From Compliance to Accountability: What the Latest Draft Privacy Reforms Signal for Organisations

By
No items found.
#
min read
From Compliance to Accountability: What the Latest Draft Privacy Reforms Signal for Organisations

What’s happening?

The Australian Government is seeking feedback on the next stage of reforms to the Privacy Act 1988 (Cth) (Privacy Act). Submissions on its Consultation Paper and the Privacy Amendment (Personal Data Protection) Bill 2026 (Cth) (Exposure Draft) close on 18 September 2026.

If enacted, the Exposure Draft would significantly change how personal information is defined, collected, used, disclosed, secured and deleted, and introduce new requirements for consent, direct marketing, data breaches and controllers and processors. The Exposure Draft also provides a useful basis for organisations to assess the potential impact on their privacy frameworks and information handling practices.

Ahead of the close of submissions on 18 September 2026, we have highlighted some of the key proposals for organisations to consider when assessing the reforms and responding to the Consultation Paper.

Why now?

The handling of personal information, and the expectations of the public, have changed significantly since much of Australia’s current privacy framework was developed. The  proposed reforms form part of the Government’s response to increasingly data-driven technologies and business models, including artificial intelligence (AI), connected devices and wearable technologies.

However, the reforms extend beyond emerging technologies and would reshape core privacy obligations across the information lifecycle.

Key themes emerging from the draft reforms

1. A new fair and reasonable test for collection, use and disclosure

(a) The Exposure Draft proposes a "fair and reasonable" test for the collection, use and disclosure of personal information. This would substantially restructure the existing Australian Privacy Principles (APPs), replacing APPs 3 and 4 and repealing APP 6, with collection, use and disclosure brought together under a new APP 3.

(b) A range of factors would be relevant to this assessment, including an individual’s reasonable expectations, whether the purpose could be achieved using less personal information, whether individuals are provided with genuine choice, the likely impact on individuals and whether an individual’s loss of privacy is proportionate to the benefits of the collection, use or disclosure. Consent may be relevant, but would not of itself determine whether information handling is fair and reasonable.

(c) Practical takeaway: Organisations should identify higher-risk collection, use and disclosure activities and document their purpose, necessity and likely impact. Existing Privacy Impact Assessments (PIAs) and privacy-by-design processes should also be reviewed to ensure they would capture and document the factors relevant to the proposed fair and reasonable test.

2. Additional protections for children’s personal information

(a) The proposed fair and reasonable test would include specific considerations where personal information relates to a child. In particular, the best interests of the child would need to be treated as a primary consideration when applying the relevant fair and reasonable factors.

(b) Practical takeaway: Organisations should identify products, services and information-handling activities involving children and build consideration of the child’s best interests into relevant PIAs, privacy-by-design assessments and product approval processes.

3. A new statutory test for consent

(a) The Exposure Draft proposes a new statutory test for consent (express or implied), requiring it to be voluntary, informed, current, specific and unambiguous. This would codify the OAIC’s guidance for valid consent and may require organisations to change when and how consent is obtained.

(b) Practical takeaway: Organisations should identify where consent is currently relied on and review the relevant forms, scripts, digital journeys and other consent mechanisms against the proposed requirements. In particular, organisations should review any reliance on pre-ticked boxes, default settings, bundled consents or inactivity and ensure that consent mechanisms provide individuals with sufficient information and a genuine choice, and are capable of producing consent that is voluntary, specific and unambiguous.

4. Expanded definitions of personal and sensitive information

(a) The Exposure Draft proposes to broaden the definition of personal information, including by replacing the existing requirement that information or an opinion be "about" an individual with a requirement that it "relates to" an identified or reasonably identifiable individual. The proposed definition would also clarify that an individual may be identifiable without their name or legal identity being known, including where they can be recognised or singled out.

(b) The definition of sensitive information would also be expanded, including to capture genomic information and certain precise geolocation tracking data. Information within these categories would therefore attract the additional protections applying to sensitive information under the Privacy Act.

(c) Practical takeaway: Organisations should review information they collect and hold to identify information that may become personal or sensitive information under the proposed definitions, particularly genomic and precise geolocation tracking data, and determine whether additional collection, access, security and consent controls would be required.

5. A proposed 72-hour data breach notification timeframe

(a) The Exposure Draft proposes changes to data breach notification obligations, including a proposed requirement to notify the Office of the Australian Information Commissioner (OAIC) within 72 hours once an organisation becomes aware of reasonable grounds to believe that an eligible data breach has occurred.

(b) This would introduce a fixed notification timeframe for the first time in Australia. Currently, once an entity has reasonable grounds to believe that an eligible data breach has occurred, it must notify the OAIC as soon as practicable, with no prescribed timeframe for notification. A separate requirement applies to suspected eligible data breaches, which entities must take reasonable steps to assess within 30 days.

(c) The Exposure Draft would also introduce broader data breach response obligations. Entities would be required to take reasonable steps to implement practices, procedures and systems to respond effectively to actual or suspected data breaches and prevent or reduce harm to affected individuals. Where an entity has reasonable grounds to suspect or believe that a data breach has occurred, it would also be required to take reasonable steps, as soon as practicable, to mitigate harm to affected individuals.

(d) The proposed notification requirements would also require entities to include the steps taken or proposed in response to the breach, including steps to mitigate harm. If all required information cannot practicably be provided within 72 hours, an interim notification could be made, with outstanding information provided as soon as practicable. Affected individuals would also need to be notified at the same time as the OAIC or as soon as practicable afterwards, with relevant updates provided where required.

(e) Practical takeaway: Organisations should test and update their data breach response plans to ensure rapid escalation and decision-making, immediate containment and harm-mitigation steps, and the ability to notify the OAIC within 72 hours even where the investigation is ongoing.

