Tell me in a minute
The Government has released an exposure draft of the long-awaited second tranche of privacy reforms, calling for feedback from stakeholders, which given the economy-wide reach of these laws should include almost every business operating in Australia.
The proposed reforms cut both ways, strengthening privacy protections while simplifying some compliance obligations. They include:
- Stronger privacy protections and individual rights: a broader concept of ‘personal information’, tighter consent rules, new overarching requirements around fairness and reasonableness, strict restrictions on direct marketing (including targeted advertising), and a new right of erasure in relation to information held by large digital platforms.
- Streamlined compliance requirements in some areas: simplified transparency requirements and a more practical approach to information access requests.
One headline change for business is the new ‘controller’ v ‘processor’ split, which will concentrate compliance obligations on the entities that actually call the shots on data handling.
Submissions close on 18 September 2026, so the window to shape the outcome is short – after a long wait, it seems that the Government is now prioritising action in this space as part of its broader push to lead on technology-related regulation.
Snapshot of Privacy Reforms Tranche 2
More than 18 months after the first tranche of privacy reforms passed Parliament (see our previous deep-dive here), the Government has released an exposure draft of its much-awaited second tranche of reforms.
Many of the proposed reforms are based on recommendations from the Privacy Act Review Report published in February 2023. However, some aspects have evolved, and there are proposed amendments aimed at streamlining compliance as well as amendments that seek to implement stricter privacy controls. One of the key changes for businesses is that the reforms introduce a ‘controller’ v ‘processor’ distinction that is a feature of many privacy laws around the world - this helps to concentrate the compliance burden on entities that have the most direct control over relevant information handling practices.
This intention to streamline compliance and be more focused on ‘controllers’ to bear the core compliance burden will come as a degree of relief to those in the business community who had expressed concerns about potential compliance costs from the continued reforms to the Privacy Act. These concerns were echoed in the Productivity Commission’s December 2025 report on ‘Harnessing data and digital technology’, which emphasised that the merits of any reforms should be considered by reference to ‘the benefits to individuals, as well as the costs to regulated entities and the resultant effect on innovation and productivity.’
We will need to wait and see whether the Government’s proposed package of reforms gets the balance right.
When are exposure draft submissions due?
Submissions on the exposure draft are due by 18 September 2026 – a relatively short period in the context of the extended multi-year review process that has brought us to this stage and the broader set of areas that the consultation seeks to cover. The Department has requested that submissions be concise, around 1,000 words, which may be a sign that it considers that there has been adequate consultation to date on the proposed changes.
Adopting a technology neutral, principles based approach to the privacy reforms
While we have set out some high-level initial thoughts in this alert, these reforms warrant deeper analysis to understand the full impact on businesses.
One threshold observation is that the Government has deliberately maintained the ‘technology neutral’ and ‘principles based’ design of the Privacy Act, without seeking to legislate specifically for technologies (eg smart glasses and other wearable devices) that have been a lightning rod for potential privacy concerns in media reports.
In our view, this is welcome as a technology-specific approach would inevitably become quickly outdated and potentially unworkable as technological progress continues at pace. Nonetheless, the consultation does explicitly invite feedback as to whether the proposed reforms are sufficient to address risks associated with wearables and other emerging technologies, so the door is still open for further changes if deemed necessary.
Key focus areas for data controllers
While the changes are perhaps more balanced than may have originally been feared by the business community, the changes will still require detailed review and analysis to ensure compliance. Some key areas data controllers will need to consider include:
- changes to key definitions, including expanding the scope of personal information, specific regulation of geolocation tracking data, and stricter rules on consent
- a new overarching requirement to ensure all information handling is ‘fair and reasonable’, with consent not providing a cure all
- ensuring adequate procedures and systems are in place to effectively respond to data breaches, including complying with strict new reporting timeframes, and destroying information that is no longer needed
- revisiting collection notices to ensure they are clear and in plain language, readily understandable, up to date and concise, particularly where the collection relates to a complex customer relationship where the use of personal information may be broad
- for large online platforms, complying with data erasure requests
- for all organisations, working through contractual allocation of liability for privacy compliance with data processors
Jump to your relevant section
- Expanded scope and core definitions
- New rules for handling personal information
- Data security and data breaches
- Data access and erasure
- Exceptions for information processors
Expanded scope and core definitions
The amendments would ‘update and clarify’ certain key concepts under the Privacy Act to ‘better reflect contemporary digital environments, data practices and community expectations.’
