A further stage of privacy reform

The Australian Government has released a new consultation paper and exposure draft of the further stage of proposed reforms to Australia's privacy laws.

The exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 (Cth) (the Bill) is the second round of significant reforms of Australia's privacy framework, following on from changes made in late 2024 by the Privacy and Other Legislation Amendment Act 2024 (Cth).

The Bill contains draft provisions that would, if enacted, amend the Privacy Act 1988 (Cth) (the Privacy Act), and the accompanying consultation paper canvasses roughly 40 proposals in total. These include 25 recommendations from the earlier Privacy Act Review directed at uplifting privacy protections, 5 review recommendations aimed at clarifying and simplifying obligations, 4 additional simplification measures, and 7 further measures to improve the efficiency of the Office of the Australian Information Commissioner (OAIC).

The proposed reforms are broad, and if enacted would touch almost every part of the Privacy Act. While many of the reforms borrow from overseas examples, including concepts from the EU General Data Protection Regulation, the Privacy Act would maintain its distinct Australian flavour.

Here we summarise the key proposed changes for business decision-makers and government agencies, following the structure of the exposure draft (Schedules 1-6), together with the further measures proposed for the OAIC and for emerging technologies such as wearables and AI.

The Australian Government has indicated that subject to the public consultation process, it will seek to introduce the Bill and legislate the proposed reforms by December 2026. Several of the substantive changes or measures are likely need a sufficient lead time for allowing business and government agencies to adapt their policies and practices, and we anticipate the start dates for specific provisions may be staggered.

Consistent with the fact that the proposed changes are subject to public consultation and none have become law, we use ‘proposes’, ‘would’ and similar conditional language throughout, rather than describing the Bill's effects as settled.

At a glance

While it does not appear in the draft Bill, the public consultation also seeks to address rising concern about smart glasses and similar wearable surveillance technologies through technology-neutral Privacy Act reforms, such as the 'fair and reasonable' standard, and right to erasure, rather than any tech-specific import bans.

Further below, we will also comment briefly on several significant changes which were proposed by the Privacy Act Review Report, but which the Government has not proposed to bring in-scope through the Bill.

Schedule 1: Core definitions

The Bill proposes to update several foundational definitions to reflect contemporary data practices.

Personal information and ‘reasonably identifiable’

The test would move from information ‘about’ an individual to information that ‘relates to’ an identified individual or one who is 'reasonably identifiable':

'Relates to' is a deliberately broader standard. It would widen the nexus or potential relationship between the individual and the information, for that information to come within scope of the Act. While the individual need not be the sole or dominant subject of the information, there must be a sufficient connection between the individual and the information in the circumstances, for it to be 'personal information'. In practical terms, whether information relates to an individual will depend on both the nature of the information and the purposes for which the information is handled. But information will not relate to an individual merely because it has a tenuous, remote, incidental or trivial connection to them.

The proposed addition of a new definition of ‘reasonably identifiable’ would require an objective assessment of whether an individual could be identified by combining information with other information reasonably available to the entity, having regard to foreseeable re-identification risk.

When read together, these definitional changes will broaden the types of information which can be treated as personal information, such as IP addresses and cookies. But it would also have wide impacts on the uses of data analytics and user behaviour monitoring tools, tokenisation in payments and digital assets, handling of geolocation data, and more.

Sensitive information

The definition would be expanded to expressly capture precise geolocation tracking data (information that identifies an individual's location to within 500 metres and is held by reference to their location over time) and genomic information relating to an individual.

De-identified information

De-identification would be confirmed as a state that can change over time, not a fixed one, and would need to be reassessed as technology, data availability and re-identification safeguards evolve.

Collects

Under the proposed definition, an entity would ‘collect’ personal information whenever it includes that information in a record, regardless of source, including information generated or derived through data analysis or AI. Sensitive information derived from other personal information would generally only be treated as collected once it is separately recorded, used or disclosed as sensitive information.

Disclosure

A new definition would tie disclosure to whether information is made accessible to another person or body. Making information accessible within an entity would be a use; making it accessible outside the entity would be a disclosure. Mere transmission or storage, including overseas, would not of itself be a disclosure.

Consent

Under the proposed amendments, consent would need to be voluntary, informed, current, specific and unambiguous, with a narrow carve-out relaxing the ‘current’ and ‘specific’ elements for ethically approved human research.

Schedule 2, Part 1: Fair and reasonable handling, consent and notice

One of the Bill's most significant proposals is to repeal existing APPs 3, 4 and 6 and replace them with a single test: personal information could only be collected, used or disclosed where it is fair and reasonable to do so in the circumstances. The test would apply alongside permitted general and health situations, and lawful authority.