6. A proposed right to request erasure

(a) The Exposure Draft includes a proposed right for individuals to request erasure of personal information held about them by certain large digital platforms that meet specified user or revenue thresholds.

(b) If enacted, this would require those platforms to erase an individual’s personal information on request, subject to a number of exceptions, including where retention is required or authorised by law.

(c) Practical takeaway: In-scope large digital platforms should map where personal information is held, identify any technical or contractual barriers to deletion and establish processes for receiving, assessing and actioning erasure requests and applicable exceptions. Other organisations should continue to monitor whether the scope of the proposed right changes through consultation.

7. A new controller and processor framework

(a) The Exposure Draft would introduce statutory concepts of controllers and processors. Broadly, a processor would handle personal information on behalf of a controller and in accordance with the controller’s documented instructions.

(b) The proposed framework would allocate APP obligations differently between controllers and processors. A processor acting within the controller’s documented instructions would remain directly responsible for certain obligations, including APPs 1 and 11, while responsibility for other acts and practices undertaken on behalf of the controller would generally rest with the controller.

(c) Practical takeaway: Organisations should identify key outsourcing, cloud and service-provider arrangements, determine the likely controller and processor roles and ensure that relevant contracts clearly document processing instructions, responsibilities and the consequences of acting outside those instructions.

8. Changes to direct marketing

(a) The Exposure Draft proposes substantial changes to APP 7, including a statutory definition of direct marketing. Disclosure of personal information for direct marketing purposes would constitute trading in personal information and would generally require consent, subject to specified exceptions. Use of personal information for direct marketing would instead be subject to the proposed fair and reasonable test.

(b) The proposed framework would also require a simple means of opting out and information about how to opt out in each direct marketing communication, and introduce specific rules for certain ad-supported services.

(c) Practical takeaway: Organisations that engage in direct marketing should map how personal information used for direct marketing is sourced, used and disclosed, including disclosures to marketing platforms and other third parties. Existing consent wording, unsubscribe and opt-out mechanisms and marketing-provider arrangements should then be assessed against the proposed requirements.

9. Trading in personal information

(a) The Exposure Draft proposes a new statutory concept of trading in personal information. A person would trade in personal information where they disclose the information for money or other consideration, or for direct marketing purposes.

(b) Subject to specified exceptions, an organisation would be prohibited from trading in an individual’s personal information without the individual’s consent.

(c) If enacted, the Exposure Draft would also affect the small business exemption, under which small business operators (generally, businesses with annual turnover of $3 million or less) are generally exempt from the Privacy Act, subject to existing exceptions. A small business could not rely on the exemption if it trades in personal information or collects personal information from a person that trades in personal information, subject to specified exceptions.

(d) Practical takeaway: Businesses should identify arrangements in which personal information is disclosed for money or other consideration or for direct marketing purposes and assess whether the proposed consent requirement would apply. Small businesses should separately assess whether their activities affect their ability to rely on the small business exemption.

10. Changes to de-identification and APP 11

(a) The Exposure Draft would change the approach to determining whether information is de-identified, requiring regard to the circumstances at the relevant time and other information that is reasonably available. Information may cease to be de-identified if circumstances change or other reasonably available information enables an individual to be identified.

(b) The Exposure Draft also proposes changes to APP 11 relating to the security, retention and destruction of personal information, including requirements directed at identifying the personal information to which APP 11 applies and regularly evaluating the effectiveness of measures taken to comply with APP 11.

(c) Practical takeaway: Organisations should confirm what personal information they hold, where it is stored and how long it is retained; review whether retention and destruction schedules are being applied in practice; and reassess whether information treated as de-identified could become identifiable when combined with other reasonably available information.

11. Other proposed reforms

The Exposure Draft also proposes other changes, including amendments to APP 5 notification requirements and the APP 12 access framework. Separately, the Consultation Paper seeks feedback on matters not currently included in the Exposure Draft, including changes to OAIC complaint-handling and investigation powers and possible specific reforms for AI, wearable surveillance technologies and connected vehicles.

What does this mean for organisations today?

As of the date of publishing, the reforms remain subject to consultation and the final legislation may differ from the Exposure Draft.

While the proposed reforms do not require immediate compliance changes, organisations wishing to respond to the Consultation Paper should do so before submissions close on 18 September 2026. Additionally, organisations should consider where the proposed reforms may have the greatest impact on their existing privacy frameworks and information handling practices, including whether:

  • existing collection, use and disclosure practices are sufficiently understood and documented to be assessed against the proposed fair and reasonable test, with PIAs and privacy-by-design processes capable of supporting that assessment;
  • existing consent mechanisms would meet the proposed statutory test;
  • data inventories and classification practices appropriately identify information that may fall within the proposed definitions of personal and sensitive information;
  • direct marketing and personal information trading arrangements are understood and appropriately governed;
  • supplier, outsourcing and technology arrangements clearly identify controller and processor roles and responsibilities; and
  • security, retention, destruction, de-identification and incident response processes would support the proposed APP 11 and data breach requirements, including the proposed 72-hour notification timeframe.

Organisations can use the Exposure Draft to identify existing practices, systems and contractual arrangements that may require material change or significant implementation lead time if the reforms proceed, while continuing to monitor the consultation process and the final form and commencement of any legislation.

To discuss what the proposed reforms could mean for your organisation, or for assistance identifying practical next steps, please contact our Privacy team. We can work with you to assess the potential impact of the proposed reforms, prioritise key risks and opportunities, and ensure your organisation is well positioned for the evolving privacy landscape.

Share this Buzz