Israeli forensics company Cellebrite has government clearance for use by law enforcement agencies to pry into your personal life – and share. Michael Sainsbury reports.
Returning from an extended stay in Bali on July 30, Peter* was stopped by Australian Border Force (ABF) officials at Perth Airport. After searching his bag, they asked to see his phone. He told MWM,
“I said why, and they said something about checking for evidence of drug trafficking or something, then they’re like, ‘ Oh, what’s your password? I’m like, why do you want that? They said, ‘Oh, we got to check it for drug trafficking. ‘
A regular business traveller for more than 15 years, Peter was surprised; despite living in Central Asia and travelling to a range of countries that Australians would consider authoritarian, this had never happened to him anywhere.
”I sort of was angry but had nothing to hide, so I just gave them the code. I then took the phone for probably half an hour in another room. When they brought it back, I asked for some sort of paperwork for what you’ve done here. But I got nothing.”
After this unsettling experience, Peter followed up with an email to Home Affairs Minister Tony Burke, whose department includes the ABF, wanting to know why these powers exist apparently unchecked. His questions remain unanswered,
including what has happened and will happen with his data.
ABF, like every nationwide police force including the Australian Federal Police, and other agencies including ASIO, has a contract with Cellebrite. The Israeli-military-founded company provides software that strips mobile phones and other digital devices of all their data, including related data.
Cellebrite clearance
On September 2, Cellebrite announced that its ‘Guardian’ cloud evidence platform had completed an independent Australian Information Security Registered Assessors Program assessment at PROTECTED level.
IRAP assessment is not government certification, but it clears a key security hurdle for agencies considering the platform. Alarmingly, Cellebrite’s announcement said agencies could move evidence into the cloud and
share it between investigators, prosecutors and partner agencies.
Australia has few effective rules governing what happens to the growing stockpile of personal data extracted from phones and other digital devices by ABF, nationwide police forces and other government security and social services agencies.
As NSW Greens MLS Sue Higginson recently highlighted, “There are no reporting requirements for any government agency on Cellebrite use, and neither are there any known policies or guidelines governing how downloaded data is stored, used, or shared, or any requirement to destroy data after matters have been finalised.”
The global reckoning over Palantir and Cellebrite – and the country that never asked
Now Cellebrite is preparing to move the evidence into the cloud and make it searchable by artificial intelligence. The company tested Genesis, which the company describes as an Agentic AI Tool “to help make our world safer” with an unnamed Australian police force.
A counter-terrorism detective from an Australian police agency with early access to Genesis. was quoted on Cellebrite’s website.
“After a targeted terrorist attack, we gained early access to Genesis and immediately began pushing its boundaries. We identified evidence and generated leads of a quality and rate that we would otherwise have expected from dozens of dedicated, highly experienced analysts.”
“We’ve used it to do things that surprised us, including generating critical new information from uploaded intelligence profiles, which changed the calculus and timeline entirely, achieving outcomes beyond what we believed possible.”
In other words, it is no longer simply who can unlock a suspect’s phone. It is who can search the resulting mountain of information, combine it with other government datasets, feed it into AI systems and obtain – and retain – the results.
A phone extraction can capture messages, emails, photographs, location histories, contacts, browsing records and other information belonging to people who are not suspects.
And it is all unchecked without privacy guardrails.
NSW leading the charge
The latest Cellebrite development comes as NSW Premier Chris Minns last week announced another expansion of police digital-forensics capabilities, including $15 million to access, download and analyse encrypted devices and digital platforms used by organised crime.
Surveillance State. NSW Police to seize mobile phone data without a warrant
At a press conference, Minns said police needed the technology to “smash open” online platforms and understand the chronology of criminal activity, including activity carried out overseas. The government said the new capabilities would be rolled out more broadly across NSW Police. The NSW announcement made no mention of how the resulting data would be retained, audited or destroyed.
The issue is becoming more urgent as police acquire systems from a growing number of technology companies. The NSW government has allocated $108.8 million for major police technology upgrades, including digital evidence management. The budget investment says a modern phone can contain one to two terabytes of information, compared with 16 to 64GB a decade ago.
NSW has said police must analyse, investigate and then store that data for up to a bewildering 99 years. But there appears to be no legal basis for this, nor
any rules governing what happens to data during those 99 years.
The Commonwealth has some destruction requirements for information obtained under the Surveillance Devices Act 2004. But those provisions do not amount to a comprehensive national regime governing data extracted from seized phones under search and other investigative powers.
A Commonwealth Ombudsman investigation found serious problems with the handling of surveillance information, including legacy holdings that had not been reviewed for retention or destruction. In one case, the Australian Criminal Intelligence Commission indicated that reviewing its legacy holdings could take up to seven years.
The UK has already moved further. Its 2022 statutory code governing digital extraction requires investigators to consider necessity and proportionality and recognises that phones contain highly sensitive information about users and people connected to them. The UK code provides a framework Australia still lacks.
Australia is instead building the technological capacity first and leaving the rules governing the resulting data fragmented between Commonwealth and state laws.
The question is no longer whether police will have the capacity to extract enormous quantities of personal information because they already do.
“Your civil liberties, in terms of the freedom from the arbitrary intervention of the state into your digital life, which is ultimately your identity, are now a thing of the past,“ Sue Higginson warned.
* Not his real name
Palantir, Cellebrite and the Surveillance Deal Nobody Voted For | The West Report
Michael Sainsbury is a former China correspondent who has lived and worked across North, Southeast and South Asia for 11 years. Now based in regional Australia, he has more than 25 years’ experience writing about business, politics and human rights in Australia and the Indo-Pacific. He has worked for News Corp, Fairfax, Nikkei and a range of independent media outlets and has won multiple awards in Australia and Asia for his reporting. He is a fierce believer in the importance of independent media.