The proposed legislated factors

Entities would need to have regard to a non-exhaustive list of factors, with no single factor being determinative:

Consent to collect sensitive information or to ‘trade’ personal information

Under the proposed amendments, organisations would not be able to collect sensitive information, or ‘trade’ personal information, without consent unless an exception applies.

Trade would be defined to capture disclosure for monetary or other consideration, or for direct marketing purposes. Four carve-outs would take a disclosure outside the definition: where necessary to provide a good or service the individual requested; where incidental to a business sale (provided the personal information is not the substantial purpose of the transaction); disclosures to a processor acting on documented instructions; and disclosures necessary to prevent, detect or remedy unlawful activity or serious fraud.

Two new exceptions to the sensitive-information consent requirement are proposed: collection from a publicly available document (a broader concept than ‘generally available publication’, potentially including social media posts); and collection that is strictly necessary to provide a good or service the individual explicitly requested, subject to added protections where a child's sensitive information is involved.

Notice

Notification requirements would be simplified to two matters: the fact and circumstances of collection, and the purposes for which the entity intends to use or disclose the information. Notices would need to be clear, concise and not obscure key matters, and would need to be updated when practices change.

Schedule 2, Part 2: Permitted general situations

Permitted General Situation 2 would be broadened by replacing ‘misconduct of a serious nature’ with ‘wrongdoing of a serious nature’, a wider concept that would not be confined to conduct in the course of a duty. This is intended to capture conduct such as financial abuse, including by persons acting in a private capacity (for example, suspected misuse of an enduring power of attorney), and would apply to both internal and external conduct.

Schedule 2, Part 3: Direct marketing

APP 7 would be replaced with a technology-neutral direct marketing framework. Direct marketing would be defined broadly to include advertising directed to an individual using their personal information, whether targeted individually or as part of a segment or cohort, capturing behavioural advertising based on browsing history.

Organisations would need to continue providing a simple opt-out, with responsibility resting on the entity making the communication (in multi-party arrangements, typically the platform, unless it is acting solely as a processor). A new concept of an ‘ad-supported service’ would allow such services to offer a different, non-marketing version of the service (or an element of it) rather than being required to continue the same service unconditionally, provided the individual has a genuine choice, drawing on ‘consent or pay’ style approaches used in the United Kingdom and the European Union. Consent to trade personal information would remain separately required even though direct marketing itself would not require consent.

Schedule 3, Part 1: Notifiable data breaches

The Bill proposes to distinguish a data breach from an eligible data breach (one likely to result in serious harm), and would introduce a positive obligation to take reasonable steps to contain a data breach even below the serious-harm threshold. Entities would need to implement practices, procedures and systems enabling an effective response, and would need to take reasonable, ongoing steps to mitigate harm as soon as practicable after becoming aware of reasonable grounds to believe or suspect a breach has occurred.

Proposed 72-hour notification

Entities would need to give the Information Commissioner a statement within 72 hours of becoming aware of reasonable grounds to believe an eligible data breach has occurred, aligning with timeframes under Australia's Security of Critical Infrastructure Act 2018 (Cth) and the Cyber Security Act 2024 (Cth). It would also align with the mandatory data breach notification timeline in overseas jurisdictions such as New Zealand, the United Kingdom and European Union, Singapore, Thailand, the Philippines, South Korea and India.

An incomplete statement could be given where a complete one is not possible within that period, with outstanding information (and reasons for the delay) to follow, and the Commissioner would need to be told of any material change or error.

Individual notification would be aligned to this staged approach, and would not be required where remedial action removes the likelihood of serious harm.

Schedule 3, Part 2: Security of personal information

APP 11 would be strengthened. Entities would need to first consider whether personal information no longer needed for any permitted purpose should be destroyed, and if not destroyed, take reasonable steps to ensure it is de-identified. Entities would also need to be able to identify the personal information to which these duties apply, and would need to regularly evaluate the effectiveness of their security, destruction and de-identification measures. Commonwealth government agencies remain exempt from destruction to the extent personal information is contained in a Commonwealth record.

Schedule 4, Part 1: Technically impossible or infeasible

A new exception to the APP 12 access obligation would apply where, despite taking reasonable steps, providing access remains unreasonable or impracticable due to technical impossibility or infeasibility. The exception would only be available where reasonable steps to provide access were first taken, and would apply only to the extent access is genuinely not achievable, so any information not affected would still need to be provided.

