Is a VPN Legal in Australia? Data Retention Law and What It Means for VPN Users
Using a VPN in Australia is not against the law. But a 2015 data retention scheme changed what internet and phone providers must record about your connections — and that has real implications for how much a VPN can actually shield you from.
Quick answer
Yes, using a VPN is legal in Australia — there is no law banning VPN software or its use for ordinary purposes such as privacy, security, or accessing region-specific content. The relevant law to understand is not a VPN ban but Australia's mandatory data retention scheme, introduced in 2015, which requires telecommunications and internet providers operating in Australia to retain certain connection metadata — not content — for two years. That obligation applies to Australian carriage service providers such as telcos and ISPs, not to VPN companies themselves, most of which are headquartered outside Australia and fall outside the scheme's reach. A VPN limits what your own Australian ISP can log about your downstream browsing, but it does not make you invisible: your ISP still retains metadata about your connection to the VPN server itself, and using a VPN does not make an otherwise illegal act legal.
Is a VPN legal in Australia?
Yes. There is no Australian law that prohibits downloading, installing, or using VPN software, and no provision anywhere in Australian federal or state legislation that makes VPN use itself a criminal act. Australians use VPNs for entirely mainstream reasons — securing a connection on public Wi-Fi, working remotely on a corporate network, protecting online banking sessions, and accessing streaming or news content from other regions — and none of that requires stepping outside the law. If you searched "is VPN legal in Australia" because you were worried the tool itself might be restricted the way it is in a small number of other countries, the direct answer is that it isn't, and you can stop worrying about that specific question.
What actually deserves attention, and what most casual coverage of this topic skips past, is a different law entirely: Australia's mandatory data retention scheme, introduced in 2015 and sometimes called the "metadata retention law." It doesn't restrict VPN use. It changes what telecommunications and internet providers operating in Australia are required to record about the connections passing through their networks — which matters a great deal if part of why you're using a VPN in the first place is to limit what gets logged about your online activity. Understanding the difference between "is this tool legal" and "what does the law require providers to record" is the key to actually answering the question this guide's title asks, rather than just repeating a yes-or-no headline.
What is Australia's mandatory data retention law?
The law in question is the Telecommunications (Interception and Access) Amendment (Data Retention) Act 2015, which amended the existing Telecommunications (Interception and Access) Act 1979. It passed the Australian Parliament in early 2015 and received Royal Assent in April of that year, with providers given a lengthy implementation window — commonly described as up to eighteen months — to build the systems needed to comply, meaning the scheme was fully in effect for covered providers by around 2017. The legislation is widely referred to in Australian media and policy discussion simply as the "data retention law" or "metadata retention law," and that's the version of the name most people searching for VPN legality in Australia will run into.
At its core, the law requires Australian telecommunications carriers and internet service providers — legally defined as "carriage service providers" under the Telecommunications Act 1997 — to retain a defined set of communications metadata for a minimum of two years, and to make that data available to a specified list of government agencies through an authorized request process. The scheme was introduced under the banner of assisting law enforcement and national security investigations, and it followed a broader international pattern in the mid-2010s of governments — including in Europe, the UK, and elsewhere — legislating some form of mandatory metadata retention for telecommunications providers, largely in response to counter-terrorism and serious-crime investigation priorities of that period.
It's worth being precise about scope from the outset, because this is the detail that gets flattened in a lot of casual summaries: the obligation applies to the companies providing telecommunications and internet access services to the Australian public — think Telstra, Optus, TPG, and the broader list of licensed carriers and ISPs — not to every company that touches the internet in some way. That distinction is the thread this guide keeps coming back to, because it's the reason VPN providers are treated differently under the scheme than your actual internet connection is.
What data does the retention scheme actually require providers to keep?
The Act specifies categories of metadata that covered providers must retain, and it's a genuinely useful exercise to look at what's actually on that list rather than assuming it means "everything you do online gets logged." The retained categories broadly cover:
- Subscriber and account information — who holds the account, and identifying details associated with it
- The source and destination of a communication — for example, which phone numbers were involved in a call, or which IP addresses and ports were used in an internet session, though not the destination website's specific page or the search you typed
- The date, time, and duration of a communication or connection session
- The type of communication or service used — for instance, whether it was a phone call, SMS, or internet access session, and details like the type of device or service
- The location of the equipment used at the start and end of a communication, at the level of detail generally available to the provider (such as which cell tower a mobile device connected through)
What's explicitly excluded is, in practical terms, the more sensitive half of the picture: the scheme does not require retention of the content or substance of a communication. That means the actual words in a phone call or a text message, the body of an email, and — the detail most relevant to anyone thinking about VPNs — your web browsing history and the specific web addresses or online activity you engaged in are carved out of the mandatory retention requirement. Your ISP, under this scheme, is not required to keep a log of which websites you visited or what you did there; it's required to keep a log of when you connected, for how long, using what IP address, and similar connection-level facts.
