On 31 August 2026 the Australian Government released the Consultation Paper and Exposure Draft for the Privacy Amendment (Personal Data Protection) Bill 2026 (Draft Bill), marking the second tranche of reforms to the Privacy Act 1988 (Cth) (Privacy Act). If passed in its current form, the Draft Bill would be the most significant overhaul of Australia’s privacy framework since the Australian Privacy Principles were introduced in 2014. The reform package includes roughly 40 proposals, encompassing 25 that uplift privacy protections, five that simplify and clarify obligations, four additional simplification measures and seven measures to improve the efficiency of the OAIC as privacy regulator. Several measures proposed in the Draft Bill are also intended to “improve transparency, accountability and individuals’ control over their personal information, and help to address the privacy risks associated with emerging technologies”. Please see our ‘Smart glasses and privacy reforms’ article which discusses the changes specifically addressed to smart glasses and other emerging technologies.

This article provides a practical guide to the key changes proposed in the Draft Bill. The Government indicates it intends to introduce this legislation to Parliament before the end of 2026. Uncertainty remains as to the length of any transition period for implementation that may be afforded to organisations once the legislation is in force. It is clear nonetheless that entities need to act now on their gap analysis and compliance planning, noting the new proposed handling obligations set out under these changes will apply to all personal information held by an entity, regardless of when it was acquired - there is no grandfathering of obligations.

Submissions on the Draft Bill close on 18 September 2026.

Changes to core definitions

Schedule 1 of the Draft Bill proposes significant changes to several foundational definitions in the Privacy Act, including:

The broadened definitions will bring significantly more data within the scope of the Privacy Act. Critically, the Draft Bill introduces the concept of ‘individuation’ — an individual will be treated as reasonably identifiable even if their name or legal identity is not known, where information enables them to be recognised, singled out or otherwise dealt with as a distinct individual. This will have broad consequences for data analytics, programmatic advertising and data sharing arrangements, as the majority of cookie, pixel and web tracking data will likely need to be treated as personal information.

For many businesses, this means that datasets and practices previously considered outside the scope of the Privacy Act may now attract full regulatory obligations, requiring a comprehensive review of all data holdings and information-handling practices at an early juncture.

A new controller-processor framework

Schedule 6 introduces a controller-processor framework. A ‘controller’ is an APP entity on whose behalf a ‘processor’ handles personal information in accordance with the controller’s documented instructions.

Processors are exempt from the APPs other than APP 1 (open and transparent management) and APP 11 (security). However, if a processor acts outside the controller’s documented instructions, then the processor exemptions do not apply, and the processor would be directly responsible for any breach of the Privacy Act.

Conversely, a controller is treated as having committed a breach where the processor acts on the controller’s instructions and the breach would have occurred if done by the controller.

The controller-processor framework will require entities to clearly document the scope of processing instructions and allocate privacy responsibilities in their service agreements.

While the framework is modelled on the GDPR’s controller-processor distinction (Articles 26-28), there are notable differences. Unlike the GDPR, no minimum contractual content is prescribed for the controller-processor arrangement. Instead, the framework relies on the existence of documented written instructions specifying purpose. The OAIC is expected to issue guidance on what form these instructions should take. Technology suppliers may seek to position themselves as processors to benefit from the APP exemptions, which could increase contracting friction for customers. It is also important to note that the processor exemptions do not extend to the Notifiable Data Breach Regime — both controllers and processors remain independently subject to those obligations.

New ‘fair and reasonable’ test

Schedule 2, Part 1 of the Draft Bill introduces a single, principles-based ‘fair and reasonable’ test for the collection, use and disclosure of personal information. Rather than focusing on whether an organisation has obtained consent or provided a privacy notice, the new test requires organisations to assess whether their handling of personal information is objectively fair and reasonable in the circumstances.

Commentators have described the fair and reasonable test as a world-first. Unlike the EU General Data Protection Regulation (GDPR), which prescribes specific lawful bases for processing (such as consent, legitimate interests or contractual necessity), Australia’s proposed test is grounded in legislation which has traditionally taken a principles-based approach. This will not change under this new test. This means that its operative meaning will be developed over time through OAIC guidance, regulatory determinations and, potentially, litigation. The test further, and comprehensively, shifts the burden of privacy protection from individuals onto organisations, requiring those who collect and use personal data to actively justify their practices.

