Article

New rules of engagement: Australia's draft privacy bill and what it means for your business

New rules of engagement: Australia's draft privacy bill and what it means for your business
Published Date
Sep 4, 2026
Related people
Image of Anna Gamvros
Anna GamvrosPartner, Sydney
Photo of Elise Northcote
Elise NorthcoteLawyer, Sydney
Australia's privacy framework is about to undergo its most significant transformation in nearly four decades. On August 31, 2026, Attorney-General Michelle Rowland released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 (the Bill), together with a consultation paper (the Consultation Paper). 
Summary

Existing collection, use and disclosure obligations (APPs 3, 4 and 6) are replaced with a new framework centred on a "fair and reasonable" test assessed against seven legislated factors, complemented by separate consent requirements for collecting sensitive information and trading personal information.

Core definitions are overhauled, including “personal information,” “sensitive information,” “consent,” “collection,” “disclosure” and “de-identification.” A new concept of “trading” is introduced, requiring consent to disclose personal information for money, consideration or direct marketing purposes.

Entities must notify the Office of the Australian Information Commissioner (OAIC) of eligible data breaches within 72 hours. New positive obligations require breach response systems and harm mitigation for all data breaches.

A right of erasure applies to large digital platforms—that is, organisations providing qualifying Online Safety Act services that meet at least one of two thresholds: AUD500 million in business group gross revenue or 2.5 million average monthly end users in Australia. A statutory controller/processor framework allocates primary compliance responsibility to controllers.

Several previously foreshadowed reforms are absent, including removal of the small business and employee records exemptions, a direct right of action, and mandatory

The proposed changes go well beyond the incremental updates of recent years. From a new “fair and reasonable” test governing all handling of personal information, to the introduction of a controller-processor distinction and a right of erasure, the Bill signals that Australia is finally moving to align its privacy laws with the expectations of a modern digital economy. The Bill is open for public consultation and submissions close on September 18, 2026.

The Bill represents the second—and far more ambitious—tranche of reforms to the Privacy Act 1988 (Cth) (the Privacy Act). The first tranche, legislated in late 2024, laid important groundwork: a statutory tort for serious invasions of privacy, mandatory privacy policy disclosures on automated decision-making, a Children's Online Privacy Code and enhanced OAIC enforcement powers. 

But Tranche 1 addressed only a fraction of the 116 proposals in the Privacy Act Review Report (the Review Report), released in February 2023, to which the Government Response of September 2023 agreed or agreed in principle with 106. Tranche 2 picks up where that process left off and raises the bar considerably.

The key proposals and what is not in the Bill is discussed below.

Updated definitions

Before turning to the new obligations, it is worth understanding how the Bill redraws the definitional boundaries. Schedule 1 updates core Privacy Act definitions in ways that will significantly expand the scope of information and activities caught by the regime. The table below sets out the key changes.

ConceptCurrent positionProposed changePractical impact
Personal information
Information "about" an identified or reasonably identifiable individual.
Replaced with information that "relates to" an identified or reasonably identifiable individual. A new definition of "reasonably identifiable" is introduced: an individual is reasonably identifiable if they could be identified by combining the information with other reasonably available information. A note clarifies that identification does not require knowledge of an individual's name or legal identity.
Broadens the Act's reach. Pseudonyms, device identifiers, location data and behavioural patterns may now fall within scope. Entities using cookies, tracking technologies or similar identifiers will need to treat these as personal information.

