Modernising data protection: key takeaways from the 2026 privacy reform package
Authored by: Miriam Beattie and James Pratt
The Attorney-General’s Department has released a package of privacy reforms for public consultation, centered on an Exposure Draft of the Privacy Amendment (Personal Data Protection) Bill 2026 (ED Bill) and an accompanying Consultation Paper. The package contains roughly 40 proposals designed to uplift privacy protections, clarify existing obligations, and enhance the regulatory efficiency of the Office of the Australian Information Commissioner (OAIC).
The proposed legislative provisions seek to modernise Australia's privacy framework to better respond to modern digital environments and emerging technologies.
You can have your say on the proposals before consultation closes on 18 September 2026. The ED Bill and the Consultation Paper can be found here.
Highlights of the Proposed Reforms
Key proposals within the Bill and Consultation Paper will:
Establish a 'fair and reasonable' test: Replace APPs 3, 4, and 6 with a new framework centred around a requirement that all collection, use, and disclosure of personal information must be fair, reasonable and lawful in the circumstances, assessed against a number of legislated factors, including:
whether a reasonable person would expect the collection, use or disclosure;
whether the information relates to one or more of the APP entity’s functions or activities;
transparency about the means and purposes of the APP entity;
whether the purpose could be met with less information/personal information;
whether genuine choice is provided to the individual;
the impact of the privacy of and risk of harm to the individual;
the best interests of the child being a primary consideration.
Entities do not have to satisfy each factor to meet the requirements. Exceptions to the test apply for permitted general or health situations or where the information handling is authorised by law.
Update core privacy definitions: Amend 'personal information' to cover information that 'relates to' an individual, insert a definition of 'reasonably identifiable', define 'disclosure' to make it clear this occurs when making personal information accessible to third parties and legislate that 'consent' must be voluntary, informed, current, specific, and unambiguous.
Expand sensitive information categories: Include 'genomic information' and 'precise geolocation tracking data' (location data within a 500-metre radius tracked over time) as sensitive information.
Require consent to trade personal information: Make it clear that an organisation must not trade personal information (disclosing data for money/consideration or direct marketing) without individual consent, subject to specific carve-outs such as business acquisitions or provision of essential services.
Simplify collection notifications: Replace the current list of notification requirements in APP 5 with requirements for clear, concise, up-to-date and plain-language notices that only need to address the fact of, circumstances of, and intended purposes of collection.
Expand permitted general situations: Replace 'misconduct of a serious nature' in permitted general situation 2 with 'wrongdoing of a serious nature' to cover unlawful and wrongful conduct, including financial abuse.
Replace APP7 with a simplified direct marketing framework: Introduce a technology-neutral definition of ‘direct marketing’ and allow ad-supported services to offer modified service terms to users who opt out of direct marketing, provided genuine choice remains to continue to use the service.
Introduce a 72-hour notification rule and harm mitigation obligations: Require entities to notify the Information Commissioner of an eligible data breach within 72 hours, create a specific obligation to take reasonable steps to mitigate harm from data breaches and require entities to consider destruction of no longer needed information instead of de-identification under APP 11.
Include a right to erasure on Large Digital Platforms (LDPs): Provide individuals a right to request the destruction of their personal information held by LDPs (defined as platforms with $500 million or more annual gross revenue or 2.5 million or more average monthly end users in Australia), subject to public interest, legal, and technical feasibility exceptions.
Introduce a technical infeasibility exception for access requests: Create an exception to APP 12 access obligations where providing access is unreasonable or impracticable due to technical impossibility or infeasibility.
Consolidate and expand research exceptions: Replace existing health and medical exceptions with a single exception for human research conducted in accordance with a single set of guidelines issued by the Privacy Commissioner.
Clarify processor liability: Establish that information processors acting strictly under a controller's documented instructions will generally be exempt from most APPs, except APP 1 (open management) and APP 11 (security).
Enhance OAIC enforcement and investigation powers: Require individuals to raise complaints with entities first (giving entities 60 days to respond), grant the OAIC power to gain practical assistance, such as access to systems, during complex digital investigations, where reasonable, and replace the broad and undefined 'reasonable excuse' defence for information-gathering notices with a set of specific, defined defences.
If your agency or organisation needs assistance with understanding how any of the legislative proposals may impact you, please reach out to our information law experts James Pratt (james.pratt@adaptbl.com.au or 0423 368 823) or Geoff Adams (geoff.adams@adaptbl.com.au or 0404 608 231) to discuss.