Round 2! The Australian Government has released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026: Tranche 2 of privacy reforms
By Morgan Lane and Katherine Jones
The Australian Government has released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, setting out the second tranche of proposed reforms to Australia's privacy laws.
In brief
Other than the introduction of the Australian Privacy Principles in 2014, and a few changes such as the enhanced enforcement powers, doxxing offences and the statutory tort of privacy in 2024 and 2025, it is arguable that Australia's privacy legislation has not been subject to substantial updates since being introduced in 1988.
Australia is now entering an age of disruption. Unprecedented technological and regulatory change is forging the path for significant reform of Australia’s privacy law.
In 2023, the Federal Government released 116 proposals to reform Australia's privacy framework. However, ultimately the Government accepted only six of them via the Tranche 1 reforms in December 2024 (including tiered penalties, doxxing offences, the Children's Online Privacy Code mandate), and the statutory tort for serious invasions of privacy, which commenced on 10 June 2025.
Yesterday, the Federal Government released a draft bill for Tranche 2 changes which is said by the Attorney General to include:
-
25 Privacy Act Review proposals that uplift privacy protections;
-
5 Privacy Act Review proposals that are designed to clarify and simplify obligations;
-
4 additional measures to further simplify current obligations; and
-
7 additional measures to improve the efficiency of the privacy regulator (the Office of the Australian Information Commissioner (OAIC)).
The headline proposed changes
-
A 72-hour notification deadline. Removing the current 30-day assessment window, once an entity is aware of reasonable grounds to believe an eligible data breach has occurred, it must give the Commissioner a statement within 72 hours, with an incomplete statement permitted where full particulars are impracticable. Individuals must be notified at the same time where practicable.
-
A right to erasure — but only for large digital platforms. Confined to providers of a social media service, relevant electronic service or designated internet service with group revenue of at least $500 million or 2.5 million average Australian end-users, then on request by an individual, the organisation must destroy their personal information.
-
A statutory test for consent. Consent must be all of the following voluntary, informed, current, specific and unambiguous. Bundled consents and consents relied on for years will not survive. Businesses should consider the validity of enrolment forms, app permissions and marketing sign-ups and whether they need re-papering.
-
A wider definition of personal information. Information that allows an individual to be recognised or singled out — pseudonyms, identifiers, location data, behavioural patterns — is expressly in the scope of what constitutes personal information. More incidents will be notifiable, and existing data maps will need revisiting.
-
More categories of sensitive information. Genomic information, biometric templates and ‘precise geolocation tracking data’ (location within 500 metres, tracked over time) are added. Wearables, workforce tracking and access-control biometrics move into the consent-required category.
-
A 'fair and reasonable' requirement (new APP 3). Collection, use and disclosure of personal information must be fair, reasonable and lawful, judged against factors including reasonable expectations, minimisation, genuine choice and proportionality of harm, and, where a child is involved, their best interests as a primary consideration. This will mean that consent stops being a complete answer; organisations must be able to justify the handling itself.
-
APP 11 becomes security and destruction. Entities must consider destroying information they no longer need, be able to identify that information and regularly evaluate whether their compliance is actually working. Retention becomes an audited obligation rather than a policy aspiration.
-
A controller and processor split. A processor acting on documented written instructions does not breach the APPs (other than APP 1 and 11), as the controller is taken to have done the act. Outsourcing and cloud contracts will need written processing instructions to obtain the benefit.
-
Consent to 'trading' personal information. Disclosure for money or direct marketing requires consent, with carve-outs for requested services, M&A transactions and controller-to-processor disclosures. Data-broking and list-rental models are directly affected.
What is not in the draft
The small business operator (at the time of writing, the current threshold being $3M) and employee records exemptions currently will remain (the exposure draft bill does not propose these be repealed). Entities planning on the basis that these will be removed should treat that as government policy, not proposed law.
Also, contrary to news articles, there are no proposed changes to directly deal with wearable surveillance (such as smart glasses), but rather they are measures still under development for which feedback is sought. We do know that the Attorney General has communicated that the government will not make law in an ad hoc manner based on the release of each new product. Indirectly, wearables may form part of a definition of personal information which is corrected, particularly for devices that provide geolocations.
Our view
Any submissions in relation to the Bill are due by 18 September 2026. If you would like to understand the potential implications for your organisation or prepare a submission, please contact Morgan Lane or Katherine Jones from our Technology & data team.