
The Australian Government has released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 (the Exposure Draft) which, if enacted in its current form, will put in place a range of very significant reforms to the Australian Privacy Act 1988 (Cth) (Privacy Act) that are likely to have a considerable impact on personal information handling practices. Submissions can be made in relation to the Exposure Draft until 18 September 2026.
The Exposure Draft includes some of the long-anticipated "second tranche" of privacy reforms, following the first tranche enacted by the Privacy and Other Legislation Amendment Act 2024 (Cth) (Amendment Act). It also includes some new changes, including overhauling certain Australian Privacy Principles (APPs) in a manner aligned with the Productivity Commission’s recommendations in its 2025 report on Harnessing data and digital technology.
Key obligations proposed in the Exposure Draft include a requirement that all collection, use and disclosure be “fair and reasonable”, additional restrictions on direct marketing, a requirement to take into account the best interests of children when applying the “fair and reasonable” standard in relation to personal information about children, and a 72-hour timeframe for notification of eligible data breaches.
The introduction of controller and processor provisions is likely to be good news for many suppliers, particularly technology providers, who process personal information as part of the products and services they provide to other entities.
It is important for entities to start assessing the proposed changes and their impacts to ensure that they can address any major issues in submissions and can comply with the amended laws when they take effect. The proposed commencement date for the legislation has not yet been published, which means that the amount of time available for entities to prepare for the changes is not yet known.
The reforms aim to bolster privacy protections for Australians and address emerging risks from new technologies, including artificial intelligence and wearable devices such as smart glasses. A Privacy Reform Consultation Paper (the Consultation Paper) released with the Exposure Draft seeks views as to whether the reforms proposed adequately address those risks.
This article provides an overview of the Exposure Draft's key proposals, sets them in the context of the broader reform process, and identifies some of the most significant practical implications for organisations subject to the Privacy Act.
Background: the reform journey
Australia's privacy reform program has been underway for several years. Following the ACCC's 2017 to 2019 Digital Platforms Inquiry and related subsequent ACCC inquiries, the Attorney-General's Department undertook an extensive review of the Privacy Act, culminating in the Privacy Act Review Report released in February 2023, which contained 116 recommendations for reform. The Government's Response in September 2023 agreed or agreed in principle with 106 of those 116 proposals.
The first tranche of reforms was legislated in the Amendment Act, which addressed 23 proposals from the Government Response. Key measures in that first tranche included:
- a new statutory tort for serious invasions of privacy, which commenced on 10 June 2025 as Schedule 2 of the Privacy Act;
- a requirement for disclosures in privacy policies in relation to certain automated decision-making (which commences on 10 December 2026);
- provision for a new Children's Online Privacy Code, to be developed and registered by the Office of the Australian Information Commissioner (OAIC) by 10 December 2026;
- a "whitelisting" mechanism for overseas data transfers to prescribed countries; and
- clarification that reasonable steps under APP 11 include technical and organisational measures; and
- new tiered penalties and infringement notices for less serious breaches.
However, many of the most significant reforms were deferred to what has become known as the second tranche of privacy reforms.
Practical implications for entities
The Exposure Draft, if enacted in its current form, will require organisations to undertake significant compliance work. Key compliance steps once the Exposure Draft has been finalised and has become law are likely to include:
- data mapping and classification: the expanded definition of "personal information" will likely bring more data within scope, particularly technical identifiers and adtech data. It will also be important for entities to ensure that all personal information is covered by their security and destruction or de-identification arrangements;
- review of data handling practices against the fair and reasonable test: entities should assess whether their current collection, use and disclosure practices would meet the new ‘fair and reasonable’ standard. There will be some uncertainty as to how the test will apply during the initial implementation period. Documentation of the basis for an entity’s view that a practice is fair and reasonable may assist in the event of any later complaint or investigation;
- review of consent mechanisms: current consent frameworks will need to be reviewed against the proposed five requirements for valid consents to be voluntary, informed, current, specific and unambiguous;
- direct marketing: organisations engaged in direct marketing should prepare for unqualified opt-out rights, primary consideration of the best interests of children as part of the ‘fair and reasonable’ test, and a consent requirement in relation to disclosure for direct marketing purposes; and
- review of agreements: entities should review their supplier agreements to take into account the new controller/processor distinction and to ensure that they contain adequate privacy clauses (including cybersecurity and data breach notification clauses). They should also consider whether any “trade” of personal information occurs under each agreement (e.g. if data is disclosed for payment or other consideration, or for direct marketing purposes), in which case consent may be required.
