Australia's proposed Privacy Amendment (Personal Data Protection) Bill 2026 represents the most significant privacy reform in decades. The draft legislation reforms would introduce a fair and reasonable test, new consent requirements, stricter breach reporting and expanded business compliance obligations. This article explores the different aspects of the reforms and what they mean for Australian businesses.
Changes 38 years in the making. The Privacy Act was passed in 1988, before the World Wide Web existed and the Australian Privacy Principles were still 26 years away.
Serious work on replacing it began seven years ago. The ACCC's Digital Platforms Inquiry recommended reform in 2019, and in December that year the Government committed to a full review. An issues paper followed in 2020 and a discussion paper in 2021. The Privacy Act Review Report came in February 2023 with 116 recommendations, and later that year the Government agreed to 38 of them and to a further 68 in principle.
Then came the first tranche. The Privacy and Other Legislation Amendment Act 2024 received assent in December 2024, raising penalties, giving the Information Commissioner more powers, creating criminal offences for doxxing, and introducing a statutory tort for serious invasions of privacy which commenced in June 2025. It covered only part of what had been agreed.
Almost everything of substance, including the fair and reasonable test, was left to a second tranche with no timetable attached. But has now arrived. On 31 August 2026 the Attorney-General released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026.
The small business exemption stays. Businesses under the $3 million turnover threshold are not brought into the Act by this Bill.
The employee records exemption stays. Private sector employers remain outside the Act in relation to their own employee records.
There is no direct right of action. An individual whose privacy has been interfered with still cannot sue the organisation responsible. The remedy is a complaint to the Information Commissioner, or the statutory tort from the first tranche, which is confined to serious invasions of privacy.
Several individual rights the Government agreed to in principle are absent. There is no right to object to the handling of personal information and no right to have search results de-indexed. The enhanced right of access, which would have required an organisation to tell an individual where it obtained information about them and what it had done with it, is also missing.
There is no Data Protection Officer requirement, and no prescribed list of approved countries or standard contractual clauses for overseas disclosures.
Nothing deals directly with smart glasses, wearables or connected vehicles. The consultation paper asks whether a technology-neutral approach is sufficient. The Act still does not apply to individuals acting in a personal capacity, and surveillance laws remain spread across Commonwealth, State and Territory legislation.
APP 3, APP 4 and APP 6 would be replaced by a single rule. An organisation may collect, use or disclose personal information only if doing so is lawful and fair and reasonable in the circumstances.
Neither a privacy policy nor consent will answer the question. The test applies even where the individual has agreed, so a practice can be unlawful despite full disclosure and genuine agreement.
Seven factors would be weighed, with none of them decisive:
How the test works in practice will depend on guidance from the Information Commissioner and on early enforcement. The activities most likely to attract attention are targeted advertising, profiling, data enrichment, and secondary uses of information collected for another purpose.
Take a retailer using purchase data to build audience profiles for its advertising partners. A clear collection notice and a tick box are usually enough today. Under the proposed test the retailer would have to ask whether customers would expect that use, how much control they have, and whether it risks harming them.
Consent would be required in two situations only: collecting sensitive information, and trading personal information. Everything else runs through the fair and reasonable test.
Where consent is required, it must be voluntary, informed, current, specific and unambiguous. Pre-ticked boxes will not meet that standard, and neither will a single tick box covering a privacy policy, marketing and third party sharing at once. Implied consent survives, but only where it can be clearly inferred from the individual's conduct and the purpose is obvious.
Collection notices would need to be short and in plain language, covering the fact and circumstances of collection and the purposes of use and disclosure.
The Bill introduces the concept of trading personal information, covering disclosure for money, for other consideration, or for direct marketing. This captures data brokerage, list sharing, advertising partnerships, and programmatic advertising involving cookies or pixels. A business passing checkout data to an advertising partner for campaign activation would be trading, and would need consent.
There are carve-outs for incidental disclosures in transactions such as mergers, and for disclosures to a processor acting solely on the organisation's behalf under documented instructions. Businesses that treat customer data as a revenue line should look at this closely, particularly where that revenue forms part of a sale process.
APP 7 would be simplified, and direct marketing defined in the Act for the first time. The definition is technology neutral: communicating marketing material to an individual by any means, where the individual has been selected or targeted using their personal information.
Group level targeting is caught, so this covers programmatic and behavioural advertising, targeted social media campaigns and audience segmentation, as well as personalised email, SMS and telemarketing.
Where a communication is already regulated by the Spam Act 2003 or the Do Not Call Register Act 2006, the new opt-out and disclosure obligations would not apply, though the fair and reasonable test and the trading consent requirement would still apply to the underlying data handling.
Organisations sending direct marketing would need a simple opt-out mechanism, clear opt-out information in each communication, and a process to act on requests.
Personal information would change from information about an individual to information that relates to an individual, with a non-exhaustive list of examples including IP addresses and device identifiers. Location data and behavioural inferences come more clearly within scope.
De-identification would be treated as context specific rather than permanent. An organisation holding de-identified or pseudonymised data would have to keep assessing the risk of re-identification against other information that is reasonably available.
Precise geolocation tracking data would become sensitive information, so consent would be needed to collect it. This affects wearables, workforce tracking and anything else that records where a person is over time.
The Bill sets a hard 72 hour deadline to notify the Information Commissioner, running from the point at which the organisation has reasonable grounds to believe an eligible data breach has occurred. The current standard is as soon as practicable.
Where a complete picture is not available in time, an incomplete statement can be given within 72 hours setting out what is known, what is missing and why, with a complete statement to follow. Affected individuals must be notified at the same time as the Commissioner where feasible.
Separately, every APP entity would need breach response practices, procedures and systems, and would have to take reasonable steps to prevent or reduce harm as soon as a breach or suspected breach is identified, whether or not it is an eligible data breach.
APP 11 would be strengthened in three ways. Where information is no longer needed, an organisation would have to actively consider destroying it rather than de-identifying it. It would have to take reasonable steps to identify the personal information it holds. And it would have to regularly assess whether its security and destruction controls are working.
In practice that means a current record of data holdings, a retention and destruction process that actually runs, documented re-identification risk assessments, and periodic review.
The Bill introduces a controller and processor model along the lines of the GDPR. A controller decides the purposes for which personal information is handled. A processor handles it on the controller's behalf under documented written instructions.
Where a processor stays within those instructions, its conduct is treated as the controller's for APP purposes, and the processor keeps direct obligations under APP 1 and APP 11 only. The protection falls away if it exercises its own discretion over the information.
This reduces the burden on service providers and increases it for the organisations that engage them. Both sides will need to map their relationships, record instructions properly, and allocate liability by contract.
A narrow exception would let an organisation refuse an access request where, despite reasonable steps, compliance remains unreasonable or impracticable because it is technically impossible or infeasible. An organisation that designed its systems that way deliberately could not rely on it.
A new right to erasure would apply only to large digital platforms: providers of social media services, relevant electronic services or designated internet services under the Online Safety Act 2021 with group revenue of at least $500 million, or 2.5 million average monthly Australian users, or which are prescribed by regulation. On request the platform must destroy the individual's personal information, subject to exceptions for frivolous requests, legal retention obligations, technical impossibility, and information strictly necessary to keep providing a service.
This is much narrower than the Privacy Act Review recommended, and narrower than the United Kingdom and European Union, where the equivalent right applies to every controller. The Bill also does not say whether deleting source data is enough where personal information has been used to train an AI model.
The Privacy Act already lets an organisation use or disclose personal information without consent in a short list of set situations. One applies where it suspects unlawful activity or serious misconduct, but that only covers misconduct by someone in the course of their job, leaving doubt about whether it can be relied on to investigate outsiders.
The Bill would replace misconduct with wrongdoing, covering people acting in a private capacity and people outside the organisation as well as staff, and would let an organisation monitor for serious wrongdoing before identifying a particular incident.
For a bank or an aged care provider, that removes the doubt about using customer information to look for scams, third party fraud, or the financial abuse of a vulnerable customer.
Consultation is now open on the draft Bill, and stakeholders, organisations and businesses should can whether to make a submission on the proposed reforms. Submissions close on Friday 18 September 2026, and the Government has indicated the Bill will be introduced this year. The work needed regardless of its final form is:
Privacy compliance is becoming increasingly complex, and the proposed reforms would require many organisations to reassess their data handling practices. Aitken Partners regularly advises businesses, including start-ups and scale-ups on privacy, data governance and regulatory compliance. To discuss further, please get in touch with our team.
Links:
BOOK A CONSULT, learn more about our Commercial Law team.
Please note: The information on this page is provided for general information purposes only and does not constitute legal advice. It is not intended to be comprehensive or to apply to any specific circumstances. You should seek independent legal advice before acting on any information contained on this page.