On 31 August 2026, the Attorney-General released a Consultation Paper and an Exposure Draft of the Privacy Amendment (Personal Data Protection) Bill 2026 (Cth) (the Bill), which would amend the Privacy Act 1988 (Cth) (the Privacy Act). The package forms the second tranche of Australia’s privacy reforms and proposes wide-ranging changes to the national privacy framework.[1] Public debate over smart glasses and other wearable recording devices provided the backdrop, but the Bill’s substance extends far beyond any single device. For Australian business reputation protection law, the practical consequence is that data handling failures will increasingly sit alongside defamation and misleading conduct as sources of corporate exposure.
What the Bill Would Change
The principal measures are these:
- A new overarching “fair and reasonable” test would replace Australian Privacy Principles (APPs) 3, 4 and 6, requiring entities to weigh factors such as reasonable expectations, transparency, data minimisation and genuine choice rather than work through a fixed checklist.
- A limited right to erasure would apply to large digital platforms, letting individuals ask platforms meeting a revenue or user threshold to delete their personal information, subject to exceptions.
- The definition of “personal information” would change, consistent with recent determinations by the Privacy Commissioner on tracking pixels and individuation as personal information.
- A controller/processor distinction would be introduced for the first time. An entity acting strictly on another’s documented instructions would generally not carry the same compliance responsibility as the entity directing how the data is used.
- Strengthened direct marketing practices, a consent requirement for trading in personal information, and a 72-hour notification requirement for eligible data breaches.
The “Fair and Reasonable” Test
The centrepiece of the Bill would replace APPs 3, 4 and 6 with a single “fair and reasonable” test for the collection, use and disclosure of personal information.[2] Regulated entities would assess their own conduct against a non-exhaustive list of factors before collecting, using or disclosing personal information. Those factors include an individual’s reasonable expectations, the relationship between the handling and the entity’s functions, transparency, data minimisation, genuine choice, proportionality, and the best interests of the child where children’s information is involved.[3] The Office of the Australian Information Commissioner (OAIC) would issue guidance on applying the test and would enforce it after the fact rather than pre-approving individual decisions. According to Australian corporate law, the introduction of a controller/processor distinction represents a fundamental shift in how responsibility for personal information will be allocated between entities, moving away from the current position under s 6 and s 6A of the Privacy Act where all APP entities bear equivalent obligations.
An entity would not need to satisfy every factor for its conduct to be fair and reasonable. The factors are weighed together, so a weakness against one can be offset by strength against others. The test calls for an overall judgment rather than a tick-box exercise. Consent is not an exception to the fair and reasonable requirement.
The reform also raises the bar on what counts as genuine transparency and choice. Simply including a practice in a privacy policy would not, by itself, satisfy the transparency factor, particularly where the policy is lengthy or hard to follow. The Bill would make clear that “take it or leave it” terms and dark patterns do not amount to genuine choice, a standard consistent with the Bill’s general emphasis on genuine choice and transparency rather than a precisely codified test under the current law.[4]
The Consultation Paper points to a common problem the test is meant to fix: entities routinely collect information such as dates of birth, gender, geolocation and copies of identity documents that is not actually necessary for the service they provide. Genuine data minimisation would form part of the overall assessment. The OAIC’s community attitudes research suggests the public already expects this discipline, with around 9 in 10 Australians (92%) saying data collection can be acceptable under certain conditions.
Right to Erasure: Large Digital Platforms Only
The Bill would give individuals a right to ask “large digital platforms” (LDPs) to erase and destroy requested personal information. A platform qualifies as an LDP if it is a social media service, relevant electronic service or designated internet service under the Online Safety Act 2021 (Cth) (the OSA) and meets the gross revenue test: either $500 million or more in gross group revenue, or 2.5 million or more average monthly Australian users. The Consultation Paper confirms LDPs captures services such as social media, messaging, email, gaming and streaming platforms that meet that threshold.[5]
The right would not be absolute. It would give way to public interest, legal interest and technical exceptions, including where destruction is technically infeasible or the information is still needed to provide an ongoing service. Legal precedent establishes that the fair and reasonable test will require entities to demonstrate genuine consideration of individual circumstances rather than mechanical compliance with prescribed factors, and this principle will shape how the erasure right is administered in practice.
