The Australian Government has an ambitious agenda for a generational change in privacy regulation, digital safety and cyber resilience.
Innovation change means developing the core technical and organizational capabilities to adapt to the increasingly intense and uncertain regulatory compliance and reform environment. It means better governance, control and risk management capabilities to help organizations not only adapt to and thrive under coming privacy reforms, to improve cyber security, and to successfully respond to regulator, consumer and shareholder scrutiny.
At Ashurst Perkins Coie, our combination of legal and risk experts help our clients build operational resilience through effective data privacy and risk management. We provide end-to-end, whole-of-life-cycle expertise across the complexity and opportunities data, privacy and risk brings. Working together, our legal, risk advisory and Advance (NewLaw and Digital) teams bring industry experience when implementing regulatory obligations.
Latest insight
Australia's 2026 privacy reforms: a first look at pivotal new changes
The tranche 2 privacy reforms propose 40 changes, including the new "fair and reasonable" data handling test, right to erasure & stricter cyber security obligations.
Understand the pivotal changesMore from this series

Automated decisions in Australia series – Part 3: Shifting from compliance to defensible decision-making
Discover why ADM transparency is more than a privacy policy update, and how to build defensible business practices ahead of the December 2026 commencement.

Automated decisions in Australia series – Part 2: Learnings from the regulator’s consultation paper
Explore the "hot button" issues and areas of regulatory focus from the OAIC's recent consultation, and learn how to apply those insights in your compliance program today.

Automated decisions in Australia series – Part 1: a quick guide to Australia's new privacy rules
Your quick-reference guide to Australia's new automated decision transparency laws, breaking down how they apply and what you need to do.

The kids are online – what Australia's Children's Online Privacy Code means for you
Find out how Australia's proposed Children's Online Privacy Code could affect a broad range of digital ser-vices, and the steps you should take before the code commences.

What's Ahead 2026 ‒ Technology industry in Australia
Our multi-disciplinary snapshot of the key regulatory, legal and commercial themes shaping Australia's technology industry in 2026 ‒ from AI and privacy reform to online safety and merger scrutiny.
Cyber readiness lessons from Australian Clinical Labs and Australia's first privacy penalty
We explore the key lessons for organisations in regard to robust cyber governance in light of the $5.8 million penalty following a major data breach.

A new privacy right of action – how to avoid unexpected consequences
A new statutory tort for a serious invasion of privacy now applies in Australia.

Australia's first tranche of privacy reforms – a deep dive and why they matter
Understand the new privacy reforms and what you need to do.

Australia: New AI safety "guardrails" and a targeted approach to high-risk settings
Explore the Australian Government's proposed Voluntary AI Safety Standard and other reforms.

Navigating Data Protection - Reforms A Comparative Analysis of UK and Australia
Key developments across jurisdictions, and how they impact your business.

Australia's blueprint for privacy reform–what you need to do today
Learn more about the Australian Government's response to the Privacy Act Review Report and the proactive steps your organisation can take to prepare.

Australian Privacy Reforms: A generational change inches closer
Get valuable insights into the first tranche of reforms and key takeaways for organisations to consider.

Australia's massive new privacy penalties become law but will be clarified
Read more about the massive new privacy penalties that are being introduced in Australia and what you can do to get on the front-foot.

Privacy risks for AI and ADM in an evolving regulatory ecosystem
Discover more about what your organisation can do to align its AI and ADM practices with rising regulatory demands and upcoming privacy reforms.
Editorial Disclaimer
Originally published before the Ashurst Perkins Coie combination. See disclaimer.
Key contacts
This publication is a joint publication from Ashurst Australia and Ashurst Risk Advisory Pty Ltd, which are part of the Ashurst Group.
The Ashurst Group comprises Ashurst LLP, Ashurst Australia and their respective affiliates (including independent local partnerships, companies or other entities) which are authorised to use the name "Ashurst" or describe themselves as being affiliated with Ashurst. Some members of the Ashurst Group are limited liability entities.
Ashurst Australia (ABN 75 304 286 095) is a general partnership constituted under the laws of the Australian Capital Territory.
Ashurst Risk Advisory Pty Ltd is a proprietary company registered in Australia and trading under ABN 74 996 309 133.
The services provided by Ashurst Risk Advisory Pty Ltd do not constitute legal services or legal advice, and are not provided by Australian legal practitioners in that capacity. The laws and regulations which govern the provision of legal services in the relevant jurisdiction do not apply to the provision of non-legal services.
For more information about the Ashurst Group, which Ashurst Group entity operates in a particular country and the services offered, please visit www.ashurst.comThe information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.Readers should take legal advice before applying it to specific issues or transactions.