Data Protection 3 Banner

Privacy Reform Tranche 2 Arrives: Major Changes Proposed, Key Reforms Still Missing

Gina Tresidder, William Stormon

Key takeaways

  • On 31 August 2026, the Attorney-General’s Department released the Exposure Draft of the Privacy Amendment (Personal Data Protection) Bill 2026 for public consultation. Submissions close on 18 September 2026.
  • The Bill contains approximately 40 proposals that would modernise definitions, introduce a ‘fair and reasonable’ test for handling personal information, strengthen data breach response obligations, and create a right to erasure on large digital platforms.
  • Several significant proposals from the Privacy Act Review are not addressed, including removing the small business and employee records exemptions, and introducing a universal right of erasure, mandatory Privacy Impact Assessments, and a direct right of action for individuals.
  • Organisations should begin assessing their readiness now but should wait for the Bill to be finalised before implementing specific compliance changes.

Key reforms at a glance

The Bill implements a substantial number of the outstanding proposals from the 2022 Privacy Act Review Report. The changes that will have the greatest practical impact on organisations are set out below:

  • A new ‘fair and reasonable’ test (see below) replaces the complex requirements under Australian Privacy Principles (APPs) 3, 4 and 6 for collecting, using and disclosing personal information.
  • Organisations must obtain consent before collecting sensitive information or trading in personal information.
  • Organisations must strengthen data security and minimisation practices, and notify the Information Commissioner of eligible data breaches within 72 hours.
  • Individuals can request large digital platforms to erase their personal information.
  • A single, broader research exception simplifies how organisations handle personal information for ethically approved human research.
  • A new controller/processor framework reduces compliance obligations for entities that process personal information on behalf of others.

The ‘fair and reasonable’ test

This is the centrepiece of the Bill. It replaces existing APPs 3, 4 and 6 with a single, principles-based test. Organisations can only collect, use or disclose personal information if doing so is fair and reasonable in the circumstances and lawful. The OAIC will issue guidance, but organisations must weigh seven legislated factors: reasonable expectations, relationship to the entity’s functions, transparency, data minimisation, genuine choice, proportionality of impact, and the best interests of the child.

Consent becomes mandatory for collecting sensitive information and for trading in personal information. Consent must be voluntary, informed, current, specific and unambiguous.

Expanded definition of sensitive information

The Bill classifies two new categories as sensitive information, triggering the stricter consent requirements:

  • Precise geolocation tracking data: information generated by a device that identifies an individual’s location within 500 metres and is tracked over time.
  • Genomic information: information about an individual’s genetic characteristics, biological relationships or potential health risks.

Organisations using location tracking, wearable devices, health technology or genetic testing need to review whether they now collect sensitive information requiring consent.

72-hour data breach notification deadline

The Bill replaces the current ‘as soon as practicable’ standard with a hard 72-hour deadline. Once an entity has reasonable grounds to believe an eligible data breach has occurred (one likely to cause serious harm), it must notify the Information Commissioner within 72 hours. The notification must set out the entity’s response and the steps taken or proposed to reduce harm.

Entities must also follow three notification pathways: notifying all affected individuals, notifying individuals at risk of serious harm, and public notification where direct notification is not practicable. Where a breach is only suspected, entities have 30 days to investigate.

Right of erasure on large digital platforms

The Bill creates a right to erasure for individuals on large digital platforms (LDPs). An LDP must destroy an individual’s personal information on request, unless an exception applies. An organisation is an LDP if its business group’s gross revenue exceeds $500 million (inclusive of overseas revenue), or its platform has 2.5 million or more average monthly end users in Australia. Exceptions cover public interest, legal obligations, technical impossibility and information strictly necessary to deliver an ongoing service.

Broader research exception

The Bill replaces the existing patchwork of health and medical research exceptions with a single exception for ‘human research’, defined as research conducted with or about individuals that involves personal information. To rely on the exception, the research must be reviewed, approved and monitored in accordance with the National Statement on Ethical Conduct in Human Research, and must comply with human research guidelines issued by the Privacy Commissioner. Where these requirements are met, acts done in the course of the research will not breach the APPs.

This broadens the scope of research that can proceed without individual consent, while maintaining ethical oversight. The exception will commence once the Privacy Commissioner’s human research guidelines are in place.

Controller/processor framework

The Bill introduces a formal distinction between controllers (entities that determine the purposes for which personal information is handled) and processors (entities that handle personal information on behalf of a controller in accordance with documented instructions). Where a processor acts within the controller’s documented instructions, primary responsibility for compliance with the APPs rests with the controller, not the processor. Processors remain directly responsible for APP 1 (open and transparent management) and APP 11 (security of personal information).

If a processor acts outside its documented instructions, the processor exception does not apply and the processor bears full responsibility for compliance. Organisations that engage third-party service providers to handle personal information should review their contractual arrangements to ensure documented instructions are in place.

Implications for AI, automated decision-making and emerging technologies

The Bill does not introduce standalone AI obligations, but its broadened definitions have direct consequences for organisations using AI and emerging technologies.

