Nearly seven years after the first announcement of a review of the Privacy Act 1988 (Cth) (the Act), on 31 August 2026, the Attorney-General released the long-awaited Exposure Draft of the Privacy Amendment (Personal Data Protection) Bill 2026 (the Bill) alongside a detailed consultation paper. The package contains roughly 40 proposals, including approximately 30 drawn from the then Attorney-General’s review of the Act (Review) and seven additional measures to “improve the efficiency of the privacy regulator”.

In comparison with the measured response that the government provided to the Review and the modest changes introduced by the first tranche of reforms to the Act, the Bill represents a decisive shift in the government’s approach and will require organisations to substantially overhaul how they collect, use and manage personal information.

History of privacy reform

Consultation on the Bill closes on 18 September 2026 with submissions capped at 1,000 words. Such a short consultation timeline and compressed word limit suggests the government’s direction is largely set, so organisations should consider, as part of the consultation, whether there are any exceptions to the rule or unintended impacts which the government should consider, rather than challenging fundamental changes.

Reform highlights

Changes to core definitions underlying amendments

The Bill updates core definitions and introduces new ones:

  • Personal information: the definition changes from information ‘about’ an individual to information that ‘relates to’ an identified or ‘reasonably identifiable’ individual. The Privacy Commissioner (Commissioner) has been strongly supportive of this change since her appointment, which expands the types of information that can be captured and brings Australia in line with the definition of ‘personal data’ in the GDPR.
    • Less anticipated, and much more significant, is the note accompanying the proposed definition – an explanatory tool with expansive impact. This states that an individual can be identified, or reasonably identifiable, even if their name or legal identity is not known but the information allows them to be ‘singled out’. The change signals a significant departure from existing interpretations (other than perhaps the Commissioner’s own) of what might amount to ‘personal information’, is a definitive move to the developing concept of individuation and sits uneasily with current practices regarding the use of de-identified information. The Commissioner foreshadowed this shift in the law in two of her recent determinations (in which the Commissioner consciously broadened the interpretation of personal information towards individuation). Notably, the Review expressly discussed and discarded this change given the risk of unintended consequences, instead favouring a more focused approach on targeted advertising. The move to individuation potentially has broad-ranging impacts for many businesses, particularly those that rely on tokenised data for any activities. It would require the application of a different layer of analysis to all data uses, including those subject to additional restrictions under the proposed new reforms.
  • Collects: the existing definition is clarified to capture any source from which information could be collected, explicitly bringing within scope the collection of publicly available information and screen-scraping. Another ‘note’ under the definition clarifies that generating or deriving information still amounts to collection – a change the Commissioner will likely be pleased to see. Further provisions in the definition relating to the collection of sensitive information that is derived from personal information will also require some effort to operationalise.
  • (new) Disclosures: information is disclosed when made accessible to another person or body. Mere transmission or storage is not disclosure unless the information is made accessible  . This departs from the Commissioner’s current guidance on the term which includes the concept of ‘releasing from effective control’, but arguably reflects the current reality in the market. In assessing compliance with APP 8 in offshore data storage contexts, this shift will need to be considered.
  • Sensitive information: expanded to include:
    • ‘geolocation tracking data’, being location information within a 500-metre radius collected and held over time; and
    • ‘genomic information’, relating to genetic characteristics, biological relationships or potential health risks.
  • When these concepts, and the requirement for consent to collect (as discussed below), are coupled with the concept of individuation (such that you do not need to identify the individual, as long as they can be ‘singled out’), there are some clear challenges for many organisations that collect device-based location data, including to support things like scam and fraud management.
  • De-identified: the Bill has introduced a temporal element so that information or an opinion is de-identified ‘at a particular time’, clarifying that de-identification is a continuous assessment. This reflects concerns regarding evolving re-identification risks in the age of AI.
  • Consent: the definition mirrors existing guidance and interpretation that consent must be voluntary, informed, current, specific and unambiguous. However, it is inexplicably silent on capacity, calling into question what this means for children and vulnerable people.

The fair and reasonable test

Possibly the most anticipated and one of the most notable changes is the introduction of the ‘fair and reasonable test’ which replaces the separate APP 3, 4 and 6 obligations with a single test of whether the collection, use and disclosure (handling) of personal information is ‘fair and reasonable in the circumstances’ and ‘lawful’.

Under the current regime, most organisations rely on privacy policies, consent and collection notices as their primary compliance tools. Going forward, that may not be enough, as handling of personal information may be non-compliant even where (in some circumstances) consent has been obtained and the necessary disclosures have  been made, if the handling is not fair and reasonable in the circumstances.

The Bill sets out seven non-exhaustive factors to determine whether the handlingof personal information is fair and reasonable in the circumstances, which are:

  • reasonable expectations of the individual
  • connection to the entity’s functions or activities
  • transparency
  • whether the purpose for handling could be met by collecting less information (data minimisation)
  • whether the individual was given a genuine choice in relation to the handling
  • the impact on the privacy of the individual and the proportionality of such impact
  • in the case of a child, consideration of their best interests.

No single factor is determinative. The assessment is intended to be holistic and principles-based, with exceptions for permitted general situations, permitted health situations or handling required or authorised by law.

The test may be difficult to apply in practice and risks over-lawyering what should, in most cases, be a straightforward decision for organisations. The OAIC is expected to publish practical guidance and examples which will hopefully provide some clarity as to how to apply the test.

Importantly, the test is distinct from consent, and an entity will need to satisfy both the fair and reasonable test and obtain consent to collect sensitive information or ‘trade’ personal information. This means that the current paradigm of centring compliance on a consent mechanism will no longer be sufficient and organisations will need to review their practices by reference to a wider range of considerations.

Right to erasure

The Bill would introduce a right to erasure for individuals whose personal information is held by a large digital platform (LDP). LDPs are defined as providers of social media, relevant electronic or designated internet services that meet one or both of the following thresholds:

  • gross revenue of at least $500 million for the business, including overseas entities; and/or
  • at least 2.5 million average monthly end users (not defined) in Australia.

On request, an LDP must destroy the information, give written notice of the outcome within a reasonable period, and explain any exception relied on.

Exceptions include permitted general or health situations, legal retention requirements, technical impossibility or infeasibility after reasonable steps, information strictly necessary to continue a requested service, and frivolous or vexatious requests.

Relevantly, the Bill leaves scope for potential dispute over what amounts to reasonable steps in particular circumstances, particularly for complex or legacy systems.

Processor and controller framework

To align with the framework in many other jurisdictions, the Bill introduces a controller-processor distinction broadly consistent with the Review’s proposal. An APP entity is a ‘processor’ when it acts in accordance with another APP entity's documented written instructions for purposes specified in those instructions, and the instructing entity is the ‘controller’. The definition applies only where both entities are APP entities and excludes contracted service providers for Commonwealth contracts, who remain governed by the existing section 95B framework.

Significantly for those companies who regularly act as processors, a processor within this meaning is exempt from all APPs except APP 1 (open and transparent management) and APP 11 (security), with breaches by the processor attributed to the controller. Notably, the Bill does not adopt the OAIC's recommendation on this change regarding mandatory contractual terms modelled on Article 28 of the GDPR, nor does it implement the Review’s proposal to bring non-APP entity processors (such as small businesses) into scope when processing on behalf of an APP entity controller.

Data security and breach notification

The Bill significantly strengthens the data breach and security framework. For eligible data breaches - those likely to result in serious harm - entities must notify the OAIC within 72 hours, and where practicable, notify affected individuals at the same time (otherwise, as soon as practicable after). Initial statements may be incomplete where full reporting is impossible or impracticable within the 72-hour window, but entities must follow up with outstanding information and notify the OAIC of any material changes or errors as soon as practicable. The new proposed timeframe of 72 hours is consistent with the GDPR and the Cyber Security Act 2024 (Cth) (in respect of ransomware reporting) but mandates a shorter timeframe than a written report is required under the Security of Critical Infrastructure Act 2018 (Cth) in respect of ‘critical’ incidents in that act.

Beyond notification, the Bill introduces a distinct obligation to implement practices, procedures and systems that enable effective breach response, including by maintaining and regularly testing a data breach response plan. This effectively mandates a standing data breach response capability. Separately, a new harm mitigation obligation applies to all data breaches - not just eligible data breaches that meet the serious harm threshold - requiring entities to take reasonable steps to prevent or reduce harm as soon as practicable after becoming aware of a suspected breach.

On the security side, the reformulated APP 11 requires entities to identify the personal information they hold, consider destruction before defaulting to de-identification, and regularly evaluate the effectiveness of their security and data retention compliance.

Critically, failures to comply with these obligations carry real enforcement consequences. A failure to implement effective breach response practices, a failure to mitigate harm, a failure to notify within 72 hours, and a failure to provide follow-up notices each constitute an ‘interference with the privacy of an individual’, exposing entities to the OAIC's full enforcement toolkit, including civil penalties of $50 million for bodies corporate under the existing penalty framework.

Trading personal information

The Bill introduces a standalone concept of ‘trading’ personal information. Trading covers an organisation's disclosure of personal information for:

  • money, other consideration; or
  • direct marketing .

An organisation is prohibited from trading personal information without the individual's consent, unless an exception applies. In practice, this means that customer-list transfers, audience matching, and certain AdTech arrangements (including tracking pixels, which are on the Commissioner’s radar) will all need to be assessed as potentially comprising ‘trading’ requiring consent.

The Bill includes several carve-outs, including disclosures necessary to provide a product or service requested by the individual, and disclosures that are merely incidental to a transaction where trading is not a ‘substantial purpose’ of the disclosure. Interestingly, what constitutes a ‘substantial purpose’ is not made clear, potentially creating tension at the heart of the exception. How that term is interpreted, whether by the OAIC in guidance or through early enforcement, may go on to affect the scope of the trading prohibition, and organisations that rely on this carve-out in the interim will be navigating this uncertainty.

Permitted general situation

The Bill amends Permitted General Situation 2 (PGS 2) by replacing ‘misconduct of a serious nature’ with the broader concept of ‘wrongdoing of a serious nature,’ extending PGS 2 to cover serious wrongdoing in a private capacity - including financial abuse and conduct by persons external to the entity.

Reforms that need further clarification

Sensitive information framework

One change that may attract scrutiny during the consultation process is the removal of the heightened protections that currently apply to the use and disclosure of sensitive information. Under the current Act, APP 6.2(a) requires that any secondary use or disclosure of sensitive information be ‘directly related’ to the primary purpose of collection - a narrower standard than the ‘related to’ test that applies to other personal information. Similarly, APP 7 currently prohibits the use of sensitive information for direct marketing unless the individual has consented. The Bill replaces these category-specific rules with the unified fair and reasonable test, under which sensitivity would be a relevant consideration but is no longer the subject of a standalone structural protection . Whether the general test will provide equivalent safeguards in practice, particularly for health, biometric and geolocation data, all of which fall within the expanded definition of sensitive information, is likely to be a key issue for regulators and stakeholders.

Direct marketing

The Bill replaces the current APP 7's layered direct marketing framework - which draws detailed distinctions based on the source of collection, whether information is sensitive, and whether the individual would reasonably expect the communication - with a  slimmed-down, technology-neutral regime.

Organisations must provide a simple opt-out mechanism, take reasonable steps to give effect to opt-out requests, and include opt-out information in each communication. A modified rule permits ad-supported services to offer the service on different terms to individuals who opt out, provided the individual retains a genuine choice to continue using the service without receiving direct marketing. Notably, the Bill does not adopt several of the Review’s more interventionist proposals, including the unqualified right to opt out of targeted advertising  and the prohibition on targeting based on sensitive information.

Reforms that were left out

Several significant reforms recommended by the Review remain absent from the exposure draft.

Most notably, the Bill does not address the small business exemption or the employee records exemption, both of which the Review recommended be removed or reformed. The persistence of each of these exemptions is particularly significant in an international context, as it remains a key barrier to Australia obtaining a GDPR adequacy decision from the EU.

Timing and next steps

The government has indicated plans to table legislation in Parliament before the end of the calendar year. Coupled with the short consultation timeframe, this signals an urgency not witnessed in the privacy reform space to date.

Finally, while we do not have dates or the government’s view on a transition period, there is clarity in the Bill that many of the new requirements are proposed to apply equally to information collected before the commencement of the Bill, as well as after. This will require, in most cases, a broad reassessment of all handling of personal information already held by organisations.