Australia’s second tranche of privacy reforms has arrived. On 31 August 2026, the Attorney-General released a Consultation Paper and an Exposure Draft of the Privacy Amendment (Personal Data Protection) Bill 2026 (Cth) (the Bill), which would amend the Privacy Act 1988 (Cth) (the Privacy Act), setting out a broad package of proposals to modernise Australia’s national privacy framework.[1] The reforms land amid growing public debate over smart glasses and other wearable recording devices, but the substance of the Bill goes well beyond any single device.
Need to know:
- a new overarching “fair and reasonable” test is proposed to replace Australian Privacy Principles (APPs) 3, 4 and 6, requiring entities to weigh factors such as reasonable expectations, transparency, data minimisation and genuine choice, rather than follow a fixed checklist.
- a limited right to erasure is proposed in respect of large digital platforms, letting individuals ask large digital platforms meeting a revenue or user threshold to delete their personal information, subject to exceptions.
- consistent with recent determinations by the Privacy Commissioner on tracking pixels and “individuation as personal information” (see our recent article, Tracking pixels and targeted advertising – what they mean for Australian privacy law – Hamilton Locke), changes to the definition of “personal information”.
- a controller/processor distinction is proposed for the first time, meaning an entity acting strictly on another’s documented instructions would generally not bear the same compliance responsibility as the entity directing how the data is used.
- the draft legislation also provides for strengthened direct marketing practices, requires consent for trading in personal information, and provides for a 72 hour notification requirement for eligible data breaches.
The headline reform: a “fair and reasonable” test
The centrepiece of the Bill would replace APPs 3, 4 and 6 with a single “fair and reasonable” test for the collection, use and disclosure of personal information.[2] The proposed “fair and reasonable” test would require regulated entities to assess their own conduct against a non-exhaustive list of factors before collecting, using or disclosing personal information. Those factors include an individual’s reasonable expectations, the relationship between the handling and the entity’s functions, transparency, data minimisation, genuine choice, proportionality, and the best interests of the child where children’s information is involved.[3] The Office of the Australian Information Commissioner (OAIC) would issue guidance on how to apply the test, and would enforce it after the fact, rather than pre-approving individual decisions.
Critically, an entity would not need to satisfy every factor for its conduct to be fair and reasonable. The factors are weighed together, so a weakness against one factor can be offset by strength against others. The test asks for an overall, holistic judgment rather than a tick-box exercise. Importantly, consent is not an exception to the “fair and reasonable” requirement.
The reform is also intended to raise the bar on what counts as genuine transparency and choice. Under the proposed test, simply including a practice in a privacy policy would not, by itself, satisfy the transparency factor, particularly where the policy is lengthy or hard to follow. The Bill would also make clear that “take it or leave it” terms and dark patterns do not amount to genuine choice, a standard that is not codified this precisely under the current law.[4]
The Consultation Paper points to a common problem the new test is intended to fix: entities routinely collect information such as dates of birth, gender, geolocation and copies of identity documents that is not actually necessary for the service they provide. The fair and reasonable test is intended to curb this by requiring genuine data minimisation as part of the overall assessment.
A new right to erasure — but only for the biggest players
The Bill would give individuals a right to ask “large digital platforms” (LDPs) to erase and destroy requested personal information. A platform would qualify as an LDP if it is a social media service, relevant electronic service or designated internet service under the Online Safety Act 2021 (Cth) (the OSA) the Consultation Paper confirms LDPs captures services such as social media, messaging, email, gaming and streaming platforms that meets the gross revenue test (either earns $500 million or more in gross group revenue or has 2.5 million or more average monthly Australian users).[5] The right would not be absolute. It would give way to public interest, legal interest and technical exceptions, including where destruction is technically infeasible or the information is still needed to provide an ongoing service.
Controller and Processor: a first for Australian privacy law
For the first time, the Bill proposes to bring a Controller/Processor distinction into the Privacy Act. Under the current law, the Privacy Act does not distinguish between an entity handling personal information on its own behalf and one handling it purely on another entity’s instructions, both are simply treated as APP entities bearing full responsibility. Under the proposed model, a Controller would be the entity that decides why personal information is handled, while a Processor would be an entity that acts strictly on a Controller’s documented instructions.[6] A Processor acting within those instructions would be exempt from most APP obligations, other than APP 1 (open and transparent management) and APP 11 (security), and its compliant acts would be treated as the Controller’s acts for liability purposes. Both Controller and Processor would need to be APP entities in order for the new rules to apply.
In addition to the definitional shift of introducing a distinction common to most other privacy regimes (such as GDPR and CCPA), some potential impacts are as follows:
- Contractual – parties are likely to focus more closely on the role of each party to either bolster (for a processor) or weaken (for a controller) the likelihood of the processor exceptions applying, and associated risk allocation;
- Governance – parties will need to determine whether they are acting as a controller or processor and ensure their data handling policies and practices reflect this distinction; and
- Insurance – for processors, insurance may not apply to the extent the processor acts outside of the controller’s instructions (assuming they are properly defined), and for controllers, subject to any contractual terms to the contrary, they will be responsible for any acts or omissions of processors acting on their behalf (where the exception applies).