The Draft Bill provides that the test requires a holistic assessment based on seven legislated factors:

  1. The reasonable expectations of the relevant individual
  2. The relationship of the collection, use or disclosure to the relevant entity’s functions or activities
  3.  Transparency about the collection, use or disclosure
  4.  Data minimisation
  5. Whether the individual has a genuine choice
  6. The impacts on the individual and the proportionality of those impacts
  7. The best interests of the child (where relevant).

Organisations will need to look beyond rudimentary compliance with notice and consent requirements and must be able to demonstrate that their data handling practices are fair and reasonable in substance and practice.

Importantly, existing APPs 3, 4 and 6 would be repealed and replaced by the new framework. The distinction between primary and secondary purposes will be no longer – these are effectively subsumed into the holistic assessment. While this simplifies the framework, it introduces significant ambiguity. Organisations will need to document their assessment against each factor for every material data handling activity – a substantial compliance undertaking. The absence of clear weighting between the factors means that a collection which is otherwise transparent and voluntary may still fail the test if the purpose could be achieved with less personal information (the data minimisation factor).

Further, the ‘fair and reasonable’ test will apply to the collection, use and disclosure of personal information immediately from commencement of the proposed reforms, regardless of when the information was acquired – even for information collected and held before that date.

This means that entities with existing consents in place for the use or collection of personal information will need to review and assess whether their ongoing handling of that information satisfies the new test – regardless of the consents currently held.

The Draft Bill has not provided specific practical guidance for how the Office of the Information Commissioner (OAIC) will assess whether an entity’s practices satisfy the proposed test. This is a principles-based assessment, and how the OAIC interprets and enforces the test in practice will be one of the most critical issues for regulated entities to monitor if the proposed reforms are implemented.

This lack of prescriptive guidance stands in contrast to the GDPR, where the European Data Protection Board has issued extensive guidance on lawful bases and legitimate interests’ assessments.

Entities should therefore anticipate a period of regulatory uncertainty as the OAIC develops its interpretive approach. From a practical standpoint, the compliance burden is likely to be high as businesses come to terms with the material administration and costs impact that reviews and compliance with this test will likely impose.

The Draft Bill also introduces targeted consent requirements for two higher-risk activities:

  1. collecting sensitive information
  2. trading personal information. While the broader reforms reduce reliance on consent as the primary basis for handling personal information, consent will remain a key requirement in these specific contexts.

Importantly, the concept of ‘trading’ personal information is defined broadly and includes disclosures of personal information for monetary or other consideration, as well as disclosures for direct marketing purposes. The inclusion of direct marketing disclosures within the trading definition is a significant departure from the current framework, under which direct marketing is regulated through APP 7 primarily by way of opt-out mechanisms. By characterising direct marketing disclosures as ‘trading’, the Draft Bill would elevate these disclosures to require mandatory prior consent – a fundamentally higher regulatory standard. The Consultation Paper confirms that disclosure “for the purposes of direct marketing” is intended to be interpreted broadly and includes disclosures that support or inform direct marketing, even where marketing is not the sole purpose. This would capture, for example, disclosures of cookies or pixels in programmatic advertising processes.

While the new ‘fair and reasonable’ test provides greater flexibility for many data handling activities, organisations that collect sensitive information or share personal information for commercial or marketing purposes should carefully review their practices in light of the proposed changes. Activities that may not previously have been characterised as data trading could now trigger specific consent obligations.

Ther are four carve-outs identified from the trading definition, which are a disclosure:

  1. necessary to provide a product or service requested by the individual
  2. incidental to the sale or transfer of a business, provided the disclosure of personal information is not the substantial purpose of the transaction
  3. to a processor acting on behalf of a controller in accordance with documented instructions
  4. necessary to prevent, detect, investigate or remedy unlawful activity or serious fraud-related misconduct.

These carve-outs will require careful analysis. Commentators note that the business sale carve-out, while welcome, leaves substantial uncertainty where customer data is central to an asset sale transaction. The limitation of the misconduct exception to fraud-related wrongdoing is also a concern, given the wider range of serious misconduct that may warrant data sharing.

Changes to Direct Marketing Schedule 2, Part 3 of the Draft Bill introduce a new, technology neutral definition of direct marketing designed to reflect modern marketing practices.

Under the proposed definition, direct marketing includes any advertising or marketing directed to an individual using their personal information, whether the individual is targeted specifically or as part of a broader audience. The definition expressly captures traditional channels such as email, SMS and telemarketing, as well as targeted social media advertising and online behavioural advertising that relies on personal information.

Organisations that use personal information for advertising, audience targeting or behavioural advertising should review their marketing practices, privacy disclosures and opt-out mechanisms to ensure they would comply with the expanded direct marketing framework proposed.

The Draft Bill also introduces specific provisions for ‘ad-supported services’ – services that derive revenue from direct marketing communications. Ad-supported services are not required to continue providing the same service to individuals who opt out of marketing but must offer a genuine choice to continue using the service without receiving direct marketing. This approach draws on the ‘consent or pay’ model debated under the UK and EU GDPR frameworks. Whether the alternatives offered constitute genuine choice will be assessed by reference to the fair and reasonable test, including whether dark patterns are used to influence decisions.

New data breach reporting requirements

Schedule 3 of the Draft Bill also strengthens the data security and breach notification framework under the Notifiable Data Breach Regime:

These reforms shift the focus from merely providing notification to actively preparing for, responding to and mitigating an eligible data breach.

Entities must, at a minimum:

  1. Review their incident response plans to include clear escalation pathways, pre-delegated decision-making authority, and rapid triage processes that can determine whether the threshold for an eligible data breach is met within the compressed timeframe.
  2. Ensure they can identify their personal information holdings. The Draft Bill expressly requires entities to be able to identify the personal information they hold. This is a precondition to effective breach response - an entity cannot assess the scope and severity of a breach, or notify affected individuals, if it does not know what personal information it holds and where it is stored.
  3. Implement proactive breach preparedness systems. The Draft Bill also introduces two new standalone obligations requiring entities to take reasonable steps to implement practices, procedures and systems that enable them to respond effectively to data breaches and prevent or reduce harm (preparedness) and take reasonable steps to prevent or reduce harm (to the individuals to whom the information is involved) where a suspected data breach has arisen (mitigation). A failure to comply with the preparedness obligation, or the mitigation obligation each constitute a separate ‘interference with the privacy of an individual’ which are enforceable.
  4. Prepare for staged reporting to the OAIC.

The Draft Bill also preserves the existing two key carve-outs from the notification obligations – the remedial actions exception and secrecy provisions exception. The 30-day assessment period for suspected eligible data breaches is also preserved. The 72-hour notification obligation is triggered only once the entity forms reasonable grounds to believe an eligible data breach has in fact occurred.

Whilst the introduction of the 72-hour notification time period is not unexpected – noting that it aligns with the GDPR (Article 33), the Security of Critical Infrastructure Act 2018 (Cth) and the Cyber Security Act 2024 (Cth), there is a critical distinction: unlike the GDPR, the Draft Bill requires entities to provide reasons justifying any omissions in an incomplete notification – imposing an additional administrative burden during what is typically a chaotic incident response period. Where it is impossible or impracticable to provide a complete statement within 72 hours, entities may submit an incomplete statement accompanied by a statement of reasons, to be updated as further information becomes available. Failure to provide any statement within 72 hours may result in an infringement notice, compliance notice, or constitute an interference with the privacy of an individual.

Right to erasure

The Draft Bill introduces a right to erasure on large digital platforms (LDPs). LDPs are defined as entities that:

  1. provide a social media service, relevant electronic service, or designated internet service under the Online Safety Act 2021 (Cth) (Online Safety Act)
  2. have a gross revenue of $500m or more, or have $2.5m or more average monthly end users in Australia.

LDPs must destroy personal information on request unless one of the following four exceptions applies:

  1. A permitted general situation or permitted health situation exists
  2. An Australian law or court order requires retention of the information
  3. It is technically impossible or infeasible to comply
  4. The information is strictly necessary for an ongoing good or service.

Although the right to erasure is limited to large digital platforms, it represents a significant expansion of individual privacy rights in Australia. Affected organisations will need robust data governance processes to ensure they can promptly locate and delete personal information on request, while balancing competing legal and operational obligations to retain data.

While the right to erasure is modelled on Article 17 of the GDPR, it is significantly narrower in scope. The GDPR provides a right to erasure applying to all data controllers, whereas the Draft Bill limits the right to large digital platforms. The original Privacy Act Review recommended a broader right for all entities; the Productivity Commission subsequently cautioned against this approach, and the Government has proceeded in limited form. However, the potential scope of ‘large digital platforms’ may be broader than first appears. ‘Designated internet service’ under the Online Safety Act captures services enabling end-users to access or deliver material via the internet, which could extend to financial services entities and online retailers with a significant digital presence, provided the revenue or end-user thresholds are met.

OAIC powers and efficiency

The Consultation Paper highlights that the final bill is intended to include measures designed to strengthen the OAIC’s regulatory role and improve the efficiency of the OAIC, through key measures such as enhancing the Privacy Act’s early dispute resolution processes and expanding the OAIC’s investigation, case management and enforcement capabilities, particularly in relation to representative complaints.

These measures are intended to equip the OAIC to respond more effectively to the increasing volume and complexity of privacy matters, driven by rapid technological changes and heightened public awareness of privacy rights. Streamlining complaint handling processes and providing more robust regulatory tools would enable more efficient resolution of privacy issues, facilitate more effective investigations, and improve the OAIC’s ability to achieve regulatory and enforcement outcomes.

A focus: Regulated financial services impacts

Financial services entities are among the most data-intensive organisations in Australia, collecting and processing large volumes of personal and sensitive information (including financial data, health information for insurance underwriting and precise geolocation data through banking apps). The proposed reforms will be particularly significant for entities in the banking, insurance, superannuation, Fintech and wealth management sectors.

Key implications for regulated financial services entities include:

  1. The expanded definition of personal information and the individuation concept will likely mean that customer behavioural data, transaction patterns and device identifiers used in fraud detection and credit scoring are captured as personal information.
  2. The trading definition may affect data sharing arrangements within corporate groups, with third-party service providers and in the context of referral and distribution arrangements where commissions or fees are paid.
  3. The 72-hour data breach notification window will require uplift to incident response capabilities, particularly given that financial services entities are already subject to overlapping notification obligations under APRA Prudential Standard CPS 234 and the SOCI Act.
  4. Entities meeting the large digital platform thresholds (for example, large banks and insurers with significant online service platforms) may become subject to the right to erasure, requiring robust processes to locate and destroy personal information on request.
  5. The fair and reasonable test will require reassessment of practices such as credit scoring, algorithmic underwriting, loyalty programs and personalised product recommendations, with particular attention to the genuine choice and proportionality factors.

At a minimum, the interaction between the proposed Privacy Act reforms and existing sector-specific obligations under APRA prudential standards, the AML/CTF Act and the Consumer Data Right framework will require careful navigation.

Implementation timeline and transition

Neither the Draft Bill nor the Consultation Paper specifies a commencement date or transition period. The commencement dates for each Schedule of the Draft Bill are currently blank.  However, the Consultation Paper notes that consequential amendments and transitional provisions will be incorporated once settled and invites views on the optimal approach.

Importantly, as highlighted above, the Draft Bill provides that the new handling obligations will apply to all personal information held by an entity, regardless of whether it was acquired before or after commencement – meaning there is no grandfathering of existing data practices.

The Government has indicated it intends to introduce legislation to Parliament before the end of 2026. We expect there will be a period of transition provided for entities to get up to speed with the new changes – noting their material impact for many – although it is difficult to confirm the length of time that may be provided. Notably, the Information Commissioner has been heralding a ‘fair and reasonable’ test for some time – at least since the 2023 Privacy Act Reviews – and some may say she provided ample warning of a need for organisations to review and update their privacy handling practices to meet the new test. The period for transition may not be as long as many businesses might hope – particularly if the current consultation period provided for this Draft Bill is anything to go by.

Based on Tranche 1 experience, any uplift to regulatory powers and penalties is expected to take effect immediately upon Royal Assent. Entities should therefore use the current consultation period to identify their key compliance gaps and begin planning their implementation programs now, as the window for preparation may be compressed.

What’s missing from the Draft Bill

While the Draft Bill is comprehensive, several significant proposals from the 2023 Privacy Act Review remain unaddressed. For example:

  1. The small business exemption (which exempts businesses with annual turnover under $3 million) has not been removed, despite the original recommendation. This exemption continues to exclude a large proportion of Australian businesses from the privacy framework and remains a barrier to achieving EU adequacy status for cross-border data transfers.
  2. Similarly, the employee records exemption under section 7B(3), which permits private sector employers to handle employee records outside the APPs, also survives unchanged.
  3. No direct right of action for individuals to sue for privacy interferences has been included — although the statutory tort for serious invasions of privacy (introduced in Tranche 1) provides a partial remedy.
  4. Mandatory privacy impact assessments for high-risk activities, which were recommended by the Review, are absent.
  5. There are no standalone AI-specific obligations beyond the automated decision-making transparency requirements enacted in Tranche 1 (commencing 10 December 2026).
  6. The political and journalism exemptions also remain unchanged.

The absence of these reforms means the Draft Bill, while a meaningful step, does not deliver the comprehensive overhaul some stakeholders anticipated and may also limit Australia’s prospects of obtaining an EU adequacy determination under the GDPR – a long-awaited hope by many international organisations doing business in Australia.

Key takeaways

The proposed reforms are broad, but their practical implications can be distilled into a number of key takeaways that organisations should begin considering now.

Key takeaway

Key actions

Significantly more data will be regulatedConduct a comprehensive data mapping exercise to identify information that may now constitute personal or sensitive information under the expanded definitions. In particular, assess whether cookie data, pixel tracking data, device identifiers and behavioural analytics may be captured by the new ‘individuation’ concept, under which individuals are treated as reasonably identifiable even where their name or legal identity is not known. Review whether precise geolocation tracking data or genomic information is collected and, if so, ensure appropriate consent mechanisms are in place.
The ‘fair and reasonable’ test will replace existing collection, use and disclosure rulesReassess all data collection, use and disclosure practices against the seven legislated factors set out in the Draft Bill. Document this assessment for each material data handling activity. Existing consents will not be sufficient on their own - entities must be able to demonstrate that their ongoing handling of personal information (including information collected before commencement) is objectively fair and reasonable. Anticipate a period of regulatory uncertainty as the OAIC develops its interpretive guidance.
Direct marketing and ‘trading’ rules are fundamentally changingIdentify all disclosures of personal information for monetary or other consideration, or for direct marketing purposes, which will now be classified as ‘trading’ and require mandatory prior consent. This is a new concept in the Privacy Act. Review programmatic advertising arrangements, data sharing with third-party marketing partners, and any disclosure of cookies or pixels that supports direct marketing. For ad-supported services, assess whether the alternatives offered to individuals who opt out of marketing provide a genuine choice. Update consent mechanisms and opt-out processes to comply with the expanded framework.
Data breach obligations are materially increasingUpdate incident response plans to meet the mandatory 72-hour notification requirement and the new positive obligation to contain breaches and mitigate harm.
A new controller-processor framework will reshape vendor accountabilityReview all vendor and outsourcing arrangements involving personal information. Clearly document controller instructions specifying the purposes for which processors may handle information. Ensure processors understand that they remain directly responsible for APP 1 (open and transparent management) and APP 11 (security), and that acting outside documented instructions removes the processor exemptions entirely. Notifiable data breach obligations continue to apply independently to both controllers and processors.
Implementation timeline is uncertainBegin gap analysis and compliance planning now, as commencement dates are currently blank and the window for preparation may be compressed. The new handling obligations will apply to all personal information held by an entity regardless of when it was acquired – there is no grandfathering. Monitor the progress of the Draft Bill through Parliament and we recommend advocating for transition periods of at least one to two years, consistent with the approach taken for the APPs and the GDPR.
Significant structural reforms remain outstandingMonitor whether the small business exemption (which excludes businesses with annual turnover under $3m), the employee records exemption, mandatory privacy impact assessments and a direct right of action for individuals are addressed during the Parliamentary process or in a future reform tranche. The retention of the small business exemption in particular remains a barrier to Australia achieving EU adequacy status under the GDPR. Consider if this is an area you wish to raise in the consultation process.

Submissions are open

Consider making a submission in response to the Draft Bill and its accompanying Consultation Paper. Given the short consultation window, we recommend that entities should prioritise escalating concerns about unintended consequences, implementation costs and transition periods. Submissions close on 18 September 2026.

If you have questions about the submission process or how these Privacy Act Tranche 2 reforms may affect your business, please feel free to contact any member of our team.

This update does not constitute legal advice and should not be relied upon as such. It is intended only to provide a summary and general overview on matters of interest and it is not intended to be comprehensive. You should seek legal or other professional advice before acting or relying on any of the content.