On 31 August 2026, the Attorney-General’s Department released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 (Cth) (Bill) and an accompanying Consultation Paper (2026 Paper).
We summarise the key proposed reforms below and provide commentary on what these changes could mean for Australian businesses.
The key impacts of Tranche 2 for businesses
The proposed amendments could have significant implications for Australian businesses. In particular:
- Individuals have stronger privacy protections in relation to more kinds of information not previously explicitly encompassed within the definitions of ‘personal information’ and ‘sensitive information’.
- Individuals have stronger privacy protections in relation to how businesses collect and store their personal information, including an overarching ‘fair and reasonable’ requirement for collection, use and disclosure of personal information, proposed statutory criteria for consent, and a limited right of erasure.
- Businesses have new and clarified obligations with respect to the collection, use, and disclosure of personal information including for direct marketing and human research purposes.
- Businesses have greater responsibilities to ensure they are handling personal information appropriately, including when working with contracted service providers (i.e. ‘data processors’) and considering whether information can be properly de-identified or destroyed.
- Businesses have new requirements to manage and respond to eligible data breaches as well as lower threshold data breaches.
Additional impacts for businesses using AI systems
The Tranche 2 reforms are intended to target privacy risks in the digital era and in emerging technologies. Notably, these changes (if passed in their current form) would impact businesses using AI systems to collect, generate, or handle personal information. For instance:
- Businesses training AI systems on de-identified information will need to assess whether that information still meets the new definition of ‘de-identified’. If not, additional consents may be required before that data can be used for AI training. This extends to businesses who may be fine-tuning third-party models using their own data.
- Businesses should consider what information is being inferred or generated by AI systems and whether this information would meet updated definitions of ‘personal information’ and ‘sensitive information’. Businesses would also need to reassess whether current uses of AI systems meet the ‘fair and reasonable’ criteria.
- Businesses engaging AI service providers would generally be the ‘controller’, and as such, remain liable for acts the provider carries out on their documented instructions, including for any privacy breaches of the service provider as ‘processor’. Risk allocation will depend on instructions provided to the service provider as well as the contract between them.
- Businesses may need to identify the personal information held in connection with AI systems, including prompt records, transcripts, and stored embeddings, in order to satisfy the strengthened Australian Privacy Principle (APP) 11 obligations and to assess their retention and destruction obligations.
- Re-identification risk increases where AI systems combine multiple datasets, since information that appeared de-identified in isolation may become ‘reasonably identifiable’ once linked or interfaced with other reasonably available information.
- Businesses that would qualify as a ‘large digital platform’ should also consider whether current data governance processes would facilitate individuals’ right of erasure.
Tranche 2 at a glance
The proposed reforms can be found here.
The road to the Tranche 2 reforms
The Bill setting out the Tranche 2 reforms follows on from previous reform and consultation efforts, including:
- the Attorney-General’s Privacy Act Review Report of February 2023 (2023 Report). The 2023 Report made 116 recommendations to address privacy risks in the digital era. In response, the Australian Government agreed to 38 recommendations and agreed-in-principle to a further 68.
- Tranche 1 of the reforms was enacted as the Privacy and Other Legislation Amendment Act 2024 (Cth), which received Royal Assent on 10 December 2024. Our analysis of those reforms can be found here: Privacy Milestone: First Tranche of Privacy Reforms Passed.
The Bill proposes more targeted reforms intended to boost regulatory enforcement powers and provide stronger safeguards for individuals in the context of emerging technologies. At this stage, the Bill remains subject to change, and a ‘go-live’ date for Tranche 2 reforms has yet to be announced.
The Tranche 2 reforms in detail
Expansion of ‘personal information’
The Bill expands the definition of ‘personal information’ from information about an identified individual (or one who is reasonably identifiable) to information that relates to such an individual. The 2026 Paper suggests that ‘relates to’ is intended to have its ordinary meaning and require a degree of connection between the information and individual, and would not include information which has a ‘tenuous, remote, incidental, or trivial connection’ to the individual.
