The Next Wave of Australian Privacy Reform: Key Proposals in the Draft Personal Data Protection Bill 2026

Sam Fiddian, Steven Klimt, John Dieckmann, Hilary Searing, Brenton Steenkamp, Eleanor Dickens, Sharon Segal, Monique Azzopardi, Alex Horder, Christina Graves, Sam Weston, Christa Queern, Leo Su
02 Sep 2026
6 minutes

On 31 August 2026, the Australian Government released an exposure draft and consultation paper of the Privacy Amendment (Personal Data Protection) Bill 2026 (Exposure Draft Bill). The Exposure Draft Bill contains roughly 40 proposals which, if all are enacted, would represent the most significant overhaul of Australian privacy law in more than a decade – modernising core definitions, introducing a ‘fair and reasonable’ test for data handling, tightening breach notification, and creating new rights for individuals. Submissions for feedback from stakeholders close on 18 September 2026.

Modernised Definitions: Casting a Wider Net

The Exposure Draft Bill would amend and clarify some of the foundational definitions in the Privacy Act 1988 (Cth), including the following:

  • Personal information would cover information that ‘relates to’ an individual (replacing the narrower ‘about’ qualifier), with a new objective ‘reasonably identifiable’ test seeking to enshrine in law the Privacy Commissioner's view that a person is identified if the information allows them to be individualised, even if their name or legal identity is unknown;

  • Precise geolocation tracking data and genomic information would be expressly classified as sensitive information, attracting higher protections;

  • Collection would be broadened to expressly capture AI-generated and derived data, meaning inferences drawn by algorithms will attract full Privacy Act obligations;

  • Disclosure would be defined as occurring when personal information is made accessible to another person or body, raising serious questions as to whether the status quo of cloud computing not constituting a disclosure will remain;

  • Consent must be voluntary, informed, current, specific and unambiguous – pre-ticked boxes and bundled consent (i.e. where an individual must consent to multiple information handling practices through one mechanism) will no longer suffice, with the consultation paper indicating that the legislation has in its sights deceptive or misleading practices, including user interfaces that make it unreasonably difficult for an individual to avoid giving consent; and

  • De-identification is not acknowledged not to be a fixed state / static condition, with the question of whether information is de-identified to depend on the context and requiring management of foreseeable risks that de-identified information may be able to be re-identified over time.

The Fair and Reasonable Test: A Single Standard

The centrepiece of the Exposure Draft Bill’s proposals would see Australian Privacy Principles (APPs) 3, 4 and 6 replaced with a single test: is the collection, use or disclosure ‘fair and reasonable’.

Under this test, both the means and the purpose of the information collection, use and disclosure must be fair and reasonable in the circumstances measured by reference to a set of legislated factors:

  • reasonable expectations – what a reasonable person in the individual’s circumstances would expect;

  • relationship to an entity's functions or activities – the connection between an entity’s functions or activities and its handling of personal information;

  • transparency – whether the information provided by the entity would enable a reasonable person to understand why their personal information is being handled and how it will be handled;

  • data minimisation – whether the entity is exercising appropriate restraint in their handling of personal information, including by assessing the amount of personal information that is required to achieve the intended objective;

  • genuine choice – the degree of control an individual has over the collection, use or disclosure of their personal information, including whether meaningful alternatives are available;

  • impacts to the individual and proportionality –consideration of the potential impacts on an individual, the steps taken to mitigate those impacts, and the expected benefits; and

  • the best interests of the child – noting that children are particularly vulnerable to privacy risks and may be less able to understand the long-term consequences of how their personal information is handled.

A new 'consent to trade' requirement means organisations would need to obtain consent before disclosing personal information for money or other consideration for direct marketing purposes, subject to limited carve-outs. In a further nod to recent determinations made by the Privacy Commissioner, direct marketing purposes are to be defined broadly, including disclosures which inform or support direct marketing such as disclosures of cookies or pixels. The requirements around collection notices also receive an overhaul, with the matters they must refer to being simplified, but with a requirement that they must no longer be excessive, vague or ambiguous.

Breach Notification

Entities would be required to notify the Information Commissioner of an eligible data breach within 72 hours and notify affected individuals of material changes to previously reported breach information. The Exposure Draft Bill would flip the script on attempts to remediate or mitigate harm. No longer a means to simply avoid notification obligations arising, the Exposure Draft Bill would introduce a positive obligation to take reasonable steps to contain breaches and mitigate harm.

