Over the past couple of weeks, the word Cellebrite has suddenly found its way into Australian social media feeds. Depending on which video, post or commentary you happen to come across, you could be forgiven for thinking the NSW Government has quietly introduced some terrifying new Israeli surveillance system that gives police the ability to stop an ordinary person in the street, take their phone, suck every piece of information out of it without a warrant and send it who knows where.
That makes for a fantastic social media clip. It is also not an accurate description of what is happening.
There is proposed legislation before NSW Parliament that significantly expands police powers around access to digital devices. There are provisions in that legislation that deserve scrutiny. There are legitimate questions around privacy, compelled access to phones, biometrics, self-incrimination and the long-term storage of digital evidence.
But Cellebrite itself is not new. It isn't actually named in the bill. NSW Police have already been using it for years, tens of thousands of extractions have already occurred, and dozens of Australian government agencies have contracted with Cellebrite or similar digital-forensics providers.
So before we all lose our minds over the scary new word of the week, perhaps it is worth understanding exactly what it is.
START WITH THE ACTUAL BILL
The legislation causing much of the current discussion is the Crimes and Other Legislation Amendment (Further Organised Crimes Reforms) Bill 2026, introduced into NSW Parliament on 6 August 2026.
As at 25 August, it has not passed Parliament. It is sitting in the Legislative Assembly at the second-reading stage, with debate adjourned. NSW Parliament is next scheduled to sit on 15 September.
That is an important starting point because there is commentary circulating as though these powers have suddenly come into operation.
They haven't.
The next thing worth knowing is that NSW hasn't suddenly invented the concept of ordering somebody to unlock a digital device. Digital Evidence Access Orders already exist in NSW. They were legislated in 2022 and commenced in February 2023. Under the existing regime, a DEAO can be obtained in connection with a search warrant or crime-scene warrant and can require a person with relevant knowledge of a device or its security to assist investigators in accessing it.
What the new bill proposes is an additional Digital Evidence Access Order for organised crime.
The significant change is that police would be able to apply for one where a computer or phone has been lawfully seized through some other police power, rather than requiring the device to have been seized in connection with a search warrant or crime-scene warrant. The Government has specifically said this could include circumstances such as a lawful arrest, roadside stop or other lawful detention. The officer must reasonably suspect that data on the device is connected with or relevant to an organised-crime investigation.
So yes, there is a genuine expansion of police power here.
But there is a massive difference between saying “police no longer necessarily need an accompanying search warrant before applying for access to a lawfully seized phone” and saying “police can now randomly stop anyone and download their phone without authorisation.”
Under the bill, police still need to apply for the Digital Evidence Access Order. For this new category, the eligible issuing officer is a Judge of the Local Court. The judge must be satisfied there are reasonable grounds to believe the device was lawfully seized, that its data is connected with or relevant to an organised-crime investigation, and that the person who would be compelled to assist either committed the organised-crime offence or has knowledge of it.
Call it an expanded police power. Question whether the threshold is appropriate. Debate whether Parliament should pass it.
But don't turn “doesn't require an accompanying search warrant” into “the cops can pull anyone over and empty their phone whenever they feel like it.”
Those are not the same thing.
THERE ARE STILL PARTS OF THIS BILL WE SHOULD BE WATCHING VERY CLOSELY
None of this means I believe Australians should simply shrug whenever Parliament gives police another power. Quite the opposite.
One provision deserves particular attention because the new order isn't limited solely to the person suspected of committing the organised-crime offence. An order can also apply to somebody reasonably suspected of having knowledge of the offence, provided that person also has relevant knowledge of the device or the security measures protecting its data.
That means the argument that “if you're not an organised criminal you've got absolutely nothing to worry about” is a little too simplistic.
The bill also allows an executing officer to require reasonable and necessary assistance to access data protected by biometric security, expressly giving fingerprints or retina scans as examples. Failure to comply without reasonable excuse carries a maximum penalty of seven years imprisonment, and the bill specifically says that potentially incriminating yourself is not, by itself, a reasonable excuse for refusing to comply.