That carve-out was a deliberate and heavily debated part of how the law was drafted and later described publicly by the government of the day, precisely because "the government is logging everyone's browsing history" was one of the loudest public objections during the legislative debate. Whether the metadata that is retained is, in practice, revealing enough to reconstruct a meaningful picture of someone's online life anyway is a separate and genuinely contested question — knowing which IP addresses you connected to, when, and for how long can reveal a great deal even without the content itself — but it's a different claim from "browsing history is logged," and it's worth keeping those two claims separate when you're evaluating what the law does and doesn't cover.
Does Australia's data retention law apply to VPN providers?
This is the question that actually matters most for a VPN user reading this guide, and the honest answer requires some care rather than a flat yes or no. The data retention obligation under the Telecommunications (Interception and Access) Act attaches to entities that meet the legal definition of a "carriage service provider" — broadly, a company supplying a listed carriage service (phone or internet access) to the public in Australia, typically using its own or a partner's telecommunications infrastructure. A consumer VPN company, in the ordinary case, is not supplying you with your underlying internet connection; it's a service you connect to over an internet connection you already have from your actual ISP. On that reading, most VPN providers fall outside the definition the retention scheme was built around, and the obligation to log the metadata described above lands on your ISP, not on the VPN company whose app you're using.
That's the interpretation reflected in how the scheme is generally discussed in Australian legal and privacy commentary, and it lines up with how VPN companies themselves — almost all of which are headquartered outside Australia, in jurisdictions like Panama, the British Virgin Islands, Switzerland, or elsewhere — describe their own obligations: as companies not directly bound by Australian telecommunications law in the way a domestic carrier is. It's also worth being clear-eyed about the limits of that reading: it hasn't, to public knowledge, been tested through a specific court case or formal regulatory ruling that definitively settles how the definition would apply to every possible VPN business structure, including one with a genuine Australian corporate presence. For an international consumer VPN provider with no Australian office, no Australian-registered entity, and no Australian telecommunications infrastructure, the practical reality is that Australian data retention law has little direct purchase — there's no local entity for the obligation to attach to or be enforced against.
The practical upshot most privacy-focused commentary settles on is this: Australia's data retention scheme is a real, substantive law with real requirements, but its requirements are aimed at your internet and phone provider, not at the VPN app running on top of that connection. That's a meaningfully different situation from a country that has passed a law specifically targeting VPN providers as such — Australia hasn't done that.
If VPN providers aren't directly covered, what does a VPN actually change about what gets logged?
This is where it's worth being precise rather than letting "VPN providers aren't covered" get oversimplified into "a VPN makes the data retention law irrelevant to you." Your Australian ISP — the entity actually bound by the retention scheme — still sees and still logs metadata about your connection whether or not you're using a VPN. What changes is what that metadata reveals.
Without a VPN, your ISP's retained metadata can include the IP addresses of the specific external servers your device connects to, which — combined with timestamps and duration — can reveal a fair amount about which services and websites you're using, even without logging the content or specific page. With a VPN active, your ISP still logs that your device connected to something, for how long, and at what times, but the destination IP address in that record is the VPN server's IP address, not the website's. Your ISP knows you connected to a VPN provider; it does not, from its own retained metadata alone, know what you did once that encrypted tunnel to the VPN server was established. That's the actual, concrete way a VPN interacts with Australia's data retention scheme: it doesn't exempt your connection from being logged, it changes what the logged connection metadata is capable of revealing, by moving the visible destination from "the website" to "the VPN server."
It's worth being honest about the other side of that trade too. Your VPN provider, sitting on the other end of that tunnel, is in a position to see more about your actual browsing than your ISP now can — which is exactly why a VPN provider's own logging policy and jurisdiction become the thing that matters most once you've moved the point of visibility from your ISP to the VPN company. A VPN doesn't eliminate the question of who can see your activity; for Australian users specifically, it relocates that question from a company bound by a two-year mandatory retention law to a company that generally isn't, but whose own policies are the thing you now need to actually evaluate.
