Business Insight

Australia's 2026 privacy reforms: a first look at pivotal new changes

Blue and teal 3D digital wave with mesh network texture

    What you need to know

    • The Australian Government is consulting on an exposure draft of a new Privacy Amendment (Personal Data Protection) Bill 2026. The consultation proposes around 40 reforms to Australia's privacy laws, signalling a significant shift in how data privacy will be managed, regulated, and enforced in Australia.
    • The consultation period is short (submissions are due 18 September 2026 and must be limited to 1,000 words), and the Government expects to introduce legislation to Parliament before the end of the year.
    • Many changes were expected from the Government's response to the Privacy Act Review Report, but many are new or modified in important ways, and there are some important omissions.
    • Predicted changes to foundational definitions take on new significance in the face of a regulator already looking to expand the boundaries of privacy law with "novel" interpretations. Expect more data to be protected as personal information, including data in your supply chains, and data you might currently consider de-identified or anonymous. This is a particular risk for data trading and data used to target advertising.
    • Many changes align with international regimes, but Australia's privacy laws remain unique. To navigate them, you need to understand both global practices and local enforcement priorities.
    • Be prepared to help the Government understand impacts of privacy reforms. Engagement may be direct or through industry associations. Important issues are often considered in Senate committee inquiries after bills are introduced.
    • This article gives you an overview of the reforms and highlights some pivotal new changes.

    Pivotal new changes

    1. Fair and reasonable data handling test, replacing existing requirements
    2. A right to erasure, for “large digital platforms” (broadly defined)
    3. Stricter cyber security and data breach obligations, requiring whole of lifecycle data governance and obligations to mitigate harm
    4. Tighter consents, refined definitions and other new requirements impacting data trading, direct marketing and sensitive information
    5. A GDPR-like data processor framework
    6. Shifting the burden of managing privacy complaints to entities, not the regulator
    7. New powers to support a regulator more focussed on strategic, large scale enforcement than complaint resolution

    Tranche 2 reforms bring around 40 reforms across 8 themes

    The Attorney-General's consultation on the Privacy Amendment (Personal Data Protection) Bill 2026 proposes roughly 40 reforms to the Privacy Act 1988.

    In this article, we look at 7 pivotal changes under consultation – a sample of the full suite. For context, we provide a brief snapshot of the 8 areas of reform under consultation.

    Core definitions

    Updates to core concepts like personal information, sensitive information, de-identification, consent, and disclosure. In many cases, the changes elevate existing guidance into law, and in others we are starting to see the OAIC’s recent approaches in determinations move into the law.

    Expect privacy laws to apply to more categories of information, existing assumptions might need to be revisited.

    Handling of personal information
    Centred around a new holistic "fair and reasonable" framework to replace existing data handling requirements under APPs 3, 4 and 6, stronger consent requirements for direct marketing (including for online services), data trading, and an expanded notion of sensitive information.
    Data security
    A new requirement to mitigate harm flowing from all data breaches (not just those that hit the "eligible data breach" threshold), streamlined notification obligations, the ability to identify all personal information held, positive obligations to monitor data that the entity no longer requires (that should be destroyed or de-identified), and ongoing assessment of security and destruction measures.
    Data access and right to erasure
    A new exception allowing data access requests to be limited or refused where access is technically impossible or infeasible, and an updated obligation to give reasons for refusal. This is coupled with a new (and controversial) right to erasure applicable to “large digital platforms”, a broad concept that would likely cover many organisations with an online presence or mobile app.
    Exception for research
    A new regime that applies consistently to Government and non-Government research involving personal information, governed by the National Statement on Ethical Conduct in Human Research and Privacy Commissioner guidelines.
    Exception for information processors
    Introducing a GDPR-like data processor / data controller distinction that places responsibility on entities giving instructions, making supplier governance even more critical.
    OAIC powers and efficiency

    New complaints handling requirements shift more of the complaint workload from the regulator to entities, regulator powers to require reasonable assistance (including from third parties), clearer ability to manage complaints as a group, as well as changes to information gathering notices exceptions, and new rules to increase oversight of social media minimum age privacy rules.

