Australia's second tranche of Privacy Act reforms proposes sweeping new rules on data handling and individual rights
Australia’s privacy regime is set for another major overhaul, with the Federal Government unveiling its long-awaited second tranche of Privacy Act reforms. The proposals could significantly change how businesses collect, use, share and protect personal information, and expand the rights individuals have over their data.
The Federal Government has released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 (Cth), together with a consultation paper, marking the second stage of reform of the Privacy Act 1988 (Cth).
Building on the Privacy and Other Legislation Amendment Act 2024 (Cth), which introduced, amongst other things, the statutory tort for serious invasions of privacy, and enhanced enforcement powers (discussed in a previous insight here), the Bill proposes approximately 40 further reforms, including the long-anticipated fair and reasonable test, that will significantly change how Australian businesses handle personal information.
The reforms are broad in scope but also respond to privacy risks associated with emerging technologies. As we explored recently in our article Smart glasses in the workplace: the privacy and surveillance risks organisations need to manage, technologies that collect personal, biometric and location data are challenging existing approaches to privacy surveillance. Several of the proposals, including the treatment of precise geolocation as sensitive information and the right to erasure, are intended to address these emerging risks.
Key takeaways
If the Bill is introduced in its current form, businesses will need to:
- Review data practices: assess whether their handling of personal information meets the legislated factors, particularly around transparency, data minimisation, and genuine choice. Revisit marketing and data-sharing arrangements where they involve trading personal information.
- Invest in data governance: map the personal information they hold, review retention and destruction policies in light of the strengthened APP 11 obligation to consider destruction of personal information and implement lifecycle management programmes.
- Mitigate data breach impacts: take reasonable steps to prevent or reduce harm to the individuals affected in actual or suspected data breaches.
- Strengthen breach response capability: update incident response plans to reflect the 72-hour notification window and regularly test breach readiness.
- Prepare for expanded individual rights: build organisational capability to respond to erasure and access requests, including the systems and processes needed to identify, locate and destroy personal information across complex data environments.
- Implement AI governance frameworks: prioritise updating AI governance frameworks, including auditing AI systems and implementing transparency measures.
- Plan for increased regulatory exposure: invest in complaint-handling infrastructure that meets the 60-day response and written decision requirements and ensure privacy programs are audit-ready for a more active Office of the Australian Information Commission (OAIC).
What is the new 'fair and reasonable' test?
The centrepiece reform is the introduction of a fair and reasonable test for the collection, use and disclosure of personal information.
Existing Australian Privacy Principles (APPs) 3, 4 and 6 would be replaced with a new framework in which collection, use, and disclosure obligations are located in a single principle (new APP 3), requiring all handling to be fair and reasonable in the circumstances, taking into account specific factors including:
- Reasonable expectation: whether a reasonable person would expect the collection, use, or disclosure in the circumstances.
- Relationship to functions or activities: whether the handling is reasonably necessary for, or related to, the entity’s functions or activities.
- Transparency: whether the entity is transparent about how and why the personal information is collected, used, or disclosed.
- Data minimisation: whether the purpose could be achieved by collecting, using, or disclosing less information, or information that is not personal information.
- Genuine choice: whether the individual is provided with genuine choice in relation to the handling of their personal information.
- Impact and proportionality: the impact on the individual’s privacy and any risk of harm, including whether that impact is proportionate to any resulting benefit.
- Best interests of the child: where the individual is a child, whether the handling is in the child’s best interests, treated as a primary consideration.
A separate principle would require consent, with some carve outs and exceptions, for collecting sensitive information and for trading personal information, a new concept covering disclosure for money, other consideration, or direct marketing purposes.
The fair and reasonable requirement does not apply where collection, use, or disclosure of personal information is required or authorised by law, a permitted general situation exists (such as lessening or preventing a serious threat to life, health or safety), or, for organisations, a permitted health situation exists.
The Bill also introduces a technology-neutral definition of direct marketing capturing targeted and behavioural advertising and audience segmentation. Consent would not be required for direct marketing itself, but the organisation making the communication must provide a simple opt-out mechanism.
Underpinning these changes are broadened foundational definitions:
- ‘personal information’ would cover information that ‘relates to’ an individual (replacing ‘about’). The phrase ‘relates to’ is capable of capturing not only information that directly identifies a person, but also information connected to them by virtue of how it is collected, used or disclosed, including behavioural data, location information and AI-generated inferences;
- ‘consent’ must be voluntary, informed, current, specific and unambiguous. This signals a move away from consent mechanisms that rely on broad, bundled permissions, or user interfaces designed to steer individuals towards a particular outcome. Pre-ticked boxes, deceptive interface designs and consent requests embedded within lengthy terms and conditions are unlikely to satisfy the new requirements;
- ‘collects’ would mean the collection of personal information for inclusion in a record or generally available publication regardless of its source or how it was obtained, including information generated or derived through data analysis or AI;
- ‘sensitive information’ would include genomic information and precise geolocation tracking data, being data that identifies an individual’s location to within a radius of 500 metres and is collected and held by reference to their location over time (one-off disclosures of location are not captured). The change could affect a broad range of businesses, including those that use location tracking, biometric verification or genetic data as part of their products, services or internal processes. These organisations should review their data collection practices and consent mechanisms to understand how the expanded definition could affect them; and
- ‘de-identified’ information would depend on circumstances at a particular time and re-identification risk.
Data minimisation and obligations
APP 11 would be strengthened to require entities to consider destroying (not merely de-identifying) personal information no longer needed, to identify the personal information they hold, and to regularly evaluate compliance measures.
The Bill also introduces a new controller-processor framework (these terms being newly defined, and reflecting terms used under the General Data Protection Regulation (GDPR) in Europe).
A processor acts on behalf of a controller where it processes personal information in accordance with the controller’s documented written instructions and solely for the purposes specified in those instructions.
Processors would be exempt from most APPs, except APP 1 and APP 11. The controller remains responsible for ensuring compliance with the APPs and may be held liable for acts or practices of the processor undertaken in accordance with its instructions. However, where a processor acts outside the scope of those instructions, it will remain directly responsible for its own conduct.
For businesses that outsource data processing, the reforms make it important to clearly document the roles and responsibilities of each party and ensure processing arrangements reflect the new framework.
Data breach response
Under the Bill, the Privacy Act would be amended to require organisations to report eligible data breaches to the OAIC within 72 hours of becoming aware of reasonable grounds to believe that an eligible data breach has occurred. There is also a positive obligation on entities to update the OAIC if they become aware of material errors or changes in previous data breach notifications made to them.
This timeframe aligns more closely with breach reporting timeframes under other legislation, including the Security of Critical Infrastructure Act 2018 (Cth) and the Cyber Security Act 2024 (Cth), as well as breach reporting timeframes in other jurisdictions (including the GDPR).
Importantly, the existing timeframe to assess suspected eligible data breaches, being to complete a ‘reasonable and expeditious’ assessment and to take all reasonable steps to ensure that this assessment is complete within 30 days, remains unchanged. However, we expect that this new 72-hour threshold will require organisations to carefully consider known circumstances about data breaches at a much earlier stage than they are required to do currently.
The Bill would also introduce a positive and ongoing obligation on organisations to take steps to mitigate the impact of an actual or suspected data breach, including to protect affected individuals whose personal information may have been compromised. This obligation applies to all data breaches, and not just eligible data breaches. Example steps provided in the Consultation Paper include disabling compromised accounts, containing unauthorised access to systems, and notifying relevant third parties to assist in preventing harm.
Supporting these amendments is the introduction of an obligation on entities to take reasonable steps to implement practices, policies and procedures to allow them to respond effectively to data breaches. A failure to do so could result in regulatory penalties.
Who will have the right to erasure?
A new APP would require large digital platforms that are providers of social media or designated internet services (meeting a $500 million gross revenue threshold or 2.5 million or more monthly Australian end users) to destroy personal information on request, and to give the individual written notice of the outcome of the request within a reasonable period. Platforms that do not meet the thresholds may also be prescribed as large digital platforms by regulation.
Exceptions to the right apply including where retention is required by law, destruction is technically impossible, the information is strictly necessary to provide an ongoing good or service to the individual, or the request is frivolous or vexatious.
While currently limited to large digital platforms, in our view the right to erasure may be extended in subsequent reform stages.
Offering a small measure of relief to businesses, APP 12 would be amended to introduce a new exception to the access requirement where, despite the entity taking reasonable steps, providing access remains unreasonable or impracticable because it is technically impossible or infeasible. The exception applies only to the extent access is unreasonable or impracticable, so entities must still provide access to any information not covered by it (unless another exception applies).
AI and automated decision-making
The broadened definition of ‘collects’ would capture information generated or derived through means such as data analysis or AI, including inferences drawn by AI-enabled technology about an individual, triggering the full suite of privacy obligations including the fair and reasonable test.
Entities will need to demonstrate that AI-driven data practices meet the legislated factors, with the proportionality factor particularly relevant given the risks of unlawful discrimination or loss of autonomy from algorithmic decision-making.
Increased regulatory and litigation risk
Key measures include mandatory, accessible complaint mechanisms for entities with 60-day response periods and written decisions setting out the outcome and available review options.
The Bill would also empower the OAIC to assess how social media platforms collect, use, retain and destroy personal information for age-assurance purposes under the Online Safety Act 2021 (Cth), and introduce broader powers to require reasonable assistance during investigations.
Emerging technologies
The consultation paper seeks feedback on privacy risks from wearable surveillance technologies, such as smart glasses and ear buds, and from connected vehicles.
As noted above, precise geolocation tracking data would be classified as sensitive information, requiring consent before collection.
How can we help
The second tranche of Privacy Act reforms could significantly change how organisations in Australia collect, use, share, and protect personal information. While the proposals remain subject to consultation, organisations should begin assessing how the changes could affect their data practices and where action may be required.
The Hall & Wilcox privacy team can help you assess the impact of the proposed reforms, review your privacy and data governance frameworks, policies, collection notices, and digital terms, and identify areas that may need change. We can also assist organisations wanting to make a submission to the Consultation Paper before the consultation closes on 18 September 2026.
Please get in touch if you would like to discuss what the proposed reforms mean for your business and how you can start preparing.
Alison Baker, Suzie Leask, and Eden Winokur are Partners at Hall & Wilcox, with Winokur also serving as Head of Cyber. Iona Goodwin is a Special Counsel and Madeline Tait is a Senior Associate at the firm. Daniel Williams is a Lawyer and Mia Gould is a Graduate Lawyer, also at Hall & Wilcox.
This article is also prepared with assistance from Lucy Korman, Law Graduate.