Privacy reform: key areas for APP entities to review now
Introduction
The Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026[1] (Exposure Draft Bill) and accompanying consultation paper[2], released by the Attorney-General[3], propose further changes to the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs).
The Exposure Draft Bill represents “Tranche 2” of the Privacy Act reforms, following the reforms from “Tranche 1”, including a new statutory privacy tort, and automated decision-making transparency obligations.
For APP entities, the reforms would require a closer review of how customer information is collected, used, disclosed, secured and managed across the business. The Exposure Draft Bill remains subject to consultation which closes on 18 September 2026, and the Government aims to introduce the legislation to Parliament by the end of 2026. It points to a shift towards substance: how information handling operates, how it affects customers, and whether the objective could be achieved in a less privacy-intrusive way.
This article focuses on the changes most likely to require review by businesses that are subject to the APPs (APP entity[4]). It looks at how the reforms may affect data governance, customer communications, outsourced handling, information security, access requests and data breach response.
1. What the Exposure Draft Bill covers
The Exposure Draft Bill is broad. It would amend core concepts that determine when the Privacy Act applies, including personal information, sensitive information, collection, disclosure, consent and de-identified information. A central proposal is a prohibition on collecting, using or disclosing personal information unless the handling is fair and reasonable in the circumstances, and lawful.
The package also includes changed collection notice requirements, revised direct marketing rules, changes to access requests, strengthened information security and destruction obligations, revised data breach response and notification requirements, and proposed controller and processor concepts.
2. Key areas to review now
The immediate task is to identify which practices and arrangements are most likely to need review if the Exposure Draft Bill proceeds. For many APP entities, relevant areas may include data governance, customer communications, outsourcing, security, access requests and breach response.
Information within privacy governance
The proposed definition of personal information should be an early focus. Under the Exposure Draft Bill, personal information would mean information or an opinion that relates to an identified or reasonably identifiable individual, replacing the current test of whether it is information or an opinion about that individual. Sensitive information would also be expanded to include precise geolocation tracking data and an express reference to genomic information that relates to an individual.
APP entities should identify information that may fall more clearly within the proposed definition of personal information, including information held outside traditional customer records, such as portal or app data, transaction or service-use data, marketing analytics, call recordings and information generated through digital channels. If that information relates to an identified or reasonably identifiable individual, it should be brought within the entity’s privacy compliance framework.
Fair, reasonable and lawful information handling
The current APPs regulate collection under APP 3, unsolicited personal information under APP 4, and use and disclosure under APP 6. The Exposure Draft Bill would replace that structure with a new APP 3, which would prohibit the collection, use or disclosure of personal information unless the handling is fair and reasonable in the circumstances, and lawful.
In determining whether a practice is fair and reasonable in the circumstances, an APP entity would need to have regard to factors set out in the proposed new APP 3, including:
- whether a reasonable person would expect the collection, use or disclosure;
- whether the collection, use or disclosure relates to the entity’s functions or activities;
- whether the entity is transparent about the means and purposes of collection, use or disclosure;
- whether the same purpose could be achieved by using less information or non-personal information;
- whether the individual has been provided with genuine choice in relation to the collection, use or disclosure of the information;
- the privacy impact and risk of harm to the individual, including whether those risks are proportionate to the benefits of the practice;
- if the information relates to a child, the best interests of the child as a primary consideration.
Under the current APPs, reasonable expectations are mainly relevant when assessing whether personal information may be used or disclosed for a related secondary purpose under APP 6. The connection between the information handling and the entity’s functions or activities is also already relevant to collection under APP 3. Under the Exposure Draft Bill, those concepts would remain relevant, but would operate within a broader fair and reasonable test that applies to collection, use and disclosure.
A use of personal information may be easier to justify where it is necessary to provide a requested product or service, meet a legal or regulatory obligation, verify a customer’s identity, prevent fraud, maintain security, or protect a customer from harm. It may require closer scrutiny where the customer would not expect it, the benefit mainly accrues to the APP entity, the practice may materially affect the customer, or the same purpose could be achieved in a less privacy-intrusive way.
Collection notices: what customers must be told
APP 5 currently prescribes a list of matters that must be addressed in a privacy collection notice. The Exposure Draft Bill would change the formulation of what must be notified by requiring notification of the fact and circumstances of collection, and the purposes for which the entity intends to use or disclose the information. It would also require the notification to be in clear and plain language, readily understandable by the individual, up-to-date and concise.
This would move APP entities away from simply working through the current APP 5 list. APP entities would need a clear view of why, when and how information is collected, used and disclosed, so they can explain those matters plainly and keep notices current as products, channels, data uses and third-party arrangements change.
Consent and trading personal information
The proposed definition of consent would require consent to be voluntary, informed, current, specific and unambiguous. The proposed APP 4 would require consent to collect sensitive information and to “trade” personal information, unless an exception applies. “Trade” would include disclosing personal information for money or other consideration, or for direct marketing purposes.
This would make broad, bundled or unclear consent less defensible. APP entities should identify where they rely on consent and assess whether it is specific to the relevant information, purpose, channel and customer choice. They should also consider whether the wording and presentation give the customer a genuine opportunity to understand and agree to the handling.