    Unlike other areas, no exposure draft legislation has been released for these measures.

    Addressing emerging technologies
    The Government has also sought views on whether its technology neutral reform agenda addresses emerging technologies, specifically calling out AI, smart glasses and connected vehicles as examples.

    Many of these reforms had already been accepted by the Government in its response to the Privacy Act Review Report, but had not been dealt with in 2024's first tranche of privacy reforms. Most of those 2024 reforms are now law, and by the end of the year we will see automated decision transparency laws commence and a children's online privacy code registered.

    1. "Fair and reasonable" data handling test

    • A new requirement that data handling be "fair and reasonable" will replace many current data handling requirements (under APP 3, 4 and 6), supported by a simplified notification requirement (under APP 5).
    • This new test significantly changes the existing regime. It goes beyond the originally proposed "fair and reasonable" duty – aspects of privacy law that were stand-alone requirements, good practice, or guidance now become factors in a holistic assessment.
    • Factors to take into account: As part of the "fair and reasonable" assessment, you will need to consider whether a reasonable person would expect the handling of information, whether the proposed handling relates to your functions or activities, transparency measures, data minimisation, whether the individual is presented with a genuine choice, the impact on the privacy of the individual and any risk of harm, and for children, the best interests of the child.
    • Factors like consent will no longer operate as a "gate" permitting that use but will instead be one factor to be taken into account. For data trading, direct marketing and sensitive information, consent will act as an additional requirement alongside the "fair and reasonable" assessment (discussed below).

    Why it matters

    • Flexibility cuts both ways: The "fair and reasonable" framework lets you assess risk mitigants holistically rather than falling at the first technical compliance hurdle. But it also gives the regulator flexibility to pursue practices that might technically comply with current privacy laws.
    • Consent is not a cure all: Voluntary, informed, current, specific, and unambiguous consent will go a long way to making sure data handling is "fair and reasonable" but is not the whole story.
    • Today's processes need re-examining: The exposure draft includes no safe harbour. Your current data handling may comply with today’s privacy laws but fail tomorrow’s "fair and reasonable" test.
    • Discipline combats bias: You need risk-informed, disciplined, and defensible assessments to combat subjectivity and positivity bias when self-assessing "fairness."

    2. Right to erasure for “large digital platforms” (broadly defined)

    • Industry and the Productivity Commission criticised the previous right to erasure as introducing costs and complexity that outweigh privacy benefits.
    • Under the current consultation, the right to erasure has been limited to apply only to so-called “large digital platforms” – which are providers of certain digital services with either:
      • global business group gross revenue of $500 million, or
      • 2.5 million end users.
    • The definition extends to websites and apps (a designated internet service), as well as social media and messaging services (a social media service or a relevant electronic service), each with end users in Australia, as defined in the Online Safety Act 2021 (Cth).

    Why it matters

    • While the proposed right appears to be focused on large digital platforms, it is likely to capture more businesses than you might expect.
    • Not just traditional "digital platforms": The types of digital services covered are broad (extending to websites and apps). If you have an online presence, the right to erasure may cover you – even if you are not a traditional "digital platform".
    • Not just large numbers of users: Because either the revenue test or the end user test can make a service a "large digital platform", larger businesses with significant global revenue will be captured even if their online services have a small number of users.
    • Not just big companies: Similarly, services with many users but limited revenue will be captured. The consultation paper describes an end user broadly – as any person who accesses the platform, whether or not they hold an account, or who accesses or purchases a service through the platform.

    3. Stricter cyber security and data breach obligations

    New obligations include:

    • Take reasonable steps to prevent or reduce harm arising from an actual or suspected data breach, even where the breach does not reach the “eligible data breach” notification threshold.
    • Take reasonable steps to implement practices, procedures and systems to comply with the new obligation to prevent or reduce harm, as well as to comply with data breach notification obligations, meaning that data breach response plans and related practices, procedures and systems are more likely to be scrutinised by the OAIC.
    • Changes to data breach notifications, including a 72 hour notification window, the ability to progressively notify new information as it becomes available, notifications to individuals at the same time as the regulator (if practicable), more detailed content in notifications, including information on early action to reduce or prevent harm, and a clearer exception that allows individual notifications to be withheld if effective remedial action has been taken.
    • An obligation to monitor personal information that is no longer required for a legitimate purpose (and that should be destroyed or de-identified), and obligations to consider destruction before de-identification (to combat re-identification risks).
    • Take steps needed to ensure you can identify all personal information to which the security and destruction obligations apply, cementing in law best practice around data traceability.
    • Obligations to regularly assess the effectiveness of both security measures and destruction and de-identification processes.

