Australia’s privacy reset: What the 2026 reforms mean for organisations
Privacy 01.10.26
On 31 August 2026, the Australian Government released its consultation paper and exposure draft legislation for the long anticipated ‘Tranche 2’ privacy law reforms. Proposed changes will have significant impacts across the economy, but particularly for organisations relying heavily on trading of personal information, secondary uses, de-identified information or digital advertising.
In this post we break down the key changes that are proposed, and what they mean for you – including:
- Updated and expanded definitions for terms that set the scope of the Privacy Act such as personal information, reasonably identifiable, de-identified, consent, disclosure, sensitive information and collection.
- The introduction of a ‘fair and reasonable’ test for the collection and handling of personal information, which fundamentally changes Australian privacy law from ‘consent-based’ to a more ‘organisational accountability’ model.
- New and simplified notification requirements.
- Stronger obligations to map, secure and dispose of personal information holdings.
- Enhanced notifiable data breach obligations, including a new 72-hour notification period.
- New requirements for ‘trading’ personal information and revised requirements for direct marketing.
Introduction
The current round of privacy law reform has been underway for almost seven years, after the Government signalled an intent to review and reform the Privacy Act in response to the Australian Competition and Consumer Commission’s (ACCC’s) landmark Digital Platforms Inquiry.
Following several rounds of consultation, the Attorney General’s Department finalised its review and the Government responded in 2023, followed in late 2024 by what was slated as ‘Tranche 1’ of the reforms.
These included some significant changes, like the introduction of a statutory tort for invasions of privacy and the Children’s Online Privacy Code. It also included some changes that had not been considered in the previous consultations and report, such as prohibitions on doxing.
However, Tranche 1 did not include the changes most likely to require process change and uplift by organisations covered by the Privacy Act, which were to be covered by Tranche 2.
What has been excluded from Tranche 2?
As with the first tranche, this Bill includes a range of topics from the Government’s final report, leaves out others that were anticipated and adds a few novel laws.
Among the most significant items missing from this round are the removal of the small business exemption, the extension of privacy protections to employee records, and higher standards for organisations relying on the journalism exemption, all of which were agreed to in principle by the Government. The Government had proposed to make some changes to these exemptions, but those changes have not been included in this round, and we haven’t heard anything further about them recently.
Worth noting also – despite widespread public support for change, Government had signalled that it would not reform the exemption for political entities – and indeed it did not.
Another significant absence from this round of reforms is the ‘direct right of action’. This was proposed to be introduced to give individuals the avenue to sue an organisation directly for breaches of the Privacy Act, rather than relying on a determination from the Privacy Commissioner as the only path to compensation. This removes an important avenue for redress for people. It also means that the opportunity for case law to help clarify the many flexible terms in the Privacy Act has been diminished.
Timeline
So far, there hasn’t been any information provided on a timeline for the introduction of the Bill or of how long between the Bill passing (if it does) and the commencement of the provisions.
However, the consultation on this Bill only ran for 3 weeks, which is unusually short for a Bill of this substance and complexity, which may indicate that the Government sees most issues as settled and is working to a relatively short turnaround.
If passed, it is unclear how long entities will have to come into compliance with the new laws. The consultation paper does not propose a transition period, which would mean it will come into effect as soon as the Bill passes. Previous privacy law reform transition periods have varied between immediately (for specific items) to an 18-month commencement period.
Jump to a section
- Fair and reasonable handling of personal information
- Personal information, reasonably identifiable and de-identified
- Key Updated Definitions
- Notification of the collection of personal information
- Security of personal information
- Eligible data breaches
- Trading personal information
- Conclusion
Fair and reasonable handling of personal information
The introduction of a ‘fair and reasonable’ test is the most substantial change introduced in these reforms, having significant impact on how information is handled by all entities covered by the Privacy Act.
A fair and reasonable test has been being pushed by privacy advocates for some time — being suggested as far back as 2008 by the Australian Law Reform Commission. The significance of a fair and reasonable test is that it moves the balance from a ‘notice and consent’ model, where the onus is on individuals to understand and make their own decisions about how their personal information is used, to a model more focused on organisational accountability, where more responsibility falls on organisations to collect and handle personal information in a way that does not cause harm and aligns with community expectations.
Under the reforms, the fair and reasonable test would replace APPs 3, 4 and 6, and in doing so would raise the standard for what is an acceptable use of personal information while also clarifying and simplifying organisations’ obligations. At present, organisations must meet certain standards about what they collect, how they collect, and how they use personal information – but each of these are a different requirement, using different language, and open to interpretation by both the Privacy Commissioner and the courts. Fair and reasonable replaces this with a single requirement with thresholds that are more explicitly established.