Those are substantial powers.
They should be debated.
We should ask where the boundaries sit, what safeguards exist, what happens to irrelevant information extracted from a device, who can subsequently access that information, how long it is retained and whether powers introduced for organised crime remain confined to organised crime five, ten or twenty years from now.
That is what government accountability looks like, but none of those questions require us to pretend Cellebrite just arrived in Australia last Thursday.
SO WHAT THE HELL IS CELLEBRITE?
Cellebrite is a digital-forensics company. One of its primary product suites, Inseyets, incorporates technology historically known as UFED along with analysis tools that allow forensic examiners to access, extract, decode and analyse data from phones and other digital devices.
Depending on the device, operating system, security patch, encryption and the capability available to the examiner, an extraction might be relatively limited or it may provide access to a much richer file system containing application information and other protected data. Cellebrite itself markets UFED as technology for lawfully accessing digital evidence from smartphones, SIM cards, SD cards, GPS units and other devices, including full-file-system extractions where supported.
In very simple terms, Cellebrite is a forensic tool.
Think of the phone as the locked filing cabinet. The law determines whether police are entitled to get into the filing cabinet. Cellebrite is one of the tools they may use to open and examine what is inside.
It is important to understand that distinction. Cellebrite does not itself create the police power. Parliament does.
Cellebrite isn't some omnipotent machine that automatically cracks every phone ever made. Extraction capability varies enormously depending on the hardware, software, encryption, lock state and vulnerabilities available at the time. Cellebrite's own technical material discusses different levels of extraction precisely because access is not uniform across every device.
NSW POLICE HAS ALREADY BEEN USING IT
This is where the current panic starts looking particularly strange. A NSW Police response released under GIPA earlier this year shows that the force recorded 13,897 Cellebrite extractions in 2022–23, 7,765 in 2023–24 and 9,132 in 2024–25.
That's 30,794 extractions across three financial years.
Of those, NSW Police recorded 20,553 logical extractions, 9,428 file-system extractions and 813 physical extractions. It also confirmed that it had 160 Cellebrite kits deployed throughout NSW police locations.
Read that again.
The technology everyone has suddenly discovered on social media has already been used for more than 30,000 recorded extractions in NSW over three years.
The proposed organised-crime legislation does not introduce Cellebrite. What it changes is one of the legal pathways through which police could compel access to a device they have already lawfully seized.
That is a very different story.
NSW Police is hardly alone.
Public Commonwealth procurement records show Cellebrite contracts across agencies including the Department of Defence, Australian Federal Police, Services Australia, Department of Home Affairs, Australian Criminal Intelligence Commission and Australian Taxation Office, among others. One federal procurement database currently records approximately $15.5 million in Cellebrite contract notices across those agencies since 2018.
Services Australia has even been questioned about Cellebrite in Senate Estimates, where officials confirmed the technology formed part of its investigative capabilities for serious non-compliance matters that commence as criminal investigations.
So if Cellebrite is the beginning of the Australian surveillance state, somebody forgot to tell us that the beginning happened years ago.
CELLEBRITE ISN'T EVEN THE ONLY ONE
This is another reason the obsession with the brand name is misguided. Cellebrite has competitors.
One of the best known is GrayKey, originally developed by Grayshift and now part of Magnet Forensics. It performs a similar role in providing forensic access to mobile devices.
Australian government agencies are buying that as well.
In May this year, the Australian Taxation Office entered a contract worth approximately $369,000 for Magnet Forensics GrayKey licence subscriptions, running until May 2028.
Other companies operating in the broader digital-forensics market include MSAB with its XRY products, Magnet's wider forensic suite, Oxygen Forensics, OpenText EnCase, Nuix and others. MSAB itself reports Australia as one of the more mature markets for its advanced XRY forensic products.