Can Australian authorities compel a VPN provider to hand over logs anyway?
An Australian court or agency can, in principle, seek to compel any company doing business with Australian customers to produce records it holds, through mechanisms like a subpoena, court order, or mutual legal assistance request to a foreign jurisdiction — that general legal mechanism isn't unique to VPN providers or to Australia. What that request can actually produce, in practice, depends entirely on two things that have nothing to do with whether the data retention scheme itself applies: whether the VPN provider is physically and legally present in Australia in a way that makes it directly answerable to an Australian court order, and whether the provider retains any meaningful connection logs in the first place. A VPN company genuinely operating a strict no-logs policy, verified through independent audits, has structured its business specifically so that even a validly served request has little or nothing to hand over — not because the request couldn't legally be made, but because there's nothing on record to produce.
Why does a VPN provider's jurisdiction matter for Australian users?
Because the data retention scheme binds Australian carriage service providers rather than foreign VPN companies, the jurisdiction a VPN provider is actually based in becomes a more meaningful factor in evaluating its privacy posture than Australian law specifically. A provider headquartered in a country with strong privacy protections and no mandatory logging requirements of its own, and with a documented, independently audited no-logs policy, offers a genuinely different assurance than a provider based somewhere with weaker protections or unclear legal exposure — regardless of where its Australian customers happen to be located.
This is also where Australia's own surveillance-adjacent legal framework outside the data retention scheme becomes relevant, if more indirectly. Australia is a member of the "Five Eyes" intelligence-sharing arrangement, alongside the United States, the United Kingdom, Canada, and New Zealand — a long-standing intelligence cooperation framework, not a VPN-specific law, but one that privacy-focused commentary and VPN providers themselves frequently reference when discussing jurisdiction. Separately, the Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 — often abbreviated TOLA — gives Australian authorities a mechanism to request or, in some circumstances, compel technical assistance from "designated communications providers" in relation to encrypted communications, subject to safeguards including a prohibition on requiring providers to build a "systemic weakness" into their systems. TOLA is a broader piece of legislation aimed at technology and communications companies generally, not written specifically around VPN providers, and its practical reach over a VPN company with no Australian legal presence is subject to the same jurisdictional limits already discussed above — but it's a real law worth being aware of if you're weighing whether a provider's operational footprint in Australia, or lack of one, matters to your decision.
None of this is a reason to treat every VPN provider as equally exposed or equally safe. It's a reason to treat jurisdiction, logging policy, and independent verification as the actual factors worth comparing between providers, since Australian law itself — for VPN companies specifically — mostly stays out of the picture.
How does VPN use interact with Australia's website-blocking regime for piracy?
Separately from data retention, Australia operates a website-blocking scheme aimed at online copyright infringement, introduced through the Copyright Amendment (Online Infringement) Act 2015, which inserted section 115A into the Copyright Act 1968. That provision allows copyright holders to apply to the Federal Court of Australia for an injunction requiring Australian ISPs to block access to specific overseas-hosted websites found to have the primary purpose of facilitating copyright infringement — commonly, but not exclusively, torrent-indexing and piracy-streaming sites. Since the scheme came into effect, it has been used repeatedly by rights holders to obtain blocking orders against a range of such sites, and the list of blocked domains has grown and shifted over time as new orders are sought and as blocked sites relocate to new domains.
A VPN is one of the more straightforward ways to route around an ISP-level domain block like this, since it routes your traffic through a server outside the blocking ISP's own network rather than relying on that ISP's DNS or IP-level filtering at all. Using a VPN to reach a site your Australian ISP has been ordered to block is not, by itself, singled out as a separate criminal offense under the section 115A scheme — the blocking order is directed at the ISP, requiring it to block access, not at individual users, and using a VPN to bypass that block doesn't create a new legal violation on top of whatever the underlying content itself might involve.
What doesn't change is the separate question of copyright law itself. If a site is subject to a blocking order because it hosts or facilitates infringing content, downloading or distributing that content remains a potential copyright infringement issue regardless of whether you reached the site directly or through a VPN — a VPN changes how you got to the site, not whether what you do once you're there is lawful. That's the same distinction this guide keeps returning to in different forms: a VPN affects visibility and access, not the underlying legality of an activity.