    Why it matters

    • Mitigating harm from all data breaches, ongoing assessments, and active monitoring of legacy data should already be part of your privacy risk management and cyber resilience strategy.
    • The regime demands rapid response to data incidents and "cradle to grave" visibility of personal information. Data breaches include not just cyber incidents but also other misuse or disclosure, including by employees or third parties.
    • The revised framework prioritises rapid action and rapid engagement: Measures to protect customers must be considered early on in the response – when you may not have full knowledge of a data breach and its potential impacts. Information released during this initial period often requires subsequent clarification or correction.
    • Response must be disciplined: Notification timeframes may force you to disclose data breaches before you fully understand them – increasing public relations and customer risks and reducing the withholding of information by entities until a more fulsome assessment is completed. Knowing a data breach has occurred is very different from understanding what data or individuals are impacted, to what degree, and what should be done in response.
    • Similar, not harmonised, reporting: While the 72 hour notification window appears aligned to other regimes like critical infrastructure cyber incident notifications and ransom payment reporting, different regimes apply different thresholds and time limits. The notifiable data breach window starts after belief (not suspicion) that an incident reaches notification thresholds, and the obligation to undertake an assessment once a reasonable suspicion has developed remains in place. Regulator notifications are one part of a cyber crisis stakeholder management.
    • More data needs tracking and securing: Identifying all personal information you hold may challenge you. In recent tracking pixels determinations, the Privacy Commissioner put forward expanded interpretations of what counts as personal information and what data you “hold”. These reforms will treat even more data as personal information.

    4. New definitions and consent for data trading, direct marketing and sensitive information

    • A tighter definition of consent (which can be express or implied, but must be voluntary, informed, current, specific, and unambiguous) elevates existing regulator guidance to law. Definitions of personal information (including what constitutes 'reasonably identifiable'), collection and disclosure, among others, together clarify and broaden what information is regulated by the Privacy Act, particularly information that is inferred or used for tracking or cohort marketing.
    • Sharing personal information for money or other consideration, or for the purpose of direct marketing, will require consent – subject to exceptions.
    • The concept of sensitive information has been expanded to include precise geo-location tracking data, meaning handling of this data (for example through mobile apps) will generally require consent.
    • Individuals may opt out of personalised direct marketing on ad-supported services, but this doesn't necessarily mean full access to the service without personalised ads. The service may be offered on different terms (eg a paid subscription for services without personalised ads).

    Why it matters

    • A firm boundary tempering new flexibility: The "fair and reasonable" requirement brings flexibility to most privacy practices, but data trading, direct marketing, and sensitive information face strict consent requirements.
    • Heightened expectations mean not all "consents" will count: You may need to revisit existing consents, particularly bundled or opt-out consents. Consent must be specific, so bundled consents covering broad purposes are unlikely to suffice.
    • Consent fatigue and customer friction: Meeting heightened expectations and providing the transparency required to obtain meaningful consents can be extremely challenging. Seeking fresh consent may create customer friction and inadvertently drive away customers – the need to regularly seek fresh consents has been criticised in the Consumer Data Right, with amendments allowing business customers to give longer term standing consents.

    5. Data processor framework

    Adopting a data controller/processor concept, as seen in other regimes such as the General Data Protection Regulation, service providers processing data under instructions will only need to comply with certain transparency and security obligations – all other privacy rules will be the responsibility of the data controller.

    Why it matters

    • Can both simplify and complicate negotiations: Both controllers and processors will want to draw clean lines around responsibilities – as such, contractual clarity becomes even more critical.
    • Not one-size-fits-all, but maybe one-size-fits-most? The framework works best for commoditised services with clearly defined responsibilities. It will not suit all relationships, particularly where a supplier operates autonomously or uses data for its own benefit – in which case the supplier would have its own controller obligations. Some arrangements might be structured to separate activities undertaken as a controller and as a processor.
    • Supply chain data governance is already critical: Even without adopting the data controller framework, you can be considered to control and "hold" information your service providers manage (as found in recent tracking pixels determinations). Supply chains remain a key cyber-attack vector, an explicit element of critical infrastructure risk management and the operational risk management prudential standard, and are specifically covered in new automated decision transparency laws.

    6. New complaints handling obligations

    • Organisations will need to provide an accessible privacy complaints mechanism, respond within 60 days, give written decisions that identify external dispute resolution pathways where relevant.
    • Individuals will generally need to lodge complaints with organisations before complaining to the regulator.
    • Complaints handling failures will be treated as an interference with privacy – bringing exposure to civil penalties, infringement notices and compliance notices.
    • Unlike most other reforms, these reforms are described in the consultation paper but not included in the exposure draft bill.

    Why it matters

    • Complaints are a source of intelligence for both the regulator and organisations.
    • Better internal complaints handling has been a regulator priority as the backlog of complaints made to the OAIC continues to grow.
    • Counter-intuitively, the "fair and reasonable" framework may make resolving complaints harder – expect differing views about what is “fair”, especially when AI can be used by complainants to craft detailed complaints addressing the various factors to be considered under the framework. But complaint trends can signal community expectations and help you adapt before regulators act.
    • By monitoring complaint volumes, themes and root causes, you can use complaints as an early-warning system for compliance weaknesses, social licence challenges, and broader governance issues. Complaints data can reveal emerging risks before they develop into regulatory investigations, systemic failures or reputational harm.
    • The Privacy Commissioner has seen large numbers of complaints about difficulty getting access to personal information, excessive collection, and unexpected uses or disclosures. Defensible and effective transparency and consent (particularly for direct marketing and data trading) should be an immediate focus.

    7.  Strategic enforcement and complaint resolution powers

    These reforms are described in the consultation paper but not yet included in the exposure draft bill.

    • Individuals must generally raise privacy concerns with the relevant entity before complaining to the OAIC, leveraging the new complaints handling obligations discussed above, and strengthening the limitations that already exist in the Privacy Act.
    • Clearer powers to group, deal with and determine multiple similar complaints at the same time and clarified powers to enforce determinations in court.
    • A broad new power to require “any person” – including third party service providers – to provide reasonable assistance to investigations (similar to powers available to ASIC).
    • The existing “reasonable excuse” defence for information gathering notices will be replaced with specific, defined defences (modelled on the regime under the Competition and Consumer Act 2010 (Cth)).
    • Removing current restrictions that limit the OAIC sharing information with Ministers about ongoing privacy investigations.
    • Power for the OAIC to assess how social media platforms handle personal information under social media minimum age laws.

    Why it matters

    • The workload of managing privacy complaints is shifting, these changes are intended to allow the regulator to focus on larger litigation and strategic intervention.
    • These changes support the OAIC's shift from individual complaint resolution to strategic intervention. Regulator resources are stretched with an ever-growing backlog of privacy complaints. Expect an ongoing push to manage complaint volumes through three mechanisms:
      • First, expecting you to deal with complaints effectively before they reach the regulator.
      • Second, pushing more complaints through industry dispute resolution schemes. The OAIC has previously suggested schemes for digital platforms, direct marketing, health care, and legal and professional services.
      • Third, regulator monitoring to identify organisations or industries requiring targeted intervention – due to inadequate complaints handling or systemic privacy failures that can be pursued more effectively by dealing with individual complaints as a group.
    • The regulator can gain leverage to achieve higher impact outcomes when dealing with complaints as a group, opening the door to larger civil penalties as well as compensation and other orders now available under the Privacy Act.
    • Do not underestimate the changes required to manage ballooning complaints volumes internally, or the potential cost of more complaints going to industry resolution schemes (which generally provide services free to individuals).

    What's missing from tranche 2?

