OUT-LAW NEWS

Australian privacy law reforms move forward with consultation on ‘tranche two’ Bill

Privacy dictionary close up

NSA Digital Archive/iStock.


Organisations should be prepared to change the way they assess compliance with privacy law in Australia under major reforms that have been proposed, according to experts.

Veronica Scott and Simon McDonald of Pinsent Masons were commenting after the Australian government opened a consultation on a second tranche of Privacy Act amendments. The proposals provide for a wide range of significant changes to be made to Australia’s data protection regime and build on the first tranche of reforms agreed in late 2024.

Under the draft new Privacy Amendment (Personal Data Protection) Bill 2026 (‘the Bill’), more data would fall within the scope of the Privacy Act; the test organisations would have to meet to collect, use or disclose personal information would be altered; stringent consent requirements would apply to the trading of data; and a new fixed 72-hour deadline for the notification of data breaches would be imposed. The Bill is expected to be passed by the end of the year.

Scott and McDonald said the proposed changes, which are open to consultation until 18 September 2026, would align Australia’s data protection framework more closely to the EU’s General Data Protection Regulation (GDPR), although gaps remain.

“The proposals would fundamentally reshape how organisations assess privacy compliance,” said Scott. “Rather than relying on a series of prescriptive rules, organisations would need to demonstrate that their handling of personal information is ‘fair and reasonable’ in the circumstances, requiring a more holistic assessment of privacy risk, transparency, proportionality and user expectations. The reforms also impose more operationally demanding obligations, including the proposed 72-hour breach notification requirement, positive obligations to address the risks from data breaches and tighter consent standards.”

McDonald said: “These reforms will be relevant to any organisation that collects, uses or discloses personal information about Australians, particularly those operating in technology, financial services, health, media, telecommunications, retail and digital platform sectors. Businesses that rely on data analytics, digital advertising, AI-enabled technologies or third-party processing arrangements are likely to be particularly affected.”

Among the main changes proposed are alterations to way important concepts in Australia’s privacy law are currently defined, including the definition of ‘personal information’ – the processing of which is governed by the Privacy Act. Specifically, the planned change would mean all information that ‘relates to’ an identified or reasonably identifiable individual would be in-scope of the regime. Currently, the Act only governs the processing of information ‘about’ an individual – a concept that has been the subject to court interpretation. The change means information connected to an individual by its nature, such as through their activities, characteristics or behaviour, or by the context in which it is handled, such as where it is used to inform decisions affecting the individual, will now be in-scope.

Under the proposed reforms, three Australian privacy principles (APPs) applicable to the collection of solicited personal information (APP 3), dealing with unsolicited personal information (APP 4), and use or disclosure of personal information (APP 6) would be replaced through the introduction of a new APP 3 that would prohibit organisations from collecting, using or disclosing personal information unless doing so is both fair and reasonable in the circumstances and lawful.

This proposed new ‘fair and reasonable’ test is principles-based and would require a holistic assessment of the circumstances. The Australian government has proposed that this assessment be made with reference to a range of legislated factors, including those that encourage businesses to reflect on a reasonable person’s expectations, whether the individual has been provided with a genuine choice, the risk of harm, and – in cases where the individual is a child – the best interests of the child.

Organisations would not be required to meet every legislated factor. Rather, the factors are to be weighed as part of an overall assessment having regard to the circumstances, with no single factor being determinative. 

There would be limited exceptions to the requirement to meet the ‘fair and reasonable’ test – including where the collection, use or disclosure is required or authorised by or under an Australian law or court/tribunal order.

Strengthened consent standards would apply where organisations wish to disclose an individual’s personal information for monetary or other consideration, or for direct marketing purposes, unless an exception applies. Consent would need to be voluntary, informed, current, specific and unambiguous.

Those consent requirements would not need to be met in certain circumstances, including where the disclosure of data is necessary to provide a product or service requested by the individual; it is incidental to a business sale, acquisition or transfer where the disclosure of personal information is not a substantial purpose of the transaction; or where it is necessary to prevent, detect, investigate or remedy unlawful activity or serious fraud-related misconduct.

To counter risks associated with data breaches, the proposals would further require organisations to take reasonable steps to implement practices, procedures and systems that enable them to respond effectively to data breaches and prevent or reduce harm to affected individuals, as well as to mitigate the impact of breaches on affected individuals in the event of an actual or suspected breach.

While certain data breaches must be notified to Australia’s privacy commissioner “as soon as practicable” currently, the proposed new law would require notification within a fixed 72-hour deadline from the point an organisation becomes aware of reasonable grounds to believe such a breach has occurred. Where it is impossible or impracticable to provide a complete statement within 72 hours, entities would have scope to submit an incomplete statement and provide outstanding information later. Failure to notify within 72 hours could attract an infringement notice or compliance notice, and it would constitute an interference with the privacy of an individual. 

Other changes envisaged include the introduction of a new APP, the ‘right to erasure’ for users of large digital platforms, as well as changes that would make controllers – the organisations that determine the purpose of data processing – liable for processing they outsource to third parties.

Also noteworthy is what is not included in the Bill. Scott highlighted how there are no direct changes proposed to the existing employee records and small business exemptions, which said “raises the question of whether the reforms will be enough to address Australia's most significant privacy risks in an AI-driven economy”.

Scott said: “Businesses that handle personal information of Australians should be aware of these proposed changes and their potential compliance implications. They will need to review their data handling practices against the new ‘fair and reasonable’ test, data processing agreements, breach response procedures and readiness for the 72-hour notification window, and consent mechanisms for data sharing arrangements.”

“It is also worth remembering that the first tranche of reforms is already in force, albeit only some of the provisions have taken effect to-date: the statutory tort for serious invasions of privacy commenced on 10 June 2025, while automated decision-making transparency obligations commence from 10 December 2026, alongside stronger OAIC enforcement powers. This new ‘tranche two’ Bill remains subject to further public consultation until 18 September and consideration by government and parliament, and may be amended before it is introduced,” she added.

Separately, the Australian government is also seeking feedback on privacy risks from emerging technologies, including wearable surveillance devices, like smart glasses, and connected vehicles. That exercise comes just days after Australia’s privacy commissioner Carly Kind confirmed her office is closely monitoring market developments on smart glasses with a view to understanding whether scrutiny of compliance practices and regulatory intervention is necessary.

We are processing your request. \n Thank you for your patience. An error occurred. This could be due to inactivity on the page - please try again.