Sensitive information

Includes racial/ethnic origin, political opinions, health information, biometric data and other prescribed categories.
Expanded to include precise geolocation tracking data (location within 500 metres, tracked over time, generated by a device or technology) and genomic information.
Geolocation data collected through mobile devices and wearables will attract the higher protections applicable to sensitive information, including a consent requirement for collection
Consent
Must be voluntary, informed, specific and unambiguous (per OAIC guidance, not legislated).
Legislated for the first time: consent must be voluntary, informed, current, specific and unambiguous. May be express or implied, but implied consent must be clearly inferable from conduct and context.
Bundled consents, pre-ticked boxes and broad permissions are unlikely to satisfy the new standard.
Collection
Information "collected" when obtained from any source, per OAIC guidance.
An entity collects personal information when it includes information in a record or generally available publication, regardless of source or means. Expressly covers generated, derived and inferred information. New timing rules govern when derived sensitive information is taken to be collected.
Catches information derived through AI, data analytics and similar processes. Entities will not be taken to collect sensitive information merely because the personal information they hold could reveal a sensitive attribute (e.g. a photo showing religious dress); the trigger is when the entity actually uses or records the derived information.
Disclosure
Not defined in the Act.
An entity discloses personal information when it makes the information accessible to another person or body. Transmission or storage (including overseas) does not amount to disclosure unless the information is made accessible to a third party.
Provides a clearer line between use (internal access) and disclosure (external access). Overseas hosting alone will not constitute a disclosure.
De-identification
Information is "de-identified" if it is no longer about an identifiable individual.
Recast as contextual: information is de-identified at a particular time if, in those circumstances, it no longer relates to an identified or reasonably identifiable individual.
De-identification can degrade over time, so entities holding de-identified or pseudonymised datasets must reassess re-identification risk on an ongoing basis.
Traders
Not defined in the Act.
New concept: disclosure of personal information for money or other consideration, or for direct marketing purposes. Consent required unless an exception applies. Four carve-outs: (1) disclosures to the recipient for the purpose of providing a product or service the individual requested; (2) disclosures incidental to a business transfer; (3) disclosures by a controller to a processor acting on documented instructions; and (4) disclosures necessary for prevention, detection, investigation or remedying of unlawful activity or serious fraud-related wrongdoing.
Businesses that monetise customer data through brokerage, list-sharing, advertising partnerships or programmatic advertising will need consent unless a carve-out applies.

Fair and reasonable test

Perhaps the most consequential change in the Bill is the consolidation of APPs 3, 4 and 6 into a new APP 3, which imposes a single overarching obligation: all collection, use and disclosure of personal information must be fair and reasonable in the circumstances, and lawful. Organisations will need to assess each data handling activity against this test, regardless of whether consent has been obtained.

Seven legislated factors guide the assessment:

  1. The reasonable expectations of the individual
  2. The relationship of the handling to the entity's functions or activities
  3. The transparency of the handling
  4. Data minimisation (whether the purpose could be met by handling less information, or non-personal information)
  5. Whether the individual has genuine choice
  6. The impact on the individual's privacy and any risk of harm, including proportionality
  7. Where the individual is a child, the best interests of the child as a primary consideration

No single factor is determinative. The Consultation Paper describes this as a holistic assessment, and the OAIC will issue guidance with practical examples. Exceptions apply where the handling is required or authorised by law, or where a permitted general or health situation exists.

The familiar primary/secondary purpose distinction falls away as a standalone requirement, with purpose limitation now embedded in the legislated factors (particularly reasonable expectations, transparency and genuine choice). A use or disclosure for a purpose arising after collection is less likely to pass the test if it falls outside what a reasonable person would expect, lacks transparency, or occurs without genuine choice.

Organisations that have relied on broad secondary purpose justifications or deemed consent should reassess those practices; behavioural advertising, audience profiling and repurposing data beyond its original collection context are likely to face the closest examination. There will be a bedding-in period while the boundaries of the test are established, so keeping a clear record of the reasoning behind key data handling decisions will matter if a complaint or regulatory inquiry follows.

Consent, exceptions and collection notices

Consent is expressly required for collecting sensitive information and for trading in personal information. Where consent is required, it must be voluntary, informed, current, specific and unambiguous. For everything else, the fair and reasonable test applies.

Two new exceptions to the sensitive information consent requirement are introduced: collection from a "publicly available document" (broadly defined to include any document accessible to the general public, even behind a fee or registration wall), and collection that is "strictly necessary" to provide a requested good or service (the Consultation Paper explains this is intended to apply only where a less privacy-intrusive alternative is not available).

Where a child is involved, the good or service must be directed at protecting the child from neglect or harm, or supporting their wellbeing. The "strictly necessary" exception does not extend to direct marketing; the publicly available document exception contains no such express exclusion, though the collection must still be fair and reasonable.

Collection notices under new APP 5 need only cover the fact and circumstances of collection and the purposes for use or disclosure, and must be clear, plain, concise and up to date. The Consultation Paper warns against notices that are "excessive, vague, ambiguous, or include irrelevant information that may obscure key matters." Getting these right will be a cross-functional exercise, drawing on privacy, communications and design expertise.