The extremely high level, of the fair and reasonable test applies a pub test for privacy i.e., it asks, “is the personal information handling what the customers/users of this organisation would expect and find reasonable”.
There are seven legislated factors that must be weighed in determining whether an act or practice is fair and reasonable:
- Reasonable expectations
This is what a reasonable person would expect, considering the relationship between the organisation and the individual, the types of personal information being handled, and the context of the information handling. That means considering community expectations, whether you have an ongoing or once-off relationship, whether you are providing a sale, an optional service or an essential service.
- The connection to the entity’s functions
This requirement is very similar to the existing ‘reasonably necessary for the entity’s functions or activities’, although a more flexible requirement than previously (given it is only one component of seven). Instead of categorising uses as ‘primary’ and ‘secondary’, the purpose of collection is placed on a spectrum — the more removed from an entities core functions and activities, the less likely it is to be reasonable.
- Transparency
Transparency relates to the extent to which an individual would understand why and how their personal information is being handled. Understanding is key — a collection notice or privacy policy may provide this understanding, but there may be circumstances where it isn’t the appropriate method for communication. This requirement also specifically states that transparency is not achieved if the privacy policy or collection notice is insufficiently clear.
- Data minimisation
A concept implied in existing privacy law, and recommended by privacy professionals, data minimisation is being pulled to the fore for the first time in the fair and reasonable test. This factor requires that entities consider if their purpose can be achieved without collecting personal information, or with de-identified information. And if not, that the minimum amount of information should be collected.
- Genuine choice
This factor sits in conjunction with the updated definition of consent (discussed below), which codifies many of the accepted components of consent. This factor effectively bans ‘take it or leave it’ conditions and practices like dark patterns. There are some limited situations were genuine choice is not required, but broadly this calls for clear privacy settings, opt-out mechanisms and options around information provision.
- Proportionality of impact
Proportionality is a touchstone legal test in human rights law and has been read into the Privacy Act by Courts and by the Commissioner through terms such as ‘reasonably necessary’. It is now given a more privileged status and an explicit place in the Act. For the fair and reasonable test, proportionality requires consideration of the privacy impacts on the individual, and that they be balanced against the benefits of the handling.
- Best interests of the child
This recognises that children are particularly susceptible to privacy harms, and less likely to be capable of assessing the potential risk of an interaction. Whether something is in the best interests of the child should be the primary consideration when assessing if the collection is fair and reasonable.
What this means in practice
The introduction of the ‘fair and reasonable’ test in place of APPs 3, 4 and 6 fundamentally changes that way in which the Privacy Act regulates the collection, use and disclosure of personal information, but for most organisations it is unlikely to have a significant impact on which processes are compliant and which are not.
Previously, the key factor determining Privacy Act compliance was often whether a use or disclosure of personal information was outlined in the Privacy Policy and a relevant collection notice. Going forward, the fair and reasonable test demotes notice and consent to one factor in seven, elevating other factors focused on balancing interests and managing impacts.
For many organisations, the fair and reasonable test will make no difference to the types of personal information they collect and handle, and why. But for many, it will make changes to what or why information is collected, and how it’s handled.
But either way, all organisations will need to do an assessment of what they collect, why, how, and for what purposes it’s used, without which is will be hard to make a confident statement that your personal information handling is fair and reasonable. Existing PIA processes and privacy by design methodologies are well adapted to assess and apply this new test.
The data processing inventory (or similar) that we consider will be necessary to meet the new requirements of APP 11 (see below) will significantly help in identifying all these factors, thus supporting this kind of assessment.
Key updated definitions
The draft Bill introduces a range of updated definitions that will have varying impact on information handling, from minimal to quite significant.
The key definitions updated are:
- Personal information (and ‘reasonably identifiable’ and de-identified)
- Consent
- Disclosure
- Sensitive information
- Collects
Personal information, reasonably identifiable and de-identified
The most significant definitional change is an expansion and clarification of the scope of ‘personal information’ to which obligations under the Privacy Act attach. The definition of personal information will change from being information ‘about’ an individual to information that ‘relates to’ an individual, bringing into scope a broader range of data which may not be ‘about’ a person, but which may indirectly ‘say something’ or allow something to be inferred about them.
Alongside this change, a new definition of ‘reasonably identifiable’ is proposed, which would write into law the ‘individuation’ threshold for identifiability that was applied by the Privacy Commissioner in her recent decisions against Monash IVF and Medmate. This threshold for identifiability is explicitly intended to include in its scope circumstances where an individual can be recognised, singled out or otherwise treated differently to others even if their name or legal identity is unknown.
The exposure draft would also amend the definition of ‘de-identified’ to carry over the changes to the definition of personal information (from ‘about’ to ‘relates to’) and to clarify that de-identification is not a static condition, being dependent on context, available technology and the control environment that prevents reidentification (among other things).