|
Topic
|
Proposal
|
What it means
|
|
Personal information |
The concept of ‘personal information’ will be expanded to include information that ‘relates to’ a person and will no longer be limited to information that is ‘about’ a person. |
This will expand the scope of information that is regulated under the Privacy Act. However, the consultation paper indicates that there will still be limits. A contextual assessment will still be required to determine whether there is a sufficient connection between the information and the individual in question (eg on the basis that the information ‘says something’ about the individual or their activities, characteristics, behaviour, circumstances, movements, preferences or interactions). |
|
Collection |
There will be a clarification that information can be collected by drawing inferences from other information. However, an entity will not be taken to collect sensitive information simply because it has collected personal information from which sensitive information can be derived. |
This will be a relief for organisations that routinely handle images of persons from which sensitive information could be readily derived (eg because the photo shows a person wearing religious garments or reveals obvious information about their health or a disability). If such images were automatically treated as sensitive information, it would make handling of images at scale challenging from a compliance perspective. |
|
Disclosure |
The amendments would define ‘disclosure’ to occur when an entity makes personal information accessible to another person or body. |
The consultation paper explains that mere transmission or storage of personal information, including overseas, will not constitute a disclosure unless the information is made accessible to another person or body. This is significant for multinationals using overseas cloud infrastructure: moving or storing data offshore will not, without more, be a disclosure, but access by an external person or body (including a processor) will be. |
|
De-identified information |
The definition of ‘de-identified’ will be revised so information is de-identified only where, in the circumstances, it no longer relates to an identified or reasonably identifiable individual. |
De-identification is not a fixed state. Analytics datasets may become re-identifiable as technology or data availability changes, requiring ongoing risk assessment and safeguards. |
|
Precise geolocation tracking data |
There will be a new concept of ‘precise geolocation tracking data’, defined as personal information that identifies an individual’s location within a radius of 500m. |
This will be deemed to be a new category of sensitive information, which can only be collected with consent. The consultation paper confirms that this is intended to capture information that enables tracking over time, rather than once-off point in time information or less precise locations. |
|
Consent |
Consent may be either express or implied, but must always be: voluntary, informed, current, specific and unambiguous. |
This is consistent with consent frameworks that have been proposed in other related laws – eg under the social media minimum age framework established under the Online Safety Act. Helpfully, implied consent is still recognised as valid provided all relevant consent criteria are satisfied. Unsurprisingly, the consultation paper identifies bundling as an example of a practice that may render consent involuntary, along with user interfaces that make it unreasonably difficult for an individual to avoid giving consent. However, subject to specific rules around direct marketing on ad-supported services (discussed further below) consent may still be voluntary where it is required to access features or elements of a good or service. |
|
Reasonably identifiable |
A person may be reasonably identifiable even if their name or legal identity is not known. For example, an individual could be identified by a pseudonym or other ‘identifier’. It will be sufficient if the information ‘allows an individual to be recognised, singled out, or otherwise dealt with as a distinct individual in practice.’ |
This effectively expands the Privacy Act to cover ‘individuated’ information, meaning that privacy compliance must be considered whenever a person can be singled out for individual treatment, even where their underlying identity remains unknown. This definition appears to move closer to the ‘individuation’ approach to interpreting when an individual is ‘reasonably identifiable’ endorsed by the Privacy Commissioner in the recent Monash and Medmate determinations as a natural evolution of the concept of ‘identifiability’ (see our discussion of those decisions here). This may have significant implications for online tracking technologies that rely on identifiers that may be assigned without knowing the underlying identity of the user in question. |
New rules for handling personal information
The exposure draft proposes to significantly revise and streamline existing rules regarding the collection, use and disclosure of personal information and associated notice requirements. Existing APPs will be replaced with new streamlined versions that will hopefully be easier to implement in practice, particularly in new digital contexts that were likely not in contemplation when the existing APPs were developed. Some aspects of these changes – most notably, the introduction of a new overarching ‘fair and reasonable’ requirement – have long been foreshadowed. Some of the simplification changes were perhaps less expected and will be welcome. An area of uncertainty concerns ad-supported service and when a genuine choice is provided for users to receive different services where they have opted out of direct marketing.
|
Topic
|
Proposal
|
What it means
|
|
Fair and reasonable |
All collection, use and disclosure of personal information must be ‘fair and reasonable’. There will be a series of factors to be considered when assessing whether a particular activity is fair and reasonable, including the relevant individual’s expectations, the level of transparency that has been provided, whether relevant objectives could be achieved with less information and whether the individual had a genuine choice in relation to the handling of their information. When children are involved, the best interests of the child will be a primary consideration. |
This is one of the cornerstones of the reform that has been consistently identified as a ‘gamechanger’ by the OAIC and other privacy advocates. Pleasingly for business, the fair and reasonable test has been introduced as a substitute for, rather than in addition to, many of the existing APPs dealing with information handling. This includes the framework in the existing APP 6 under which organisations must establish consent or some other legal basis to support any proposed ‘secondary’ use of information beyond the particular purpose for which it was collected – a process that can at times become quite artificial. The consultation paper explains that, under the new single ‘fair and reasonable’ principle, the concepts of ‘primary’ and ‘secondary’ purposes will become less relevant, though identifying the original purpose of collection will ‘remain central to the assessment of subsequent uses and disclosures’. The further away an entity strays from the original purpose, the harder it will be to argue that its actions are fair and reasonable. |
|
Permitted General Situations |
The permitted general situation exceptions to handling of personal information in section 16A have been amended to enable entities to take appropriate action to address unlawful and wrongful conduct, including financial abuse. |
While this seems sensible, many of the permitted general situations only authorise disclosure of information to entities that are not overseas recipients, for example, even where the disclosure is reasonably necessary for a confidential alternative dispute resolution process. This may impact the ability of multinational entities which have arbitration clauses providing for arbitration outside of Australia to disclose personal information for the purposes of any arbitrations. |
|
Consent to collection of sensitive information and trading |
Consent will be required for all collection of sensitive information and any ‘trading’ in personal information. In this context, ‘trading’ will automatically include any disclosure of personal information for the purposes of direct marketing unless it is from a controller to a processor for the purposes of providing services to the controller. Consent will not be required in certain circumstances, including where:
|
The consultation paper expressly states that ‘trading’ in personal information is intended to be interpreted broadly and will extend to disclosure of information collected by cookies or pixels (and presumably other types of online tracking technologies) for use in programmatic advertising processes. This may complicate existing online advertising practices, where information may be automatically shared across websites for the purposes of identifying user interests and delivering relevant advertising across different platforms and websites. The implications will need to be carefully assessed by the industry. Consistent with recent Privacy Commissioner determinations on tracking pixels (see our coverage here), the changes may drive more explicit consent requirements and other tracking banners or notices on websites aimed at Australian users. The exception for information drawn from publicly available documents may ease concerns around the practicality of complying with consent requirements when collecting information from the public internet. However, the consultation paper warns that the underlying ‘fair and reasonable’ standard will still apply even where consent is not strictly required, so it will not mean that scraping information from the public internet is fair game – other fairness considerations as outlined above will still operate as a constraint. |
|
Transparency |
Requirements around privacy collection notices will be significantly streamlined, doing away with much of the present overlap between collection notices and privacy policies. Going forward, the focus will simply be on ensuring that individuals are aware of the fact and circumstances of the collection of their information along with the purposes for which the collecting entity intends to use or disclose the information. Other details about information handling practices will remain in the privacy policy. There will be a new obligation to ensure that notices are in clear and plain language, readily understandable by the individual, up-to-date, and concise. |
