Momentum SpaceAn antivirus knowledge base for Australian readers

In practice · Entry 5

Scanning and privacy

A scanner is the program with the deepest access to a device. What it reads, what leaves the machine, and how Australian privacy law applies to the organisation receiving it.

Part of the Momentum Space knowledge base · Last reviewed 22 September 2026

Short answer

Security software necessarily reads everything on a device. Most of that stays local, but file hashes, metadata, visited addresses and sometimes whole files are sent to the vendor. If the vendor handles the personal information of Australians, the Privacy Act 1988 and the Australian Privacy Principles are the framework, and the vendor's privacy policy is the document that states what it actually does.

The access a scanner requires

To do its job, an antivirus product needs to read every file it might be asked to judge, observe processes as they run, and often inspect network connections. On Windows that means kernel-level components; on macOS it means full disk access and an approved system extension; on Android it means broad file and application permissions. There is no version of the job that requires less.

This is a reasonable requirement and also a significant one. It means the product can, in principle, read documents, photographs, saved messages and browsing activity. The question for a buyer is not whether the software can see these things, since it must, but what the vendor does with what it sees, how long that is kept, and who else receives it.

What typically leaves the device

Products differ, and a vendor's privacy policy is the authority for its own product. The categories below are the ones that commonly appear.

File hashes and metadata
A hash is a short fingerprint calculated from a file's contents. It does not reveal what is inside the file, but it does identify that exact file, so it can show that a device holds a copy of something specific. Sent alongside it: file name, size, path, digital signature details and where the file came from.
Whole files
Some products upload files that look suspicious but cannot be classified locally, so the vendor can analyse them. This is the category with the greatest privacy weight, because a document mistakenly judged suspicious is a document sent to a third party. Products usually offer a setting controlling it, and it is worth finding.
Web addresses
Where a product filters browsing, addresses or shortened representations of them are checked against the vendor's lists. A full browsing history and a stream of individually checked addresses are not far apart in what they reveal.
Device and account information
Operating system version, hardware identifiers, installed application inventory, licence and account details, and an IP address, which indicates approximate location.
Detection telemetry
Records of what was detected, when and on which device, forming the vendor's view of what is circulating.

How detection works explains why the cloud lookups exist: a purely local engine is weaker, because it cannot draw on what is being seen across every other installation. The privacy cost is the price of that benefit, which makes it a trade to understand rather than a flaw to eliminate.

The Australian framework

The Office of the Australian Information Commissioner is Australia's privacy regulator. It administers the Privacy Act 1988 (Cth) and publishes the Australian Privacy Principles, the thirteen principles that govern how covered organisations handle personal information. The OAIC's own publications are the accurate source for what the principles require, and the points below are the ones most often relevant to security software rather than a summary of the whole scheme.

  • Openness. A covered organisation must have a clearly expressed and up-to-date privacy policy describing how it manages personal information. A vendor without one, or with one that describes a different product, is telling you something.
  • Collection limits. Personal information should be collected only where reasonably necessary for the organisation's functions, and by lawful and fair means.
  • Notification. People should be made aware of the collection and of the matters the principles require, at or before the time it happens.
  • Cross-border disclosure. Sending personal information overseas carries obligations, described in the eighth principle. Security vendors are frequently based outside Australia and operate global analysis infrastructure, so this applies routinely rather than exceptionally.
  • Access and correction. Individuals can generally ask what an organisation holds about them and ask for corrections.
  • Notifiable Data Breaches. The OAIC administers a scheme requiring notification of eligible data breaches likely to result in serious harm.

Not every organisation is covered, and the coverage of small businesses in particular has exceptions. The OAIC's site sets out who the Act applies to; this entry does not attempt to determine that for any particular vendor.

Reading a vendor's privacy policy in ten minutes

A privacy policy is a long document written for lawyers, but a small number of passages carry most of the meaning. These questions locate them.

  1. Does it name the product? A group-wide policy covering a website, an app and several services may say little specific about the scanner.
  2. What does it say about files? Search for "sample", "submit" and "upload". The answer to whether files are sent for analysis, and whether that can be turned off, is usually in that paragraph.
  3. What does it say about browsing? Search for "URL" and "web". Address checking is frequently described separately from everything else.
  4. Who else receives it? Look for the list of recipients or service providers, and for whether any of it is used for advertising or shared with analytics partners.
  5. How long is it kept? A stated period is meaningful. "As long as necessary", with nothing further, is not.
  6. Where is it processed? Named countries or regions, which is the paragraph that matters for cross-border disclosure.
  7. What can you turn off? Whether the settings described actually exist in the product is something to check in the application itself.

Free products deserve the question asked twice

Software with deep device access and no purchase price is paid for somehow. That may be a legitimate arrangement — a free tier promoting a paid one, or a vendor funded by business customers. It may also be data. The policy is where the answer is, and a free product whose policy describes sharing with advertising or analytics partners is answering it.

Shared, family and workplace devices

Security software installed by one person on a device used by another creates a second set of questions. A parental control feature that reports browsing is a monitoring tool, and its use on a teenager's phone, a partner's laptop or a staff member's device raises considerations that are not technical. The eSafety Commissioner publishes guidance on monitoring and on situations where a device may be watched by someone the owner knows, including advice for people who suspect this is happening to them.

The distinction worth holding onto: a scanner that identifies malicious files is protective, and a feature that reports one adult's activity to another is monitoring. They are sold in the same bundle and they are not the same thing. Malware types, defined covers stalkerware, which is the same capability without consent.

If something goes wrong

The route for a privacy complaint in Australia is sequential, and skipping the first step usually delays the outcome. Contact the organisation directly and give it a reasonable opportunity to respond — the OAIC generally expects this to have happened. If the response is unsatisfactory or none arrives, a complaint can be made to the OAIC, which sets out the process and time expectations on its site. Where a data breach is involved, the same site describes the Notifiable Data Breaches scheme and what an affected individual can expect to be told.

For a suspected compromise of a device or an account, the Australian Cyber Security Centre publishes step-by-step recovery guidance and operates the reporting route for cybercrime, and Scamwatch is where scams are reported. These are separate routes for separate problems, and using the right one matters more than using all of them.

What this site collects

For completeness, since this entry asks readers to hold vendors to a standard: Momentum Space collects nothing. There is no form on any page, no analytics, no advertising tag and no cookie of any kind, so no consent banner appears — there would be nothing to consent to. The hosting provider keeps ordinary server logs, and a web font request reaches Google. That is the complete list, and it is set out in the privacy policy and the cookie policy.