What this means in practice
These changes have significant implications for organisations that rely on de-identified or non-identified information for activities data sharing, marketing and advertising as they will need to assess whether processes previously thought to be outside the scope of the Privacy Act are now in scope.
This updated definition also combines with updates around trading in personal information (discussed below), resulting in a broader application of the new trading requirements.
The broader scope for personal information also combines with the introduction of the fair and reasonable test (discussed above) to provide a simple and broadly applicable baseline privacy rule of thumb:
- if you can use information to reach out and affect a distinct individual (identifiable),
- then you must balance your objectives with the privacy rights and interests of that individual (fair and reasonable).
Consent
Updates to the definition of consent codify in the Privacy Act the components of consent that are today set out in non-binding Guidelines issued by the Commissioner. The effect of this will be to establish as a legislated baseline for valid consent what some have read previously as ‘best practice’.
Under this new legislated baseline, consent must be:
- Bundled consent (which has long been considered not best practice) is specifically called out as not likely to be valid. The issue of a genuine opportunity to refuse consent is also called out – this is an important inclusion, because many digital platforms and services rely heavily on a ‘consent or don’t use’ model that does not meet this standard. While this may still be allowed for some goods and services, the bar for when this is allowed is lifted.
- This requires that individuals have adequate information to understand what they are providing or refusing consent to, and any risks and consequences of that choice. In our opinion, this has flow on effects to issues like notices and accessibility.
- If circumstances materially change in how personal information is being handled, or a long time has passed consent must be renewed. The requirement for currency also necessarily implies a right to withdraw consent.
- This again calls out the inappropriateness of bundled consent, and the practice of collecting consent against unspecified future uses.
- This raises the standard for when implied consent is considered adequate. While implied consent is still permitted, this calls out practices like pre-selected tick boxes as insufficient to meet the ‘unambiguous’ standard as it may not be clear that the individual is made an explicit choice.
What this means in practice
Organisations with complex or large volume personal information collection and handling may need to update their communications and consent mechanisms. Breaking these notices and consent collections up to make them more specific will help address the requirements of this change. Ultimately, this change calls for clearer communication, more active interaction with consent mechanisms, and potentially more layered service offerings to ensure components of a service can be consented/non-consented.
We consider that accessibility has always been implicit in APP notice requirements, and these changes further indicate this. Individuals should be able to access information about personal information collection regardless of their reading level or accessibility requirements to access this information. Improved clarity, the introduction of plain English and more accessibility measures will support this raised standard.
Disclosure
The amendments would insert a definition of disclosure that centres around whether information is made accessible. This represents a significant change to the current interpretation of the term, which turns on whether control over the information has been handed over (if an organisation retains control over information, it is not ‘disclosed’).
What this means in practice
While it hasn’t made many headlines, this amendment has significant implications for organisations with offshore outsourcing arrangements. Under the current definition, it is open for organisations to argue that information shared with offshore contracted service providers (e.g., call centres or software services) is not ‘disclosed’ and so Australian Privacy Principle (APP) 8 (cross-border disclosure of personal information) does not apply. Under the revised definition, APP 8 will apply to a much broader range of transfers.
New categories of sensitive information
The Exposure draft proposes to introduce two new categories of ‘sensitive information’ – ‘genomic information’ and ‘precise geolocation tracking data’. Genomic information refers to additional types of information that typically accompany genetic information, such as findings about genetic characteristics, biological relationships or health risks. Precise geolocation data includes data generated or derived from a device that identifies someone’s location within a 500-metre radius over time, reflecting the sensitive nature of location traces and their capacity to reveal intimate facts about a person or expose them to physical risks.
What this means in practice
Most organisations handling genetic or genomic information already do so under strict controls and consent protocols but should nevertheless review their processes to ensure the broader scope of genomic information is covered.
The addition of precise geolocation data as a sensitive category is likely to most significantly impact software developers and smart device manufacturers but will need to be considered in relation to an ever-expanding range of ‘location aware’ products and services, from car manufacturers and insurers to advertisers. Even organisations who don’t use precise geolocation as part of their services should review whether any internal functions or processes rely on precise geolocation data (such as fleet management or IT security).
Collects
The definition of ‘collects’ will be amended to clarify that information that is generated, inferred or derived through analysis or AI is collected. This aligns with existing guidance and practice.
What this means in practice
This clarification resolves a long-standing interpretive issue that many privacy teams have found challenging: when you collect personal information from which sensitive information can be derived (for example, a photo of a person from which health information or a religious belief may be inferred), are you collecting personal information or sensitive information. If enacted, the exposure draft would clarify that sensitive information is only collected if and when the inferred sensitive information is derived and recorded.
