Australia Privacy Update – Proposed privacy law reform

Alert
|
20 min read

On August 31, 2026, the Australian Government released a Privacy Reform - Consultation Paper (the Consultation Paper) and an exposure draft of the Privacy Amendment (Personal Data Protection Bill) 2026 (Exposure Draft) detailing proposed changes to the Privacy Act 1988 (Cth) (the Privacy Act).

This is a significant milestone, and the proposed changes are further reaching than those introduced under the first tranche of reforms in 2024. If the proposed changes are legislated by the Government, this will shift Australia's privacy landscape and require businesses to undertake comprehensive reviews of their data handling and collection practices. They span core definitional changes, a new "fair and reasonable" requirement for collection, use and disclosure of personal information, refined consent requirements, a simplified direct marketing framework, strengthened data breach and security obligations, and a new right to erasure. The consultation is open for submissions until only September 18, 2026.

A more detailed analysis of each of the key areas of proposed amendments to the Privacy Act is below.

Definitional changes to personal information and other concepts under the Privacy Act

Some of the proposals introduce new defined terms and amend existing definitions to clarify and broaden key concepts under the Privacy Act. This reflects the changing of nature and concept of data itself, how it is used and collected by businesses, and technological developments.

Personal information

It is proposed that the definition of 'personal information' is amended by replacing the requirement that information be 'about' an individual with a requirement that it 'relates to' an identified or reasonably identifiable individual. This reflects that despite a particular individual not being the dominant subject of the information, it may relate to the individual where there is a sufficient connection between the information and the individual.

A note in the Exposure Draft clarifies that an individual may be identified or reasonably identifiable, even if their identity is not known, where that information enables them to be recognized, singled out or otherwise treated as a distinct individual in practice. The note provides examples of information that may fit this definition of personal information and enable this 'individuation', including:

  • a name, date of birth or address;
  • contact information (phone number or email address);
  • a pseudonym or identifier;
  • characteristics, behaviors, traits, preferences or patterns of activity; and
  • location data or geolocation data.

The inclusion 'characteristics, behaviors, traits, preferences or patterns of activity' reflects the recent determinations made by the Privacy Commissioner in Commissioner Initiated Investigation into Monash IVF Pty Ltd (Privacy) [2026] AICmr 40 (11 June 2026) and Commissioner Initiated Investigation into Medmate Australia Pty Ltd (Privacy) [2026] AICmr 41 (11 June 2026). The determinations related to the use of pixel tracking technologies under which the Commissioner considered that the current definition of personal information does not expressly require that an individual must be specifically identifiable or identifiable by direct identifiers (i.e., their name or other identity documents). The Commissioner was of the view that the concept of 'identifiability' has evolved alongside technology that makes it possible for businesses to track and target individuals, so that where information facilitates 'individuation' (i.e., permits an entity to single out or distinguish them from others in a way that affects an individual's rights or interests), the information is personal information even where the individual is not directly identified.

Businesses that use technologies that allow for individuals to be tracked and distinguished from one another, or use large data sets to identify and target individuals based on certain characteristics, may find that these activities will be captured by the Privacy Act.

Reasonably identifiable

A definition of 'reasonably identifiable' is proposed to clarify that an individual will be reasonably identifiable from information or an opinion if the individual could be identified by combining the information or opinion with other information or opinions that are reasonably available.

The Consultation Paper notes that whether information is reasonably available to an entity will depend on the availability of the other information, technical feasibility, the time, cost and effort required to identify the individual and any controls on access, use or re-identification.

Sensitive information and collection

The definition of 'sensitive information' will be updated in line with the proposed amendments to the definition of 'personal information' so that the information will be required to 'relate to' individuals. Additionally, the definition of sensitive information will also include 'precise geolocation tracking data' and 'genomic information that relates to an individual' as types of sensitive information. The inclusion of geolocation tracking data means that any devices or technologies that capture an individual's specific location within a radius of 500 m will become subject to the stricter requirements that apply to the collection and use of sensitive information (such as obtaining consent and more limited permitted use rights for the information).

