Australia's second-wave Privacy Act reforms: the fair-and-reasonable test arrives
Australia's second-wave Privacy Act reforms: the fair-and-reasonable test arrives
On 31 August 2026 the Attorney-General's Department released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, alongside a 42-page consultation paper. That package is the second tranche of Privacy Act reform, and it is where the real rewrite lives. The first tranche, passed in December 2024, was mostly plumbing: OAIC enforcement powers, a statutory tort for serious invasions of privacy, automated-decision transparency, a children's online privacy code. Useful, but modest. Tranche 2 runs to roughly 40 proposals and rebuilds the core of the Act — how personal information is collected, used, disclosed and destroyed (IAPP).
Consultation closed on 18 September 2026. The bill is reportedly headed to Parliament this calendar year. So the window for input is gone; the window to prepare is short.
What's actually in the second wave
The headline is the fair and reasonable test. But the package is broader:
- A single fair-and-reasonable test replacing the rules in Australian Privacy Principles 3, 4 and 6. Collection, use and disclosure of personal information would only be permitted where it is fair and reasonable in the circumstances — and lawful.
- Stronger consent requirements. Consent becomes mandatory for collecting sensitive information and for trading in personal information, and must be voluntary, informed, current, specific and unambiguous.
- Expanded definitions. "Personal information" would capture behavioural and device-generated data and information that can single someone out without identifying them. AI-drawn inferences count as collection. Precise geolocation becomes sensitive information, requiring consent before collection.
- Data security and minimisation uplift, including a hard 72-hour deadline to notify the Information Commissioner of an eligible data breach, replacing the current "as soon as practicable" standard.
- Controller and processor concepts, borrowed in spirit from GDPR, governing how organisations direct service providers that handle data on their behalf.
- A right to erasure — but only for large digital platforms, and only for some information (Russell Kennedy).
- Digital identity protections, tightening how accredited digital identity data is handled under the Privacy Act, extending the accountability logic of the reform to the government's wider digital ID program.
That last point matters more than it looks. Australia's digital identity rollout has historically sat in its own legislative lane. Folding digital identity data into the reformed Privacy Act's obligations is a quiet but significant consolidation.
The fair and reasonable test, in practice
Here is the mechanism. An entity may not collect, use or disclose personal information unless doing so is fair and reasonable in the circumstances. Seven legislated factors feed that assessment: the reasonable expectations of the individual, the relationship to the entity's functions or activities, transparency, data minimisation, genuine choice, the proportionality of impact on the individual, and — where children are involved — their best interests as a primary consideration. The OAIC will issue guidance with worked examples. No single factor decides the question; the assessment is holistic.
Two consequences stand out. First, consent stops being a cure-all. Even where a user has ticked the box, the underlying handling still has to clear the fairness bar. A consent flow wrapped around a practice a reasonable person would find startling does not launder it. Second, the old primary-purpose/secondary-use scaffolding mostly disappears. The consultation paper says the further a use strays from the original purpose of collection, the harder it becomes to argue the handling was fair and reasonable. Purpose still matters; it just works differently.
This is genuinely a world-first design. The EU's GDPR runs on lawful bases plus a balancing test for some processing. Australia's version applies a fairness assessment across the entire information lifecycle with legislated factors, untested anywhere else. That is the interesting part — and the risky part. Nobody knows precisely how a regulator or a court will weigh "reasonable expectations" against a legitimate analytics use case. Expect the first two years after commencement to be a period of aggressive interpretation, with the OAIC's guidance doing most of the work the statute leaves open.
My position: the test is a net improvement over the current "reasonably necessary" collection standard, which has aged badly. It converts a checkbox compliance culture into an evidence culture — you will need to document why a use is fair, not just disclose that it happens. The conceded limitation: for novel uses (AI training on customer data, behavioural ad targeting), the honest answer today is "probably not fair and reasonable, but nobody is certain." Businesses should not treat uncertainty as permission.
How it differs from what already passed
Tranche 1 was enforcement and individual remedies; tranche 2 is structural. The December 2024 amendments gave the OAIC information-sharing powers, civil penalties tied to the existing regime, a statutory tort for serious invasions of privacy (in force from June 2025), and automated-decision transparency obligations that commence from 10 December 2026. Those transparency obligations require privacy policies to describe the kinds of automated decisions made with personal information. Tranche 2 goes further: it doesn't just ask you to disclose automated decisions, it asks you to justify the underlying data handling against a fairness standard.
The sequencing matters for planning. If you have not yet done tranche 1 readiness — automated decision mapping, tort exposure review — do it now, because tranche 2 compounds it.
Small business: the exemption survives
Here is the part our readers at StealthOz asked about most, and the answer will relieve most of you: the $3 million small business exemption was not removed. It was recommended for removal back in the 2023 Privacy Act Review report, and it has been the single largest source of anxiety for small operators. The exposure draft leaves it in place, with the only related adjustment being how the "trading" carve-in operates. Multiple firm analyses confirm it (Allens).
Do not read that as "nothing to do." Three caveats.
First, the exemption has carve-ins that bite: health service providers, businesses that trade in personal information, and credit reporting bodies are covered regardless of turnover. If your small business sells or shares customer data in exchange for benefit, you may already be inside the Act without realising it.
Second, the expanded definition of "personal information" is a compliance multiplier for everyone, exempt or not. If you run a small site with analytics, ad pixels, or any device-generated behavioural data, the boundary of what counts as personal information moves toward you even while the turnover threshold holds.
Third, and most important: the exemption's survival is a political fact, not a settled principle. It has been formally recommended for removal once already. A future tranche or a parliamentary amendment could revive it with little notice. Treat the current position as a reprieve with a short shelf life, not a promise. If you collect more than your core service needs — and most operators do — the cheapest defence is to stop collecting it now, under the data minimisation logic that tranche 2 makes explicit anyway.
One more thing worth flagging for the small-business audience: while the small business exemption survives, employee records remain excluded too, and mandatory privacy impact assessments and a direct right of action for individuals were both left out of the draft bill entirely. The lobby did well this round.
What consumers should expect
If the bill passes roughly as drafted, here is what changes for individuals. Your consent requests should get shorter and more specific, because vague blanket consent will no longer satisfy the statute. Sensitive information and precise geolocation will demand explicit consent before collection. Data breaches will be notified to the regulator faster — 72 hours — which should feed into faster individual notification in the worst cases, though the bill's three-pathway notification scheme does not guarantee individuals are always told directly. Erasure will exist in theory, but only against large digital platforms — roughly, businesses with over $500 million in group revenue or 2.5 million or more Australian monthly users — and only subject to exceptions for legal obligations, public interest and technical necessity. Most consumers will never use it against anyone but the major platforms, which is precisely where it will matter.
While that plays out in the Senate, the working controls stay on your side of the glass: a degoogled Pixel narrows the app-tracking surface the old law never reached, and a USB-C data blocker keeps the data-harvesting chargers of the world out of your handset.
The honest limitation: none of this is law yet. It is an exposure draft, subject to parliamentary negotiation, and transitional arrangements remain underspecified. Commencement will likely be deferred for most obligations, but the exact runway is unknown. Anyone building a compliance roadmap today should build one with fat margins around the dates.