Any entity that collects personal information through technologies like smart glasses, biometric scanners or AI-generated inferences must comply with the fair and reasonable test and the new consent requirements. The recently introduced statutory tort for serious invasions of privacy also applies to harms caused by emerging technologies. However, the Bill stops short of imposing specific rules on AI systems, agentic AI or algorithmic decision-making beyond the automated decision-making transparency obligations already enacted in Tranche 1 (commencing 10 December 2026). The consultation paper separately seeks feedback on privacy issues associated with wearable technologies, connected vehicles and smart glasses.

What is conspicuously absent from the Bill?

  • Removal of the small business exemption. The Privacy Act Review recommended removing the exemption for businesses with annual turnover under $3 million. The Government agreed in principle but the Bill does not address this, meaning a large proportion of Australian businesses remain outside the privacy framework.
  • Employee records exemption. The Review recommended removing the broad exemption that allows private sector employers to handle employee records outside the APPs. This remains untouched.
  • Universal right of erasure. The erasure right in the Bill applies only to large digital platforms meeting the $500 million revenue or 2.5 million user threshold. Most organisations are not covered. The Review envisaged a broader right for all entities.
  • Mandatory Privacy Impact Assessments (PIAs). The Review proposed that entities undertake PIAs for high-risk activities. The Bill does not include this obligation.
  • AI-specific obligations. While the Bill’s broadened definition of ‘collects’ covers AI-generated inferences, there are no standalone obligations governing AI systems, agentic AI, or automated decision-making beyond the transparency requirements already enacted in Tranche 1 (commencing 10 December 2026).
  • Algorithmic transparency and fairness. The Review proposed that entities be required to explain substantially automated decisions that significantly affect individuals’ rights. The Bill does not build on the basic transparency obligation in the 2024 amendments.
  • Wearable surveillance technology. The Consultation Paper invites views on privacy issues arising from smart glasses and connected vehicles, but no specific obligations for individuals using these devices are included in the Bill.
  • Direct right of action. The Review recommended allowing individuals to bring court proceedings directly for privacy interferences, without first complaining to the OAIC. This is not in the Bill.

The absence of these proposals means the Bill, while a meaningful step, does not deliver the comprehensive overhaul many stakeholders expected. Organisations should monitor whether any of these measures are introduced during the parliamentary process or in a future tranche.

What organisations should do now

  • Review data collection, use and disclosure practices against the proposed fair and reasonable test, including whether current uses align with reasonable expectations and whether de-identified or less personal information could achieve the same purpose.
  • Audit consent mechanisms and privacy notices, ensuring consent is not bundled or overly broad and that notices are clear, transparent and up to date.
  • Strengthen data governance and retention practices by identifying personal information that is no longer required and establishing regular reviews of data holdings.
  • Test and uplift cyber incident response and breach readiness, including ensuring systems can respond within the proposed 72-hour notification window.
  • Review AI systems and use of emerging technologies such as biometric technologies, location tracking, smart devices or profiling tools.

What to do once the Bill is enacted

Certain actions should wait until the Bill is introduced to Parliament and enacted. Once the legislation is finalised, organisations should:

  • Update privacy policies and collection notices to reflect the enacted fair and reasonable test, the new consent requirements and the updated definitions of personal and sensitive information
  • Implement revised consent mechanisms that satisfy the legislated requirements of voluntary, informed, current, specific and unambiguous consent
  • Adjust data breach response plans to comply with the finalised 72-hour notification timeframe and three-pathway notification obligations If an LDP, establish systems and processes to receive, assess and action erasure requests within the required timeframes
  • Review and update controller-processor arrangements to ensure they align with the enacted processor exception, including ensuring documented instructions are in place
  • Train staff on the finalised obligations and embed compliance into day-to-day operations.

How Russell Kennedy can assist:

Russell Kennedy’s Technology, Media and Telecommunications team advises organisations on privacy compliance, data governance and regulatory reform. We can help you:

  • Conduct a gap analysis of your current privacy framework against the proposed reforms
  • Review and update privacy policies, collection notices and consent mechanisms to align with the new requirements
  • Advise on the fair and reasonable test and how it applies to your specific data handling practices
  • Review and strengthen data breach response plans in preparation for the 72-hour notification obligation
  • Advise on controller-processor arrangements and ensure documented instructions meet the proposed standards
  • Assist with right of erasure obligations for large digital platforms Provide tailored training for your teams on the reformed privacy framework
  • Prepare submissions on the Exposure Draft if you wish to influence the final form of the legislation before the 18 September 2026 deadline

For further information, please contact a member of our team.

If you’d like to stay up to date with Russell Kennedy Alerts and Events, you can subscribe to our mailing list here.

View related insights

airport

Qantas passes the OAIC’s preliminary data breach test: what helped and what organisations should be doing now

30 Jul 2026

Despite a data breach affecting approximately 5.12 million Australians, the OAIC declined to open a formal investigation into Qantas, finding no evidence the airline failed to take reasonable steps to ...

View
professional services

Legal Checklist for Professional Services Firm Owners Considering a Sale, Equity Succession or Merger

28 Jul 2026

Recent years have seen a significant increase in consolidation across professional services sectors, driven not only by succession planning and growth ambitions, but also by mounting regulatory and co ...

View
director signage

ASIC Director ID Reforms: Companies Must Report Director IDs to ASIC from 1 July 2027

22 Jul 2026

From 1 July 2027, companies will be required to provide directors' director IDs to the Australian Securities and Investments Commission (ASIC) through company reporting processes, including annual rev ...

View