On 31 August 2026, the Australian Government released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 (Draft Bill) and accompanying consultation paper, marking the long-awaited arrival of the second tranche of privacy reforms to the Privacy Act 1988 (Cth) (Privacy Act).
The Draft Bill proposes a broad package of reforms, including:
- amendments to key privacy definitions;
- a new "fair and reasonable" test for collection and handling personal information;
- strengthened consent and data security requirements;
- a right to erasure; and
- introduction of a controller and processor framework.
Stakeholders have until 18 September 2026 to provide submissions on the proposed reforms. This article highlights six key reforms proposed by the Draft Bill.
This article highlights six key reforms proposed by the Draft Bill.
Key proposed reforms
1. Changes to privacy definitions
The most notable amendments include:
|
Key Definition |
Amendment |
|
|
|
|
Collects |
Clarifies that an entity is not taken to collect sensitive information merely because it holds personal information from which sensitive information may be derived. The intention is to ensure that the obligations applying to the collection of sensitive information (including the requirement for consent) do not arise solely because of collection of personal information that incidentally is also capable of revealing a sensitive attribute. Instead, the concept of "collection" of sensitive information would require that an entity either collects it for a purpose that involves using or disclosing it as sensitive information or otherwise when it is first used or disclosed as sensitive information or separately recorded. |
|
Consent |
Requires consent to be voluntary, informed, current, specific and unambiguous. The definition retains the possibility that consent may be implied. However, given the additional requirements for consent, the circumstances in which consent can be implied are likely to be significantly narrower than under the current definition. |
|
Personal Information |
Expanded to information that "relates to" an identified or reasonably identifiable individual, rather than information that is "about" an individual. New notes to the definition of personal information clarify that an individual can be reasonably identifiable even if the individual's legal identity is not known - for example, if an individual can be "singled out" or dealt with as a distinct individual (such as based on a pseudonym, location data, behaviours or patterns of activity). This is likely to capture information such as website tracking data not associated with a named individual. |
|
Sensitive Information |
Expanded to include precise geolocation tracking data, being location data that enables the tracking or monitoring of an individual's movements over time. |
|
Trade |
Introduction of a new concept of "trading" personal information. Disclosure of information by an organisation is a trade of that information if the organisation discloses the information: a. for money or other consideration; or b. for the purposes of direct marketing. Trading in personal information will require consent in all cases which, based on the proposed definition of consent, must be voluntary, informed, current, specific and unambiguous. |
2. Fair and Reasonable Handling of Personal Information
The Draft Bill proposes to replace existing APPs 3, 4 and 6 (collection, use and disclosure framework) with a new requirement that personal information may only be collected, used or disclosed where the handling is both:
- fair and reasonable in the circumstances; and
- lawful.
In determining whether handling is fair and reasonable, organisations would be required to consider a range of factors, including:
- an individual's reasonable expectation;
- transparency regarding information handling practices;
- whether less personal information could be used;
- whether individuals are provided with a genuine choice;
- privacy impacts and the risk of harm; and
- where a child is involved, the best interest of the child as a primary consideration.
This requirement imposes a significantly higher threshold that must be met by organisations collecting, using and disclosing personal information. In particular, the requirement introduces:
- a new requirement to consider reasonable expectations of individuals;
- a concept of data minimisation by requiring organisations to consider whether the same purpose can be achieved with less personal information; and
- a requirement to consider the best interests of children (consistent with requirements under the draft Children's Online Privacy Code).
3. Strengthened Consent Requirements
The Draft Bill would strengthen consent requirements under the Privacy Act by prohibiting organisations from collecting sensitive information, or trading personal information, without an individual's consent unless an exception applies.
The reforms place greater emphasis on ensuring individuals have genuine choice and meaningful control over how their personal information is handled. Organisations may therefore need to review existing consent mechanisms, particularly where they rely on broad disclosures, bundled consents or online collection practices that do not provide clear and specific choices to individuals.
4. Strengthened Data Security and Breach Notification Obligations
The Draft Bill proposes a number of measures aimed at strengthening data security and incident response obligations.
Among other things, organisations would be required to:
- maintain practices, procedures and systems that enable effective responses to data breaches;
- take reasonable steps to mitigate harm arising from actual or suspected data breaches; and
- identify personal information holdings and consider whether information that is no longer required should be destroyed or de-identified.
Importantly, entities would also be required to notify the OAIC of an eligible data breach within 72 hours after becoming aware of reasonable grounds to believe that an eligible data breach has occurred. Individuals must also be notified at the same time as the OAIC if practicable or, if not practicable, as soon as practicable after. This change would bring Australia in line with GDPR requirements and require significant uplifts to many organisations data breach handling processes.
5. Right to erasure
The Draft Bill introduces a new right to erasure.
Organisations which qualify as a large digital platform would be required to destroy personal information they held about an individual upon request (unless an exception applies). This right is aimed at social media platforms and other large digital service providers who are also regulated by online safety laws.
6. Controller and Processor Framework
The Draft Bill also introduces a new controller and processor framework that aligns more closely with the GDPR privacy regime.
It is proposed that where an APP entity handles personal information on behalf of another APP entity, primary responsibility for compliance with the APPs will generally rest with the entity that determines the purposes for which the information is handled. This position will not apply, however, if a processor acts other than in accordance with the controller's instructions.
What organisations should do now
While the reforms remain subject to consultation, organisation should begin considering the potential impact of the proposed changes on their business models and privacy compliance frameworks. Given the breadth of the proposed reforms, organisation should continue to monitor the progress of the Draft Bill an assess what changes may be required to their privacy governance, data handling and compliance processes if the reforms are enacted.
All information on this site is of a general nature only and is not intended to be relied upon as, nor to be a substitute for, specific legal professional advice. No responsibility for the loss occasioned to any person acting on or refraining from action as a result of any material published can be accepted.