Australia publishes initial proposals for second wave of Privacy Act reforms

Proposed privacy law changes in Australia would expand individual rights, strengthen digital identity protections and require organizations to assess whether data handling is fair and reasonable in practice.

Contributors:
Adam Ford
Managing Director, Australia, New Zealand
IAPP
The release of the privacy reform consultation package by Australian Attorney-General's Department, outlining the details within the Privacy Amendment (Personal Data Protection) Bill 2026, marks the next major step toward a robust regulatory framework that is fit for purpose in the current modern digital age.
While public commentary has recently focused on AI-enabled smart glasses, the proposed right to erasure and new digital identity protections, a closer review of the consultation paper and exposure draft legislation reveals a much broader reform agenda. Collectively, the proposals signal a shift toward greater accountability, expanded individual rights and stronger expectations around responsible data use.
The Attorney-General's Department is seeking feedback from regulated entities, non-government organizations, consumer organizations, legal experts, privacy advocates and others on the proposed measures and how they would operate in practice. The consultation is open until 18 Sept.
The first tranche of Privacy Act updates were introduced in September 2024 and approved by the Parliament of Australia less than three months later. That package included new enforcement powers for the Office of the Australian Information Commissioner's privacy division, approval to establish an OAIC-drafted Children's Online Privacy Code, transparency requirements around automated decisions and a new statutory tort for individuals to use with emerging risks of "serious invasions of privacy."
Those amendments passed alongside separate legislation for Australia's social media ban for users under age 16.
Inside the new draft changes
Perhaps the most significant proposal within the consultation package is the introduction of a new fair and reasonable test for the collection, use and disclosure of personal information. If implemented, organizations will need to do more than simply rely on consent mechanisms and lengthy privacy notices. Instead, they will need to demonstrate that their handling of personal information is objectively fair and reasonable in the circumstances. This reform has the potential to fundamentally reshape privacy compliance, particularly for organizations deploying advanced analytics, digital marketing technologies, artificial intelligence systems and large-scale data processing environments.
From a practical perspective, the proposed test encourages organizations to consider a broader set of factors when assessing data handling activities, including the sensitivity of information involved, the reasonable expectations of individuals, the risks of harm that may arise and whether a particular collection or use is proportionate to the intended purpose. This reflects an emerging regulatory view that legality alone may not be sufficient. Increasingly, organizations are expected to demonstrate that their practices align with community expectations and can withstand objective scrutiny.
The significance of this shift becomes particularly clear when viewed through the lens of emerging technologies. AI-enabled smart glasses have become a prominent example because they combine unobtrusive data collection capabilities with increasingly sophisticated AI functionality. These devices raise important questions about consent, transparency, surveillance and biometric information. More broadly, they demonstrate how technological innovation can challenge privacy principles that were developed in a very different era.
The consultation package suggests future privacy regulation will focus less on individual technologies and more on whether the underlying collection and use of personal information is fair, reasonable and appropriately governed.
The proposed right to erasure further reinforces this policy direction. The reform would provide Australians with greater ability to request that certain organizations destroy personal information that is no longer required or that individuals no longer wish to have retained. Together with other transparency and accountability measures, this reflects a growing emphasis on individual autonomy and ongoing control over personal information. Privacy is increasingly being treated as a continuing relationship rather than a one-off interaction supported by a privacy notice.
Another important element of the reform package is the continued strengthening of identity protections. The proposed IDLock initiative would give Australians greater visibility and control over the use of identity credentials such as passports and driver's licenses. Following a number of high-profile cyber incidents and data breaches in recent years, policymakers are increasingly recognizing that privacy, cybersecurity and identity management are deeply interconnected disciplines. Providing individuals with practical tools to manage identity risks has the potential to improve trust while reducing opportunities for fraud and misuse.
The proposed reforms point toward a future where privacy considerations are embedded into product design, technology development, risk management and executive oversight processes. Privacy professionals, AI governance leads, security teams and business leaders will increasingly need to work together to assess emerging risks and ensure technologies are deployed responsibly.
The consultation package reinforces the importance of organizational accountability. Governance frameworks, privacy impact assessments, record keeping, transparency obligations and documented decision-making are all becoming more important indicators of compliance maturity. The regulator appears increasingly interested not only in outcomes, but also in the quality of decisions and processes that organizations establish before problems arise.

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEsContributors:
Adam Ford
Managing Director, Australia, New Zealand
IAPP