The changes at a glance: quick summary table
General | |
Broader definition of personal information (and clarification about ‘reasonably identifiable’) | The definition of personal information has been expanded to include any information or opinion that ‘relates to’ an identified individual or an individual who is reasonably identifiable. This is intended to capture a broader range of information than the current definition which is restricted to information or an opinion ‘about’ an individual. The accompanying note clarifies that a person may be identified or identifiable even if their name or legal identity is not known. For example, information that ‘allows an individual to be recognised, singled out, or otherwise dealt with as a distinct individual in practice’, such as pseudonyms or identifiers, is captured. Updates to the law clarify that an individual is ‘reasonably identifiable’ if they could be identified by combining information with other information that is ‘reasonably available’. |
New categories of sensitive information | ‘Genomic’ information and ‘precise geolocation tracking data’ are added to the definition of sensitive information. Precise geolocation tracking data is device- or technology-generated data that identifies an individual’s location within a radius of 500m over time (i.e. more than a single point-in-time capture). |
Five conditions of valid consent | A new provision confirms that for (express or implied) consent to be valid, it must be voluntary, informed, current, specific and unambiguous. |
Concept of personal information ‘trading’ | A number of new provisions refer to ‘trading’ in personal information. ‘Trading’ is defined broadly as disclosure for money or other consideration, or for the purposes of direct marketing. There are a number of exceptions, such as when the disclosure is in the context of providing services to the individual, incidental to M&A transactions, made by a processor in the context of providing services to a controller, and to respond to unlawful activity or wrongdoing. |
Other | The definition of a ‘publicly available document’ has been updated to include documents publicly available subject to an access barrier which can be overcome by an ordinary member of the public (e.g. paying a fee, establishing an account). |
Small business exception | |
Small business exception | Proposed drafting updates the description of which businesses with a turnover of under A$3 million cannot rely on the small business exception. In addition to the existing carve outs in relation to health services, contracted service providers to the Commonwealth and credit reporting bodies, the Privacy Act will capture:
These do not apply where a sole trader is trading or receiving their own information. |
Controller/Processor | |
Controller/Processor concepts | The proposed amendments introduce the concept of a processor, being an entity that engages in an act or practice, on behalf of another APP entity (the controller) in accordance with the controller’s instructions, which must be documented in writing. |
Processors are only liable for compliance with APP 1 and 11. | Processors are always liable for compliance with APP 1 and 11. Otherwise, acts or practices engaged in by processors on behalf of controllers, do not constitute a breach of the Privacy Act by the processor. Controllers are liable for breaches of the APPs by processors who are following the controller’s instructions. |
Fair and reasonable collection, use and disclosure | |
Definition of collection | The concept of ‘collection’ – for inclusion in a record or generally available publication – has been updated to clarify that collection occurs regardless of the source or means of collection. Where sensitive information could be derived from personal information held by an entity, it is not deemed to be collected unless the entity intends to collect sensitive information, or uses or discloses sensitive information. |
Broader definition of disclosure | The concept of ‘disclosure’ has been defined as any instance where personal information is made accessible to another person or body. This is broader than existing OAIC guidance, which refers to releasing information from an entity’s effective control. |
All collection, use and disclosure must be fair, reasonable, and lawful | APP 3 has been replaced with:
This ‘fair and reasonable test’ is a holistic assessment that requires consideration of:
As use and disclosure is subject to the overriding principle of fairness and reasonableness, APP 6 is no longer required and has been removed. |
Special rules for sensitive information and trading | The existing requirement to obtain consent to collecting sensitive information (subject to exceptions) is retained. There is a new exception where collection of sensitive information is from a publicly available document (however this is still subject to the fair and reasonable test). There is a new prohibition on trading (for money/consideration, or any direct marketing) personal information without consent, subject to limited exceptions. |
Simplified notice requirements | Collection notice requirements under APP 5 have been substantially simplified. The matters required to be addressed are:
Notices must be in clear and plain language, readily understandable, up-to-date and concise. |
Refreshed list of permitted general exceptions | At a high level, the permitted general exceptions for organisations are similar to the current exceptions, with some drafting updates and carve outs for overseas disclosure. There are new permitted general exceptions for the Immigration Department, other enforcement bodies and agencies (including to permit the disclosure of biometric information or biometric templates in accordance with OAIC guidelines). Now that relevant exceptions are housed in the ‘permitted general exceptions’, consequential amendments have been made to APPs 8 and 9. |
Direct marketing | |
Direct marketing disclosure requires consent | As set out above, there is a new prohibition on disclosure of personal information for direct marketing using personal information without consent, subject to limited exceptions. If an entity is only using personal information for direct marketing, then it is subject to the standard ‘fair and reasonable’ test. |
Direct marketing requirements clarified | The requirements for direct marketing communications to individuals (which are not otherwise subject to the Spam Act 2003 (Cth) or other marketing acts) have been restated clearly:
|
Ad supported service can be on different terms, as long as genuine choice | Where an organisation provides an ‘ad supported service’ (where subscribing to direct marketing is a source of revenue for the organisation) and an individual unsubscribes:
