
The Australian Government has released an Exposure Draft of the Privacy Amendment (Personal Data Protection) Bill 2026 and a detailed Consultation Paper for the second tranche of Privacy Act reform, following the first tranche of amendments passed in December 2024. The package contains roughly 40 proposals and would significantly reshape the way organisations collect, use, disclose, secure, retain and destroy personal information.
For the InfoGovANZ community, the most important point is that these reforms go directly to enterprise information governance: what personal information an organisation holds, why it holds it, where it is located, how long it is retained, whether it remains necessary, how its security is tested, and how quickly the organisation can respond when a breach occurs.
| Consultation closes 18 September 2026
The consultation period is short. The Attorney-General’s Department is seeking feedback on how the proposed measures would operate in practice, including operational and compliance impacts. |
The Reforms at a glance
A new overarching fair and reasonable test for the collection, use and disclosure of personal information.
- Modernised core definitions, including personal information, reasonably identifiable, sensitive information, de-identified information, collection, disclosure and consent.
- Stronger consent requirements, including consent for trading personal information, subject to exceptions.
- A simplified direct marketing framework, including clearer opt-out requirements and rules for targeted and behavioural advertising.
- Major changes to the Notifiable Data Breaches scheme, including a 72-hour notification period to the OAIC once an entity has reasonable grounds to believe an eligible data breach has occurred.
- Strengthened APP 11 obligations covering security, identification of personal information, destruction or de-identification, and regular evaluation of compliance effectiveness.
- A right to request erasure of personal information held by large digital platforms, subject to exceptions.
- A new controller and processor framework allocating primary responsibility for many APP obligations while preserving direct processor responsibility for APP 1 and APP 11.
- Changes to privacy complaint handling and stronger OAIC case management and enforcement arrangements.
- Further measures under development for emerging technologies, including wearable surveillance technologies and connected vehicles.
1. Fair and reasonable handling becomes the central test
The Exposure Draft would restructure the existing APP 3, 4 and 6 structure with a single principles-based requirement. An APP entity must not collect personal information, or use or disclose personal information it holds, unless the handling is both fair and reasonable in the circumstances and lawful.
The proposed test requires entities to consider a set of legislated factors. These include reasonable expectations, whether the handling relates to the entity’s functions or activities, transparency, data minimisation, genuine choice, the privacy impact and risk of harm, proportionality, and, for children, the best interests of the child as a primary consideration.
Why this matters for information governance. The test would move privacy compliance further away from a narrow notice-and-consent model. An organisation will need to be able to justify its information handling in context. Importantly, the test embeds data minimisation. Entities must consider whether the same purpose could be achieved with less personal information, or without personal information at all. This creates a stronger governance imperative to understand purpose, necessity, information flows and downstream reuse across the information lifecycle.
| Governance implication
Privacy policies alone will not make a practice fair and reasonable. Organisations will need evidence that their information practices are necessary, proportionate, transparent and appropriately controlled. |
2. APP 11: a major shift from security obligation to lifecycle accountability
For the InfoGovANZ community, the proposed APP 11 amendments are among the most significant reforms in the package. APP 11 would be reframed as Australian Privacy Principle 11, “security and destruction of personal information”, and would impose clearer positive obligations across the information lifecycle.
- Identify the personal information subject to APP 11. An entity must take the steps needed to identify the personal information to which the security and destruction requirements apply.
- Protect personal information through reasonable security measures, preserving the existing requirement to protect against misuse, interference, loss and unauthorised access, modification or disclosure.
- Consider destruction first when personal information is no longer needed for any permitted purpose, then take reasonable steps to destroy it or ensure it is de-identified.
- Regularly evaluate the effectiveness of APP 11 compliance, including security controls, destruction and de-identification measures, and whether de-identified information remains appropriately protected against re-identification.
This is a substantial information governance development. The proposed law effectively requires organisations to know what personal information they hold before they can demonstrate that it is properly protected or disposed of. That brings information inventories, information asset registers, classification, retention and disposal programs, data mapping, legacy system remediation and assurance testing directly into the privacy compliance framework.
It also strengthens the case for regular defensible disposal. Retaining information merely because storage is inexpensive, or because it may be useful one day, becomes increasingly difficult to reconcile with a statutory obligation to consider destruction when the information is no longer needed.
| Priority action for organisations
Assess whether you can reliably identify where personal information is held, link it to a lawful and current purpose, apply retention rules, and demonstrate that security and disposal controls are regularly tested for effectiveness. |
3. Data breaches: positive response duties and 72-hour OAIC notification
The proposed changes to the Notifiable Data Breaches scheme are also significant. The reforms distinguish a “data breach” from an “eligible data breach”, so obligations to manage and contain a breach may apply even where the serious harm threshold for notification is not met.