Notification of the collection of personal information
Privacy notices are being simplified, with a focus on ensuring the individual can easily understand how their personal information is going to be used. The long list of APP 5.2 matters might be a thing of the past, with the new notification obligations focussing on the fact and circumstances of the collection, and the purposes for which the organisation intends to use or disclose the personal information. The notification must also be:
- clear and in plain language;
- readily understandable by the individual;
- up-to-date; and
- concise
What this means in practice
Privacy collection notices will need to be reviewed, and in many cases, simplified. Consumer-centric and short statements will be the focus, with legalistic, dense and complicated notices or links to privacy policies being insufficient under these proposed obligations.
Organisations considering their obligations around changes to notifications also consider changes to the definition of consent (discussed above).
Security of personal information
APP 11 is getting another tweak, with two new obligations of note.
The first new obligation requires entities to know what personal information they hold and the purposes for which that personal information can be used or disclosed. It also requires organisations to actively identify when personal information is no longer needed for the
The second new proposed security obligation requires entities to regularly test the effectiveness of their compliance with security and destruction/de-identification obligations, including the new obligation to know what information they hold.
What this means in practice
Entities will need to have a complete view of not just the personal information they hold, but also how and why it was collected, how it can be used or disclosed, and a clear view on when it is no longer required or can no longer be used or disclosed. This would most easily be achieved by a thorough data processing inventory, mapping not just the personal information holdings and systems, but purposes and processes too.
Entities will also need to establish robust assurance programs to regularly test the steps they are taking to protect personal information (including technical and organisational measures), as well as measures to destroy and de-identify personal information.
The Consultation Paper elaborates on this further, also noting that the regular assessments should consider whether de-identified information remains de-identified, and whether retaining it in de-identified form remains justified (i.e., a set and forget reliance on de-identification wouldn’t be enough).
Eligible data breaches
The draft legislation strengthens the notifiable data breach regime by simplifying and clarifying some obligations and clarifying that organisations have an obligation to contain a data breach and minimise harm to individuals even where the data breach is not notifiable. Entities would also be explicitly required to take reasonable steps to implement practices, procedures and systems that allow them to respond effectively to data breaches.
The amendments would also shorten the timeline for notifying the OAIC and impacted individuals from 30 days down to 72 hours of becoming aware that there are reasonable grounds to believe an eligible data breach has occurred. Where organisations don’t have all the facts within 72 hours, they may provide an initial notification followed by updates as further detail comes to light. The significantly shorter notification period aligns with other Australian regulation (such as under the Security of Critical Infrastructure Act 2018) and brings the Privacy Act into line with laws found in other parts of the world.
What this means in practice
Updating and testing data breach procedures will be important here, including clarity on decision making, as those notifying decisions must be made faster than they have been previously. Pre-prepared communications templates and well thought out comms processes will be extra helpful here in meeting those 72-hour timelines.
We expect that even with the best incident response procedures, in most cases it will be impossible to provide a complete statement about an incident to affected individuals within 72 hours. As a result, organisations should think carefully about how they will engage with and manage concerned customers and stakeholders in the window between initial notification and the completion of investigations.
Trading personal information (including disclosures for direct marketing)
An updated APP 4 will require organisations to obtain consent if they trade personal information. It sounds simple enough, until you read the definition of ‘trade’, which includes any disclosure of personal information for consideration or for the purposes of direct marketing. The Consultation Paper notes this should be interpreted broadly, stating disclosures of cookies or pixels in programmatic advertising processes may be a trade of personal information and therefore require consent.
There are also simplified, but slightly stricter direct marketing rules, which include stronger opt-out rights, and seek to clarify obligations between entities procuring the direct marketing and those delivering it.
What this means in practice
The broad definition of trading means that organisations should review all transactions that involve sharing or exchanging of personal information, even where that sharing is only incidental to a broader partnership or transaction.
Businesses leveraging cookies and pixels and disclosing personal information for direct marketing will need to review their consent to do so (and start obtaining it if they aren’t already). Don’t forget, there are new definitions for personal information and consent too.
Organisations will also need to review their arrangements with direct marketing providers to clarify that the necessary consents and opt-out arrangements are in place.
Conclusion
This is by no means all the changes introduced by the Privacy Amendment (Personal Data Protection) Bill 2026. Changes such as the ‘right to erasure’ on large digital platforms and boosting OAIC powers are also important but will only impact specific entities. The changes we have summarised above are those we consider will be the most significant to implement for all APP entities.
We’d encourage organisations to read the consultation paper (although the consultation is closed, the paper is still valuable background reading) and the exposure draft of the legislation.
You can also tune in to Episode 161 of our podcast plain.txt for a discussion of some of the implications of the new changes.