The definition 'collects' is proposed to include clarification about the time of collection for sensitive information that can be derived from personal information. Information will not be sensitive information simply because it could be derived from personal information collected—the new times for collection of sensitive information are proposed to be at the time of:

  • collection, if personal information is collected for the purpose of using or disclosing sensitive information derived from it; 
  • use or disclosure of the information where the information is being used or disclosed as sensitive information; or
  • separate recording of sensitive information.

Removal of APPs 3,4 and 6 and the introduction of ‘fair and reasonable’ requirement

In a departure from the current privacy regime, the existing APPs 3, 4 and 6 are proposed to be removed and replaced by a new framework for the collection, use and disclosure of personal information which would permit the handling of personal information where it is 'fair and reasonable' in the circumstances. This places an onus on businesses to thoroughly examine the nature and scope of their personal information handling practices, particularly when handling sensitive personal information, including whether they could achieve their purposes by collecting, using or disclosing less personal information or information that is not personal information.

Whether the handling of personal information is 'fair and reasonable' requires businesses to consider their data collection, use and disclosure against the following factors:

  • Reasonable expectations. Whether a reasonable person would expect the collection, use or disclosure of the information in the circumstances. This is determined objectively and entities do not need to consider an individual's personal or subjective expectations. Reasonable expectations are shaped by the context of the relationship and broader community standards, as well as the information the entity has provided, and vary depending on factors such as whether the interaction is a one-off transaction or an ongoing service. Where there is a significant power imbalance or the entity provides an essential service, a reasonable person is less likely to expect their information to be used beyond what is necessary for the entity's core functions;
  • Relationship to the entity's functions or activities. There must be a clear connection between an entity's functions or activities and its handling of personal information. Where personal information is used or disclosed for an additional purpose, rather than relying solely on consent, the connection to the entity's functions or activities becomes relevant. If personal information is not related to the functions or activities of an entity then it is likely that such handling will not be fair or reasonable. This requirement has some similarities to the 'legitimate interests' basis for lawful processing personal data under Article 6 of the GDPR, so it will be interesting to see whether (and, if so, how) overseas principles and decisions affect the application of this element in Australia;
  • Transparency. Information that enables a reasonable person to understand why and how their personal information is being handled must be provided via a collection notice. Information must be explained in easy to understand language, provided in a timely manner and be readily accessible to individuals;
  • Data minimization. Entities must consider whether the purpose for which the information is being collected, used or disclosed could be achieved with less personal information or information that is not personal information (such as de-identified information). Consideration should be given to the nature and volume of information collected and whether information could contain sensitive information which creates significant privacy risks; personal information must be considered. Choice is not genuine when individuals are presented with terms, would suffer detriment from refusal or are influenced by dark patterns or other technologies. The degree of choice will also depend on whether the use of a service is by choice, or it is an essential good or service with limited alternatives for individuals to access;
  • Impacts to the individual and proportionality. This includes assessing the potential impacts on individuals, including whether there is any risk of harm to the individual (for example, discrimination, financial harm, injury, intrusion into private life, deprivation of rights or freedoms, etc.) and if the risk of harm is proportionate to the benefits to the individual or the entity. The greater the risk of harm, the stronger the justification for handling and safeguards that are required; and
  • Best interests of the child. The consideration of whether personal information handling is in the best interests of the child will apply in the collection of personal information from children. Entities must consider the age of the child, the nature of the service and the benefits/risks of the information handling.

The existing exemptions and permitted general situations will continue to apply to collection, use and disclosures of personal information, with some proposed amendments to clarify the permitted general situation where entities are enabled to take appropriate action to address unlawful and wrongful conduct.

New definition of consent and consent required for the collection of sensitive information

A definition of 'consent' is proposed to be included into the Privacy Act. Where businesses must have consent, it may be express or implied, but it must be:

  • Voluntary. Individuals must have a genuine opportunity to provide or withhold consent. This prevents the use of bundled consent or hiding consent in policies or other terms and conditions;
  • Informed. Enough information must be provided to individuals so that they understand the consequences of providing or withholding consent and what they are consenting to;
  • Current. The consent must relate to the current circumstances. Businesses cannot collect consent to use personal information for a particular purpose and then use that information for a materially different purpose. Consent cannot be relied upon where it has been withdrawn;
  • Specific. The consent must be precise in the context of the proposed information handling, so that businesses cannot collect overly broad or bundled consents or for future undefined uses of personal information. The consent must specify the purposes for which the personal information is being handled; and
  • Unambiguous. The choice of the individual must be clear. Businesses cannot use pre-checked boxes or preselected settings. Consent may be implied where it can be clearly inferred from the individual's conduct and the purpose of the consent is obvious from the context.

In addition to the inclusion of a definition of consent, it is proposed to include an express APP requiring entities to obtain consent to the collection of sensitive information. The consent requirement in relation to sensitive information reflects the current requirements in relation to the collection and use of sensitive information under the Privacy Act. Two new exceptions are proposed so that consent will not be required to collect sensitive information where the collection is from a publicly available document and where the collection is strictly necessary to provide or deliver a requested good or service.

Consent required for the trading of personal information

An express APP is proposed which requires entities to obtain consent to the trading of personal information which captures the sale of personal information for money (or other consideration) and the disclosure of personal

information for the purposes of direct marketing. There are four proposed carve-outs to the definition of 'trade', so that a disclosure of personal information will not be a trade where it is:

  • necessary to provide a product or service requested by the individual;
  • incidental to the sale, acquisition of a business (and is not the substantial purpose of the transaction);
  • disclosed to a processor acting on behalf of a controller, and only in accordance with its documented instructions; or
  • necessary to prevent and detect unlawful activity or serious fraud related misconduct.

The Consultation Paper notes disclosures for the purpose of direct marketing includes disclosures of cookies or pixels in advertising and disclosures of personal information that support or inform direct marketing. The interpretation and possible application of the processor/controller distinction in the disclosure of personal information could impact the extent to which this new consent requirement will impact direct marketing activities, and we are watching this area closely for further guidance.

Replacement of APP 7 with a simplified direct marketing framework

It is proposed to replace the current APP 7 with a simplified direct marketing framework that captures all advertising or marketing material directed at individuals using their personal information (whether they are targeted individually or as part of a broader audience, segment or cohort). This broadens the application of the Privacy Act to targeted advertising techniques and online behavioral advertising.

The new framework will require businesses to provide individuals with a simple means of opting out of direct marketing communications and to ensure that each communication contains information about opting out. The framework also includes modified opt-out requirements for ad-supported services (i.e., services that derive revenue from the making of direct marketing communications to individuals who use the service).

Changes to the notification of the collection of personal information

Currently, APP 5 sets out a list of matters to be notified to individuals at the time of collection of their personal information. This is proposed to be shortened to:

  • the fact and circumstances of the collection; and
  • the purposes for which the entity intends to use or disclose the information. 

The details provided to individuals must be relevant, clear and concise. This proposal permits businesses to provide a shorter and more efficient notification to individuals at the time of collection of personal information. This is consistent with streamlining and simplifying privacy notices and keeping more detailed disclosures in an APP-compliant privacy policy, given the previous regime had a significant degree of overlap between the two.

Changes to the data breach notification regime

There are important, proposed changes to the data breach notification regime which will impose additional obligations on businesses in managing and preparing for data breaches. The key proposed changes to the regime include:

  • Broadening the definition of data breach to distinguish between a 'data breach' and an 'eligible data breach', to clarify that requirements to manage and contain a data breach may apply even where the incident is not an 'eligible data breach';
  • A requirement on businesses to take reasonable steps to implement practices, procedures and systems to enable them to respond effectively to data breaches and prevent or reduce harm to affected individuals. Entities will need to establish and implement data breach response plans and maintain a level of preparedness to respond to breaches;
  • A specific obligation on businesses to take reasonable steps to prevent or reduce harm arising from a data breach (for example, containing the incident, notifying individuals and disabling compromised accounts); and
  • Seventy-two-hour notification period under which businesses must notify the OAIC of an eligible data breach. The clock starts ticking upon a business becoming aware of reasonable grounds to believe that an eligible data breach has occurred. Having established data breach response plans and governance over the response will be crucial in meeting the timeframes for response. 

In addition to the proposed changes to the Privacy Act, the Government announced the introduction of IDLock which is a new digital identity service enabling Australians to manage the use of identity documents through a document verification service that permits them to block, unblock and monitor the use of the documents.

Increased requirements in relation to security of personal information

The proposed amendments to APP 11 increase obligations on businesses by requiring them to:

  • Consider destroying personal information where personal information is no longer required for the purposes for which it may be used or disclosed. Destruction of personal information must be given consideration as retaining de-identified information holds risks in relation to re-identification;
  • Identify personal information that it holds. Entities may need to undertake data mapping and implement management tools to understand the personal information that they hold, take steps to protect the information and to determine whether the information should be retained or destroyed or de-identified; and
  • Undertake ongoing evaluation of its compliance with APP 11, including the reasonable steps they take to secure personal information and its destruction and/or de-identification measures. Entities will need to implement regular reviews and governance processes in relation to the security of personal information.

In addition to the above amendments, there is a proposal to include a new definition of 'de-identified' into the Privacy Act, which clarifies that information is de-identified where, in the circumstances, it does not relate to an individual who is identified or is reasonably identifiable. It is possible that under this new definition entities will need to review whether de-identified information in fact remains de-identified and may also need to take additional steps to de-identify information.

Introduction of a right to erasure

A new right to erasure is proposed to be introduced as a new APP which would permit individuals to request that 'large digital platforms' destroy personal information that they hold in relation to an individual upon request, unless an exception applies. The definition of 'large digital platform' will capture those entities that are social media services, relevant electronic services or designated internet services under the Online Safety Act 2021 (Cth) but only where they also meet a revenue ($500 million in gross revenue in the previous financial year) and a user threshold test (average of 2.5 million monthly end users in Australia). There is also proposed scope for regulations to prescribe specific digital platforms or classes of platforms as 'large digital platforms'.

Digital platforms will need to roll out functions to provide individuals with the means to submit requests for destructions of their personal information and appropriate policies and processes to respond to such requests and implement the destruction of personal information. Many larger platforms that have operations across numerous jurisdictions will already have these processes in place to comply with similar requirements under the privacy laws of other jurisdictions (such as the General Data Protection Regulation (GDPR) in the EU).

The requirement to delete personal information will only extend to personal information that an exception does not apply to. The exceptions to erasure include public interest, legal interest and technical/circumstantial exceptions (such as where destruction is technically impossible). Depending on the scope of the use of personal information by digital platforms, it remains to be seen how this requirement will practically be complied with where personal information is used in the training of AI data sets, which is a consideration not addressed by the exceptions under the Exposure Draft.

Introduction of an exception for research

A new exception to the APPs for 'human research' is proposed to replace the current exceptions for research to permit 'human research' that meets certain criteria to be exempt from the requirements under the APPs. To be exempt research will need to be reviewed, approved and monitored in accordance with the National Statement on Ethical Conduct in Human Research and comply with human research guidelines issued by the Privacy Commissioner.

Introduction of ‘processor’ and ‘controller’ concepts

A proposal for the introduction for an exception for information processors introduces the concepts of 'processor' and 'controller', drawing on the GDPR model.

  • Controller = determines the purposes and instructions on which personal information is handled.
  • Processor = an entity handles personal information on the controller's behalf and acts in accordance with the controller's instructions and for the purposes specified by the controller. The definition excludes contracted service providers under Commonwealth contracts.

The instructions provided by a controller to a processor must be documented. Where a processor acts in accordance with those instructions then those acts will be attributed to the controller for the purposes of compliance with the Privacy Act (except for breaches of APP 1 or 11).

This change will require businesses to understand and map their contractual arrangements where they may transfer or disclose personal information to third parties for processing (such as, managed IT services, marketing functions or to provide other back-end functions to the business, such as accounting services) to determine where they may be liable for the acts of those third parties. Contractual arrangements will need to be reviewed and updated to ensure that any instructions/obligations on third party service providers clearly require those service providers to comply with the obligations of the Privacy Act and narrow the scope of the use and handling of any disclosed personal information by third party service providers.

OAIC powers and efficiency

While not detailed in the Exposure Draft, the Consultation Paper indicates that there is intent to include additional measures to enhance the powers and efficiency of the OAIC, including:

  • Uplifting dispute resolution requirements to facilitate early resolution of complaints which would require entities to respond to complaints within 60 days and provide written decisions setting out the outcome and available review options;
  • Uplifting powers to enforce complaint handling obligations. Non-compliance with new dispute resolution requirements will be an interference with the privacy of an individual under the enforcement framework;
  • Enable more efficient management by the OAIC of representative complaints;
  • Providing the OAIC with powers to oversee privacy protections associated with the Social Media Minimum age scheme in the Online Safety Act 2021 (Cth);
  • Empowering the OAIC to require any person who can assist an investigation to provide reasonable assistance to the Information Commissioner. This measure would be supported by a civil penalty for non-compliance and would apply to investigations and public inquiries;
  • Clarify the OAIC's ability to share information with the Attorney-General and other Ministers about ongoing privacy investigations; and
  • Introduce specific and defined defenses to information gathering notices to replace the broad and undefined 'reasonable excuse' defense for refusing to comply with the OAIC's information gathering notices.

What is next in Australian privacy reform?

The proposed reforms under the Exposure Draft do not include all the reforms previously accepted by the Australian Government in full or 'subject to consultation' in the Government Response to the Privacy Act Review.

In particular, the key proposals not included in the current Exposure Draft are:

  • the removal of the small business exemption and employee records exemption;
  • the introduction of additional rights for individuals;
  • a prescribed list of countries and contractual clauses for overseas data transfers; and
  • prescribed data protection officer requirements.

It is unclear at this stage whether these amendments will be considered by the Government in the future.

As for the current Exposure Draft, the very short consultation period suggests that the Government is looking to put legislation before the Parliament in the near future and likely in a form very close to that presented in the Exposure Draft. It is possible that the Exposure Draft may be presented and passed by Parliament this calendar year or in early 2027, with grace periods of between 6-12 months prior to the changes commencing, depending on the nature of the proposed change. That would be consistent with the approach to the last tranche of changes passed in late 2024.

Given these reforms are now seemingly moving quite quickly, organizations that are subject to the Australian Privacy Act should be reviewing their existing privacy practices and procedures against the Exposure Draft and developing plans to revise and uplift those prior to or alongside the passage of legislation through the Parliament. These changes are significant and privacy compliance is increasingly a significant customer and public relations focus area.

Please contact a member of our team if you would like to discuss the impact of the proposed reforms further.

White & Case means the international legal practice comprising White & Case LLP, a New York State registered limited liability partnership, White & Case LLP, a limited liability partnership incorporated under English law and all other affiliated partnerships, companies and entities.

This article is prepared for the general information of interested persons. It is not, and does not attempt to be, comprehensive in nature. Due to the general nature of its content, it should not be regarded as legal advice.

© 2026 White & Case LLP

Top