Australia Privacy Amendment (Personal Data Protection) Bill 2026 (Tranche 2 exposure draft)
Exposure draft released 31 August 2026: a fair-and-reasonable test for collection and use, a right of erasure aimed at large platforms, a statutory controller/processor framework, restrictions on trading personal data, and stronger consent and breach duties.
| Jurisdiction | Australia |
|---|---|
| Category | Privacy & Data Protection |
| Status | Proposed |
| Latest development |
Analysis
The Privacy Amendment (Personal Data Protection) Bill 2026 (Tranche 2 exposure draft) is a consultation-stage draft, not yet enacted, released by the Attorney‑General’s Department on 31 August 2026 as the second tranche of reforms to the Privacy Act 1988 (Cth).Privacy Amendment (Personal Data Protection) Bill 2026 – Exposure Draft PDF Privacy Reform – Consultation on Exposure Draft legislation (AGD) Attorney‑General media transcript – Blue Room press conference 31‑08‑2026
Below is a structured analysis aligned with your requested sections. Because this is an exposure draft, all obligations are proposed and subject to change pending Parliamentary passage and commencement provisions.
Key Requirements
Main themes: fair‑and‑reasonable test, right of erasure for large digital platforms, controller/processor framework, restrictions on trading personal data, and stronger consent and breach duties.Privacy Amendment (Personal Data Protection) Bill 2026 – Exposure Draft PDF Privacy Reform – Consultation on Exposure Draft legislation (AGD) Attorney‑General media transcript – Blue Room press conference 31‑08‑2026
1. Fair and reasonable test for collection and use
- The draft Bill introduces a statutory “fair and reasonable” test governing the collection, use and disclosure of personal information, applying even where consent is present. Privacy Amendment (Personal Data Protection) Bill 2026 – Exposure Draft PDF Attorney‑General media transcript – Blue Room press conference 31‑08‑2026 Australia: Privacy Reform – A Significant Expansion of Privacy Framework (Baker McKenzie)
- The Attorney‑General has explained that entities can no longer justify collecting more information than they need, or using it for purposes Australians would not reasonably expect, even if they obtained consent. Attorney‑General media transcript – Blue Room press conference 31‑08‑2026 Major Changes Proposed, Key Reforms Still Missing (Russell Kennedy)
- The consultation paper and commentary indicate this test will consider factors such as the nature and sensitivity of data, individuals’ reasonable expectations, and impacts on privacy. Privacy Reform – Consultation on Exposure Draft legislation (AGD) Australia: Privacy Reform – A Significant Expansion of Privacy Framework (Baker McKenzie)
2. Right of erasure for large digital platforms
- The draft establishes a right to erasure (right to request destruction) of personal information held by large digital platforms such as social media and search engines. Attorney‑General media transcript – Blue Room press conference 31‑08‑2026 Major Changes Proposed, Key Reforms Still Missing (Russell Kennedy) Australia: Privacy Reform – A Significant Expansion of Privacy Framework (Baker McKenzie)
- The right applies primarily to large digital platforms, rather than all APP entities, and would require platforms to comply with valid erasure requests subject to specific exemptions (e.g., legal obligations, public interest). Major Changes Proposed, Key Reforms Still Missing (Russell Kennedy) Round 2! Privacy Amendment (Personal Data Protection) Bill 2026 – Exposure draft (Colin Biggers & Paisley)-bill-2026-exposure-draft-released-for-second-tranche-o)
3. Controller/processor framework
- The draft introduces a statutory distinction between “controllers” and “processors” within the Australian privacy regime, aligning more closely with concepts under the GDPR. Australia: Privacy Reform – A Significant Expansion of Privacy Framework (Baker McKenzie) Privacy Reform 2026: What the Draft Bill Means for Businesses (Aitken Lawyers)
- Controllers would be primarily responsible for determining the purpose and means of processing, while processors would be subject to contractual and statutory limitations on processing on behalf of controllers. Australia: Privacy Reform – A Significant Expansion of Privacy Framework (Baker McKenzie) Privacy reset on a deadline: Key changes and practical steps (Squire Patton Boggs)
4. Restrictions on trading personal data
- The Government has committed to “measures to stop businesses from trading in personal information without clear permission”, specifically targeting commercial trade in personal information such as shopping habits, online interests, and location data. Attorney‑General media transcript – Blue Room press conference 31‑08‑2026 Australia unveils draft second tranche of changes to privacy laws (MLex summary)
- Commentary on the draft indicates enhanced requirements for transparency and consent when personal information is sold or otherwise traded, and restrictions on using inferred or sensitive data for advertising without robust consent. Round 2! Privacy Amendment (Personal Data Protection) Bill 2026 – Exposure draft (Colin Biggers & Paisley)-bill-2026-exposure-draft-released-for-second-tranche-o) Major Changes Proposed, Key Reforms Still Missing (Russell Kennedy)
5. Stronger consent requirements
- The draft proposes “stronger, more meaningful standards for consent” to ensure individuals make informed choices, with clearer information and less reliance on take‑it‑or‑leave‑it terms. Attorney‑General media transcript – Blue Room press conference 31‑08‑2026 Australia: Privacy Reform – A Significant Expansion of Privacy Framework (Baker McKenzie)
- Commentary notes proposals to clarify when consent is voluntary, informed, current and specific, with higher expectations where sensitive or high‑risk data processing is involved. Major Changes Proposed, Key Reforms Still Missing (Russell Kennedy) Privacy reset on a deadline: Key changes and practical steps (Squire Patton Boggs)
6. Stronger data breach notification duties (including 72‑hour window)
- The draft removes the existing 30‑day assessment window and requires entities to notify the OAIC of an eligible data breach within 72 hours from becoming aware of reasonable grounds to believe a breach has occurred, permitting incomplete notifications where full particulars are impracticable. Round 2! Privacy Amendment (Personal Data Protection) Bill 2026 – Exposure draft (Colin Biggers & Paisley)-bill-2026-exposure-draft-released-for-second-tranche-o) Australia: Privacy Reform – A Significant Expansion of Privacy Framework (Baker McKenzie)
- This would significantly compress breach response timelines, bringing Australia closer to the GDPR’s 72‑hour breach reporting standard to regulators. OAIC Notifiable Data Breaches scheme – Existing guidance Privacy reset on a deadline: Key changes and practical steps (Squire Patton Boggs)
7. Expansion and clarification of key definitions, including personal information
- Tranche 2 implements modernised definitions, clarifying the scope of personal information, de‑identified data, and inferred data, building on recommendations in the Attorney‑General’s Privacy Act Review Report. Australia: Privacy Reform – A Significant Expansion of Privacy Framework (Baker McKenzie) RulesMate overview of second tranche reforms Privacy Act Review Report (Attorney‑General’s Department, 2022)
Compliance Challenges
Because the draft Bill is not yet enacted, compliance challenges are mostly anticipatory, based on known proposals and comparable regimes.
Common Challenges
- Interpreting and operationalising the “fair and reasonable” test
- Organisations may find it difficult to document and demonstrate that every collection, use and disclosure is fair and reasonable, especially for complex analytics, AI and ad‑tech ecosystems. Australia: Privacy Reform – A Significant Expansion of Privacy Framework (Baker McKenzie) Major Changes Proposed, Key Reforms Still Missing (Russell Kennedy)
- Mapping controller/processor roles in complex outsourcing and cloud ecosystems
- Australian businesses with existing vendor arrangements will need to re‑classify relationships (controller vs processor) and update contracts and governance structures. Privacy reset on a deadline: Key changes and practical steps (Squire Patton Boggs) Privacy Reform 2026: What the Draft Bill Means for Businesses (Aitken Lawyers)
- Meeting the 72‑hour breach notification window
- Many organisations currently struggle to assess and investigate incidents under the existing Notifiable Data Breaches scheme, and a 72‑hour requirement will increase pressure on incident response, forensics, and coordination. Round 2! Privacy Amendment (Personal Data Protection) Bill 2026 – Exposure draft (Colin Biggers & Paisley)-bill-2026-exposure-draft-released-for-second-tranche-o) OAIC Notifiable Data Breaches – Quarterly reports (data breach statistics)
- Limiting data trading and ad‑tech practices
- Businesses whose models rely on data brokering, targeted advertising and third‑party data enrichment may face significant re‑design of practices, particularly around location and behavioural data. Australia unveils draft second tranche of changes to privacy laws (MLex summary) Australian Privacy Reform 2026 overview (BizTech Lawyers)
Examples and Case‑Style References
- Previous NDB reports showing recurring failures
- OAIC’s Notifiable Data Breaches reports highlight recurring issues: delayed detection, inadequate access controls, and insecure credential management, indicating current challenges likely to be amplified under a 72‑hour rule. OAIC Notifiable Data Breaches – Statistics reports OAIC NDB Scheme – General guidance
- Industry analyses of GDPR‑style fair‑and‑reasonable and controller/processor issues
- Australian law firms and consultancies are already referencing GDPR experience to illustrate potential difficulties in assigning controller/processor roles and evidencing fairness, reasonableness, and lawful basis. Privacy reset on a deadline: Key changes and practical steps (Squire Patton Boggs) Australia: Privacy Reform – A Significant Expansion of Privacy Framework (Baker McKenzie)
Implementation Best Practices
Because this is only a draft, best practices are preparatory, focusing on alignment with likely obligations and existing OAIC/AGD guidance.