Is it illegal to use a VPN to access geo-restricted streaming content in Australia?
No — and this specific question has actually had public commentary from Australian government figures directly addressing it. Around the time discussion intensified in Australia over Australians using VPNs to access other countries' streaming catalogs — most commonly cited in the context of accessing a US Netflix library that differed from the Australian one — Australian government officials were widely reported as stating that using a VPN to access geo-restricted overseas content does not, by itself, breach Australian copyright law. The reasoning generally given was that the act of a consumer using a VPN to appear to be located elsewhere isn't the same legal act as unauthorized reproduction or distribution of copyrighted material; you're still paying for and using a legitimate subscription service, just accessing a different regional catalog than the one your actual location would otherwise show you.
What's separate from Australian law, and worth not confusing with it, is that individual streaming services have their own terms of service that typically prohibit using a VPN to access a catalog outside your registered region. That's a private contractual matter between you and the streaming provider, enforceable through account-level consequences like a warning or suspension, not a matter of Australian government law. Streaming platforms have also become considerably more effective over time at detecting and blocking known VPN server IP ranges specifically to enforce these regional restrictions, which is why VPN users sometimes find a particular server no longer works for a particular streaming service even when nothing about the legal picture has changed — that's a technical enforcement measure by the streaming company, not a legal escalation.
Does using a VPN affect law enforcement's ability to investigate crimes in Australia?
Using a VPN does not make an otherwise illegal act legal, and it does not place someone beyond the reach of Australian law enforcement as a matter of principle. What a VPN does is add a layer of technical difficulty to identifying and attributing specific online activity to a specific person, by masking the IP address that would otherwise connect that activity to your home internet connection. For serious criminal investigations, Australian law enforcement and national security agencies have a range of legal powers well beyond the data retention scheme discussed in this guide — including warranted interception powers, mutual legal assistance arrangements with other countries, and the ability to compel evidence through court processes — that don't depend on a VPN provider being bound by Australia's own metadata retention law specifically.
For the overwhelming majority of ordinary VPN users — people using one for privacy, security on public networks, remote work, or accessing region-specific content — none of this is a live concern in the first place, since a VPN, like any privacy tool, is neutral with respect to what it's used for. It's included here because "does a VPN put me above the law" is a genuine, common question behind searches about VPN legality, and the honest answer is no: a VPN changes what's visible and to whom, it doesn't change what's legal.
What should Australians actually check before choosing a VPN, given the data retention law?
Given everything above, the data retention scheme itself isn't really a reason to avoid VPN use in Australia — if anything, wanting to limit what your own ISP can see about your connections is a reasonable, common motivation for using one in the first place. What it does mean is that the provider you choose is doing more of the actual privacy work than the law is, since Australian data retention law mostly isn't reaching your VPN company at all. A few things are worth checking on any provider you're considering, rather than taking a "no-logs" badge on a homepage at face value:
- Read the provider's actual privacy policy, not just its marketing page, for specifics on what connection data — if any — is logged, and for how long, rather than relying on a general "no-logs" claim alone.
- Look for a documented history of independent no-logs audits, since third-party verification is a meaningfully stronger signal than an unverified claim, even though an audit is a snapshot in time rather than a permanent guarantee.
- Consider the provider's jurisdiction, given that Australian data retention law largely doesn't bind foreign VPN companies — meaning the laws of the country the provider is actually headquartered in matter more to your privacy posture than Australian law does in this specific context.
- Check for a working kill switch and DNS/IP leak protection in the provider's app, since these are the features that actually determine whether your connection metadata reliably routes through the VPN server rather than occasionally leaking your real IP address to your ISP or to the sites you visit.
- Don't assume streaming access to a specific regional catalog is guaranteed or permanent, since that's a function of the streaming service's own VPN-detection efforts shifting over time, separate from anything about Australian law.
None of this requires an unusual amount of technical expertise — it's the same due diligence worth applying to evaluating any VPN provider's privacy claims, in any country, just applied with the specific detail that Australian law itself is largely not the thing doing the privacy work here.
Has Australia's data retention scheme faced criticism or review since it passed?
Yes, on both counts, and it's worth knowing the scheme wasn't quietly passed and forgotten. The 2015 Act was contested during its own passage through Parliament, with privacy advocates, digital rights groups, and sections of the media arguing at the time that mandatory metadata retention represented a disproportionate expansion of surveillance capability relative to the crime-prevention benefit it was expected to deliver, and that metadata alone — despite excluding content — could still be revealing enough to raise genuine privacy concerns. Journalists' organizations raised a related concern specific to their own profession: that metadata retention could make it easier to identify confidential sources through call and connection records, even without ever accessing the content of a conversation. Those objections led to a specific carve-out requiring a journalist information warrant before certain agencies could access metadata for the purpose of identifying a source — a narrower, source-protection-focused safeguard rather than a general exemption from the scheme.
The law has also been subject to formal parliamentary review. Australia's Parliamentary Joint Committee on Intelligence and Security examined aspects of the scheme's operation in the years after it took effect, including which government agencies should retain access to the retained metadata without a warrant. That review process led to a narrowing of the list of agencies permitted to access retained data under the scheme, on the reasoning that the original list had grown broader than the law's stated national-security and serious-crime rationale justified. This guide isn't going to cite a specific, current count of exactly how many agencies retain access today, since that list has been revisited more than once and a specific number risks being out of date by the time you're reading this — if that level of detail matters for your situation, checking the current text of the Act or recent parliamentary committee reporting directly is more reliable than any fixed figure repeated in a general guide.
The broader point worth taking from this history is that the data retention scheme isn't a settled, uncontroversial piece of infrastructure that's been left alone since 2015 — it's been amended, reviewed, and narrowed in specific respects since its introduction, which is a reasonably normal pattern for a significant piece of surveillance-adjacent legislation, and a reminder that the exact operational details of who can access what, and under what process, are worth checking against current sources rather than treating any single description — including this one — as permanently fixed.
How does Australia's approach compare with VPN laws in other countries?
Placed alongside the wider global picture, Australia sits toward the more permissive end of the spectrum specifically with respect to VPN use itself, while sitting toward the more active end with respect to what it requires of domestic telecommunications infrastructure. That's a genuinely different combination from what you'll find in a country like China, which layers a licensing requirement for VPN services on top of an extensive, technically enforced national filtering system that actively detects and blocks VPN traffic — a scenario covered in detail in our guide to VPN laws in China. It's also different from a country like the UAE, where VPN use itself is broadly legal but specific uses — such as certain VoIP calling — are separately restricted under cybercrime legislation, discussed in our UAE VPN legality guide.
Australia doesn't fall into either of those patterns. It hasn't licensed or restricted VPN software, and it hasn't built technical infrastructure to detect and block VPN traffic at the network level the way some more restrictive regimes have. What it has done is legislate a data retention requirement aimed at the telecommunications layer everyone's traffic passes through regardless of whether a VPN is involved — a regulatory approach with more in common with data retention frameworks adopted around the same period elsewhere, including various European countries under earlier EU data retention rules, than with a VPN-specific restriction. If you're comparing Australia's situation to another country's for a specific decision — relocating, traveling, or running a business across borders — treat each jurisdiction as its own question rather than assuming the same framework applies, since the legal mechanisms involved (VPN-specific bans versus telecommunications-level data retention versus technical filtering) are genuinely different tools with different implications.
Do businesses and remote workers face different considerations when using a VPN in Australia?
The legal picture covered throughout this guide applies the same way regardless of whether you're an individual or a business — there's no separate, more restrictive VPN law that applies specifically to commercial use in Australia. What does shift for businesses is the practical stakes and the reasons a VPN is being used in the first place. A company operating a corporate VPN for employees to reach internal systems remotely is running a materially different kind of deployment than a consumer connecting through a commercial VPN app, even though neither is doing anything Australia's data retention law was written to restrict.
For a business specifically, the more relevant question is usually less about whether a VPN is legal — it plainly is — and more about the company's own obligations under separate Australian frameworks, such as the Privacy Act 1988 and the Australian Privacy Principles, if the business handles personal information as part of its operations. Those obligations exist independently of whether the company uses a VPN, and a VPN doesn't substitute for broader data-handling compliance if a business has obligations under that Act. Remote workers connecting to an employer's systems through a company-provisioned VPN are typically operating under their employer's own security and compliance policies rather than making an independent choice about provider or logging policy the way an individual consumer does — worth checking with your employer's IT or security team if a work VPN's specific configuration or provider matters to you, rather than assuming it works the same way a personal consumer VPN subscription does.
Does Australia's online safety regulator have any powers relevant to VPN users?
