPNs has never been in scope. Remote access to an employer’s network, site-to-site links between offices, and contractor access to client systems sit outside the age-assurance provisions.
Why VPN Use in Australia Is Rising
RMIT University reported in March 2026 that VPN use in Australia was climbing as people responded to the new age-verification rules, and several VPN services moved up mobile app store rankings over the same period.
Most of that demand is ordinary. Australians looking for a free vpn australia option are typically covering public Wi-Fi in cafés and airports, home connections shared with housemates, or travel.
Privacy interest has also risen independently of the codes, driven by a run of large Australian data breaches and by biometric collection in retail — a subject this publication has covered directly.
The policy debate and the usage curve are being treated as the same story. They are not.
Is Australia Banning VPNs?
No. The codes impose obligations on platforms, and the obligation is to take “reasonable steps.” Nothing in the registered codes, the April 2026 regulatory guidance, or the FOI material directs VPN providers to do anything, and no penalty attaches to a person for using one.
The distance between “platforms must take reasonable steps” and “Australia is banning VPNs” is where most of the public reaction has landed. It matters commercially, because organisations reading the headline version may start planning around a restriction that does not exist.
Why Detection Lands on Business First
Commercial VPN detection generally works from IP reputation rather than traffic inspection. It flags address ranges known to belong to hosting and cloud providers, and treats connections arriving from those ranges as suspect.
The method establishes where a connection appears to originate. It does not establish why the connection is encrypted.
| What IP-Reputation Detection Registers | What It Does Not Distinguish |
| The connection arrives from a hosting provider’s address range | A consumer VPN from a cloud-hosted corporate gateway |
| The address is not a residential ISP allocation | A personal account from a contractor reaching a client system |
| The address is shared across many accounts | A social platform session from an internal CRM session |
Three patterns common in Australian organisations produce exactly the signal detection is built to catch:
- Cloud-hosted remote access. Employers that moved remote access onto cloud gateways during and after the shift to hybrid work now route staff traffic through hosting provider address space.
- Contractor and agency access. Marketing agencies, MSPs and consultancies reach client systems from their own networks, frequently through a VPN, and often from addresses shared across a client book.
- Offshore teams. Australian companies running development or support functions overseas connect inbound through the same infrastructure.
The most upvoted response in the largest Australian discussion thread on the FOI reporting made the point before any outlet did: the commenter uses a VPN to reach their employer’s network.
When detection becomes evidence of compliance, platforms have an incentive to set the threshold low, and the cost of a false positive falls on the business whose staff cannot get in.
The Evidence Points to Weak Age Checks, Not VPNs

The clearest argument against treating VPNs as the central problem comes from the industry that sells age verification.
The Age Verification Providers Association has stated that “there are ways to detect and address circumvention and there is no need to even consider banning VPNs outright.”
eSafety’s own findings point the same way. Nine in ten of the most visited adult sites used by Australians now have age checks in place.
Even so, close to two in five children have got past an age check directly — not through a VPN, but because the check itself was the simplest and least effective kind available. eSafety has also recorded services allowing repeated attempts at the same age-assurance method despite signals that the result was wrong.
That is an implementation problem. Detection aimed at encrypted connections does not fix it.
What to Watch Next
Three things will determine how much this affects Australian organisations.
The first is how eSafety interprets “reasonable steps” in its compliance assessments, and whether it distinguishes between a platform that applies VPN detection narrowly and one that blocks hosting provider ranges wholesale.
The second is enforcement. Penalties under Australia’s age-assurance regime already reach $49.5 million, and this publication has reported the first cases landing on betting apps outside BetStop. The level at which platforms decide to over-block will track how large the downside looks.
The third is whether any platform publishes a false-positive rate. No Australian service has done so. Until one does, businesses have no way to size the risk to their own remote access, and the argument stays where it is now — between people reasoning from headlines and people reasoning from documents.