Actionable Steps
- Conduct a data mapping and use‑case inventory aligned to a fair‑and‑reasonable test
- Map all personal information processing activities, noting purposes, data categories, legal bases and whether the activity would meet a “reasonable expectations” standard. Privacy Reform – Consultation on Exposure Draft legislation (AGD) Privacy Act Review Report (AGD)
- Introduce internal “fairness assessments” for high‑risk processing
- Implement checklists or DPIA‑style assessments for profiling, AI, and behavioural advertising based on fairness, necessity, and proportionality. [OAIC Guide to privacy impact assessments](https://www.oaic
Recent developments
- — Allen Overy Shearman & Sterling analyses the exposure draft released on 31 August 2026, highlighting major changes such as the broader definition of **personal information**, a new **fair and reasonable** handling test, tighter consent requirements and 72-hour breach notification, and outlines practical impacts for businesses and compliance programs[5][2][1]. (source)
- — Colin Biggers & Paisley provides an expert legal perspective on the Tranche 2 exposure draft, emphasising expanded privacy protections, simplification of some existing obligations, and measures to enhance OAIC efficiency, and notes the short consultation window closing on 18 September 2026[12][1][8]. (source)
- — Dentons describes the Bill as a substantial rewrite of Australia’s privacy framework, explaining the new purpose-built **personal information** definition covering behavioural and device-generated data, the single fair and reasonable test replacing multiple APP rules, and other structural changes that will significantly reshape data handling practices[2]. (source)
- — Baker McKenzie characterises the Draft Bill as a significant expansion of the Privacy Act, noting that it implements many 2022 Review proposals plus new measures targeting emerging technologies, and discusses expected alignment with global standards and increased regulatory risk for organisations processing personal data[4][2]. (source)
- — Colin Biggers & Paisley’s “Round 2!” article summarises the Bill’s 25 proposals uplifting privacy protections, 5 clarifying obligations, 4 simplifying measures, and 7 initiatives to improve OAIC efficiency, including the **72-hour notification** deadline for eligible data breaches and a limited **right to erasure** for large digital platforms[1]. (source)
- — Pinsent Masons reports on the opening of consultation for the Tranche 2 Bill, explaining that more data will fall within scope, consent rules for data trading will tighten, and a fixed 72‑hour breach notification will apply, and comments that the reforms move Australia closer to **GDPR‑style** protections and may be passed by the end of 2026[11]. (source)
- — Colin Biggers & Paisley notes that submissions on the exposure draft are due by 18 September 2026, urging organisations to assess impacts such as broader personal information coverage, enhanced individual rights, and increased compliance burden, and to participate in the consultation process[1][8]. (source)
- — The Attorney‑General’s Department launches the official **Privacy Reform** consultation page, publishing the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 and consultation paper, and inviting submissions on modernising and strengthening privacy laws for the digital age by 18 September 2026[8][3]. (source)
- — MLex reports on the government’s unveiling of the second‑tranche privacy reforms, focusing on the new fair and reasonable test, stronger consent rules, rights to request deletion from major platforms, and measures addressing AI, smart devices and data trading, and flags the consultation period through 18 September 2026[7][6]. (source)
- — Privacy lawyer Peter A Clarke comments on the release of the exposure draft and consultation paper, criticising the very short consultation window (closing 18 September 2026) and highlighting the breadth of proposed changes that will require significant adjustments by regulated entities to governance, consent and breach‑response practices[14][15]. (source)
Related regulations
- Australia Cyber Security Act 2024 (Ransomware Payment Reporting) — Australia, Active, effective 2026-01-01
- Australia Online Safety Amendment (Social Media Minimum Age) Act 2024 — Australia, Active, effective 2025-12-10
- Australia Children's Online Privacy Code — Australia, Upcoming, effective 2026-12-10
- UK Data Protection Act 2018 — United Kingdom, Active
- Texas Data Privacy and Security Act (TDPSA) — Texas, Active, effective 2024-07-01
- General Data Protection Law (LGPD) — Brazil, Active, effective 2020-09-18
- COPPA (Children's Online Privacy Protection Act) — United States, Active
- Oregon Consumer Privacy Act (OCPA) — Oregon, Active, effective 2024-07-01
Put it into practice
- Generate the policy: Australian Privacy Act policy generator (generatepolicy.com)
- Buy the policy pack: Australia Privacy Act Compliance Policy (cyberpolicy.shop)
- Build it yourself: GDPR & DPIA Compliance Workbook (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates