A new era for privacy in Australia: implications of Privacy Act reform tranche 2
09 September 2026
Earlier this week, the Australian Government released a Consultation Paper and Exposure Draft for the Privacy Amendment (Personal Data Protection) Bill 2026 (the Bill), which is the highly anticipated second tranche of privacy reforms. The Bill addresses a number of recommendations in the Attorney-General’s Department’s Privacy Act Review Report of 2022 (the 2022 Review).
If passed, the Bill will implement a number of key changes including:
- introducing core definitions into the Privacy Act 1988 (Cth) (Privacy Act)
- streamlining the Australian Privacy Principles (APPs) relating to the collection, use and disclosure of personal information by introducing a single ‘fair and reasonable’ test
- updating obligations relating to data breaches
- introducing a right to erasure of personal information held by large digital platforms, and
- introducing a carve-out from the APPs for research activities.
In this article we discuss some of the key changes proposed by the Bill (and some of the obvious gaps) and what your agency or organisation should be doing to prepare for the changes.
What are some of the key changes proposed?
Core definitions
Turning first to the core definitions, the Bill will introduce a number of key definitions which have been missing from the Privacy Act to date, including defining the following key terms:
- collect
- controller
- consent
- de-identified
- direct marketing
- disclose, and
- processor.
By and large, the definitions proposed will align the Privacy Act with the guidance provided by the Office of the Australian Information Commissioner (OAIC) in its Australian Privacy Principles Guidelines.
Significantly, the definition of ‘personal information’ will change. The current definition refers to information or an opinion about an individual, whereas the new definition will capture information or an opinion that relates to an individual. Practically, information that 'relates' to an individual will expand the scope of information that is captured by the Privacy Act – for example, IP addresses of a person’s device might not be information about a person but will relate to a person and come within the scope of the Privacy Act. Location data, behavioural pattens, pseudonyms and unique identifiers are also going to come within the scope of the expanded definition of ‘personal information’. Clarification will also be added by way of a note recognising the principle of individuation (that a person will be reasonably identifiable when they can be recognised, singled out or otherwise dealt with as a distinct individual, even when no direct identifier is known).
A single framework for the collection, use and disclosure of personal information
APPs 3, 4, 5 and 6 will be repealed and substituted with a new framework to simplify the requirements for the collection and handling personal information through a single requirement that the handling is fair and reasonable (and lawful) in all the circumstances. Whether the handling is fair and reasonable will be assessed against a range of factors including:
- what a reasonable person would expect in the circumstances
- whether the collection, use or disclosure relates to an APP entity’s functions or activities
- whether the APP entity is transparent regarding its collection, use or disclosure, and
- whether the purpose for the collection, use or disclosure could be achieved by collecting less personal information.
The fair and reasonable framework will apply to all personal information held by an APP entity, whether the information is solicited or unsolicited (and the different requirements for the collection of solicited and unsolicited personal information will be repealed).
In respect to the collection of sensitive information (as well as trading of personal information), the Bill introduces the concept of ‘strictly necessary’ – that is, the collection of sensitive information must be strictly necessary for the APP entity to provide or deliver goods or services that the individual has requested be provided. Sensitive information which is optional (or provided with consent) will not be authorised. The collection of sensitive information for direct marketing purposes will never be ‘strictly necessary’.
Changes to data breach requirements
The Bill will introduce a requirement for APP entities to take reasonable steps to prevent or reduce harm arising from data breaches, even before it is assessed to be an eligible data breach (i.e. a data breach that is likely to result in serious harm to an individual to whom the personal information relates).
Additionally, if a data breach is an eligible data breach, the requirement to notify the OAIC is within 72 hours (as opposed to ‘as soon as practicable’) from the time an entity is aware there are reasonable grounds to believe that it is an eligible data breach.
A new (but limited) right to erasure
The Bill will introduce new APP 14, which provides individuals with a right to require large digital platforms to erase personal information that relate to the individual. A large digital platform will be a provider of a social media service, relevant electronic service or designated internet service within the meaning of the Online Safety Act 2021, that has a gross revenue of at least $500 million.
The right to erasure will not apply to all APP entities (which is a deviation from Government’s in-principle agreement to Proposal 18.3 of the 2022 Review).
Carve-out for research activities
The Bill will create an exception so that acts or practices done in the course of human research in accordance with approved ethical guidelines will not breach the APPs.
Human research is defined broadly to mean research that is conducted with or about individuals and involve personal information.
What is not covered?
The Bill makes general amendments to the Privacy Act that will support better privacy practices.
That said, the Bill omits a number of key recommendations that Government agreed to in its response to the 2022 Review. Notable omissions include:
- removal of, or updates to the small business exemption
- enhancement to privacy protections for private sector employees
- prescribe requirements for the journalism exemptions
- legislating for withdrawal of consent under the Privacy Act
- requiring all APP entities to conduct a Privacy Impact Assessment for high privacy risk projects, and
- the right to access data lineage of personal information about an individual (or that relates to an individual) held by an APP entity.
The absence of change to the small business exemption means the small businesses with an annual turnover of less than $3 million will continue to sit outside the scope of the Privacy Act. The employee records exemption also remains (and the Bill doesn’t propose any changes to the exemption).
The Bill also doesn’t specifically address the privacy risks associated with smart glasses or wearables (notwithstanding media reporting to the contrary) and measures to deal with smart glasses remain under development – although data collected by smart glasses may come within the expanded definition of personal information if the glasses capture information that relates to an individual – for example, location data, but only when collected by a APP entity (as opposed to the individual wearing smart glasses).
When will the changes commence?
We anticipate the changes will be considered in the November 2026 sitting period with commencement likely to occur in 2027.
What can you be doing to prepare for the changes?
The proposed reforms shift greater accountability to APP entities to ensure their collection and handling of personal information is 'fair and reasonable'. APP entities should act now to prepare themselves for when tranche 2 reforms commence.
We recommend APP entities prepare by doing the following things:
- map personal information end-to-end to ensure you have a comprehensive record of your personal information holdings
- critically assess whether information collection and handling practices are ‘fair and reasonable’ by assessing at a minimum:
- the extent to which the collection of personal information is necessary (not optional),
- whether the individual would reasonably expect the APP entity to collect their personal information by reviewing website and other public facing communications, privacy policies and collection notices,
- whether the individual has a genuine choice to provide their personal information, and
- whether the benefit of collecting personal information is proportionate to the privacy risk
- critically assess higher risk privacy activities for compliance including personal information used for direct marketing activities, customer analytics and profiling, AI use cases, employee monitoring and data sharing arrangements
- review third party arrangements where personal information is outsourced to assess the impact of the controller / processor changes on outsourcing arrangements starting with arrangements relating to cloud platforms, SaaS providers, data analytics vendors and AI providers
- improve personal information retention and destruction practices to ensure personal information is not held for longer than is required (including required by law) and conduct periodic checks to ensure personal information is being destroyed, and
- prepare for increased individual rights – review your processes for managing privacy complaints and APP 12 access arrangements to ensure your organisation or agency can support an increase in correction, access and erasure requests
Contact us
If you require any further information or advice about how your organisation or agency can design its operations or governance in anticipation of any legislative change, please reach out to Chantal Tipene or Kelly Matheson.
