The next stage of Australia’s privacy law reform is taking shape.
The Australian Government has released the Exposure Draft of the Privacy Amendment (Personal Data Protection) Bill 2026, together with a Consultation Paper. The package contains around 40 proposals and is expected to represent one of the most substantial changes to Australia’s privacy framework in more than a decade.
For organisations, the significance of Tranche 2 goes beyond updating privacy policies or notices.
Several of the proposed reforms reach into the way personal information is collected, used, retained, shared and protected. If implemented, they may require organisations to reconsider existing data flows, governance arrangements, contracts, incident response processes and direct marketing practices.
What is changing?
One of the central proposals is a new “fair and reasonable” test applying to the collection of personal information under APP 3.
The proposed test would place greater emphasis on the substance of an organisation’s data practices. Factors such as reasonable expectations, transparency, data minimisation, genuine choice, privacy impacts and the risk of harm would become increasingly important when assessing whether personal information is being handled appropriately.
The Exposure Draft also proposes significant changes across a number of other areas, including:
- strengthened data breach response and notification obligations, including the proposed 72-hour window for notifying the OAIC
- a broader definition of personal information
- new statutory requirements for consent
- changes to direct marketing rules
- stronger data security and minimisation requirements
- a new controller-processor framework
- restrictions relating to the trading of personal information
- a right to erasure for certain large digital platforms
Taken together, the proposals point towards a broader shift in privacy regulation. Compliance is increasingly concerned not simply with what an organisation tells individuals about its practices, but whether those underlying practices can be demonstrated to be fair, reasonable and subject to appropriate governance.
What should organisations be considering now?
The legislation remains in draft form, but the scale of the proposed changes means organisations may benefit from evaluating their existing privacy framework before the final reforms are settled.
That includes understanding what personal information is held, how it moves through the organisation, the role of third-party providers and processors, how consent is obtained and recorded, how data is retained or destroyed, and whether existing breach response procedures could meet the proposed requirements.
We have prepared a concise two-page overview of Privacy Act Reforms Tranche 2, setting out some of the key proposals and what they could mean for organisations.
Download our Privacy Act Reforms Tranche 2 summary
The Consultation Paper is currently open for submissions, with submissions due on 18 September 2026. Organisations that may be materially affected by the proposals should also consider whether there are issues they wish to raise through the consultation process.
For further information about the proposed Privacy Act reforms, their potential impact on your organisation, or making a submission to the Consultation Paper, please contact Candy Lau, Partner at Ironbridge Legal.
Further Information
For further information about the proposed Privacy Act reforms, the new fair and reasonable test for personal information handling, strengthened data breach obligations, the proposed controller-processor framework, and what the changes may mean for your organisation, please contact the author of this article: