Privacy reform update September 2026

The Australian Attorney-General has released a Consultation Paper and Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026 to modernise and strengthen Australia’s privacy laws as well as responding to emerging risks from new technologies, including artificial intelligence, wearable surveillance technologies (such as smart glasses and ear buds) and connected vehicles.

It is also intended to provide greater certainty for businesses and other regulated entities.

The paper canvasses a range of proposed reforms, including:
* amending the definition of personal information to cover information that ‘relates to’ an individual who is identified or reasonably identifiable, and a new definition of reasonably identifiable is introduced.
* making it clear that personal information is ‘collected’ when an entity includes it in a record or generally available publication, regardless of the source from which, or how, the information is obtained. The amendments also clarify when entities will be taken to collect sensitive information that is derived from other personal information, regardless of whether the entity makes a separate record of that sensitive information.
* introducing a definition of disclosure based on whether an entity makes personal information accessible to another person or body, including where personal information is transmitted or stored overseas.
* strengthening and clarifying requirements for data security and minimisation, and responses to data breaches
* introducing a right for individuals to request the erasure of personal information held by large digital platforms, and an exception where compliance is technically impossible or infeasible and
* supporting research and innovation by simplifying research exceptions and facilitating the handling of personal information for ethically approved human research.

Existing APPs 3, 4 and 6 would be replaced with a new framework for the collection, use and disclosure of personal information. This framework is centred around a new test which permits the handling of personal information only where it is fair and reasonable in the circumstances, with reference to a non-exhaustive list of factors. There are exceptions where a permitted general or health situation applies or the information handling is required or authorised by law.

Data breach notification
The proposed amendments provide that an entity must, within 72 hours of becoming aware of reasonable grounds to believe that an eligible data breach has occurred, give the Information Commissioner a statement that notifies the Commissioner of the eligible data breach and sets out required content.

The introduction of the 72-hour notification requirement would not alter the obligation for assessment of suspected eligible data breaches. An entity that has reasonable grounds to suspect that there may have been an eligible data breach but has not yet established reasonable grounds to believe that an eligible data breach has occurred, must continue to take all reasonable steps to ensure that the assessment is completed within 30 days.

The small business exemption has not been removed.

If you found this article helpful, then subscribe to our news emails to keep up to date and look at our video courses for in-depth training. Use the search box at the top right of this page or the categories list on the right hand side of this page to check for other articles on the same or related matters.

Author: David Jacobson
Principal, Bright Corporate Law
Email:
About David Jacobson
The information contained in this article is not legal advice. It is not to be relied upon as a full statement of the law. You should seek professional advice for your specific needs and circumstances before acting or relying on any of the content.

 

Your Compliance Support Plan

We understand you need a cost-effective way to keep up to date with regulatory changes. Talk to us about our fixed price plans.