Data breach notification

The Bill introduces a hard 72-hour deadline for notifying the OAIC of an eligible data breach (one likely to result in serious harm), replacing the current "as soon as practicable" standard. The clock starts when an entity becomes aware of reasonable grounds to believe a breach has occurred, aligning with timeframes under the Security of Critical Infrastructure Act 2018 (Cth) and the Cyber Security Act 2024 (Cth).

Organisations that lack a well-rehearsed breach playbook, including staged notification protocols and template statements, may find themselves scrambling. Entities may file an incomplete statement within 72 hours (with written notice of what is missing and why), with the balance to follow as soon as practicable. Statements must also cover steps taken or proposed in response to the breach.

Three pathways for notifying individuals are retained (all affected individuals, those at risk of serious harm, or public notification). The 30-day assessment period for suspected breaches is preserved. Two new obligations also apply to all data breaches, not just eligible ones: entities must maintain effective breach response systems, and must take reasonable steps to prevent or reduce harm as soon as practicable. Non-compliance is an interference with privacy.

Security and destruction

APP 11 is restructured. On top of the existing security obligation, entities must now:

  • actively consider whether information no longer needed should be destroyed, and take reasonable steps to destroy or de-identify it
  • identify the personal information their obligations cover and
  • regularly evaluate whether their compliance measures are effective.

The Consultation Paper stresses that de-identified form still carries re-identification risk and should not be the default. Organisations collecting health information for research in a permitted health situation must also de-identify it before disclosure (new subsection 16B(2A)). In practice, this calls for a clear picture of what data is held and why, disciplined retention and deletion workflows, ongoing re-identification risk assessment, and regular review of security controls.

Right to erasure for large digital platforms

Individuals will be able to request that large digital platforms (LDPs) destroy their personal information. An LDP is an organisation providing a social media service, relevant electronic service or designated internet service (each per the Online Safety Act 2021 (Cth)) that meets one or both of two thresholds:

business group gross revenue of at least AUD500m, or at least 2.5 million average monthly end users in Australia.

Organisations may also be prescribed as LDPs by regulation. LDPs can refuse requests that are frivolous or vexatious, where retention is required by law, destruction is technically impossible or infeasible despite reasonable steps, or the information is strictly necessary to provide a service the individual requested. Information held solely in a processor capacity is excluded.

This is narrower than the Review Report envisaged, which had proposed erasure against all APP entities with third-party notification obligations. It puts Australia on a different footing from the UK and EU, where erasure rights apply to all data controllers. There is also an open question around AI: if personal information has been absorbed into a trained model, it is unclear whether removing the source data would suffice or whether derived outputs would also need to be addressed.

Controller and processor framework

The Bill formalises a controller/processor distinction. Under new section 16D, a processor is an APP entity that handles personal information on behalf of another APP entity (the controller) under documented written instructions. Both must be APP entities; contracted service providers for Commonwealth contracts are excluded. Where a processor acts within instructions, its acts do not breach the APPs (other than APP 1 and APP 11) but are deemed acts of the controller, and the controller bears responsibility for any breach. If a processor acts outside instructions, it bears full APP compliance responsibility.

Instructions need not prescribe the technical or operational means of processing, though processors may prefer prescriptive instructions to preserve the compliance exception. For processors, this should meaningfully reduce the compliance load; for controllers, it will demand strong governance. Key practical steps include:

  • identifying and formally documenting each controller/processor relationship
  • keeping clear written records of the instructions given to each processor
  • making sure contractual terms properly allocate privacy risk and
  • reviewing whether any arrangement could amount to a "trade" (for example, where data is shared for payment or other value), which would trigger a consent requirement.

Existing data processing agreements and outsourcing arrangements will need review and, in many cases, renegotiation.

Direct marketing

Existing APP 7 is replaced with a simplified, technology-neutral framework. Direct marketing covers any advertising or marketing material directed to an individual selected, identified or targeted using their personal information, including programmatic advertising, online behavioural advertising, targeted social media campaigns and audience segmentation.

Organisations must include a simple opt-out in each communication and action opt-out requests. Ad-supported services may offer different terms to individuals who opt out, provided the individual retains a genuine choice to use the service without direct marketing.

Where communications are already regulated by the Spam Act 2003 (Cth), the Do Not Call Register Act 2006 (Cth) or other prescribed legislation, the new APP 7 obligations do not apply, but the fair and reasonable test and trading consent requirements still govern the underlying data handling. Consent is not required for direct marketing itself, but is required to trade personal information for that purpose. Where advertising is delivered through a third-party platform, the platform will ordinarily bear opt-out responsibility unless acting purely as a processor; advertisers should confirm the platform's opt-out functionality meets the new requirements.

Other changes

  • The existing patchwork of health and medical research exceptions is replaced with a single exception for "human research" (research conducted with or about individuals that involves personal information). Research must be reviewed, approved and monitored in accordance with the National Statement on Ethical Conduct in Human Research and comply with guidelines to be issued by the privacy commissioner. The exception will not commence until those guidelines are in place.
  • Permitted General Situation Item 2 (PGS 2) is amended by replacing "misconduct of a serious nature" with "wrongdoing of a serious nature," broadening the provision to cover wrongdoing in a private capacity (such as exploitation of a customer's vulnerability or misuse of an enduring power of attorney).
  • A new exception to the access obligation in APP 12 applies where, despite taking reasonable steps, access remains unreasonable or impracticable due to technical impossibility or infeasibility. An entity cannot design systems that deliberately avoid access obligations and then invoke the exception.

What is not in the Bill

The Consultation Paper flags seven additional measures to strengthen the OAIC's powers, but no draft provisions are included. These would require entities to respond to complaints within 60 days and provide written decisions, with individuals generally required to raise concerns with the entity first. The commissioner would gain powers to group representative complaints, compel reasonable assistance in investigations, and assess social media platforms' handling of personal information for age-assurance purposes under the Online Safety Act's minimum age scheme.

The proposals would also clarify the OAIC's ability to report to ministers on ongoing investigations, replace the "reasonable excuse" defence for information-gathering notices with defined defences, and classify breaches of complaint-handling requirements as an interference with privacy. The Consultation Paper also invites feedback on whether the Bill's technology-neutral approach adequately addresses risks from emerging technologies, including smart glasses and connected vehicles.

Beyond these OAIC measures, several Review Report recommendations that the government agreed or agreed in principle to remain unaddressed:

  • The small business exemption (the AUD3m turnover threshold remains)
  • The employee records exemption
  • A universal right of erasure (the right is limited to LDPs)
  • Mandatory privacy impact assessments for high-risk data processing
  • A direct right of action for Privacy Act breaches (the only private cause of action remains the statutory tort for serious invasions of privacy)
  • Specific prohibitions on direct marketing to children and trading in children's personal information (proposals 20.5–20.7 of the Review Report)
  • Organisational accountability requirements, including a mandatory senior privacy officer;
  • actual prescription of whitelisted countries and standard contractual clauses for overseas data transfers (the enabling mechanism was introduced in Tranche 1, but the substance has not yet been settled)
  • The right to de-index search results or object to handling of personal information

The Bill's commencement table is blank, and further consequential amendments and transitional provisions are yet to be settled, making it hard for organisations to plan implementation timelines.

What to do now

The scope of the proposed reforms is clear enough for organisations to begin preparing. The consultation period closes on September 18, 2026, and the department has asked that submissions be concise (approximately 1,000 words).

Priority steps include:

  • mapping current collection, use and disclosure practices against the seven fair and reasonable factors, focusing on areas where reliance on broad secondary purpose justifications or bundled consents may not hold up
  • reviewing consent mechanisms across digital and offline channels against the heightened standard
  • conducting a data inventory to determine what personal information is held, whether it is still needed, and whether sensitive information is being derived from other data
  • stress-testing incident response plans against the 72-hour notification deadline and
  • assessing AI and emerging technology deployments against the broadened definitions of personal information, sensitive information and collection.

Once enacted, organisations will need to:

  • revise privacy policies and collection notices
  • redesign consent flows
  • reconfigure breach response plans
  • formalise controller/processor arrangements
  • build erasure request workflows (for LDPs), and
  • embed ongoing security evaluation under APP 11.

Organisations with meaningful privacy exposure should engage with the consultation, particularly on measures still under development and transitional provisions.

 

Related capabilities