Legal Insights

Privacy Reform 2026: Australia's biggest privacy overhaul in a decade

• 02 September 2026 • 7 min read

Earlier this week, the Australian Government released a comprehensive package of proposed reforms designed to uplift and modernise Australia’s national privacy laws. The reform package is long awaited and primarily delivers the ‘Tranche 2’ reforms foreshadowed by the Government well prior to the last election. 

However, recent commentary regarding the need for more adequate regulation of AI together with rapidly emerging privacy invasive technologies, such as wearable surveillance devices, appear to have accelerated the current reform agenda. Until now, delivery against many of the Tranche 2 privacy reforms, some of which have been under consultation and discussion since 2019, appeared to have stalled. 

The detailed reform package which has now been released includes a Consultation Paper outlining and explaining approximately 40 amendments to existing legislation. That Paper is accompanied by the Privacy Amendment (Personal Data Protection) Bill 2026 (the Exposure Draft Bill), which is now open for public consultation and response.

In this article, we consider the key changes proposed, practical implications for organisations, the questions stakeholders may wish to consider as part of the consultation process, and the steps organisations should be taking now as Australia's privacy landscape continues to evolve.

Key Takeaways and Action Items 

The Bill is open for consultation and response until 18 September 2026. 

While this may seem like a relatively short window, the majority of these reforms have been subject to consultation and debate for a period of many years, and have already been approved in principle by the Attorney General in its response to the Privacy Act Review Report. We don’t expect to see significant movement in relation to a number of these proposed changes as a result the consultation period, unless there is significant industry pushback.

The reform package falls broadly into two categories. 

While many of the reforms represent long-awaited 'Tranche 2' reforms arising from the Privacy Act Review, the Government has also incorporated proposed changes which respond to emerging technologies and contemporary data practices, introducing obligations in relation to AI, wearable surveillance technologies, connected vehicles and targeted digital advertising.

What will the reforms deliver? 

The proposed package includes approximately 40 measures which the Government states are designed to strengthen privacy protections, simplify aspects of the current regime and further enhance the OAIC's regulatory powers. In several cases the proposed changes would align Australia’s privacy laws more closely with the applicable regulatory regimes in the EU, the GDPR.  

What is missing?

Interestingly, key changes which proposed to close gaps in the coverage of Australia’s existing privacy laws, such as the ‘employee records exemption’ and the ‘small business exemption’, have not made their way into the current package of reforms. These changes, which had been part of each of the earlier consultation processes, but would also be likely to have greatest operational impact on businesses, are largely ignored.

When will the changes actually take effect?

The draft Exposure Bill does not include any timeframes for transition – commencement dates for each Schedule of the Bill are currently blank. 

Based on our experience following the introduction of the Tranche 1 reforms, any uplift to regulatory powers and penalties will be made immediately once the Bill received Royal Assent. 

That said, we anticipate that any changes requiring significant shift in the way in which organisations ‘do business’ would be subject to reasonable transition periods of at minimum 6 months and potentially longer in some cases.

What are the headline changes?

The proposed reform and why it matters

  • New "fair and reasonable" test

    The most significant of the proposed reforms is a new overarching framework that replaces existing APPs 3, 4 and 6, consolidating collection, use and disclosure obligations into a single principles-based test. 

    Under the proposed new APP 3, personal information may only be collected, used or disclosed where it is both fair and reasonable in the circumstances and lawful.

    The practical implication is that organisations may no longer be able to rely solely on privacy notices or consent mechanisms to justify a particular data practice. The new test is outcomes-focused: an entity must be able to demonstrate that the practice itself is appropriate, proportionate and consistent with community expectations – even where the individual has been notified or has consented. Notably, a practice described in a privacy policy does not automatically become 'reasonably expected', and a privacy policy that is lengthy or unclear will not satisfy the transparency factor.

    This has the potential to affect a wide range of activities, including data analytics, customer profiling, AI generated inferences, information sharing arrangements and digital marketing practices and secondary uses of personal information for purposes that arise after collection. In particular, secondary uses or disclosures are less likely to be fair and reasonable where they fall outside an individual's reasonable expectations, lack transparency, or occur in circumstances where the individual has not been provided with genuine choice.

    This concept is a world first and there are already concerns being expressed around the lack of detail and how it might apply in practice.

  • Stronger consent requirements

    The reforms propose to define “consent”. While consent may be implied or express, consent must be voluntary, informed, current, specific and unambiguous. 