Australia's eSafety Commissioner, established under the Online Safety Act 2021, holds powers to order the removal of certain categories of harmful online content — such as cyberbullying material targeting a child, image-based abuse, or content depicting abhorrent violent conduct — and, in some circumstances, to seek the blocking of access to material assessed as seriously harmful. This is a content-regulation framework aimed at specific categories of harmful material and the platforms hosting it, not a VPN-specific law, and it doesn't change the legal status of VPN software or ordinary VPN use in any way covered elsewhere in this guide.
Where it becomes tangentially relevant to a VPN user is the same general pattern already discussed for the copyright site-blocking scheme: if a specific piece of content or a specific site becomes subject to a removal or blocking action under this framework, a VPN could technically be used to attempt to route around an ISP-level block, in the same technical sense described earlier in this guide. That doesn't change the underlying legal status of the content itself, and material that's unlawful to possess, create, or distribute under Australian law — separate from any blocking order — doesn't become lawful because it was reached through a VPN. This framework is genuinely a different topic from the data retention scheme this guide is centrally about, and it's included here only because "online content law in Australia" and "VPN legality in Australia" are adjacent enough topics that it's worth being clear about which one a specific rule belongs to, rather than blending them together.
Practical takeaway
Is a VPN legal in Australia? Yes, plainly and without qualification — there is no law against using one. The thing actually worth understanding is Australia's mandatory data retention scheme: a 2015 law that requires Australian telcos and ISPs to retain two years of connection metadata — who, when, and how long, but not browsing content or specific websites visited — and makes that metadata available to authorized government agencies through a defined process. That obligation lands on your Australian internet provider, not on VPN companies, most of which are based outside Australia and fall outside the scheme's reach. Using a VPN changes what your ISP's retained metadata can reveal, by substituting the VPN server's IP address for the destination sites you actually visit, but it doesn't erase logging altogether — it shifts the point of visibility to the VPN provider itself, which is exactly why that provider's own logging policy, jurisdiction, and independent audit history are the things worth actually evaluating, rather than assuming Australian law alone settles the question.
Frequently asked questions
Is it illegal to use a VPN in Australia?
No. There is no Australian law banning VPN software or restricting its use for ordinary purposes such as privacy, security on public Wi-Fi, remote work, or accessing region-specific content. Using a VPN does not, by itself, break any Australian law.
What is Australia's data retention law?
The Telecommunications (Interception and Access) Amendment (Data Retention) Act 2015 requires Australian telecommunications carriers and internet service providers to retain certain connection metadata — such as subscriber details, source and destination IP addresses, timestamps, and connection duration — for two years, and to make it available to authorized government agencies. It does not require retention of the content of communications or a record of the specific websites visited.
Does Australia's data retention law apply to VPN providers?
Generally, no. The obligation applies to entities meeting the legal definition of a "carriage service provider" — broadly, companies supplying phone or internet access to the public in Australia, such as telcos and ISPs. Most consumer VPN companies are not carriage service providers and are typically headquartered outside Australia, which puts them outside the scheme's direct reach. Your own Australian ISP remains bound by the law regardless of whether you use a VPN.
If my ISP still has to retain data, does a VPN actually do anything under this law?
Yes, but it's worth being precise about what changes. Your ISP still logs that your device connected to something, when, and for how long — but with a VPN active, the destination recorded is the VPN server's IP address rather than the specific websites you visited. Your VPN provider, not your ISP, is then the party with visibility into your actual browsing, which is why that provider's own logging policy and jurisdiction become the more important factor to evaluate.
Is it illegal to use a VPN to access geo-restricted streaming content in Australia?
No. Australian government officials have previously and publicly stated that using a VPN to access geo-restricted overseas content, such as a different regional Netflix library, does not breach Australian copyright law. Individual streaming services may still prohibit this in their own terms of service and block known VPN server IP ranges to enforce it, but that's a private contractual and technical matter, not a legal one.
Can using a VPN help me get around Australia's website-blocking orders for piracy sites?
Technically, often yes, since a VPN routes traffic through a server outside the blocking ISP's network. Using a VPN to reach a site blocked under an Australian court order isn't, by itself, a separate offense under the blocking scheme, which is directed at ISPs rather than individual users. However, using a VPN doesn't change the underlying copyright status of any content you access — if downloading or distributing that content would otherwise infringe copyright, it still does.