- Entities would have an express obligation to implement practices, procedures and systems that enable an effective response to actual or suspected data breaches.
- Entities would have a positive and ongoing obligation to take reasonable steps to prevent or reduce harm arising from a breach.
- Once an entity has reasonable grounds to believe an eligible data breach has occurred, it would have 72 hours to notify the Information Commissioner.
- If a complete statement cannot practicably be provided within 72 hours, an incomplete statement may be lodged, with outstanding information supplied later.
- Notifications would include information about steps already taken or proposed to reduce harm to affected individuals.
- Material errors or material changes in information previously given to the Commissioner would need to be corrected as soon as practicable.
- The existing 30-day period for assessing a suspected eligible data breach remains where an entity has grounds to suspect, but not yet grounds to believe, that an eligible breach has occurred.
Operationally, this raises the bar for breach readiness. Organisations will need clear escalation thresholds, tested response plans, rapid access to reliable information about affected systems and data, and established decision-making responsibilities. The 72-hour period starts when there are reasonable grounds to believe an eligible breach has occurred, so delays in internal escalation or uncertainty about data holdings can create immediate compliance risk.
4. Other changes InfoGovANZ members should watch
Broader definition of personal information. The definition would move from information “about” an individual to information that “relates to” an identified or reasonably identifiable individual. The draft also recognises that identifiability may arise by combining information with other information reasonably available to the entity, and that de-identification is not a fixed state.
Derived and inferred information. The proposed collection concept expressly addresses information generated or derived from other personal information. This is particularly relevant to analytics, profiling and AI systems that infer characteristics, preferences, risks or other attributes.
Consent and trading personal information. Consent would need to be voluntary, informed, current, specific and unambiguous. Organisations would generally need consent before trading personal information, with “trade” intended to capture disclosures for monetary or other consideration and disclosures for direct marketing purposes, subject to specified carve-outs.
Direct marketing and online advertising. The proposed framework is technology-neutral and captures targeted advertising and online behavioural advertising based on personal information, including browsing history. It retains a simple opt-out requirement and provides specific rules for ad-supported services.
Controllers and processors. A new framework would recognise processor relationships where an APP entity handles personal information on behalf of another APP entity in accordance with documented instructions. Primary responsibility for many APP obligations would sit with the controller, but processors would remain directly responsible for APP 1 and APP 11. The need for documented instructions will make contractual governance and supplier oversight especially important.
Right to erasure for large digital platforms. The Bill proposes a right for individuals to request erasure of personal information held by large digital platforms, rather than a general economy-wide right to erasure. The proposal includes exceptions, including where compliance is technically impossible or infeasible.
Complaints and OAIC enforcement. The consultation proposes stronger complaint-handling requirements, including accessible complaint mechanisms, responses within 60 days and written decisions setting out the outcome and review options. It also proposes measures to improve the OAIC’s case management and enforcement powers.
What organisations should be doing now
The Bill is an exposure draft and the final legislation may change. Even so, the direction of travel is clear. Organisations should use the consultation period to assess whether their current information governance arrangements can support the obligations being proposed.
- Map personal information holdings and flows, including data held in SaaS platforms, cloud services, archives, shared drives and legacy systems.
- Review whether collection, use and disclosure practices can be justified as fair and reasonable, including whether less personal information could achieve the same purpose.
- Review retention and disposal rules and identify areas of unnecessary or indefinite retention.
- Test whether personal information can be identified and located quickly enough to support APP 11 compliance, access requests and breach response.
- Review and test data breach response plans, escalation pathways and the ability to meet a 72-hour OAIC notification period.
- Review processor and service-provider arrangements, documented instructions, security responsibilities and access to breach information.
- Consider the effect of broader personal information and derived-information concepts on analytics, profiling and AI systems.
- Prepare for stronger evidence-based assurance, rather than relying on policy documentation alone.
Official consultation materials
- Consultation hub: Privacy Reform – Consultation on Exposure Draft legislation(opens in new tab)
- Consultation Paper: Privacy Reform – Consultation Paper (PDF)(opens in new tab)
- Exposure Draft legislation: Privacy Amendment (Personal Data Protection) Bill 2026 – Exposure Draft (PDF)(opens in new tab)
- Attorney-General’s announcement: Modernising Australia’s privacy laws for the digital age(opens in new tab)
InfoGovANZ submission
InfoGovANZ will prepare a submission on the proposed reforms, with a particular focus on their practical implications for information governance, privacy, data security, records and information management, AI and organisational assurance.
If you would like to be involved in the InfoGovANZ submission, please email infogovanz@infogovanz.com or susna.bennett@infogovanz.com.