    What the consultation doesn't include is just as important as what it does. Several significant reforms that the Government agreed or agreed in-principle to in its 2023 response to the Privacy Act Review Report have not been progressed in either the exposure draft bill or the consultation paper. These omissions signal a shift in priorities, especially if these other reforms are not progressed.

    • Small business exemption – the Government had agreed in-principle to a removal of the small business exemption after an impact analysis, development of appropriate support and consultation with small business. The omission of small businesses from the regime means there remains a significant gap compared to many international regimes.
    • Employee records exemption – the consultation paper and exposure draft do not deal with employee protections. The absence of changes to the employee records regime is significant given the growing regulatory focus on workplace surveillance, and the use of AI in employment.
    • Direct right of action – outside of the statutory tort for serious invasion of privacy, the Privacy Act Review included a proposed direct right of action allowing individuals to bring action in court for breaches of the Privacy Act. The absence of this remedy means that individuals will continue to be reliant on the OAIC to bring actions through the complaints process.
    • Mandatory privacy impact assessments – although privacy impact assessments are a requirement under the Privacy (Australian Government Agencies) APP Code 2017 (Cth) and are a feature of the proposed Children's Online Privacy Code, an obligation to complete a privacy impact assessment for high-risk privacy use cases is absent.
    • Other individual rights – outside of the right to erasure, proposals for a right of objection, a limited right of explanation, and rights to require search engines to de-index and online publications to correct information, have each been omitted.

    While these items may be progressed in a future tranche, or through a new code or sector-specific regulation, for the meantime it appears these items will remain off the table until future reforms bring them back into the conversation.

    Authors: Geoff McGrath, Partner and Andrew Hilton, Expertise Counsel.

    Want to know more?

    • Visit our Privacy Reform Australia hub here

    This publication is a joint publication from Ashurst Perkins Coie Australia, Ashurst Perkins Coie Risk Advisory LLP and Ashurst Perkins Coie UK LLP, which are all part of the Ashurst Perkins Coie Group.

    Ashurst Perkins Coie Australia (ABN 75 304 286 095) is a general partnership constituted under the laws of the Australian Capital Territory.

    Ashurst Perkins Coie Risk Advisory Pty Ltd is a proprietary company registered in Australia and trading under ABN 74 996 309 133.

    Ashurst Perkins Coie UK LLP is a limited liability partnership registered in England and Wales under number OC330252. It is a law firm authorised and regulated by the Solicitors Regulation Authority of England and Wales under number 468653. A list of members of Ashurst Perkins Coie UK LLP and their professional qualifications is open to inspection at its registered office, London Fruit & Wool Exchange, 1 Duval Square, London E1 6PW.

    The Ashurst Perkins Coie Group comprises Ashurst Perkins Coie UK LLP, Ashurst Perkins Coie US LLP, Ashurst Perkins Coie Australia and their respective affiliates (including independent local partnerships, companies or other entities) which are authorised to use the name "Ashurst Perkins Coie" or describe themselves as being affiliated with Ashurst Perkins Coie. Some members of the Ashurst Perkins Coie Group are limited liability entities. Some members of the Ashurst Perkins Coie Group provide legal services and some provide non-legal services. Different legal entities in the group may operate in the same jurisdictions. Information about which Ashurst Perkins Coie Group entity operates in any country can be found on our website at www.ashurstperkinscoie.com.

    The services provided by Ashurst Perkins Coie Risk Advisory Pty Ltd do not constitute legal services or legal advice, and are not provided by qualified legal practitioners acting in that capacity. The laws and regulations which govern the provision of legal services in the relevant jurisdiction do not apply to the provision of non-legal services. Legal fees are not shared with non-lawyers.

    This material is current as at 7 September 2026 but does not take into account any developments after that date. It is not intended to be a comprehensive review of all developments in the law or in practice, or to cover all aspects of those referred to, and does not constitute professional advice. The information provided is general in nature, and does not take into account and is not intended to apply to any specific issues or circumstances. Readers should take independent advice. No part of this publication may be reproduced by any process without prior written permission from Ashurst Perkins Coie. We accept no liability for use of these materials and reliance upon it by any person.