    The addition of 'unambiguous' as a statutory requirement is the key change: pre-selected settings, pre-ticked boxes and bundled consents will generally not satisfy the test. These changes seek to legally mandate expectations which are current contained in regulatory guidance, but may be inherently difficult to achieve in practice.

    Existing consents, enrolment processes, sign-up flows and collection practices may need review. Organisations that rely on pre-ticked boxes, broad bundled consents or inactivity-based consent mechanisms are most at risk of non-compliance.

  • Broader definition of personal information

    The definition of personal information has been amended to cover information that 'relates to' an identified or reasonably identifiable individual, replacing the previous requirement that information be 'about' an individual. 

    This broader definition extends to information that 'says something' about an individual or their activities, characteristics, behaviour, preferences or interactions – including information used to inform or influence actions or decisions affecting them. 

    A new statutory definition of 'reasonably identifiable' is also introduced, requiring an objective assessment of whether an individual could be identified by combining the information with other reasonably available information, having regard to technical feasibility, availability of other data, and re-identification risks. 

  • Expanded categories of sensitive information

    Two new categories are added to the definition of sensitive information:

    (1) genomic information relating to an individual (expanding on the existing reference to genetic information, and now expressly covering findings about genetic characteristics, biological relationships and potential health risks); and

    (2) precise geolocation tracking data, defined as information generated by or derived from a device that identifies an individual’s location within a radius of 500 metres and is collected and held by reference to that individual’s location over time.

    The inclusion of precise geolocation data as sensitive information means organisations, including those operating wearable technologies, connected vehicles, employee monitoring systems and location-based services, must obtain consent before collecting this data (unless an exception applies) and comply with the heightened obligations applicable to sensitive information. The 500-metre radius threshold is intended to exclude one-off or coarse location data while capturing persistent tracking activity.

  • Enhanced security obligations

    APP 11 is strengthened and introduces three key new obligations:

    (1) a positive obligation for entities to take any steps needed to identify all personal information to which APP 11 applies (i.e. entities must know what they hold); 

    (2) an express obligation to consider whether personal information that is no longer needed should be destroyed (rather than merely de-identified), and then to take reasonable steps to destroy or de-identify it; and 

    (3) an ongoing obligation to regularly evaluate the effectiveness of security measures and destruction practices. 

    These changes recognise that retaining de-identified information still creates re-identification risk, and that security measures may become less effective over time as technologies evolve. Entities cannot treat security compliance as a point-in-time exercise.

  • 72-hour breach notification requirement

    Under new section 26WK of the Bill, once an entity becomes aware of reasonable grounds to believe that an eligible data breach has occurred, it must notify the Information Commissioner within 72 hours. 

    This is a significant compression of the current timeframe and will require organisations to have embedded mature incident response, data visibility and escalation processes.

    The 72-hour timeframe is not unexpected and aligns with reporting obligations under the Security of Critical Infrastructure Act 2018 (Cth) and the Cyber Security Act 2024 (Cth), and is consistent with the position under the GDPR.

  • Consent for trading personal information

    The Bill proposes a new requirement for consent before “trading” personal information which would apply to certain use cases such as sharing personal information for direct marketing or consideration (i.e., selling personal information). Depending on the final form of the legislation, the concept may extend beyond traditional data sales and affect a broader range of data-sharing, advertising and digital ecosystem arrangement. 

  • Right to erasure for large digital platforms

    New APP 14 introduces a right for individuals to request destruction of their personal information held by a ‘large digital platform’ (LDP).

    An LDP is defined as an organisation that provides a social media service, relevant electronic service or designated internet service (as defined under the Online Safety Act 2021) and which either: 

    (a) has an average monthly Australian end-user base of at least 2.5 million for the previous financial year; or 

    (b) is prescribed by regulations. 

    This is a significant and novel right in the Australian context. An LDP must assess and, where no exception applies, destroy the requested information within a reasonable period and provide written notice of the outcome, unless an exception applies. 

    Key exceptions include where a permitted general situation applies, where an Australian law requires retention, where destruction is technically impossible or infeasible, or where the information is strictly necessary to continue providing an ongoing service to the individual. 

    Organisations that qualify as LDPs will need to build infrastructure and workflows to receive, assess and respond to erasure requests.