So hypothetically removing Cellebrite tomorrow does not remove the capability. It changes the logo on the forensic workstation. Once again, the important question isn't which company manufactured the crowbar.
The important question is who is legally allowed to use it, against whom, under what circumstances and with what oversight.
WHERE DOES YOUR PHONE DATA ACTUALLY GO?
Another claim that deserves some daylight is the suggestion that using Cellebrite automatically means the entire contents of an Australian's phone are secretly transferred overseas to Cellebrite.
That isn't how the product necessarily operates.
Cellebrite extraction technology can produce forensic data for storage and analysis within an agency's own investigative environment. Cellebrite also now offers Guardian, a cloud-based evidence-management platform that can integrate directly with its extraction software, allowing evidence to move from forensic extraction into a managed investigative environment. Guardian uses Amazon Web Services infrastructure and Cellebrite currently lists an Australian Guardian region, allowing Australian data residency where that platform is deployed.
That does not establish that NSW Police uploads every Cellebrite extraction into Guardian.
This is where we think the public should be asking a much better question.
In June, the NSW Government announced a $108.8 million technology investment for NSW Police that included upgrades to digital evidence management, forensic systems, data analytics and Evidence.com. In explaining the scale of the problem, the Government said modern seized phones may contain between one and two terabytes of data and that police can be required to analyse, investigate and then store data for 99 years.
Ninety-nine years.
What gets retained for 99 years? Is an entire phone extraction retained or only evidentiary material? What happens to intimate photographs, private conversations, medical information, communications with people completely unrelated to an offence or years of personal information that turns out to be irrelevant? Who can subsequently search it? What audit trail exists when somebody accesses it? Can information originally collected in one investigation later be used in another?
Those are questions worth asking.
NOW FOR THE PART SOME PEOPLE AREN'T GOING TO LIKE
Australians are suddenly furious about the prospect of the Government getting access to information stored inside a mobile phone.
While we've been worrying about what police might obtain under a judge-approved order, most of us have spent years voluntarily producing enormous amounts of information about ourselves for private companies.
We tap loyalty cards.
We install apps.
We accept cookies.
We allow location access.
We order groceries online.
We store payment methods.
We click “accept” on privacy policies we haven't read.
We carry smartphones everywhere we go.
We use the same device to communicate, shop, bank, navigate, search, photograph our families, access social media and identify ourselves.
None of that means corporate data collection is legally or ethically equivalent to a police search. It isn't. But if this Cellebrite debate finally makes Australians interested in their privacy, perhaps we should broaden the conversation beyond the police officer holding the phone.
Take Coles.
Its privacy policy says it may collect identity and contact information, financial and transaction information, transaction history, loyalty-program purchases, location information where permission has been granted, product purchases and interests, interactions with digital services, audio and video footage, CCTV and monitoring information and even automotive number-plate recognition data.
Its policy also describes digital technologies that can collect information including IP addresses, browsing behaviour, purchase history and the contents of a shopping basket. It says information collected through cookies and similar technology may be combined with other information such as loyalty-card use and in-store purchases, and describes circumstances where hashed identifiers and order-related information may be used with advertising partners to deliver relevant advertising.
Most Australians will walk into a supermarket today without giving any of that a second thought. Then they'll open Facebook in the carpark and post about the surveillance state.
Perhaps that deserves a little self reflection.
THEN THERE'S PALANTIR
Coles also has a three-year relationship with Palantir Technologies, one of the world's most powerful data-integration and analytics companies and a business with longstanding relationships across military, intelligence and government organisations.
Palantir announced in 2024 that its platforms would be deployed across more than 840 Coles supermarkets. The publicly disclosed use focuses on workforce strategy, supply-chain functions, bakery production planning and operational decision-making, with the system identifying opportunities across more than 10 billion rows of data involving stores, team members, shifts and allocations.
There has been renewed controversy over that relationship this year, including a campaign by GetUp calling for Coles to end it. But here, again, accuracy matters.