The Bill further clarifies that an individual is reasonably identifiable from information or an opinion where the individual could be identified by combining the information or opinion with other information or opinions that are reasonably available (our emphasis). In practice, this threshold is likely to be a low one in the digital era, where emerging technologies routinely generate rich streams of personal information capable of being aggregated, linked or cross-referenced with other reasonably available datasets. Information that appears innocuous or de-identified when viewed in isolation may, once combined with such adjacent data, be sufficient to render an individual reasonably identifiable and therefore bring that information within the scope of ‘personal information’.
To illustrate the practical significance of these changes, technical data such as IP addresses, device identifiers, cookie IDs, MAC addresses and network or metadata logs have, under the current framing, often fallen outside ‘personal information’ where the connection to a person could only be drawn indirectly (for example, by cross-referencing the data with subscriber records held by a third party). Australian courts have taken a relatively narrow view of the ‘about an individual’ requirement, with the result that such technical identifiers were treated as being about a service, device or transaction rather than about the person behind it.
Under the proposed formulation, the same data is more likely to be caught: it plainly ‘relates to’ the individual once it can be linked to them using other reasonably available information – whether held by the entity itself, obtainable from another party, or otherwise accessible using reasonable means. The practical effect is that a range of behavioural, telemetry, advertising, analytics and machine-generated data that businesses have historically treated as non-personal, and therefore outside the APPs, may need to be re-characterised and brought within their privacy compliance framework.
The Bill also clarifies that an individual can be identified, or reasonably identifiable, even if their legal name is not known. Personal information includes information which ‘allows an individual to be recognised, singled out, or otherwise dealt with as a distinct individual in practice’. This captures a broad array of information. In particular, the Bill provides the following examples:
- address
- contact information, such as email address
- pseudonym or identifier
- geolocation data (being ‘personal information generated by or derived from a device or technology that identifies an individual’s specific location to within a radius of 500 metres and is collected and held by reference to the individual’s location over time’)
- characteristics, behaviours, traits, preferences or patterns of activity.
These clarifications are proposed with a view to ‘modernise’ the definition to apply to ‘behavioural information and other data generated or collected by wearable devices including smart glasses’.
Further, the Bill proposes additional categories of ‘sensitive information’ such as precise geolocation tracking data and ‘biometric information that is to be used for the purpose of automated biometric verification or biometric identification’. This change was proposed in acknowledgement that certain classes of information warrant additional safeguards, such as explicit consent.
De-identified information
The Bill proposes a new meaning of ‘de-identified’ information as follows:
Information or an opinion is de-identified at a particular time, or in particular circumstances, if, at that time or in those circumstances, the information or opinion has ceased to be information or an opinion that relates to an identifiable individual or an individual who is reasonably identifiable.
Notably, this definition is closely tied to the proposed definition of ‘reasonably identifiable’ (discussed above). Although de-identification has never been as straightforward as removing identifiers such as names and dates of birth from information (a common area of misunderstanding in applying privacy laws), the amendment will require businesses to consider other ‘reasonably available’ information in assessing whether information has been properly de-identified. Given the nature of emerging technologies, this will likely require an ongoing assessment as new datasets become available and interlinked.
The ‘fair and reasonable’ test
This Bill provides a substantive and significant overhaul of APP 3 (collection of solicited personal information), APP 4 (dealing with unsolicited personal information) and APP 6 (use or disclosure of personal information). At a high-level, these APPs (in their current form) generally require that APP entities:
- only collect solicited personal information where it is reasonably necessary for (and, in the case of agencies, directly related to) the organisation’s functions or activities;
- only collect personal information by lawful and fair means;
- destroy or de-identify unsolicited personal information which is not reasonably necessary for an organisation’s functions or activities; and
- only use or disclose personal information for the purpose for which it was collected, unless an exception applies.
The proposed new test is set out in the Bill as an amendment to APP 3.1:
An APP entity must not collect personal information, or use or disclose personal information held by the APP entity, unless the collection, use or disclosure of the information is: (a) fair and reasonable in the circumstances; and (b) lawful.