Data Security

Aligned with the changes to the definition of 'De-identification' discussed above, entities would need to consider whether to destroy, not merely de-identify, personal information that is no longer needed. Retention in de-identified form where needed for research or statistical purposes would be permitted, but wholesale policies of de-identification over destruction are unlikely to survive.

Right to Erasure: A new right affecting large platforms

A new right to erasure would apply to large digital platforms (those with $500 million or more in gross revenue or 2.5 million or more average monthly end users). On request, platforms would need to destroy an individual’s personal information, subject to limited exceptions including law enforcement, legal compliance and technical impossibility.

Controller-Processor Framework

The Exposure Draft Bill would see the formal adoption of a form of the controller-processor distinction modelled on European data protection law. A new exemption to the APPs (except APP 1 and APP 11) would be introduced for 'processors' who engage in an act or practice on behalf of a 'controller'. While processors acting within documented instructions would receive these APP exceptions, a processor that acts outside those instructions would be directly responsible for compliance. That said, where a processor acts in accordance with a controller’s documented instructions, the processor’s acts would be taken to be acts of the controller.

Individual privacy complaints

Seeking to ensure privacy complaints are taken seriously by entities while guarding against the 'AI slop' issue faced by authorities such as the Fair Work Commission, the Exposure Draft Bill would require that entities provide accessible complaint mechanisms and written decisions within 60 days while requiring that an individual establish that they have used this internal pathway before submitting a complaint to the Privacy Commissioner.

Representative complaints

The Exposure Draft Bill would also clarify the ability to bring representative complaints, borrowing from other similar legislative schemes to more clearly define the bounds of the use of such a pathway that is bound to be of interest to class action litigators.

Transitional provisions

Application and transitional provisions have been included in the Exposure Draft Bill in certain instances to aid in understanding the intended operation of the reforms. It is generally proposed that the changes to permitted information handling would apply to all personal information held by an entity, regardless of whether it was acquired or created before, on or after the commencement of the reforms. However, it remains unclear whether an initial grace period would be provided to allow entities time to prepare for the proposed changes.

What would be required of regulated entities?

Should the Exposure Draft Bill be enacted, it would represent a significant shift in personal information collection and handling practices. Among others, if all 40 proposals are implemented in their current form, regulated entities would likely need to adopt many of the following steps to ensure they will be in a position to comply:

  1. Conduct a data mapping exercise - identify all new personal information holdings that will potentially fall within the new remit of the Privacy Act, (including for example, AI-generated and derived data) and understand the data flows and sharing arrangements in respect of these new data flows.

  2. Review and update privacy notices and consent mechanisms - audit all consent collection points against the new voluntary, informed, current, specific and unambiguous standard.

  3. Assess data practices against the fair and reasonable test - map existing collection, use and disclosure practices against the legislated factors and identify those that may be difficult to justify.

  4. Update supply chain agreements - review outsourcing and data-sharing arrangements in light of the controller-processor framework and ensure processor instructions are clearly documented.

  5. Strengthen breach response capabilities - the 72-hour notification window for eligible data breaches demands well-rehearsed incident response plans with clear escalation pathways.

  6. Review data retention and destruction practices - implement defensible retention schedules that consider destruction, not merely de-identification, as the default endpoint.

  7. Collection of children's personal information – if your organisation collects children's personal information, especially any sensitive information, revisit if you are entitled to collect that personal information for the purposes you propose.

The Exposure Draft Bill should be closely scrutinised not only because the additional compliance costs will be significant but because it will shift the privacy law landscape in Australia in a manner that will likely require material changes to the systems, processes and practices of regulated entities.

Have your say?

Consultation on the draft legislation closes on 18 September 2026. Those seeking to shape the new proposals should act promptly to engage with the consultation process by this date. Further information about the Exposure Draft Bill and how you can engage in the consultation process, is available here.

Disclaimer
Clayton Utz communications are intended to provide commentary and general information. They should not be relied upon as legal advice. Formal legal advice should be sought in particular transactions or on matters of interest arising from this communication. Persons listed may not be admitted in all States and Territories.