Privacy Act reforms: what the second tranche means for businesses

Insights3 Sep 2026
By Alison BakerSuzie LeaskEden WinokurIona GoodwinMadeline TaitDan Williams and Mia Gould

Australia’s privacy regime is set for another major overhaul, with the Federal Government unveiling its long-awaited second tranche of Privacy Act reforms. The proposals could significantly change how businesses collect, use, share and protect personal information, and expand the rights individuals have over their data. 

The Federal Government has released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026  (Cth), [1] together with a consultation paper, [2] marking the second stage of reform of the Privacy Act 1988 (Cth). 

Building on the Privacy and Other Legislation Amendment Act 2024 (Cth), which introduced, amongst other things, the statutory tort for serious invasions of privacy, and enhanced enforcement powers (discussed in a previous insight here), the Bill proposes approximately 40 further reforms, including the long-anticipated fair and reasonable test , that will significantly change how Australian businesses handle personal information.

The reforms are broad in scope but also respond to privacy risks associated with emerging technologies. As we explored recently in our article Smart glasses in the workplace: the privacy and surveillance risks organisations need to manage, technologies that collect personal, biometric and location data are challenging existing approaches to privacy surveillance. Several of the proposals, including the treatment of precise geolocation as sensitive information and the right to erasure, are intended to address these emerging risks. 

Key takeaways 

If the Bill is introduced in its current form, businesses will need to:

  • Review data practices: assess whether their handling of personal information meets the legislated factors, particularly around transparency, data minimisation and genuine choice. Revisit marketing and data-sharing arrangements where they involve trading personal information.

  • Invest in data governance: map the personal information they hold, review retention and destruction policies in light of the strengthened APP 11 obligation to consider destruction of personal information and implement lifecycle management programs.

  • Mitigate data breach impacts: take reasonable steps to prevent or reduce harm to the individuals affected in actual or suspected data breaches.

  • Strengthen breach response capability: update incident response plans to reflect the 72-hour notification window and regularly test breach readiness.

  • Prepare for expanded individual rights: build organisational capability to respond to erasure and access requests, including the systems and processes needed to identify, locate and destroy personal information across complex data environments.

  • Implement AI governance frameworksprioritise updating AI governance frameworks, including auditing AI systems and implementing transparency measures.

  • Plan for increased regulatory exposure: invest in complaint-handling infrastructure that meets the 60-day response and written decision requirements and ensure privacy programs are audit-ready for a more active Office of the Australian Information Commission (OAIC).

What is the new ‘fair and reasonable’ test?

Data minimisation and obligations

Data breach response

Who will have the right to erasure?

AI and automated decision-making

Increased regulatory and litigation risk

Emerging technologies

How we can help

The second tranche of Privacy Act reforms could significantly change how organisations in Australia collect, use, share and protect personal information. While the proposals remain subject to consultation, organisations should begin assessing how the changes could affect their data practices and where action may be required. 

The Hall & Wilcox privacy team can help you assess the impact of the proposed reforms, review your privacy and data governance frameworks, policies, collection notices and digital terms, and identify areas that may need change. We can also assist organisations wanting to make a submission to the Consultation Paper before the consultation closes on 18 September 2026. 

Please get in touch if you would like to discuss what the proposed reforms mean for your business and how you can start preparing. 

This article is prepared with assistance from Lucy Korman, Law Graduate 


[1] Attorney-General (Cth), Privacy Amendment (Personal Data Protection) Bill 2026 (Exposure Draft, 2026). 
[2] Attorney-General’s Department (Cth), Privacy Reform Consultation Paper (Consultation Paper, 2026).

Contact

Hall & Wilcox acknowledges the Traditional Custodians of the land, sea and waters on which we work, live and engage. We pay our respects to Elders past, present and emerging.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of service apply.