If enacted, APP entities would be required to have regard to the following matters in the proposed new APP 3.2. The assessment will be a holistic one, and no single factor will be determinative. Similarly, not all factors must be satisfied to meet the new ‘fair and reasonable’ test.
- whether a reasonable person would expect the collection, use or disclosure of the information in the circumstances;
- whether the collection, use or disclosure of the information relates to one or more of the APP entity’s functions or activities;
- whether the APP entity is transparent about the means and the purposes of the collection, use or disclosure of the information;
- whether the purpose for which the information is being collected, used or disclosed could be met by collecting, using or disclosing less information, or information that is not personal information;
- whether the individual to whom the information relates is provided with genuine choice in relation to the collection, use or disclosure of the information;
- the impact on the privacy of the individual to whom the information relates, and any risk of harm to the individual, arising from the collection, use or disclosure of the information (including whether that impact or risk of harm is proportionate having regard to any benefits to the individual or the APP entity arising from the collection, use or disclosure);
- if the individual to whom the information relates is a child, the best interests of the child as a primary consideration.
If this framework is passed in Tranche 2, further guidance is expected to be provided by the OAIC.
The lawfulness requirement at APP 3.1(b) has the consequence that if an APP entity’s collection, use or disclosure breaches another provision of the Privacy Act, it will also breach APP 3.1.
Exceptions to the “fair and reasonable” component apply where the handling is required or authorised by law, or where a permitted general or health situation exists.
Introduction of controller and processor distinction
The Bill introduces new concepts of ‘controller’ and ‘processor’ which will align Australian privacy laws more closely with the EU General Data Protection Regulation (GDPR) regime:
- a ‘processor’ is an APP entity that does an act or engages in a practice on behalf of a controller (who must also be an APP entity). This means the processor acts on the controller’s documented instructions and handles personal information only for purposes set out in those instructions;
- a ‘controller’ is an APP entity on whose behalf a ‘processor’ handles personal information.
Some exceptions apply, such as contracted service providers under Commonwealth contracts.
Where a processor acts in accordance with a controller’s documented instructions, the processor’s acts are taken to be acts of the controller. This means that if a processor, under the direction of the controller, breaches the Privacy Act, the controller would be deemed to have committed the breach. This has implications for APP entities engaging third party service providers who are themselves an APP entity, for the purposes of handling, storing, or using personal information.
If passed in its current form, Australian businesses will need to revisit their existing contracts, understand whether they act as a ‘controller’ or ‘processor’, and ensure that risk and liability is appropriately allocated between them.
In practice, we expect controllers will look to reverse this statutory allocation of liability through their contractual arrangements. Because the Bill treats acts of the processor done on the controller’s documented instructions as acts of the controller, a controller who has done nothing more than issue standard instructions could nevertheless be exposed to civil penalties, regulatory action and third-party claims arising from a processor’s non-compliant handling of personal information (for example, inadequate security measures, unauthorised sub-processing, or use of the data outside the scope of the controller’s instructions). Controllers will therefore typically seek robust contractual protections from their processors, including detailed and comprehensive documented processing instructions; positive warranties as to Privacy Act compliance and the maintenance of appropriate technical and organisational security measures; obligations to notify, assist with and cooperate on data breach response (aligned with the proposed 72-hour notification timeframe); restrictions on sub-processing and cross-border transfers; audit and information rights; and broad indemnities in respect of loss arising from the processor’s acts or omissions, ideally uncapped (or subject to enhanced caps) for privacy breaches. Processors, in turn, will resist open-ended exposure and press for carve-outs where they have acted strictly on the controller’s instructions. Renegotiating existing supplier arrangements – particularly with large technology and cloud service providers – is likely to be a significant undertaking and should be prioritised well ahead of commencement.
New obligations for data breaches
Currently, the term ‘data breach’ is not a defined term in the Privacy Act.