|
Access rights | |
Minor amendments to the access regime | The access regime has been updated so that:
|
Right of erasure (large platforms only) | |
Right to erasure applies to large digital platforms | Large digital platforms are defined as social media service, relevant electronic services or designated internet services (within the meaning of the Online Safety Act 2021 (Cth)), which are either declared by regulations or have:
|
Right to erasure requests | If an individual requests, a large digital platform must destroy the individual’s personal information. Exceptions include:
There are requirements to assess and respond to requests. |
Information security and data breaches | |
Separate concepts of ‘data breach’ and ‘eligible data breach’ | The amendments have separated out the concept of a ‘data breach’ (unauthorised access/disclosure or loss in circumstances where unauthorised access/disclosure is likely) from an ‘eligible data breach’ (where there is a likely risk of serious harm to affected individuals). A number of new obligations apply to data breaches. |
Data breach response preparation obligations | There is a new obligation on entities to take reasonable steps to implement practices, procedures and systems to effectively respond to actual or suspected data breaches, and to prevent or reduce harm to affected individuals. |
Obligation to mitigate harm | If an entity has reasonable grounds to suspect or believe that a data breach has occurred, it must, as soon as practicable, take reasonable steps to mitigate harm to affected individuals. |
Remedial exception | A data breach is not an eligible data breach if an entity takes remedial action. Updates to the ‘remedial action’ provision clarify that either:
|
72-hour notification timeframes | When an entity has reasonable grounds to believe that there has been an eligible data breach, they must notify the OAIC within 72 hours. (Entities still generally have up to 30 days to expeditiously assess a suspected data breach and determine if there are reasonable grounds to believe one has occurred.) In addition to existing statement requirements, the statement must detail the steps the entity has taken (or proposes to take) in response to the eligible data breach, including steps to mitigate harm to affected individuals. If a statement addressing the mandatory matters within 72 hours is impossible or impracticable, the entity must provide an interim notification to the OAIC and provide more complete particulars as soon as practicable. Entities must promptly update the OAIC if there is any material change to, or material errors in, information that has been provided to the OAIC. |
Notifications to individuals | Affected individuals must be notified at the same time as the OAIC (72 hours after reasonable grounds to believe the eligible data breach has occurred) or as soon as practicable after. Updates given to the OAIC must also be given to affected individuals. |
Know your information obligations | For the purposes of an entity’s information security obligations, the entity is required to take any steps needed to ensure that it can identify personal information to which its information security obligations apply. |
Regularly evaluate effectiveness | Under a new provision, entities are required to regularly evaluate the effectiveness of their compliance with their information security obligations. |
Destruction and de-identification | |
Definition of de-identified | ‘De-identified’ has been given a definition so that it refers to, ‘at a particular time, or in particular circumstances’ information that has ceased to be information that relates to an identified or reasonably identifiable individual. |
Active requirement to consider destruction | When the valid purposes for which personal information is held have expired (and if it is no longer required to be retained by law), an entity must first consider ‘whether to destroy the personal information’ before either destroying or de-identifying it. |
Know your information obligations | For the purposes of an entity’s destruction and de-identification obligations, it is required to take any steps needed to ensure that it can identify personal information to which its destruction and de-identification obligations apply. |
Human research | |
Human research compliance exception | Provided human research is undertaken in accordance with the national statement on ethical conduct in human research and the OAIC’s human research guidelines, acts or practices do not constitute a breach of the APPs. |
De-identification of health information before disclosure | If an organisation collects health information in connection with the existing permitted health situation for research, then that organisation must take reasonable steps to de-identify that information before disclosing it. |
Breach and infringement provisions | |
Revised set of APPs subject to infringement and compliance notices | Non-compliance by a large digital platform with obligations to provide notices in response to a request for deletion has been added to the list of contraventions which are subject to infringement and compliance notices. Otherwise, existing provisions in relation to direct marketing, record keeping, and non-compliance data breach notices have been redefined to reflect the updated provisions. |
Provisions which constitute a privacy breach | A number of obligations have been boosted so that a breach constitutes an ‘interference with the privacy of an individual’, attracting different consequences. Notably, it includes the new obligation on health researchers to de-identify health information before disclosing it, as well as a raft of data breach-related obligations. |
Other changes foreshadowed in the Consultation Paper
The Consultation Paper also addresses a number of proposed measures aimed at enhancing the OAIC’s powers and efficiency, including:
- imposing a range of complaint handling requirements on APP entities, including requiring written responses within 60 days;
- updating how the OAIC may handle representative complaints;
- permitting the OAIC to oversee and assess compliance with privacy protections under the social media minimum age scheme in the Online Safety Act 2021 (Cth);
- requiring persons to provide reasonable assistance in relation to an OAIC investigation;
- clarifying the OAIC’s power to report to the Attorney-General and Ministers; and
- updating the bases on which a person may refuse to comply with an information gathering notice.
The Exposure Draft does not address these proposals. They may be introduced at a later stage.