A consultation draft has been published outlining a number of major reforms to the Australian privacy framework. If implemented in its current form, the Privacy Amendment (Personal Data Protection) Bill 2026 (Amendment Bill) would significantly reshape how Australian businesses collect, use, disclose and protect personal information under the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs).

The consultation includes roughly 40 proposals designed to strengthen privacy protections, clarify existing obligations and improve the efficiency of the Office of the Australian Information Commissioner (OAIC). Some of the recommendations adopt changes recommended by the Attorney-General’s Department in its 2023 review of the Privacy Act (discussed here), whilst others are new.

Whilst the proposals remain subject to consultation, businesses should start assessing how the changes could affect their data governance, technology, marketing and incident-response practices. The consultation closes on 18 September 2026.

The key changes proposed in the Amendment Bill include:

Each of these changes is considered further below.

A broader test for handling personal information

One of the most significant proposals is the introduction of a new requirement that the collection, use and disclosure of personal information must be fair, reasonable and lawful.

This would replace the current requirements in APPs 3 and 6, which establish different tests for collection and use/disclosure.

Factors relevant to whether a collection, use or disclosure is fair and reasonable would include:

  • whether a reasonable person would expect it;
  • whether the collection, use or disclosure relates to the organisation’s functions or activities;
  • the transparency of the means and purposes of the collection, use or disclosure;
  • whether the purpose could be achieved using less personal information (i.e. data minimisation);
  • whether individuals have a genuine choice;
  • the impact on privacy and risk of harm to the individual (including whether the harm is proportionate to any benefits to the individual); and
  • in the case of data relating to minors, the best interests of the child.

Compliance would therefore involve more than securing consent or including appropriate wording in a privacy policy. Businesses will need to demonstrate that their processing practices are objectively fair and proportionate.

Introduction of controller and processor roles

The Amendment Bill proposes a formal distinction between controllers, which determine why and how personal information is handled, and processors, which act on their behalf.

A processor may avoid liability for certain acts when it acts:

  • in accordance with the controller’s instructions;
  • for purposes specified by the controller; and
  • under instructions documented in writing.

However, processors will retain direct obligations under APP 1 (open and transparent management of personal information) and APP 11 (security of personal information).

Businesses will need to review agreements with their service providers and ensure that responsibilities and instructions are clearly documented. Existing privacy clauses may not include sufficient detail.

New rules for “trading” in personal information

The proposals introduce a framework for trading in personal information. A “trade” is a disclosure for money or other consideration, or for direct marketing purposes. There would be exceptions (where a disclosure does not constitute a trade), including where the disclosure is connected with the supply of a product or service requested by the individual to whom the information relates from the recipient of the information, incidental to a business sale, the disclosure occurs as part of a controller to processor transfer or where the disclosure is for the purpose of investigating or remedying unlawful or fraudulent activity.

Personal information can only be traded with consent, unless the disclosure is required or authorised by law or falls within another specified exception.

Importantly, entities that trade in personal information, or collect it from a third party where the disclosure from that party constitutes a trade, will become subject to the Privacy Act, regardless of turnover, as a new carve-out from the existing small business exemption.

This could affect data brokers, advertising businesses, digital platforms and other organisations that monetise or exchange customer information.

Faster and more active responses to data breaches

The proposed data-breach reforms will place greater emphasis on speed, mitigation and operational readiness.

Key measures include:

  • a requirement to notify the OAIC of eligible data breaches within 72 hours, beginning when the organisation forms a reasonable belief that an eligible data breach has occurred. If it is impossible or impracticable to submit a notification at that time, an incomplete statement may be lodged, along with details of subsequent material changes or errors;
  • imposing a duty to mitigate actual or reasonably suspected data breaches (not just those which constitute “eligible data breaches”), by taking reasonable steps to prevent or reduce harm to the individuals whose information is involved in the breach; and
  • a requirement to take reasonable steps in the circumstances to implement practices, procedures and systems to ensure compliance with the data breach regime.

These changes will make planning, early escalation and decision-making critical.

Stronger direct-marketing protections

The Amendment Bill defines direct marketing broadly as advertising or marketing directed to an individual where personal information is used to select, identify or target that person.

Organisations would need to provide a simple opt-out mechanism and clearly explain how an individual can request not to receive direct marketing communications.