Controller and Processor: A First for Australian Privacy Law
For the first time, the Bill proposes to bring a controller/processor distinction into the Privacy Act. Under the current law, the Act does not distinguish between an entity handling personal information on its own behalf and one handling it purely on another entity’s instructions. Both are simply treated as APP entities bearing full responsibility under s 6 and s 26WA. Under the proposed model, a controller would be the entity that decides why personal information is handled, while a processor would be an entity that acts strictly on a controller’s documented instructions.[6] A processor acting within those instructions would be exempt from most APP obligations, other than APP 1 (open and transparent management) and APP 11 (security), and its compliant acts would be treated as the controller’s acts for liability purposes. Both controller and processor would need to be APP entities for the new rules to apply.
The distinction is common to most other privacy regimes, including the GDPR and CCPA. Its introduction carries several practical consequences:
- Contractual. Parties are likely to focus more closely on each party’s role, either to bolster (for a processor) or weaken (for a controller) the likelihood of the processor exceptions applying, and on associated risk allocation.
- Governance. Parties will need to determine whether they act as controller or processor and ensure their data handling policies and practices reflect that distinction.
- Insurance. For processors, cover may not apply to the extent the processor acts outside the controller’s instructions, assuming those instructions are properly defined. For controllers, subject to any contractual terms to the contrary, they will be responsible for acts or omissions of processors acting on their behalf where the exception applies.
A Technology-Neutral Approach
Consistent with the Government’s stated preference for technology-neutral regulation, the Consultation Paper does not impose a ban on smart glasses or any other device. It relies on the Bill’s core reforms to address emerging technology risk generally. It also notes that the 2024 statutory tort for serious invasions of privacy already applies on a technology-neutral basis and could capture harms from wearable surveillance technology.[7]
Attorney-General Michelle Rowland reinforced this approach on ABC Radio National Breakfast on 1 September 2026, confirming the Government is not pursuing an import ban on smart glasses at this stage, even as the Privacy Commissioner actively examines the issue. She said the Government is “[not] having a regulatory environment that’s playing whack-a-mole every time a new technology is developed”, adding that it wants “sustainable and durable laws” rather than rules written for one product at a time, and that “[The] Government does not want to see nefarious use but we want to ensure we get this right; we get the balance appropriate”.[8]
The Government is seeking targeted feedback on whether the proposed definitions and consent framework are flexible enough to address wearables and AI-driven data collection, and whether existing remedies are adequate.
A related but separate reform, the Digital Duty of Care, is being progressed under the OSA and the Communications portfolio. It would require platforms to identify foreseeable risks of harm from their algorithms and take reasonable steps to prevent or reduce them, along lines similar to duties already in force in the UK and the EU. It sits apart from the Bill, though both draw on OSA definitions and form part of the Government’s wider digital regulation agenda.
Individuation and the Definition of Personal Information
The definition of “personal information” would be amended by replacing the requirement that information be ‘about’ an individual with the requirement that it ‘relate to’ an individual. The change is intended to capture information that ‘says something’ about an individual, their activities or their behaviours. Context matters, to the extent the information is used to influence decisions affecting that individual.
This proposed change is likely to support recent determinations by the Privacy Commissioner on the use of tracking pixels by Monash IVF Pty Ltd [2026] AICmr 12 and Medmate Pty Ltd [2026] AICmr 18. Those determinations emphasised the potential for otherwise anonymous information gathered by tracking pixels on individuals accessing websites to qualify as ‘personal information’, because it was used to influence marketing directed at those individuals.
Notifiable Data Breach Scheme
Changes are also proposed to the Mandatory Notifiable Data Breach Scheme, supplementing the existing regime. The key changes are:
- A separate definition of ‘data breach’, noting that some obligations to protect individuals may arise even if the breach is not an ‘eligible data breach’.
- Overarching obligations on organisations to have systems in place to respond to a data breach and reduce harm to affected individuals, and to take active steps to mitigate harm once aware a breach has occurred.
- A 72-hour deadline to notify the Privacy Commissioner of an eligible data breach, although the 30-day assessment timeframe would still apply. This aligns with reporting timeframes in the SOCI and Cyber Security Acts.
Businesses already managing overlapping breach obligations under the AML/CTF tranche 2 reforms will recognise the compliance pressure. Our analysis of AML/CTF tranche 2 privacy obligations covers how those regimes interact.
What Is Missing From This Tranche
What is most surprising is what is not in the Bill. Several reforms anticipated in this tranche do not appear in the draft legislation: removal of the small business exemption, removal or reform of the employee records exemption, mandatory standard contractual clauses for overseas disclosures, and mandatory privacy impact assessments for high-risk activities. The Consultation Paper confirms that further reforms remain “under development” for future consideration, so this tranche is unlikely to be the Government’s final word on privacy reform.
If implemented in its current form, the draft legislation would be significant for Australia’s privacy laws and for the data handling and operations of regulated entities.
Where This Leaves Corporate Reputation Risk
Data handling failures and reputational attacks increasingly occupy the same risk register, and the remedies overlap. Where a business cannot sue for defamation, business defamation alternatives such as misleading and deceptive conduct and injurious falsehood often carry the weight. Privacy compliance failures can compound that exposure, particularly where a breach is mishandled or a marketing practice is later found not to reflect genuine choice. Legal precedent establishes that the fair and reasonable test will require entities to weigh competing factors holistically, and cases such as Australian Broadcasting Corporation v O’Neill (2006) 227 CLR 57 and Dow Jones & Company Inc v Gutnick (2002) 210 CLR 575 demonstrate how Australian courts approach the balance between reputational harm and other interests. The academic literature on defamation and corporate reputation in Australia, England and Wales and Canada illustrates how differently common law systems treat corporate reputational harm, which is why statutory alternatives matter here.
Submissions on the Consultation Paper and Exposure Draft Bill close on Friday, 18 September 2026. The Government has invited feedback from all interested stakeholders, including regulated entities, industry bodies, consumer organisations, legal experts, privacy advocates, academics and individuals. That feedback will shape both the drafted provisions and the measures still under policy design, including the questions regarding emerging technology.
[1] Attorney-General’s Department, Privacy Reform – Consultation Paper (31 August 2026), p 1; Attorney-General’s Department, Consultation on Exposure Draft legislation, https://consultations.ag.gov.au/rights-and-protections/privacy-reform/
[2] Attorney-General’s Department, Privacy Reform – Consultation Paper, p 10.
[3] Ibid, p 10.
[4] Ibid, p 13-14.
[5] Ibid, p 33.
[6] Ibid, p 37.
[7] Ibid, p 41-42.
[8] ABC Listen, Radio National Breakfast, ‘Govt taken ‘balanced approach’ to privacy proposals, Attorney General says. https://www.abc.net.au/listen/programs/radionational-breakfast/michelle-rowland-federal-government-privacy-proposals/107098426.
Book an appointment with one of our Lawyers to discuss your specific needs.
Book a ConsultationA Note on the Information We Share
Reading this information does not create a lawyer-client relationship between you and SLK Lawyers. This only occurs with a formal written agreement. Content is current at publication and applies to Victorian law unless stated otherwise. It is general information only and not a substitute for specific legal advice. Strict time limits apply to legal claims. You should seek immediate legal advice on your specific situation to ensure your rights are protected.