The next phase of Australian privacy reform has arrived with the tranche 2 exposure draft proposing around 40 changes to the Privacy Act. This signals a major shift towards greater accountability, stronger data security obligations for organisations and enhanced rights for individuals.
The Australian Government has proposed reforms to significantly uplift the Privacy Act 1988 (Cth) (Privacy Act) as a part of the second tranche of the federal privacy agenda. The exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 and accompanying consultation paper contains approximately 40 proposals, some of which are from the Attorney General’s Privacy Act Review Report (2023), and there are some additional proposals that aim to address emerging technologies. The consultation also seeks views on measures still under development in relation to emerging technologies such as smart glasses and connected vehicles.
The exposure draft signals a material shift in Australia’s privacy framework, with greater accountability across the personal information lifecycle and stronger obligations around data security, data minimisation and data breach response. It also proposes a simplified principles-based framework for handling personal information, strengthened consent requirements and a reformed direct marketing regime. The proposal to introduce a new right to erasure for personal information held by large digital platforms is also significant. We outline the key proposals being explored below.
Submissions are currently open and close on 18 September 2026.
If you want assistance in making a submission, or to understand what the proposed reforms could mean for your business, please get in touch with our privacy experts, Alex Hutchens, Melissa Miller and Belinda Breakspear.
How did this come about?
The proposed reforms are a part of a broader reform journey that were prompted by the ACCC’s Digital Platforms Inquiry Final Report (2019) which recommended privacy reform to respond to the increasingly complex digital environment that individuals are situated in and interact with. In response, the Australian Government committed in December 2019 to a comprehensive review of the Privacy Act. The Attorney-General released the Privacy Act Review Report in February 2023, making 116 recommendations and calling for further targeted consultations.
In December 2023, the Government agreed to 38 recommendations and 68 recommendations in principle. The Privacy and Other Legislation Amendment Act 2024 (Cth) was the first tranche of reforms which introduced higher penalties for serious or repeated privacy breaches, new notifiable data breach obligations, enhanced OAIC information-gathering powers, and civil remedies for serious invasions of privacy including doxxing.
As part of the Government’s ongoing commitment to implementing the Privacy Act Review, the measures in the proposed reforms seek to strengthen safeguards for individuals, provide greater clarity for regulated entities, and increase the effectiveness of the administration and enforcement of the Privacy Act by the Office of the Australian Information Commissioner.
Summary of proposals
| Proposed change | |
| Modernised core definitions | Updates and modernises key concepts, including: (a) broadening personal information to information that “relates to” an identified or reasonably identifiable individual; (b) expanding sensitive information to include new categories such as precise geolocation tracking data and genomic information; (c) clarifying that de-identification is context-dependent and not a permanent state; (d) clarifying when personal information is collected, including where information is generated or derived from other data, regardless of source; (e) introducing a clearer definition of disclosure based on making information accessible to another person or body; and (f) strengthening the requirements for valid consent by requiring it to be voluntary, informed, current, specific and unambiguous. |
| Fair and reasonable handling of personal information, consent and notice requirements | Replaces existing APPs 3, 4 and 6 with a simplified framework governing the collection, use and disclosure of personal information through a single requirement that handling be fair, reasonable and lawful. This framework introduces a principles-based “fair and reasonable” test assessed against a range of factors (such as reasonable expectations, transparency, data minimisation, genuine choice and proportionality) and simplifies notification requirements by requiring notices to be clear, concise and relevant. |
| Consent requirements for sensitive information and trading personal information | Requires organisations to obtain consent before collecting sensitive information or trading personal information, unless a specified exception applies. The reforms also introduce a statutory definition of “trade” covering disclosures for consideration or direct marketing purposes, subject to limited carve-outs. New exceptions would permit the collection of sensitive information from publicly available documents and where collection is strictly necessary to provide a requested good or service. |
| Reformed direct marketing regime | Replaces APP 7 with a simplified direct marketing framework, including a technology-neutral definition of direct marketing, mandatory opt-out mechanisms, and specific rules for ad-supported services and clarifies multi-party advertising arrangements. |
| Right to erasure for large digital platforms | Introduces a right for individuals to request the destruction of personal information held by large digital platforms, unless an exception applies. The right applies to online platforms that meet specified thresholds. |
| Enhanced data breach response obligations | Introduces a standalone definition of “data breach” (as distinguished from “eligible data breach”) and clarifies that entities have a positive obligation to take reasonable steps to contain a data breach and prevent or minimise harm to affected individuals, supported by appropriate response practices, procedures and systems. |
| 72-hour OAIC notification requirement and ongoing updates | Eligible data breaches must be notified to the Information Commissioner within 72 hours of becoming aware of reasonable grounds to believe the breach has occurred, with ongoing obligations to provide updated information where necessary. |
| Strengthened APP 11 security requirements | Strengthens APP 11 by specifying requirements relating to the protection, destruction and de-identification of personal information. This includes requiring entities to identify the personal information they hold, consider whether personal information no longer required should be destroyed or de-identified, and regularly evaluate the effectiveness of their security and information management measures. |
| Technical impossibility exception to access requests | Introduces a limited exception to an APP entity’s obligation to provide access to personal information where, despite taking reasonable steps, providing access remains unreasonable or impracticable due to technical impossibility or infeasibility. Where only part of the requested information is affected, entities must continue to provide access to any information that can reasonably be provided and comply with existing requirements regarding refusals and complaint mechanisms. |
| Controller/processor framework | Introduces a controller and processor model that allocates primary responsibility for privacy compliance to the controller, aligning Australia’s privacy framework more closely with international privacy regimes such as the GDPR and UK GDPR. |
| OAIC powers | Strengthens the OAIC’s complaint-handling, investigation and enforcement powers, including enhanced information-gathering powers, representative complaint management and enforcement of privacy complaint obligations. |
What should organisations do now?
With the Government signalling a significant uplift in privacy obligations and individual rights, Australia is at a turning point in the modernisation of its privacy regime. Organisations that want to make a submission to help influence this process should do so by 18 September 2026, and more generally, should continue to monitor developments, with the proposed legislation reportedly to be introduced into parliament this calendar year.
If you would like to understand what these changes mean for your organisation, or to make a submission, please get in touch with any of the partners from our Digital and IP team, Alex Hutchens, Melissa Miller or Belinda Breakspear.