Australia’s Next Wave of Privacy Reforms: Unexpectedly Bold but also Timid

Published
02 Sep 2026
Read time
7 min read
Category

On 31 August 2026, the Attorney-General announced the next phase of privacy reforms. The Privacy Amendment (Personal Data Protection) Bill 2026, now out for consultation, carries roughly 40 proposals.

The Bill isn’t a crack down on smart glasses (despite what some confused media outlets have been saying). However, some of the reforms go beyond what we at Privacy 108 expected to emerge from the long consultations of the last few years around Privacy Act reform while there are also some interesting omissions.

What’s Positive in the Proposed Reforms

First, there are many positive proposals in this package that bring Australia more into line with GDPR and other global privacy laws. For example:

A wider definition of personal information: Information that allows an individual to be recognised or distinguished from others is now included, even if it is via pseudonyms or device identifiers or browser IDs. The crucial definitional change is that it is now information that ‘relates to’ an identified or reasonably identifiable individual rather than information ‘about’ an individual.

A positive move is that the definition of sensitive information has now grown to include precise location data, meaning data that identifies an individual’s specific location to within a radius of 500 metres. Genomic information is also now proposed which brings us into line with the GDPR.

A 72-hour data breach notification timeframe: In line with the GDPR, an organisation needs to notify the regulator within 72 hours once they have grounds to believe an eligible data breach has occurred. This is down from the current 30-day assessment period. Individuals must be notified at the same time.

Tighter definition for consent: a consent for handling personal information must be all of: voluntary, informed, current, specific and unambiguous. Seeking consent through preselected settings or pre-ticked boxes wouldn’t meet the test.

Bold and Internationally Unusual Proposals

New ‘fair and reasonable’ test

A centrepiece “fair and reasonable” test is the most notable proposed reform. The new requirement is that the collection, use and disclosure of personal information must be “fair and reasonable in the circumstances.” This single objective test would replace the current collection, use and disclosure rules in APPs 3, 4 and 6.

The Bill sets out the factors an entity must weigh: what a reasonable person in the individual’s circumstances would expect, the connection to the entity’s functions, transparency, data minimisation, genuine choice, the impact on the individual, proportionality, and, where a child is involved, the child’s best interests.

This is a unique approach. As technology lawyer, former ACCC boss, now academic Rob Nicholls has pointed out, while the GDPR is all about the lawful bases of which consent is one, with this fair and reasonable test, businesses “cannot consent their way around it.” As he notes, the framing is closer to a duty of care, shifting the burden from individuals onto organisations.

On the one hand, this is welcome because it brings the rules for handling data more into line with general consumer protection rules which are also high level – e.g. a prohibition on misleading and deceptive practices and unfair contracts.

We don’t need to read and agree to our toaster’s technical specifications, we can trust that the businesses involved have to do the right thing without us conducting our own engineering research exercise. It should be that way also for businesses that use personal information.

At the same time, with this kind of high-level test, businesses could find there is a lot of room for uncertainty about what is permissible. There may also be a temptation to engage in commercially wishful thinking about what is fair and reasonable.

Some detailed guidance from the OAIC will be needed to ensure that doesn’t happen.

The right to delete, but only on the big platforms

The second notable reform is a new right to erasure, letting individuals ask that their personal information be destroyed. This is where the Government becomes timid.

The right would apply only to “large digital platforms,” – i.e. the big social media platforms. Every other organisation that holds your personal information is not included.

This is a much weaker right than exists in comparable countries. Under the EU’s GDPR, the right to erasure applies to every data controller. California’s deletion right applies to every covered business. Canada’s proposed reforms also take a general approach.

In fact, no major privacy law regime defines right to erasure so narrowly. Even within the proposal, the right is qualified: it is subject to exceptions for public interest and the platforms’ own legitimate interests, and it does not apply where destruction is technically impossible or infeasible.

Digital marketing rules

The other area that will generate some confusion is how the proposed changes to direct marketing provisions will affect digital marketing.  The proposal is for consent to be mandatory for trading personal information which includes “disclosure of personal information by an organisation for monetary or other consideration or for direct marketing purposes”.

This is a notoriously complex industry and the consultation paper is itself quite complex on what is direct marketing, and how ‘direct’ the marketing must be to qualify.

It seems to indicate that direct marketing includes group-level targeting that relies on personal information. The sentence that caught our eye in the consultation paper was that

“disclosure for the purposes of direct marketing is intended to be interpreted broadly and includes disclosures that support or inform direct marketing, even where marketing is not the sole purpose. For example, this may include disclosures of cookies or pixels in programmatic advertising processes.”

If loading a Meta, Google or TikTok pixel, or setting an advertising cookie, is a “disclosure for the purposes of direct marketing” and therefore trading, then a lot of websites would need opt-in consent.

If that is what is intended, that is a big shift for Australia which has never operated under a cookie-consent regime.

What’s Missing

It’s probably not a great surprise that the removal of the exemptions for small businesses and employee records handled by private companies has been kicked down the road.  Removal of the exemption for political parties was never really on the agenda, unfortunately.

The obligations to implement privacy by design and by default has not been included.  Nor is there an obligation to conduct mandatory PIAs for high‑risk processing.

The individual rights introduced are less expansive than expected – with no right to object or to data portability.  Perhaps most importantly there is no individual right of action for breach of the Privacy Act.  Given the regulator’s current issues with handling complaints in a timely way (to be covered in an upcoming blog post), an individual right of action might have given those impacted by privacy breaches a much needed alternative course of action.

What’s Next

On the whole, if enacted this package will be a big step forward for Australians’ privacy. The definitions and details still aren’t finally settled, so there is room to influence outcomes.

The published consultation paper is open for submissions up to 18 September 2026. We will be making a submission (which we will publish on our website) and we would encourage anyone whose business depends on getting this right, to also contribute.

It looks like we are finally getting some real movement in privacy reform in Australia, even if it took concerns about smart glasses to get it moving.

Ready to turn insight into action?
Connect with Privacy 108.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Privacy 108 collects your name and contact details to respond to your enquiry and communicate with you about it. If you do not provide this information, we may be unable to respond. We do not disclose this information to third parties. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au.
Related articles
Subscribe to our Newsletter

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.