The focus on the quality of notices rather than their contents is welcome on all fronts. These changes will hopefully drive shorter and more accessible collection notices that concentrate on key information regarding the purpose for which information will be used and disclosed. We expect that this is an area where there would be value in lawyers working alongside experts on communication and user experience to hone relevant messaging. The consultation paper warns against notices that are ‘excessive, vague, ambiguous, or include irrelevant information that may obscure key matters or make them hard to understand’. This is consistent with the recent focus by consumer protection regulators on dealing with ‘dark patterns’ and similar behaviours that may confuse consumers or encourage them in directions that may not be in their best interests. Finally, we think that the new requirements around consents and opt-outs from direct marketing would be likely to drive cookie consent pop-ups in Australia in the same way that the GDPR did in the European Union. |
|
Direct marketing |
The concept of ‘direct marketing’ will be expressly defined to include any type of advertising or marketing to an individual who is identified or targeted as part of a class, where the identification or targeting is done using personal information. Rules regarding the use of personal information for direct marketing will be substantially simplified, with the key requirements being to provide a simple opt-out, which must be explained in each direct marketing communication. Ad-supported services (ie services that generate revenue directly from direct marketing rather than from goods and services that are the subject of direct marketing) will be able to impose different service conditions for users who do not consent or request not to receive direct marketing, provided that users still have a ‘genuine choice’ to continue using the service without receiving direct marketing communications. |
These changes will settle the long-running debate as to whether targeted online advertising is a form of direct marketing – under the proposed changes it clearly will be. Somewhat less clear is whether content or product recommendations (say on a video streaming site or an online shopping site) will be caught, or whether they would not be considered advertising or marketing material within the ordinary meaning of those terms. The provisions dealing with ad-supported services may be challenging to apply in practice, given uncertainty as to what will constitute a ‘genuine choice’. The consultation paper indicates that relevant considerations will include how easy it is to choose another option, the information provided to explain the options and the ‘comparative value’ of the options. |
Data security and data breaches
The exposure draft includes a number of changes that tighten and clarify existing aspects of the notifiable data breach regime and information security compliance requirements under APP 11. These largely reflect standard practices that many organisations would already follow. The overarching desire appears to be to lift the standard of compliance across the Australian economy to ensure a good compliance baseline is in place to minimise the risk to Australians of the inevitable data breaches that will occur in an increasingly digitised world.
|
Topic
|
Proposal
|
What it means
|
|
Data breaches |
There will be new positive obligations for entities to:
|
The obligation to implement practices and procedures to enable organisations to respond to data breaches will sit alongside the existing APP 11 obligation to protect the security of personal information. It effectively legislates the need for organisations to have an appropriate data breach response plan. The new obligation to mitigate the risk of harm will apply even if the affected individuals are not likely to suffer serious harm. This clarifies that entities must still take action even where the breach is not a notifiable data breach. |
|
Notifiable data breaches |
There will be a number of refinements to the existing notifiable data breaches regime, including:
|
These changes should all largely reflect what organisations are currently doing in practice. The new 72-hour notification period will not alter the process for assessing suspected breaches. Where there has been a suspected breach, an entity would still be required to undertake an expeditious assessment (aiming to complete the assessment within 30 days), with the 72-hour period only kicking in once there are reasonable grounds to believe that the notification threshold has been satisfied. However, note that the obligation to notify the eligible data breach to affected individuals will still need to be made at the same time, or as soon as practicable after, the complete notification is made to the Privacy Commissioner. |
|
Data security |
There will be a number of changes to tighten existing data destruction and de-identification obligations, including requirements for entities to:
|
These changes are all consistent with existing recommended risk management practices, but reflect an ongoing concern that not all entities have good data management hygiene and some may be holding records containing personal information without appropriate awareness or consideration for ongoing data security risks. Where information is no longer required for an ongoing business purpose, it makes good sense to destroy the information to limit the possible fallout in the event of a future data breach. |
Data access and erasure
There will be a new exception to the existing access rights under APP 12 where providing access is unreasonable or impracticable due to technical impossibility or infeasibility. This would relieve entities from any disproportionate burden imposed by broad access requests and will likely be welcomed by businesses that have been grappling with the absolute nature of the existing access regime.
