Are Encrypted Phones Illegal in Australia?
NSW Police just charged three men over encrypted devices. The short answer is no — but the line is worth understanding properly.
27 July 2026 · ~8 min read
No — owning an encrypted phone is not illegal in Australia. Every modern smartphone encrypts its storage by default, including every iPhone and every stock Android device sold in the country.
New South Wales does have a specific offence aimed at what the legislation calls dedicated encrypted criminal communication devices. It came into force in February 2023, and in July 2026 NSW Police used it in a significant prosecution. But the offence describes a narrow and quite specific category of purpose-built criminal handset, and it requires a criminal purpose element. It is not a law against encryption, and it is not a law against privacy phones.
Because we sell privacy-focused phones in Australia, this is a question we get asked often — so here is the honest, specific answer, including the parts that are less convenient for us.
Key facts
- Operation
- Strike Force Harskamp, NSW Police State Crime Command Organised Crime Squad
- Established
- April 2025
- Target
- An alleged network importing, encrypting and selling dedicated encrypted criminal communication devices (DECCDs)
- Alleged scale
- Around 1,000 devices a year, an estimated $2 million turnover
- Seized
- 60+ devices in Botany and Banksmeadow raids, plus 35 devices, ~$35,000 cash and luxury watches in Kogarah, Bexley and Rockdale
- Charged
- Three men, refused bail, appearing 10 July 2026
- Relevant law
- Crimes Act 1900 (NSW) ss 192O–192P; DECCD Prohibition Orders Act 2022 (NSW), in force since 1 February 2023
- Maximum penalty
- 3 years imprisonment
What happened
NSW Police's State Crime Command established Strike Force Harskamp in April 2025 to investigate an alleged organised crime network importing devices from overseas, encrypting them, and selling them into criminal groups across the state. Detectives allege the operation ran as a commercial enterprise, turning over an estimated $2 million from roughly 1,000 devices a year.
Raids in Botany and Banksmeadow reportedly seized more than 60 devices and accessories. Further raids at properties in Kogarah, Bexley and Rockdale seized another 35 devices, around $35,000 in cash, and luxury watches. Three men were charged with offences including participating in a criminal group, dealing with proceeds of crime, and aiding or abetting possession of a dedicated encrypted criminal communication device to commit serious criminal activity. They were refused bail and appeared in court on 10 July 2026.
The charges are allegations. Nobody has been convicted, and we are not naming the accused.
What the law actually says
The relevant provisions sit in sections 192O and 192P of the Crimes Act 1900 (NSW), introduced alongside the Dedicated Encrypted Criminal Communication Device Prohibition Orders Act 2022 (NSW), in force since 1 February 2023.
Section 192O defines a DECCD as a mobile electronic device that has been modified and specifically designed or equipped to facilitate communication between persons reasonably suspected of being involved in serious criminal activity, in order to defeat law enforcement detection. On the statutory description, a device generally needs to meet all of the following:
- It is a modified device — hardware or software changes that block or replace standard features such as voice calls, web browsers, or geolocation
- It enables encrypted communication between users on a closed network
- It is configured in a way that specifically impedes law enforcement access to information
- It is specifically designed or equipped to facilitate communication between people reasonably suspected of serious criminal activity, in order to defeat law enforcement detection
Section 192P then creates the offence. Critically, mere possession is not enough. The prosecution must prove both that the device was a DECCD and that possession was for the purpose of facilitating serious criminal activity — defined as an offence punishable by five years imprisonment or more. No specific crime needs to have been carried out or even planned, but that purpose element has to be established. The maximum penalty is three years imprisonment. Statutory defences include possession in the ordinary course of government agency duties, and honest and reasonable mistake of fact.
Section 192P(2) also lists factors a court may weigh when assessing purpose:
- The service is operated under a false name, or is not linked to an identifiable owner
- The device has no International Mobile Equipment Identity (IMEI) number
- The device was obtained from associates in a criminal network
- The device is configured to wipe data on entry of a duress password
Where a GrapheneOS phone sits
The DECCD description is built around a specific product category: a handset deliberately crippled and rebuilt as a single-purpose criminal comms tool, sold through criminal channels, deliberately untraceable to its owner. A standard Pixel running GrapheneOS is a materially different object on nearly every element.
Not modified
A SOVEREIGN phone runs official, unmodified GrapheneOS — the exact build the GrapheneOS Project publishes free for anyone to download. We publish the verified boot fingerprint so you can confirm it matches their own official value. Nothing is added, removed, or hidden.
Standard features all work
Voice calls, SMS, web browsing, geolocation, camera, banking apps, Android Auto. It is a fully functional phone, not one stripped down to a single encrypted channel. That is close to the opposite of the DECCD description.
Standard retail hardware with a normal IMEI
Every device is a retail Google Pixel with its factory IMEI intact. Nothing is done to obscure the hardware identity.
Sold by an identifiable Australian business
SOVEREIGN is a trading name of Flux Holdings, ABN 50 427 230 683, operating under Australian Consumer Law, selling to named customers at real addresses with a paper trail. Not a closed network, not a subscription under a false name.
Open source, publicly auditable
GrapheneOS source code is public. Anyone — including law enforcement — can read exactly what it does. There is no proprietary layer only we can see.
The part that cuts against us
One of the indicators a court may consider is whether a device is configured to wipe its data on entry of a duress password. GrapheneOS supports duress passwords, and we configure them on request. We would rather say that plainly than let you find it out somewhere else.
