Skip to main content

On-demand webinar coming soon...


On-demand webinar coming soon...

Blog

Australia’s Privacy Act Reforms Raises the Standard for Personal Information Handling

Australia’s 2026 privacy reform consultation proposes changes across data handling, consent, privacy rights, security, and emerging technology governance.

Lara Eguia
Privacy Analyst
September 7, 2026

Australia privacy act

Australia’s latest Privacy Act consultation proposes significant changes to how organisations collect, use, disclose, secure, and respond to requests involving personal information.

On August 31, 2026, the Australian Government released a consultation paper and Exposure Draft of the Privacy Amendment (Personal Data Protection) Bill 2026 as the next stage of reforming the Privacy Act 1988.

The package contains roughly 40 proposals spanning core definitions, consent, personal information handling, direct marketing, data security, erasure, processors, regulatory powers, and emerging technologies. The Government is seeking feedback on how the measures would operate in practice, with submissions closing September 18, 2026. The Bill remains subject to further government consideration.

These measures are proposals rather than final obligations. Still, their breadth gives privacy teams a useful view of where Australia’s framework is heading. The consultation places particular attention on whether organisations understand the information they hold, why they use it, how individuals exercise meaningful choice, and whether governance keeps pace with technologies such as AI, smart glasses, and connected vehicles. 

Key Takeaways

  • The proposals would introduce a fair and reasonable test across the collection, use, and disclosure of personal information.
  • Consent would need to be voluntary, informed, current, specific, and unambiguous, with greater scrutiny of bundled consent, dark patterns, and preselected choices.
  • Proposed reforms span privacy operations, including data identification, direct marketing, erasure requests, security, breach response, processors, and regulatory oversight.
  • AI and wearable technologies sit directly within the consultation, increasing the importance of understanding derived data, behavioural information, biometric data, and precise geolocation.

 

A Fair and Reasonable Test Would Reach Across Data Use

One of the most consequential proposals is a single fair and reasonable test governing the collection, use, and disclosure of personal information.

The assessment would look at factors including an individual’s reasonable expectations, the relationship between the processing and the organisation’s activities, transparency, data minimisation, genuine choice, impacts on individuals, proportionality, and the best interests of children where relevant.

The practical effect reaches further than privacy notices. An organisation might describe a secondary use of customer data in its privacy policy, yet transparency alone would not establish that the use is fair and reasonable. Teams would also need to consider whether an individual would reasonably expect the activity, whether the organisation needs that amount of information, what choice the person had, and whether a less privacy-invasive approach achieves the same purpose.

For organisations, that creates a stronger connection between policy decisions and the underlying data map. Assessing an activity requires visibility into its purpose, data categories, systems, users, downstream disclosures, and associated risks. 

Consent Would Need to Demonstrate Genuine Choice

The proposed definition of consent would require it to be voluntary, informed, current, specific, and unambiguous.

The consultation provides useful signals about what that means in digital experiences. Bundled consent and interfaces that make refusal unreasonably difficult would weigh against voluntariness. Preselected settings and pre-ticked boxes would likely fall short of an unambiguous choice. Consent for undefined future uses would conflict with the requirement for specificity.

The proposal therefore shifts attention toward how consent works through the full customer experience.

Privacy and digital teams would need to understand which processing purposes require consent, how those purposes appear to the individual, where the resulting choice is recorded, and whether changes in data use require the organisation to revisit that choice.

A related proposal would require consent before an organisation trades personal information, subject to specified exceptions. The proposed definition reaches disclosures for monetary or other consideration and disclosures supporting direct marketing, including certain uses of cookies or pixels in programmatic advertising.

That connection between consent, data sharing, and marketing makes purpose-level governance especially relevant. 

Personal Information Would Cover More Modern Data Practices

The proposal would amend the definition of personal information from information “about” an individual to information that “relates to” an identified or reasonably identifiable individual.

The consultation explains that information might relate to someone through their activities, characteristics, behaviour, movements, preferences, or interactions. Identifiability would also account for information that identifies someone when combined with other information reasonably available to the entity.

This becomes especially relevant for AI and connected technologies. The proposed definition of collection expressly addresses information generated or derived through data analysis, artificial intelligence, or other technological processes. The consultation also discusses smart glasses, connected vehicles, and AI-generated inferences as areas where existing privacy concepts need to work in contemporary technical environments.

Privacy inventories therefore need to account for information organisations generate from existing data, alongside information collected directly from individuals.

Sensitive information would also expand to include precise geolocation tracking data and genomic information, while the consultation highlights biometric templates in the context of emerging technologies.

Privacy Rights and Data Retention Move Closer Together

The proposed reforms would introduce a right to erasure for individuals using large digital platforms.

The right would apply to qualifying platforms meeting specified revenue or Australian user thresholds. Those platforms would need to destroy personal information following a valid request unless an exception applies, then provide written notice explaining the outcome.