Schedule 4, Part 2: Right to erasure on large digital platforms

A new right to erasure would apply to organisations that are ‘large digital platforms’ (LDPs), being providers of a social media, relevant electronic, or designated internet service (as defined in the Online Safety Act 2021 (Cth)) that meet a gross revenue test ($500 million or more group-wide in the previous financial year) or an end-user test (2.5 million or more average monthly Australian end-users), or other test to be prescribed by regulation.

An LDP would need to destroy an individual's personal information on request and give written notice of the outcome, unless an exception applies. Exceptions would fall into three categories: public interest (including law enforcement); legal interest (where retention is required by law or a court or tribunal order, where a permitted general or health situation exists); and technical or circumstantial grounds (technical infeasibility, or frivolous or vexatious requests), plus a further exception where the information is strictly necessary to provide an ongoing good or service. Information held solely in a processor capacity would not be subject to the right.

Schedule 5: Exception for research

The current, fragmented set of research-related exceptions would be repealed and replaced with a single exception for ‘human research’: research conducted with or about individuals that involves personal information, reviewed, approved and monitored in accordance with the National Statement on Ethical Conduct in Human Research and complying with guidelines to be made by the Privacy Commissioner. This is intended to remove the confusion and barriers to research partnerships created by the current, narrower exceptions.

One area of concern about the Privacy Act in its current form has been that the research exemptions did not extend to the statutory tort of serious invasion of privacy (added into the Privacy Act by the first tranche of reforms in late 2024) and nor would this be addressed in new proposed reforms, either.

Schedule 6: Exception for information processors

A formal controller/processor framework would be introduced. Under the proposed definitions, a processor would be an APP entity that acts on a controller’s documented instructions and handles information only for the purposes those instructions specify; the concept would only apply between two APP entities, preserving the existing framework for Commonwealth contracted service providers. Acts done strictly in accordance with those instructions would not breach the APPs or a registered APP code as against the processor, except APP 1 and APP 11, for which the processor would remain directly responsible.

Where a processor acts within its instructions, its acts would be treated as the controller's acts for liability purposes; a processor that acts outside its instructions would remain directly responsible for its own compliance.

These new provisions expressly exclude contracted service providers to government, meaning that while most service providers will benefit from the change, those with government contracts will remain obligated to comply with the APPs as if they were the relevant agency.

Proposed OAIC powers and efficiency measures

Alongside the Bill, the Government is developing further measures to support the OAIC, which are not yet in exposure draft form:

Emerging technologies: wearables, AI and connected vehicles

The consultation paper separately raises privacy risks from emerging technologies, including wearable surveillance devices such as smart glasses, AI systems and connected vehicles. The Privacy Act generally does not apply to individuals acting in a personal capacity, other than the statutory tort of serious invasions of privacy introduced in 2024, which is technology-neutral and can apply to harms arising from wearable surveillance technology.

Where an entity regulated by the Privacy Act uses such technologies (for example, collecting photos, audio or AI-generated inferences), the Bill's other proposed reforms are intended to help address the risks, including: modernised definitions that would confirm behavioural and wearable-generated data can be personal information; a broadened concept of collection that would capture AI-generated inferences; the fair and reasonable test's proposed focus on harm and reasonable expectations; a proposed requirement for meaningful consent to trade information collected by wearables; proposed treatment of precise geolocation data as sensitive information; proposed strengthened security, destruction and breach obligations; and the proposed new LDP erasure right.

The consultation paper poses several open questions on whether these measures would go far enough, including on the adequacy of existing remedies and the practicality of meaningful consent for wearable technologies; this remains an area for further consultation rather than settled drafting.

What the Bill doesn't address

Comparing the 2026 Bill's proposed scope against the Privacy Act Review Report (February 2023) and the Government's response (September 2023), we see that several notable proposals were agreed or agreed in-principle in 2023, yet don't appear in the exposure draft of the Bill:

What this means in practice

Suggestions for businesses

Suggestions for government agencies

Have your say

The Attorney-General's Department is running a public consultation on the Bill's exposure draft, inviting written submissions on the Bill (including practical implementation issues) and separately seeking views on the emerging technologies questions.

The consultation opened on 31 August 2026 and submissions must be lodged by Friday 18 September 2026. The department has indicated it will not consider submissions received after that date and encourages concise submissions of around 1,000 words.

Submissions can be made through the consultation page linked below, or queries directed to PrivacyReform@ag.gov.au.

To collaborate on a submission to this public consultation, or for further information on how these proposed changes to Australia's Privacy may affect your organisation, please contact our expert Data and Privacy team.