Two things matter here. First, an indicator is evidence going to the purpose element — it is not the offence, and it does not convert a lawful device into an unlawful one by itself. A lawyer holding privileged client material, a doctor holding patient records, or a journalist protecting a source has an obvious lawful reason to want a device that resists coercion. Second, this is part of why we do not enable duress passwords by default and do explain the trade-offs first — a position that has not changed, and which the US prosecution currently testing that feature in court only reinforces.
We sell and configure phones. We are not lawyers, and nothing on this page is legal advice. It is a plain-language summary of publicly available law as at July 2026, and the law changes. If your situation calls for certainty, get it from an Australian criminal lawyer.
Why closed platforms keep falling
There is a technical pattern worth drawing out of this, and it is the opposite of what the marketing for these criminal platforms claims. Bespoke encrypted networks are sold as unbreakable. They keep being broken — not because the encryption fails, but because of who controls the software.
The clearest example is the Ghost platform, dismantled by the AFP's Operation Kraken in September 2024. Police did not crack the cipher. They intercepted and modified the software updates the platform's own administrator was pushing to users, which gave them access to device contents. ANOM, years earlier, went further still: the platform was law enforcement infrastructure from the beginning. In both cases the fatal weakness was structural — a single operator with the power to silently change the software on every handset, and users with no way to verify what they were running.
That specific weakness is what open-source, verifiable software is designed to remove. GrapheneOS publishes its source code and its build fingerprints; you can confirm the operating system on your device is byte-for-byte the same build the project published, and we publish the fingerprints for every device we ship so you can check ours against theirs. Signal's protocol and clients are likewise public and independently audited. None of this makes anything magically unbreakable — but it does mean there is no operator who can quietly push you a compromised update without it being detectable.
The uncomfortable irony for the criminal device market is that its customers are paying a premium for precisely the architecture that keeps getting them caught: closed, unverifiable, and entirely dependent on trusting one operator.
Our position
We are not in the business this strike force was investigating, and we do not want to be. Our customers are lawyers, doctors, accountants, journalists, executives and people managing difficult personal situations — all of whom have ordinary, lawful reasons to keep their communications confidential, and most of whom have professional obligations requiring it.
We sell standard retail Google Pixel hardware running free, open-source software that anyone can download and install themselves. We operate as a registered Australian business under Australian Consumer Law, we publish verified boot fingerprints so our claims can be independently checked, and we would decline a sale to anyone who described defeating a lawful investigation as their objective. That is not a legal disclaimer — it is the actual business.
Common questions
- Is it illegal to own an encrypted phone in Australia?
- No. Owning a phone with encryption is not an offence in Australia — every modern smartphone, including every iPhone and every stock Android device, encrypts data by default. NSW does have a specific offence targeting dedicated encrypted criminal communication devices, but that offence requires more than encryption: the device must meet the statutory DECCD definition, and possession must be for the purpose of facilitating serious criminal activity.
- What is a DECCD under NSW law?
- Under section 192O of the Crimes Act 1900 (NSW), a dedicated encrypted criminal communication device is a mobile electronic device that has been modified and specifically designed or equipped to facilitate communication between persons reasonably suspected of serious criminal activity, in order to defeat law enforcement detection. In practice it describes purpose-built criminal handsets — typically stripped of ordinary functions like calling, browsing or GPS, locked to a closed encrypted network, and sold through criminal channels.
- Does the offence require criminal intent?
- Yes. Mere possession of an encrypted device is not sufficient. Under section 192P, the prosecution must prove both that the device was a DECCD and that its possession was for the purpose of facilitating serious criminal activity — meaning an offence punishable by five years imprisonment or more. No specific crime needs to have actually been committed or planned, but the criminal purpose element must be established. The maximum penalty is three years imprisonment.
- Is a Pixel running GrapheneOS a DECCD?
- On the statutory description, it does not resemble one. GrapheneOS is official, unmodified, free, open-source software installed on standard retail hardware with an intact IMEI, and it leaves all ordinary phone functions working — calls, browser, GPS, camera, banking apps. It is not a closed network, it is not sold under a false name, and its source code is public. That said, whether any particular device in any particular circumstance falls within the definition is a question for a court, not for a phone vendor.
- Does having a duress password make my phone a DECCD?
- Not on its own. A duress password is listed among the indicators a court may consider, which is worth knowing before enabling one — but an indicator is evidence going to the criminal purpose element, not the offence itself. A lawyer protecting privileged client material or a journalist protecting a source has an obvious lawful reason to want a device that resists coercion. We do not enable duress passwords by default, and we explain the trade-offs before configuring one on request.
- Should I be worried about buying a privacy phone in Australia?
- Buying a standard Pixel running open-source software from a registered Australian business, for legitimate professional or personal confidentiality reasons, is ordinary lawful commerce. If you have a specific concern about your own situation, speak to an Australian criminal lawyer. Nothing on this page is legal advice.
Want to verify what you're actually buying?
That is the whole point of published fingerprints — you should not have to take our word for any of this.
Sources: NSW Police and contemporaneous reporting on Strike Force Harskamp (July 2026); Crimes Act 1900 (NSW) ss 192O–192P; Dedicated Encrypted Criminal Communication Device Prohibition Orders Act 2022 (NSW); AFP reporting on Operation Kraken (September 2024). Charges referred to are allegations that have not been proven in court. This page is general information current as at July 2026, not legal advice. GrapheneOS is a trademark of the GrapheneOS Project; SOVEREIGN is not affiliated with or endorsed by the GrapheneOS Project.