Quick Hit

The Australian Government has proposed a series of privacy law reforms.The reforms are the second tranche of reforms following the Attorney-General’s 2023 Privacy Act Review Report. The reforms are designed to strengthen protections for Australians in the digital age, particularly in response to growing risks from data breaches and emerging technologies such as AI and smart glasses.

The Government has released a Consultation Paper and an exposure draft of the proposed reforms (the Privacy Amendment (Personal Data Protection) Bill 2026).

The proposed reforms would make some foundational changes to Australia’s privacy laws that may have a significant impact on Australian businesses that collect, store, use and disclose personal information.

What are the key proposed changes?

Key proposed changes include:

  • A change to the definition of ‘personal information’, from information that is ‘about’ an individual who is identified or reasonably identifiable, to information that ‘relates to’ such an individual.In addition, a new note clarifies that an individual can be identified or “reasonably identifiable” even where their name or legal identity is not known, where they can be recognised, singled out or treated as a distinct individual. This means that more information would be covered by privacy protections;
  • A new framework to permit the collection, use and disclosure of personal information only where it is “fair and reasonable” in the circumstances. This involves an assessment of various factors including reasonable expectations, the purpose for which the information is collected and used, transparency, genuine choice, and any risks to the relevant individual to whom the information relates. This new test would replace most of the existing requirements under Australian Privacy Principles 3, 4 and 6;
  • A prohibition on “trading” personal information (a disclosure made for payment or other consideration, or for direct marketing purposes), unless the individual has consented or an exception applies;
  • The requirement for a simple ‘opt out’ for direct marketing communications. ‘Ad-supported’ services may still be offered, as long as individuals are given genuine choice;
  • Consent (including where required for the collection of sensitive information or for the “trading” of personal information) must be voluntary, informed, current, specific and unambiguous. In practice, this may require businesses to remove bundled consents or preselected or pre-ticked boxes;
  • New obligations for data breaches, including a requirement to take reasonable steps to prevent or reduce harm to individuals, and to notify the Information Commissioner within 72 hours if there are reasonable grounds to believe that an eligible data breach has occurred; and
  • Businesses to take steps to identify personal information that is no longer needed and consider whether to destroy or de-identify that information.


Next steps

Submissions on the Consultation Paper and Exposure Draft close on 18 September 2026.

Given the short response timeframe, and since the reforms were developed over a number of years with previous consultation, we anticipate that the government is keen to progress these reforms fairly quickly.

For assistance or more information on privacy law, please contact Adam Simpson or Anna Spies.