The Bill proposes the following definition for ‘data breach’:
“If:
(a) there is unauthorised access to, or unauthorised disclosure of, the information; or
(b) the information is lost in circumstances where there is likely to be unauthorised access to or disclosure of the information;
the access, disclosure or loss is a data breach of the APP entity”
An ‘eligible data breach’ is currently defined in section 26WE of the Privacy Act as a two-limb test:
“if:
(a) both of the following conditions are satisfied:
(i) there is unauthorised access to, or unauthorised disclosure of, the information;
(ii) a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates; or
(b) the information is lost in circumstances where:
(i) unauthorised access to, or unauthorised disclosure of, the information is likely to occur; and
(ii) assuming that unauthorised access to, or unauthorised disclosure of, the information were to occur, a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates.”
Where a data breach does not meet the higher threshold (so as to constitute an ‘eligible data breach’), the Bill proposes that APP entities should still have legislative obligations to respond to data breaches effectively and mitigate the impact of a known or suspected data breach on individuals. Failure to do so would constitute an interference with the privacy of an individual.
Eligible data breach amendment and 72-hour notification period
The Bill also proposes to streamline the current definition of ‘eligible data breach’ and distinguish the concept from a ‘data breach’, as follows:
“(a) for a data breach constituted by unauthorised access to, or disclosure of, information – a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates; or
(b) for a data breach constituted by a loss of information – a reasonable person would conclude that any unauthorised access to, or unauthorised disclosure of, the information would be likely to result in serious harm to any of the individuals to whom the information relates.”
In the event of an ‘eligible data breach’, the Bill introduces a new requirement for APP entities to notify the OAIC by way of statement within 72 hours of becoming aware that there are reasonable grounds to believe an eligible data breach has occurred. In certain circumstances, an incomplete statement can be provided in the first instance, followed by a complete notice as soon as practicable thereafter. Failure to provide a statement within 72 hours is a civil penalty contravention.
Security, destruction and de-identification
The Bill significantly strengthens APP 11 obligations with respect to the security of personal information. If passed in its current form, the amended APP 11 would require APP entities to know what information they hold. This means being able to identify the personal information an entity no longer needs for the purpose for which it may lawfully use or disclose it, in order to determine whether it should be appropriately destroyed or de-identified.
Further, APP entities would be required under the amended APP 11 to ‘regularly’ assess its compliance with APP 11, including what reasonable measures are in place to protect information from data breaches, and to mitigate against excess retention.
Consent
The Bill proposes a statutory definition for what constitutes privacy ‘consent’. Consent may be express or implied, but must be all of the following: voluntary, informed, current, specific and unambiguous. This would require businesses to reconsider their existing consent practices and collection notices to ensure they meet all of these criteria. Including the ‘fair and reasonable’ test will take some of the pressure off individuals who are asked to consent in circumstances where they have limited ability to provide consent meeting these new criteria.
Interestingly, consent in the context of human research that is reviewed, approved, and monitored in accordance with the National Statement on Ethical Conduct in Human Research will not have to be current and specific. This will assist in recognising consent for future research, where the scope of that research is not well defined at the time the consent is given.
Trading personal information
The proposed amendments would require that an organisation not trade information about an individual unless the individual has provided their consent.
Under the Bill, some disclosures of personal information could constitute a ‘trade’ in circumstances where a disclosure is made:
- for money or other consideration; or
- for the purposes of direct marketing.
The Bill carves out specific exceptions, such as where the disclosing entity reasonably believes disclosure is necessary for prevention, detection or investigation of an unlawful activity.
Direct marketing
Proposed amendments to APP 7 provide that an organisation must not make a direct marketing communication to an individual unless the organisation provides ‘simple means’ by which the individual can request not to receive such communications and be accompanied by information about how the individual may request not to receive direct marketing communications. The information required to be provided must meet the following criteria:
(a) set out in clear and plain language;
(b) readily understandable by an ordinary person;
(c) up-to-date; and
(d) concise.
If an organisation receives a request from an individual to cease receiving direct marketing communications, the organisation must take reasonable steps to give effect to the request.
Additionally, the Bill provides flexibility for services that derive revenue from the making of direct-marketing communications (referred to as ‘ad-supported services’). The Bill provides a carve out which enables ad-supported services to continue to send direct marketing communications to individuals who have opted out, provided individuals are provided a ‘genuine choice’ to continue using the service without receiving direct marketing communications.
Limited right of erasure
The Bill proposes a limited right of erasure for individuals applying to ‘large digital platforms’, which is intended to be inserted as a new APP 14.
‘Large digital platform’ is intended to refer to an organisation providing a social media service, relevant electronic service, or designated internet service (as these terms are defined in the Online Safety Act 2021 (Cth)). To qualify as a large digital platform, the organisation must also either have a gross revenue of over $500 million in the previous financial year and/or provide a platform with an average of 2.5 million monthly end users in Australia in the previous financial year. This has potentially far-reaching impacts and could, according to the 2026 Paper, encompass social media, messaging, email, gaming, and streaming platforms.
Large digital platforms would be required to destroy personal information they hold about a person upon request from that individual, unless an exception applies.
Exceptions outlined in the Bill include where there is a public interest (e.g. information is relevant for law enforcement activities), where destruction would be inconsistent with law or a court order, or where (despite having taken reasonable steps) destruction remains technically impossible or infeasible.
Human research exception
Relevantly for organisations or agencies undertaking ‘human research’ (as defined in the National Statement on Ethical Conduct in Human Research) involving personal information, the Bill proposes major reforms, including in relation to current limited research exception activities and requirements to obtain ethics approval. Instead, the Bill proposes to implement a single exception for human research accompanied by one set of guidelines. These guidelines would be developed following a further consultation period with relevant stakeholders and will be issued by the Privacy Commissioner. These proposed amendments are likely to be popular amongst the research community, which has been looking for clearer guidance on the complex approval pathways for research.
Collection statements
Currently, APP 5 requires that an APP entity that collects personal information takes reasonable steps to notify individuals of specific matters. In order to satisfy this requirement under the Tranche 2 reforms, the Bill provides that valid notices would need to be:
(a) in clear and plain language;
(b) readily understandable by the individual;
(c) up-to-date; and
(d) concise.
This shortened list of items that must appear in a collection notice and the direction about the form of the notice will hopefully lead to more effective communications in collection statements, and a clear role for them as distinct from the privacy policy.
OAIC dispute resolution processes
Separate to the Bill, the 2026 Paper proposes a new dispute resolution framework to assist the OAIC manage privacy complaints more efficiently. In particular, individuals would be required to raise concerns with the relevant APP entity in the first instance before lodging a complaint with the OAIC. If the matter does not resolve, individuals can then bring a complaint to the regulator, but would need to provide evidence of this attempted resolution.
To support this, APP entities would be required to provide ‘accessible complaint mechanisms’, respond to complaints within a 60-day period, and provide written responses. Failure to do so would constitute an ‘interference with the privacy of an individual’ and be enforced as such.
Amendments are intended to apply to existing datasets
Many of the amendments will apply to personal information held at the time the operative provision commences. At present there is no indication that obligations will be grandfathered, so APP entities will face new obligations in respect of information they already hold, including information that may not previously have been caught by the expanded definition of personal information.
What businesses should do now
The Australian Government is currently seeking feedback on the 2026 Paper and Bill. The consultation period closes on 18 September 2026.
At this stage, noting the Bill remains subject to change, businesses may wish to:
- make a submission to provide feedback on the Bill;
- undertake an audit of personal information and other data currently collected and held by the business;
- consider whether current collection, use, and disclosure processes align with the proposed ‘fair and reasonable’ test;
- review current privacy consent processes and consider whether they align with the proposed definition of valid ‘consent’ and direct marketing opt-out requirements;
- consider data breach response plans to account for the lower threshold ‘data breach’ concept and proposed 72-hour notification period for ‘eligible data breaches’;
- review existing contracts with service providers in the context of how controller and processor responsibilities may be allocated; and
- review their retention, de-identification, and destruction processes.