There is currently no evidence we have found that Palantir is being handed Coles facial-recognition feeds or simply ingesting every customer's shopping history. Coles has said the Palantir software has no direct access to customer-surveillance feeds and is being used for areas including supply-chain management, bakery planning, staff rostering and promotion analysis.
We could ignore that because it weakens a sensational headline or we could tell the truth.
Our concern shouldn't be that every technology company is automatically evil. It should be that extremely powerful data systems are becoming normal infrastructure across government and corporate Australia, often without the average Australian having the faintest idea what information exists, where it travels, how systems connect or what conclusions can eventually be drawn from it.
WHAT ABOUT FACIAL RECOGNITION?
The same thing is happening with facial recognition.
Coles and Woolworths recently confirmed testing of facial-recognition technology, although neither has announced an Australian supermarket rollout. Coles says its test was a small controlled proof of concept that did not use customer or employee data and that it does not currently use facial recognition in its stores. Woolworths' test was reportedly conducted in its New Zealand office.
Bunnings is further down that road.
Bunnings previously used facial recognition in dozens of Australian stores, matching customers against a watchlist intended to identify individuals associated with serious retail crime, violence and abuse. Earlier this year the Administrative Review Tribunal found that Bunnings had been reasonably entitled to use the technology for that limited purpose, although the tribunal found it could have done more to properly notify customers about the collection.
Again, this is not an argument that corporations and police are identical.
They aren't.
It is an argument that surveillance and data collection have been gradually becoming part of ordinary Australian life for years.
The difference is that most of it happened one convenience at a time.
One loyalty card.
One app permission.
One security camera.
One cookie banner.
One online account.
One “I agree”.
Nobody called it Cellebrite, so nobody made a TikTok about it.
WHILE EVERYONE IS YELLING ABOUT CELLEBRITE, LOOK AT WHAT ELSE IS IN THE SAME BILL
There is one final irony in this entire debate.
While much of the online conversation has become obsessed with a brand of mobile-forensics software that isn't even named in the legislation, the actual bill contains other surveillance and information-sharing changes sitting there in black and white.
The bill facilitates NSW participation in the Commonwealth's face-matching services, including sharing driver-licence and photo-card images through the national identity-matching framework. It also establishes provisions dealing with the collection, storage and disclosure of toll-camera images, including access by authorised agencies in specified circumstances.
Those changes may be justified. They may be useful in catching violent criminals, locating missing people and preventing identity crime.
They should still be scrutinised because this is precisely how sensible adults should approach government power. We don't need to scream that every new police technology is tyranny.
THE REAL PRIVACY CONVERSATION IS MUCH BIGGER THAN CELLEBRITE
There is nothing unreasonable about Australians being protective of their phones.
For most people, that little rectangle contains a more complete record of their life than anything that has ever existed before it. Messages, photographs, locations, relationships, banking, searches, health information, work, family, mistakes, jokes and private conversations can all live in one place.
Government access to that information deserves a high threshold.
But we are doing ourselves no favours when genuine scrutiny is replaced by technically inaccurate social-media hysteria.
The proposed law does not simply give every police officer an unrestricted power to randomly download anybody's device.
It does expand the circumstances in which police investigating organised crime can seek a judicial order compelling access to a device that has already been lawfully seized.
If we're going to suddenly become passionate defenders of privacy, good, it's about time. But privacy doesn't begin when a police officer picks up your phone.
It begins much earlier. When you download the app, scan the loyalty card, allow the location permission, walk beneath the camera, create the account, connect the device and click the little box beside the privacy policy you didn't read.
Cellebrite isn't the whole story. It isn't even the most interesting part of it. The real story is how much information now exists about every one of us, how easily we have become accustomed to producing it, and who we ultimately allow to access it.
That is where Australians should be paying attention.
SOURCES:
NSW Police - Digital Forensics Unit Responses to GIPA-2025-0944772