Big Tech Companies: What They Know, What They Do, and How to Fight Back
By Tony · FreedomTech · 9 min read · Updated June 2026
In September 2025, Australia's eSafety Commissioner said something the big tech companies you rely on every day would rather you never heard. Defending the incoming under-16 social media ban, she explained it would be unreasonable to reverify everyone's age, because the platforms usually already had enough data to know who was under 16. They can, in her words, target us with deadly precision when it comes to advertising.
Sit with that. A federal regulator confirming these companies profile us so finely they can pick a teenager out of a crowd of millions. That precision is not a glitch or an overreach. It is the business model working exactly as designed.
And the more they collect, the more there is to lose when it leaks. This post sets out what big tech companies operating in Australia actually gather, how they use it, who they share it with, and the practical steps Australians can take to shrink the footprint.
The short version
- Big tech companies build detailed profiles from your location, browsing, purchases and even your AI chatbot conversations.
- A hidden data broker industry buys, combines and resells those profiles, often without your knowledge or meaningful consent.
- Governments can compel platforms to hand over what they hold, and Australian disclosures have risen sharply over the past decade.
- The fix is not paranoia. It is choosing technology that never collects the data in the first place: a deGoogled phone, a Linux computer, and hardware isolation when you need it.
What These Companies Actually Know About You
For big tech companies, the collection starts the moment you pick up your phone, and it never really stops.
Google handles billions of searches a day. Meta's tracking pixel sits on a large share of the world's most visited websites, quietly logging your behaviour long after you have closed Facebook or Instagram. Amazon knows your purchasing patterns and your delivery address. Apple knows where you have been. When a journalist requested her data from Meta, the file ran to tens of thousands of pages, including activity on sites and apps with no obvious connection to her account at all.
- Location history, IP address and device type.
- Browsing behaviour and the time you spend on each page.
- The contacts in your phone and your health data from apps.
- Your biometric data from facial recognition.
- And now the content of your conversations with AI chatbots.
In late 2024 Meta confirmed it would begin using conversations with its AI assistants across Facebook, Instagram and WhatsApp to target advertising. None of this is accidental. It is how big tech companies make their money, and your data is the raw material that fuels a digital advertising industry measured in the hundreds of billions of dollars.
The Data Broker Industry Most Australians Don't Know Exists
Collection is only half the story. What happens to your data next is worse.
Australia has a thriving data broker industry: companies you have almost certainly never heard of that collect, combine, package and sell detailed profiles of individual Australians. Much of their raw material comes from the same big tech companies you use every day. The ACCC's 2024 data broker report, the first in-depth look by an Australian regulator at the sector, examined nine data brokers and data firms and found people are routinely profiled without their knowledge or meaningful consent.
A broker can know your medical history, your location and even what you watch on television. Under Australian Privacy Principle 3.6, collecting personal information from third parties for profiling is meant to be off limits unless it would be unreasonable or impracticable to collect it directly from you. In practice that provision has almost never been enforced.
Government Requests: When Big Tech Hands Over Your Data
Advertising is not the only reason big tech companies share your data.
Between 2014 and 2024, the volume of user accounts handed to law enforcement climbed sharply. Across that decade Google, Meta and Apple shared data from more than three million accounts with US law enforcement alone, and that figure excludes requests made under secret intelligence provisions. Australia is part of the Five Eyes intelligence alliance, and when Edward Snowden revealed the PRISM program in 2013, it emerged that Australia's signals directorate was cooperating with NSA programs that reached user data held by Microsoft, Google, Facebook, Apple and others.
A deGoogled phone running GrapheneOS does not send your location, contacts or usage patterns to Google in the first place. There is nothing to hand over, because the data was never collected.
Facial Recognition in Australian Retail: The New Normal
The surveillance is not confined to your phone. It is waiting in your local shopping centre.
Two of Australia's best-known retailers have already been found to have crossed the line.