At the same time, proposed changes to APP 11 would place greater emphasis on identifying personal information and evaluating whether information that is no longer needed should be destroyed rather than retained in de-identified form.

Together, these proposals connect individual rights with broader data lifecycle governance.

An erasure workflow depends on knowing where personal information sits. A retention decision depends on knowing why it remains necessary. De-identification requires continued assessment of whether re-identification remains reasonably possible as technology and available information change.

That makes data discovery, processing inventories, retention controls, and privacy request workflows closely related parts of the same operating model.

Breach Response Would Face a Clearer Clock

The proposed amendments to Australia’s Notifiable Data Breaches scheme would introduce a 72-hour period for notifying the Information Commissioner after an organisation becomes aware of reasonable grounds to believe that an eligible data breach has occurred.

Where completing the full statement within that period is impossible or impracticable, the organisation would submit an incomplete statement and provide missing information later.

The proposals also establish a positive obligation to take reasonable steps to contain breaches and reduce harm, alongside requirements for practices, procedures, and systems that support effective response.

For privacy and security teams, readiness therefore depends on the path from detection to legal assessment, escalation, notification, remediation, and evidence. The timeline matters, but the operating process behind it determines whether the organisation reaches the right decision and records its actions as the incident develops.

AI and Wearables Make Privacy Governance a Cross-Functional Issue

The consultation gives emerging technologies a prominent role. The Government is specifically seeking feedback on whether the proposed definitions and safeguards adequately address technologies such as smart glasses and whether the definition of collection remains flexible enough for information generated through new technologies.

That brings privacy governance closer to AI, product, security, and data governance teams.

An AI system might derive information about an individual from existing data. A wearable device might continuously collect location, audio, video, or biometric information. A connected service might create new behavioural insights from several data sources.

Understanding those activities requires an inventory of systems and data uses, clear ownership, privacy risk assessment, and documentation that links technical behaviour with the purposes and safeguards approved by the organisation.

What Organisations Should Do During the Consultation Stage

The proposals remain subject to further consideration, so the current task is assessment rather than wholesale redesign.

Privacy teams should identify where the proposals would create the greatest operational impact across existing programs. The fair and reasonable test points toward reviewing high-volume and higher-risk processing activities. The consent provisions warrant examining current consent language and choice architecture. Proposed erasure and security changes place attention on data visibility, retention, rights workflows, and incident response. AI and wearable technology proposals make inventories of emerging technology use increasingly relevant.

These activities span several parts of the privacy program. OneTrust Privacy Automation supports processing inventories, privacy risk assessments, rights workflows, and compliance documentation. Consent & Preferences supports the governance of consent and individual choices across digital experiences. Incident Management supports structured breach assessment and response, while AI Governance connects AI inventories, ownership, assessments, and supporting evidence.

The common requirement across each area is operational visibility. Teams need to connect regulatory interpretation with the systems, data, decisions, and owners responsible for putting it into practice. 

Preparing for the Next Stage of Australia’s Privacy Reform

Australia’s consultation asks a practical question: how should stronger privacy protections work inside modern organisations and digital services?

The answer will continue to develop after submissions close on September 18, 2026. Privacy teams still have useful work to do now. Mapping the proposals against existing processing activities provides a clearer view of where future change would affect consent, data governance, individual rights, security, AI, and internal ownership.

Explore OneTrust’s Australian Privacy Act Compliance Solutions for further guidance on managing privacy requirements and operational readiness as Australia’s reform process progresses.

 

Key Questions About Australia’s 2026 Privacy Reform Consultation

 

The Government is consulting on the Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026 and related proposals for further reform of the Privacy Act 1988. The package contains roughly 40 proposals covering definitions, information handling, consent, security, erasure, processors, regulatory powers, and emerging technologies.

Submissions close on September 18, 2026. The Government is seeking feedback on how the draft provisions and related proposals would operate in practice, including operational considerations and compliance impacts.

The test would govern collection, use, and disclosure of personal information. Organisations would consider factors including reasonable expectations, transparency, data minimisation, genuine choice, proportionality, impacts on individuals, and the best interests of children where relevant.

 

Yes, for large digital platforms. Qualifying platforms would need to destroy an individual’s personal information following a valid request unless an exception applies. The proposed thresholds include more than $500 million in gross revenue or an average of 2.5 million monthly Australian end users.

An organisation would need to notify the Information Commissioner within 72 hours after becoming aware of reasonable grounds to believe an eligible data breach occurred. An incomplete initial statement would be permitted where providing complete information within that period is impossible or impracticable.

The proposals broaden concepts such as personal information and collection to address information generated or derived through AI and other technologies. The consultation also seeks feedback on privacy risks associated with smart glasses, connected vehicles, wearable devices, location data, and AI-generated inferences.

No. The Privacy Amendment (Personal Data Protection) Bill 2026 is an Exposure Draft and remains subject to further government consideration. Feedback from the consultation will inform the Government’s work on the final reform package.