Additional requirements are proposed for ad-supported services, where the making of direct marketing communications to users is itself a source of revenue for an organisation. Providers would need to offer the service on different terms to people who opt out, and that alternative must offer users a genuine choice to continue receiving the service.

As with the current regime, the direct marketing requirements under APP 7 will not apply to commercial electronic marketing (which is regulated by the Spam Act 2003 (Cth)).

Businesses should start identifying the extent of their direct marketing practices and any ad-supported services.

Recognition of precise geolocation tracking data

Precise geolocation tracking data would be treated as sensitive information, meaning that it can only be collected with consent (subject to specific exceptions).

The proposed definition covers information generated or derived from a device or technology that:

  • identifies an individual’s location within a radius of 500 metres; and
  • is collected and held by reference to the individual’s location over time.

Organisations operating mobile applications, connected devices, location-based services or behavioural advertising should consider if this information is collected, and whether appropriate consent mechanisms are in place to satisfy the new requirement.

Enhanced security and deletion obligations

The reforms will uplift information security and deletion/de-identification expectations. Organisations would need to:

  • consider whether personal information should be destroyed when it is no longer required under the APPs (as well as take reasonable steps to destroy or de-identify the information);
  • take steps (including both technical and organisational measures) to ensure information to which APP 11 obligations apply can be identified across systems;
  • regularly evaluate the effectiveness of security and deletion measures; and
  • de-identify health information prior to disclosure where collected for research or statistical analysis relevant to public health or safety, or the management, funding or monitoring of a health service.

These measures reinforce the importance of data mapping, retention schedules and technical deletion capabilities.

Right of erasure on large digital platforms

The Amendment Bill broadens the suite of data rights available under the Privacy Act by proposing a new APP 14, which would give individuals the right to requires deletion of their personal information by certain “large digital platforms”. Large digital platforms are defined by reference to the Online Safety Act 2021 (Cth) and include providers of social media services, relevant electronic services and designated internet services.

The right would only apply to organisations with an annual group turnover of at least AUD $500 million, or which serviced at least 2.5 million end users, in the preceding financial year.

Clarification of existing definitions

A number of changes to existing definitions have been proposed, which codify the OAIC’s current expectations:

  • Personal information will include any information “that relates” to an individual or an individual who is reasonably identifiable. A note at the end of the definition confirms that data should be classified as personal information if it allows an individual to be recognised, singled out, or otherwise dealt with as a distinct individual, even if direct identifiers are not included. This confirms the Privacy Commissioner’s position on “individuation” adopted in recent determinations regarding the use of tracking pixels (discussed here);
  • The concept of “collection” includes personal information collected indirectly, obtained from a website or generated or derived from other information;
  • De-identification is contextual (and reversible). Information will be considered to be de-identified if, at a particular time or in particular circumstances, it has ceased to be information or an opinion which relates to an identifiable or reasonably identifiable individual; and
  • An individual will be “reasonably identifiable” if they can be identified by combining the information or opinion with other information or opinions that are reasonably available.

What is not expected to change

A number of changes agreed “in-principle” as part of the Attorney-General Department’s 2023 review have not been incorporated into the Amendment Bill. This includes:

  • Abolishing the small business exemption;
  • Reducing the scope of the employee records exemption;
  • Mandatory privacy impact assessments for “high risk processing” activities;
  • The proposed expansion of data subject rights to include rights of objection, erasure (by all APP entities regardless of size or revenue) and de-indexation from public search engines;
  • Introducing a “direct right of action” allowing individuals to apply directly to courts for relief where their privacy has been interfered with;
  • Requiring entities to establish maximum and minimum retention periods; and
  • Proposing an Australian equivalent to the Standard Contractual Clauses to underpin overseas data transfers.

What businesses should do now

Organisations should use the consultation period to:

  1. Map current data practices, including direct and indirect collection, targeting, trading, location tracking and third-party sharing.
  2. Assess fairness and proportionality of current and proposed processing activities.
  3. Review controller–processor contracts and document processing instructions.
  4. Test breach-response procedures against a 72-hour notification deadline.
  5. Examine marketing opt-outs, particularly for advertising-funded services.
  6. Strengthen information security and deletion controls across systems and service providers.