Bunnings, 2024
- Faces scanned across 62 stores over a three-year period.
- No consent, matched against a persons-of-interest database.
- Found by the OAIC to breach the Australian Privacy Principles.
Kmart, 2025
- The same finding across 28 stores.
- Security justification rejected by the Commissioner.
- Confirms your face is sensitive personal information.
Australia's first civil penalty under the Privacy Act arrived in 2025, $5.8 million against Australian Clinical Labs, and proceedings are now underway over the 2022 Optus breach. But regulation only ever acts after the damage is done.
For a closer look at how biometric data is used against Australians, read our guide to biometric privacy risks and facial recognition.
AI Is Making the Problem Worse
Artificial intelligence does not just add to the problem. It multiplies it.
- It makes previously unusable data useful. Fragments too scattered to act on individually can now be combined and cross-referenced at scale, so the old comfort of hiding in a mountain of data no longer holds.
- It accelerates collection. Big tech companies are moving toward advertising that runs largely on its own, fed by everything they know about you, including your chatbot conversations.
The recommendation engines behind YouTube, Instagram, TikTok and Facebook are tuned to maximise engagement, which means surfacing whatever provokes the strongest reaction. The US Federal Trade Commission described this as vast surveillance of users to monetise their behaviour.
Children are not exempt. From 10 December 2025, Australia became the first country to set a social media minimum age, requiring platforms including Facebook, Instagram, TikTok, YouTube, Snapchat and Reddit to keep under-16s off their services, with fines of up to $49.5 million. To understand how AI surveillance is reshaping Australian life, read our piece on AI, ethics and privacy in a hyperconnected world.
The Australian Privacy Landscape in 2026
The law is catching up, but it is starting a long way behind.
The Privacy and Other Legislation Amendment Act 2024 expanded the OAIC's enforcement toolkit, adding infringement notices, broader civil penalties and stronger investigative powers. A new statutory tort for serious invasions of privacy took effect on 10 June 2025, letting individuals sue directly for intentional or reckless violations without having to prove financial loss.
These are meaningful developments. But they govern what big tech companies do with your data once they hold it. They do not address the deeper problem: that the data is collected at all, on a scale no regulatory framework has managed to contain. Australians who want genuine privacy cannot rely on regulation alone.
What Practical Privacy Actually Looks Like
Understanding the problem is step one. Step two is building a setup that does not feed it.
Protecting yourself from big tech companies does not mean disappearing from the internet. It means reducing what can be collected in the first place, across both software and hardware.
Software layer
- deGoogled phone on GrapheneOS: no location data, app usage profile or advertising ID sent to Google.
- Linux laptop on Mint Cinnamon: no Windows telemetry, no documents harvested, no search profiling.
Hardware layer
- Faraday bag: blocks cellular, WiFi, Bluetooth and GPS when isolation is what you need.
- Dedicated machine: separates serious activity from your everyday device and its tracking.
The deGoogled phone is the approach Edward Snowden recommends, with the bootloader relocked after installation so you keep the security of a stock device without the surveillance. Every FreedomTech machine is configured in Australia and ready to use. For anyone managing serious digital assets, a dedicated crypto computer keeps that activity off your everyday machine entirely.
For more on the mechanics, read our look at the dark side of Big Tech, and on how surveillance shapes politics, our piece on digital privacy, voting and data manipulation.
Big Tech Companies: Common Questions
Are big tech companies subject to Australian privacy law? +
What is a data broker and how do they get my information? +
Does using a VPN protect me from big tech data collection? +
Is it legal for companies to scan my face without my consent in Australia? +
What were the Optus and Medibank data breaches? +
How do I stop big tech companies from tracking me? +
Take back control
Practical, tested technology that keeps your data with you, configured in Australia and ready to use.
Questions, or just keen to talk privacy with like-minded Australians? Visit our Telegram community.
FreedomTech · The Privacy Experts · freedomtech.com.au