Invested in Client Success

Icon

Australia’s second wave of Privacy Act reforms: significant new obligations proposed for businesses

Banner
Donna Short
Donna Short
Partner
Cate Sendall
Cate Sendall
Special Counsel
Cindy Phan
Graduate

On 31 August 2026, the Attorney-General’s Department released a consultation package and exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 (Cth) (Bill), proposing the next major phase of reforms to Australia’s privacy framework.

The proposed reforms build on the changes introduced by the Privacy and Other Legislation Amendment Act 2024 (Cth), which enhanced the Office of the Australian Information Commissioner’s (OAIC) powers, introduced a statutory tort for serious invasions of privacy and established a Children’s Online Privacy Code.

The consultation is open until 18 September 20261.

The Bill represents a significant shift in Australia’s privacy regime. Rather than relying on increasingly complex collection, use and disclosure rules, the Bill introduces a broader data protection framework focused on whether personal information is handled in a way that is fair and reasonable in the circumstances. The reforms are accompanied by strengthened consent requirements, expanded data security obligations, a right to be forgotten and enhanced accountability measures.

A summary of the key reforms and likely impacts on businesses are set out below.

A new “fair and reasonable” test

At the center of the reform package is a new Australian Privacy Principle (APP) 3 requiring organisations to ensure that their collection, use and disclosure of personal information is both fair and reasonable in the circumstances and lawful. The new test would replace many of the existing collection, use and disclosure requirements.

Whether handling is fair and reasonable would require organisations to consider a broader range of factors, including:

  • whether a reasonable person would expect the information handling;
  • the connection between the entity’s functions or activities and its handling of personal information;
  • transparency regarding the purpose and method of collection, use and disclosure;
  • whether less personal information could be used (ie data minimization);
  • whether individuals have genuine choice;
  • privacy impacts, risks of harm and proportionality; and
  • for children, whether their best interests have been treated as a primary consideration.

This represents a substantial shift away from a compliance model focused primarily on notices and consent toward a broader assessment of whether information handling practices can be objectively justified.

Expanded definitions and stronger consent requirements

The Bill would modernise core Privacy Act definitions to better reflect contemporary data practices. In particular:

  • “personal information” would be expanded to capture information that relates to an identified or reasonably identifiable individual (which may include AI inferences);
  • a new definition of “reasonably identifiable” would be introduced;
  • a new definition of “precise geolocation tracking data” would be introduced which is personal information generated by a device or technology which identifies an individual’s location within a radius of 500 metres and is collected/held by reference to the location of an individual over time;
  • “sensitive information” would be expanded to include precise geolocation tracking data and genomic information (which means that consent will ordinarily be required to be provided before this information can be collected); and
  • “consent” would be expressly defined as requiring consent to be voluntary, informed, current, specific and unambiguous.

The introduction of a statutory consent standard will require organisations to reassess existing consent mechanisms, particularly where consent is bundled, implied through pre-ticked settings or obtained through complex user interfaces.

The reforms will have significant implications for organisations using location-based services, behavioural tracking technologies and emerging AI-enabled products.

Consent required to “trade” personal information

One of the more significant proposals is a new requirement that organisations obtain consent before they “trade” personal information. The concept of trading is defined broadly and would include disclosures made for consideration as well as disclosures for direct marketing purposes, subject to a limited range of exceptions.

The Consultation Paper indicates that disclosures supporting digital advertising systems, including certain cookie and pixel-based advertising arrangements, may fall within the concept of trading personal information. As a result, organisations involved in behavioural advertising, audience targeting, data sharing arrangements and digital marketing partnerships may face increased compliance obligations.

New direct marketing framework

The Bill would replace the existing direct marketing provisions in APP 7 with a simplified framework centered on opt-out rights. Organisations would be required to:

  • provide a simple means for individuals to opt out of direct marketing;
  • action opt-out requests through reasonable steps; and
  • ensure communications explain how individuals can unsubscribe.

Importantly, the proposed definition of direct marketing is intentionally technology-neutral and expressly extends to targeted online advertising and marketing based on personal information. The Consultation Paper confirms that the reforms are intended to capture both individual targeting and broader audience segmentation practices used in contemporary advertising models.

Stronger data security and breach response obligations

The reforms would significantly strengthen Australia’s notifiable data breach regime.

Entities would be required to implement practices, procedures and systems designed to ensure effective responses to actual and suspected data breaches and to take reasonable steps to mitigate harm as soon as they become aware of a potential breach. Failure to comply would constitute an interference with privacy.

The Bill also introduces a new requirement to notify the Information Commissioner within 72 hours after becoming aware of reasonable grounds to believe an eligible data breach has occurred. Organisations would also be required to notify affected individuals (or individuals at risk of serious harm) of the eligible data breach, at the same time as notifying the Information Commissioner where practicable, or otherwise as soon as practicable thereafter. Additional reporting obligations would apply where information subsequently changes or becomes available.

In addition to notification of breaches, entities would be required to:

  • identify personal information they hold;
  • actively consider destruction where information is no longer required;
  • regularly evaluate security controls; and
  • continually assess re-identification risks where information has been de-identified rather than destroyed.

A right to be forgotten

The Bill would introduce a new right allowing individuals to request erasure of personal information held by large digital platforms (LDPs). The obligation would apply to organisations providing online platform services that satisfy prescribed revenue or user thresholds, including organisations with annual business group revenue of at least $500 million or at least 2.5 million average monthly end users in Australia.

The right is not absolute. Exceptions would apply where information must be retained by law, where erasure is technically impossible or infeasible, where the information is necessary to continue providing a requested service, or where public interest exceptions apply.

The proposal reflects a broader international trend toward greater individual control over personal information and is likely to require substantial investment in data governance and deletion capabilities for affected platforms.

Exception for information processors

The Bill would introduce GDPR-style concepts of “controller” and “processor”. Where the processor is handling personal information on behalf of the controller, the processor will not breach the APPs (except for APP 1 and APP 11) provided that the processor is acting in accordance with the controller’s documented instructions. Where the processor does not act in accordance with those instructions, the processor will be directly responsible for complying with the APPs.

Emerging technologies such as AI and smart glasses

The Privacy Act and APPs have been drafted to be technology-neutral. The rise of AI and privacy concerns with the use of smart glasses have received considerable recent media attention. The Bill does not address these matters specifically. The Government considers that various proposed amendments will improve transparency and individuals’ control over their personal information, as well as address emerging technology privacy risks, for example, requiring meaningful consent (including where precise geolocation data is being collected) and information handling to be fair and reasonable in the circumstances. Feedback is being sought on whether the various reform proposals are adequate to address the privacy risks posed by emerging technologies.

Looking ahead

While these reforms remain subject to consultation (which closes on 18 September), they represent one of the most substantial overhauls of Australia’s privacy regime since the Privacy Act commenced. Organisations should begin assessing how the proposed reforms would apply to existing data practices (including notification and consent processes), particularly where personal information is used for digital marketing, behavioural analytics, AI-enabled systems or large-scale data processing.

If enacted, the reforms would move Australian privacy law beyond a compliance model centered on privacy policies and consent notices, and toward a framework focused on accountability, proportionality and responsible data handling that can be demonstrated and justified.

Please contact a member of Addisons’ Privacy & Data Protection team for more information.

Liability limited by a scheme approved under Professional Standards Legislation.


© ADDISONS. No part of this document may in any form or by any means be reproduced, stored in a retrieval system or transmitted without prior written consent. This document is for general information only and cannot be relied upon as legal advice.

Related Insights