A neutral approach to emerging technologies
True to the Government’s stated preference for technology-neutral regulation, the Consultation Paper does not impose a ban on smart glasses or any other device. Instead, it relies on the Bill’s proposed core reforms to address emerging technology risk generally. It also notes the 2024 statutory tort for serious invasions of privacy already applies on a technology-neutral basis and could capture harms from wearable surveillance technology.[7]
Attorney-General Michelle Rowland reinforced this approach on ABC Radio National Breakfast on 1 September 2026, confirming the Government is not pursuing an import ban on smart glasses at this stage, even as the Privacy Commissioner actively examines the issue. She said: “[We’re] not having a regulatory environment that’s playing whack-a-mole every time a new technology is developed,” adding that the Government wants “robust and sustainable laws” rather than rules written for one product at a time, highlighting that “[The] Government does not want to see nefarious use but we want to ensure we get this right; we get the balance appropriate.”[8]
The Government is seeking targeted feedback on this issue, posing questions including whether the proposed definitions and consent framework are flexible enough to address wearables and AI-driven data collection, and whether existing remedies are adequate.
A related but separate reform, the Digital Duty of Care, is also being progressed under the OSA and the Communications portfolio. It would require platforms to identify foreseeable risks of harm from their algorithms and take reasonable steps to prevent or reduce them, along similar lines to duties already in force in the UK and the EU. This sits apart from the Bill, though both draw on OSA definitions and form part of the Government’s wider digital regulation agenda.
Individuation
The definition of “personal information” will be amended by replacing the requirement that information be ‘about’ an individual with the requirement that it ‘relate to’ an individual. This change is intended to capture information that ‘says something’ about an individual or their activities or behaviours. Context is also important, to the extent the information is being used to influence decisions affecting that individual.
This proposed change is likely to support, for example, recent determinations by the Privacy Commissioner in the use of tracking pixels by Monash IVF and Medmate. Those determinations emphasised the potential for otherwise anonymous information gathered by tracking pixels on individuals accessing websites, qualifying as ‘personal information’ as it was used to influence marketing directed at those individuals.
Notifiable Data Breach Scheme
Changes are also proposed to the Mandatory Notifiable Data Breach Scheme, which supplement the existing regime. Key changes relate to:
- A separate definition of ‘data breach’, noting that some obligations to protect individuals may arise even if the breach is not an ‘eligible data breach’;
- Overarching obligations on organisations to have systems in place to respond to a data breach and reduce harm to affected individuals, and to take active steps to mitigate harm to individuals upon becoming aware of a data breach occurring; and
- A 72-hour deadline to notify the Privacy Commissioner of an eligible data breach occurring (although the 30-day assessment timeframe would still apply). This also aligns with reporting timeframes in the SOCI and Cyber Security Acts.
What is missing from this tranche
What is most surprising is what is not in the Bill. Some notably absent reforms that were anticipated in this tranche do not appear in the draft legislation: these include removal of the small business exemption, removal or reform of the employee records exemption, mandatory standard contractual clauses for overseas disclosures and mandatory privacy impact assessments for high-risk activities. The Consultation Paper itself confirms that further reforms remain “under development” for future consideration, so this tranche is unlikely to be the Government’s final word on privacy reform.
The draft legislation, if implemented in its current form, would be transformative for Australia’s privacy laws and the data handling and operations of regulated entities.
Submissions on the Consultation Paper and Exposure Draft Bill close on Friday, 18 September 2026. The Government has invited feedback from all interested stakeholders, including regulated entities, industry bodies, consumer organisations, legal experts, privacy advocates, academics and individuals. That feedback will shape both the drafted provisions and the measures still under policy design, including questions regarding emerging technology.
Hamilton Locke’s IP and Technology team will be monitoring the process of this consultation and reporting on any updates as they unfold.
For more information, please contact Toby Patten, Sophie Bradshaw and Sarah Gilkes.
[1] Attorney-General’s Department, Privacy Reform – Consultation Paper (31 August 2026), p 1; Attorney-General’s Department, Consultation on Exposure Draft legislation, https://consultations.ag.gov.au/rights-and-protections/privacy-reform/
[2] Attorney-General’s Department, Privacy Reform – Consultation Paper, p 10.
[3] Ibid, p 10.
[4] Ibid, p 13-14.
[5] Ibid, p 33.
[6] Ibid, p 37.
[7] Ibid, p 41-42.
[8] ABC Listen, Radio National Breakfast, ‘Govt taken ‘balanced approach’ to privacy proposals, Attorney General says. https://www.abc.net.au/listen/programs/radionational-breakfast/michelle-rowland-federal-government-privacy-proposals/107098426.