  • New controller and processor definitions

    The reforms introduce new definitions of ‘controllers’ and ‘processors’:

    • a controller is an APP entity on whose behalf a processor handles personal information, and 
    • a processor is an APP entity that acts in accordance with a controller's documented written instructions and only for the purposes specified in those instructions.

    The introduction of the controller-processor framework clarifies the allocation of primary compliance responsibility where one APP entity handles personal information on behalf of another. The controller bears primary responsibility for APP compliance. With the exception of APP 1 (privacy governance) and APP (data security) 11, the processor will be shielded from most APP obligations, provided it stays within those instructions. 

    Organisations that engage third-party service providers to handle personal information on their behalf will need to ensure documented written instructions are in place to establish processor status and allocate compliance responsibility appropriately.

Immediate action items: what should organisations be doing now?

The reforms assume a level of organisational maturity that many entities are still working towards.

Regardless of the final form of the legislation, organisations should consider whether they can confidently answer the following questions:

  • Do we understand what personal information we hold and where it resides?
  • Have we mapped key data flows across systems, vendors and third parties?
  • Can we justify our higher-risk data practices as "fair and reasonable"?
  • What are our collection points and where do we rely on consent? 
  • Could we identify affected information and meet a 72-hour breach reporting deadline?
  • Are retention and destruction processes actually operating in practice?
  • Does the Board receive meaningful reporting on privacy risk and compliance?
     

"The content of the reform package codifies a number of quasi-regulatory positions which have been consistently signalled in recent OAIC determinations and commentary from Commissioner Kind. The approach makes clear that Australia's privacy framework will continue its current shift in focus towards greater accountability, governance and responsible data practices, with strong emphasis on ensuring that Australia has a well-equipped and active regulator driving the agenda in this space." – Ooma Khurana, Maddocks TMT Partner

Don't wait for the reforms

Over recent years, the OAIC has consistently demonstrated through its guidance, investigations and enforcement activity that expectations around privacy governance, transparency and accountability are increasing. 

Many of the proposed reforms also reflect emerging themes across:

  • OAIC guidance and enforcement;
  • privacy best practice;
  • associated regulatory and compliance obligations;
  • cyber and data governance frameworks; and
  • community expectations.

Although the current uplifts to legislation remain in draft form, organisations should not delay privacy uplift initiatives.
 

"Many clients don’t know what to do when there is a development in the reform process. The reality is we don’t know if and when these laws will pass and what their final shape will be. In the meantime, organisations that are already investing in data mapping, privacy management plans, governance frameworks and incident response capability will be significantly better positioned for the next phase of privacy reform." – Sonia Sharma, Maddocks TMT Partner (Privacy, Cyber and AI)

The consultation window is short

The Government has specifically requested feedback on how the proposed reforms will operate in practice.

For many organisations, submissions are likely to be most valuable where they focus on:

  • implementation challenges;
  • operational impacts;
  • compliance costs;
  • transitional periods;
  • data governance challenges;
  • breach-response practicality; and
  • industry-specific consequences.
     

“One of the Government’s objectives with these reforms is to try to simplify compliance obligations. However, practical and operational realities mean that whether the proposed reforms will achieve that objective and simplify compliance obligations remains to be seen. The Government is calling for submissions on practical realties- now is the time to be heard” – Rob Gregory, Maddocks Partner and Education Sector Head


With submissions due by 18 September 2026, organisations have only a limited window to influence reforms that could significantly affect privacy compliance, data governance, technology deployment and cyber resilience for years to come.

Would you like assistance assessing the impact of the proposed reforms or preparing a submission?

Please contact the Maddocks Privacy & Cyber team.

Sonia Sharma

Sonia has wide ranging experience advising on technology, cyber, telecommunication and general commercial matters, specialising in cyber and data resilience advice.

View profile

Ooma Khurana

Ooma provides specialist legal advice to both public and private sector clients with a focus on privacy, data protection and technology.

View profile

Robert Gregory

Rob is an experienced commercial lawyer who advises Australian and international public, private and for‑purpose clients across education, technology, media, telecommunications and consumer law.

View profile

Georgia Hunt

Georgia is an experienced commercial lawyer advising government, professional services and education organisations.

View profile

Shivani Thirayan

Shivani has extensive experience advising on a broad range of commercial matters with a focus on technology procurement, telecommunications, consumer laws, privacy and intellectual property protection.

View profile

Recent articles

Online Access