The exposure draft also proposes a narrowly framed right of erasure targeted specifically at information held by ‘large digital platforms’.
|
Topic
|
Proposal
|
What it means
|
|
Data access exceptions |
There will be new exceptions that enable an entity to refuse information access requests where ‘giving access remains unreasonable or impracticable due to technical impossibility or infeasibility’ despite reasonable steps having been taken. |
This will be a relief for businesses that have experienced technical challenges in complying with broad, all-encompassing information access requests that may extend to material in long-term archives that is very challenging to identify and access. The consultation paper clarifies that the exception will not apply where an entity has deliberately designed its systems to make access difficult, as a way of avoiding access obligations. The exception also only applies ‘to the extent’ that doing so is unreasonable or impracticable, so an entity will still need to comply with a request to the extent it is reasonably capable of doing so. |
|
Data erasure rights |
There will be a new APP 14 introduced to give effect to a new right for individuals to seek the erasure of personal information held by ‘large digital platforms’. Relevant platforms will be obliged to comply with an erasure request within a reasonable period, unless a relevant exception applies. Exceptions include where:
A large digital platform is one that is part of a business group with gross revenue for the previous financial year of at least AU$500m and/or that has at least 2.5m average monthly end users in Australia. |
The prospect of a broad right of erasure being introduced under the Privacy Act was one of the more controversial aspects of the privacy reform process to date. Businesses were concerned that such a right could present a disproportionate compliance burden. The Productivity Commission agreed and in its report on ‘Harnessing data and digital technology’ recommended against the introduction of a broad right. The exposure draft adopts a more limited approach that is focussed only on information held by ‘large digital platforms’. The consultation paper does not provide a clear rationale for narrowing the scope of the right in that way, though presumably it reflects the Government’s assessment of the generalised concerns that Australians have about the information-gathering and processing capabilities of ‘big tech’ companies. The distinction between large digital platforms and other large businesses in Australia with extensive data holdings is not immediately apparent. |
Exceptions for information processors
There will be a new distinction introduced between a ‘processor’ and a ‘controller’ consistent with many privacy laws in other jurisdictions, which will support a more targeted compliance burden for those entities which determine how personal information is collected and used.
|
Topic
|
Proposal
|
What it means
|
|
Processors and controllers |
An APP entity will be a ‘processor’ where it does an act or engages in a practice on behalf of another APP entity (a ‘controller’) in accordance with the controller’s written instructions and for a purpose specified by the controller in those instructions. |
The distinction between processors and controllers is a common one used in many privacy laws around the world. It is a helpful mechanism for focussing compliance obligations on entities that determine in practice how information is collected and used. The distinction only applies where both entities are bound by the APPs. Given some of the quirks of the Privacy Act, which does not apply to small business entities, this may still mean that entities acting as processors will have broader compliance obligations in certain circumstances. For example, where a service provider is providing services for a small business entity, the service provider may still be exposed to the full scope of APP compliance obligations even if that would not be the case when dealing with a larger business customer. |
|
Exceptions for processors |
An act or practice by an entity that is acting as a processor will not be in breach of the APPs if it is done on behalf of a controller. This will not apply in relation to:
|
An entity will only be acting as a processor if it is acting in accordance with written instructions from a controller. The consultation paper makes clear that, where a processor acts outside the documented instructions, the exceptions will not apply, and the processor entity will be subject to the full scope of APP compliance obligations. This will inevitably put significant pressure on the scope of the instructions and the way that they are documented as written instructions. This could require greater diligence in documenting service arrangements where information-handling practices may currently have been subject to oral directions or directions given in operational correspondence rather than a formalised set of instructions. While the consultation paper indicates that instructions would still be able to leave technical and operational matters to the discretion of the processor (to leverage its relative expertise in those matters), in practice processors may prefer prescriptive instructions, or at least instructions that expressly delineate the scope of any technical discretion, to ensure that they retain the benefit of the compliance exceptions. |
|
Allocation of liability |
An exempt act or practice by a processor in accordance with the controller’s instructions will be deemed to have been done or engaged in by the controller. That means that a controller will in effect become directly liable for breaches caused by the conduct of the processor. |
The attribution of liability to the controller makes sense from the perspective of ensuring that individuals have appropriate recourse for mishandling of their information. However, it will inevitably become a sensitive point in contractual negotiations, with controllers and processors seeking clarity on how any liability should be allocated, particularly if there may be room for ambiguity as to what the relevant processing instructions required of the processor. |
We will continue to monitor developments and update clients. If you would like to discuss further what the proposed reforms mean for your business, or require assistance with developing a submission, please contact one of our privacy specialists listed below.
You can also access our other privacy related insights via our Data and privacy insights hub.