Direct marketing
The reforms propose to recast APP 7 and define “direct marketing” as the communication of advertising or marketing material to an individual, where the individual is selected, identified or otherwise targeted, whether as an individual or as a member of a class, for receipt of that material using personal information that relates to the individual. APP entities may need to test how an audience, segment or cohort is built and what personal information is used to include or exclude customers from it.
The opt-out obligations would be retained and would apply to the organisation that makes the direct marketing communication. That organisation would need to take reasonable steps to give effect to an opt-out request and ensure information about how to opt out is clear, concise, up to date and written in plain language that is readily understandable by an ordinary person.
The revised APP 7 would also recognise “ad-supported services” — services where making direct marketing communications to users is itself a revenue source. This may matter for some digital services that earn revenue from delivering targeted direct marketing, rather than from selling the products or services being marketed. If a user opts out, different service terms may be offered only if the user still has a genuine choice to keep using the service without direct marketing.
APP entities should assess whether their opt-out processes would meet the revised APP 7 obligations if the reforms proceed, and which communications would fall within the direct marketing requirements. This means reviewing how marketing is targeted, including the data inputs, targeting logic, communication ownership and preference settings used to include, exclude or target customers.
Outsourced data handling and responsibility
The reforms would introduce “controller” and “processor” concepts to help allocate responsibility for APP compliance where one APP entity handles personal information on behalf of another. The policy intent is that primary responsibility should generally rest with the entity that determines the purposes for which the information is handled.
The consultation paper describes a “controller” as the APP entity on whose behalf a processor handles personal information. A “processor” is an APP entity that acts on behalf of a controller, in accordance with documented instructions and only for the purposes specified in those instructions.
APP entities would need to identify who determines the purposes for which personal information is handled, what documented instructions apply, and whether another entity acts only for those specified purposes. Where a processor acts in accordance with those instructions, its acts are taken to be acts of the controller. Processors would remain directly responsible for APP 1 and APP 11.
If the proposals proceed, APP entities may need to review outsourced arrangements for identity verification, marketing, lead generation, platform administration, data analytics and other third-party technology or operational services.
Information security, destruction and ongoing evaluation
The package would make APP 11 more specific on information security, destruction and de-identification. APP 11 would continue to require reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. Those steps would include technical and organisational measures[5].
Where an APP entity no longer needs personal information, it would need to consider whether to destroy it, and take reasonable steps to either destroy it or ensure it is de-identified. Under the Exposure Draft Bill, information would be “de-identified” if, at the relevant time or in the relevant circumstances, it has ceased to relate to an identifiable individual or an individual who is reasonably identifiable.
The revised APP 11 would also require APP entities to identify the personal information to which APP 11 applies and regularly evaluate whether their security, destruction and de-identification measures remain effective. The consultation paper explains that security measures and information handling practices may become less effective as technologies, business practices and privacy risks evolve.
Organisational measures would be central to complying with the revised APP 11. Information security is not a technology issue alone. APP entities should consider whether their policies, processes and controls support the steps required under APP 11, whether they operate across relevant products, channels and systems, and whether they remain effective for the entity’s operating model.
Access requests and technical feasibility
The Exposure Draft Bill would also amend APP 12 by recognising that access requests may be refused where, despite reasonable steps, giving access remains unreasonable or impracticable because of technical impossibility or infeasibility. APP entities would need to assess where customer information is held, how readily it can be retrieved, and what operational or system constraints may affect their ability to respond to access requests.
Data breach response
The notifiable data breach changes would compress the timeline of notification decisions. Under the current regime, an entity that suspects an eligible data breach must conduct a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days. The Exposure Draft Bill would add a more immediate obligation: where an APP entity is aware of reasonable grounds to believe an eligible data breach has occurred, it would need to give a statement to the Information Commissioner within 72 hours containing the required information. Staged reporting would be available where it is impossible or impracticable to provide all required information within that period.
Breach response procedures need to support prompt escalation, legal assessment, containment, harm reduction, third-party coordination and notification decision-making. APP entities would need to assess a suspected breach quickly enough to identify whether the 72-hour statement obligation has been triggered.
What APP entities should do before the Bill is finalised
The Exposure Draft Bill would encourage a more mature privacy compliance model. The issue is not only whether policies and systems are up to date. APP entities also need an organisational view of whether they can explain and defend how personal information is handled across the business.
The proposed fair and reasonable test is the clearest example of that shift, but the same judgement-based approach runs through collection notices, direct marketing, outsourcing, security, access requests and breach response.
Readiness work should focus on building privacy practices that can be explained and evidenced. That means identifying where judgement will be required, who owns those decisions, and which existing practices may need to change. APP entities that start that work now will be better placed to respond when the final Bill is settled, and to show boards, regulators and customers that personal information is handled with care, accountability and proper oversight.
Please contact us if you would like to discuss what the proposed privacy reforms may mean for your business.
| Contact Us | Our Expert Team | Our Training |
Author: Iona Luke (Special Counsel)
[1] https://consultations.ag.gov.au/rights-and-protections/privacy-reform/user_uploads/exposure-draft-bill-2026.pdf
[2] https://consultations.ag.gov.au/rights-and-protections/privacy-reform/user_uploads/consultation_paper.pdf
[3] Privacy Reform – Consultation on Exposure Draft legislation – Attorney-General’s Department – Citizen Space
[4] In this article, “APP entity” is used to refer to organisation that is subject to the APPs under the Privacy Act.
[5] For more on why information security requires organisational measures as well as technical controls, see our recent article.
