Privacy Act tranche 2: what the exposure draft means for your business
COMPLIANCE

Privacy Act tranche 2: what the exposure draft means for your business

CyberCorp Australia
Cybersecurity & GRC Team
22 September 20269 min read

On 31 August 2026 the Attorney-General's Department released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, along with a consultation paper. It is the second tranche of reform to the Privacy Act 1988 (Cth), following the first tranche that received Royal Assent on 10 December 2024. Submissions closed on 18 September 2026.

This is a draft. The Department's own consultation page says the Bill "remains subject to further consideration by government", and no commencement date has been announced. What follows is a reading of the proposals as reported by the Department and by law firms that have analysed the draft. It is not a prediction of the final law and not legal advice. Organisations should seek legal advice for their specific position.

Even so, the direction is clear enough that privacy, security and technology teams can start preparing now. Most of the work the draft implies is work a well-governed organisation should be doing anyway.

What the draft proposes

MinterEllison and LK, both of which published summaries in September 2026, describe a broad package. The headline items are:

  • A single "fair and reasonable" test for collecting, using and disclosing personal information, replacing the current Australian Privacy Principles (APPs) 3, 4 and 6.
  • A wider definition of personal information, and new categories of sensitive information.
  • A higher standard for consent, and mandatory consent before personal information is traded.
  • A controller and processor framework modelled on the GDPR.
  • A right of erasure that applies to large digital platforms.
  • A 72-hour deadline for notifying the Office of the Australian Information Commissioner (OAIC) of an eligible data breach.

We take the parts that matter most for security and governance work in turn.

The fair and reasonable test

LK reports that the draft would remove APPs 3, 4 and 6 and replace them with one test: personal information may not be collected, used or disclosed unless doing so is lawful and fair and reasonable in the circumstances. The entity holding the data would have to weigh seven factors:

  • whether a reasonable person would expect the handling, judged objectively;
  • whether it relates to the entity's functions or activities;
  • how transparent the entity is about the means and purposes;
  • whether less information, or non-personal or de-identified information, would achieve the purpose;
  • whether the individual has a genuine choice;
  • the impact on the individual's privacy and any risk of harm, including proportionality;
  • where the individual is a child, the best interests of the child as a primary consideration.

MinterEllison notes that the factors are weighed together. No single factor decides the outcome, and not every factor has to be met. LK adds that, apart from limited exceptions, the test applies whether or not the individual has consented. Consent alone would not make a practice acceptable.

What this means for analytics, AI and marketing

The practical shift is from asking "did we tell people?" to asking "should we be doing this at all?". A privacy policy that discloses a practice would no longer settle the question.

Three uses of data are worth reviewing first.

  • Analytics and telemetry. The draft would change "about" an individual to "relates to" an individual. MinterEllison's reading is that IP addresses, device identifiers, cookie IDs and metadata logs, which have often sat outside the definition, are more likely to be caught, particularly where they can be linked to a person using other reasonably available information. Behavioural and advertising data may need to be brought inside your privacy framework.
  • AI systems. MinterEllison points out that businesses training models on data they treat as de-identified would need to test that assumption against the new definition, and that information an AI system infers or generates may itself be personal information. LK reports that the draft would treat information as "collected" even where the entity generates or derives it, including through AI, profiling or data analytics. Prompt records, transcripts and stored embeddings would also need to be located to meet the strengthened APP 11 duties on retention and destruction.
  • Marketing. LK reports that consent would be required before "trading" personal information, which covers selling it for money or other consideration and disclosures made for direct marketing purposes, subject to carve-outs. The draft would also replace APP 7 with a simplified direct marketing regime that requires an opt-out in every marketing communication.

None of these uses would be banned. The test asks whether the purpose could be met with less data, whether the person had a real choice, and whether the impact on them is proportionate. Those questions need documented answers.

Processors, vendors and contracts

Under the draft, as LK describes it, a controller is an APP entity on whose behalf a processor handles personal information. A processor acts on the controller's documented instructions and handles the information only for the purposes those instructions specify.

The liability split matters most. A processor acting within its instructions would not breach the APPs, other than APP 1 (open and transparent management) and APP 11 (security), for which it remains directly responsible. For anything else, the controller is treated as having done the act. A processor that steps outside its instructions loses that protection.

MinterEllison expects controllers to try to reverse this allocation by contract, since a controller that has issued only standard instructions could still be exposed to regulatory action for what its processor does. LK's advice is that controllers should not assume outsourcing moves their compliance obligations to the supplier.

For IT and procurement teams this turns vendor management into a privacy control. A useful first pass covers the following:

  1. List every supplier that handles personal information for you, including cloud, SaaS, HR, payroll and AI platforms.
  2. Check each contract for a written statement of what the supplier may do with the data, and for what purpose.
  3. Confirm that security obligations, breach notification timing and sub-processor controls are stated, not implied.
  4. Decide who carries the cost when a supplier acts outside its instructions.

72-hour breach notification

LK reports that the draft would require notification to the OAIC within 72 hours of becoming aware of reasonable grounds to believe an eligible data breach has occurred. The deadline is described as aligning with other incident reporting regimes, including the Security of Critical Infrastructure Act 2018 and the Cyber Security Act 2024.

Two details shape readiness. First, the current 30-day timeframe for assessing a suspected breach, where there are not yet reasonable grounds to believe it is an eligible breach, would not change. The 72-hour clock would start later, once that threshold is met. Second, an incomplete statement could be lodged first if a full one is impractical within 72 hours, with the rest supplied as soon as practicable.

The draft also proposes a broader defined term, "data breach", and new duties to take reasonable steps to prevent or reduce harm from any actual or suspected breach, and to maintain practices and systems that let the entity respond effectively. MinterEllison recommends reviewing response plans to account for both the lower-threshold concept and the 72-hour period.

The readiness gap

The gap is rarely the notification form. It is the time between first detection and a defensible decision that the "reasonable grounds" threshold has been met. Many organisations use most of the assessment window because their triage depends on people who are not on call, on logs that take days to retrieve, or on a vendor that reports slowly. Under a 72-hour rule, those delays stop being tolerable.

Questions to test against your last incident or tabletop exercise:

  • Who decides that reasonable grounds exist, and can they be reached at 2am?
  • How quickly can you establish which personal information was affected?
  • Do supplier contracts oblige vendors to tell you fast enough for you to meet your own deadline?
  • Can your team draft an incomplete but accurate statement from partial facts?

What the draft leaves out

LK observes that the exposure draft makes no mention of several recommendations from the Privacy Act Review. These include removing the small business exemption, which currently leaves most businesses with annual turnover of $3 million or less outside the Act, and removing the employee records exemption. LK also lists the appointment of privacy officers and prescribed privacy impact assessments as absent.

Absence from this draft is not abandonment. LK notes that the wider reform agenda may not be finished, so it is unwise to assume these exemptions are permanent.

The right of erasure in the draft is limited to large digital platforms, which LK reports as those with gross revenue of at least $500 million or at least 2.5 million average monthly Australian end-users. Most mid-market organisations would not be directly subject to it. They would still face the data minimisation duties in APP 11, which would require them to know what personal information they hold, consider destroying it once it is no longer needed, and regularly evaluate their security and destruction measures.

Separately, organisations should not lose sight of the 10 December 2026 deadline for disclosing automated decision-making in privacy policies, which LK also flags.

A 90-day readiness plan

Nothing here needs to wait for the Bill. Each step below improves your position under the current Act and would carry over if the draft passes in similar form.

Days 1 to 30: know what you hold

  • Build or refresh a data map covering personal information across systems, suppliers, analytics tools and AI platforms, including derived and inferred data.
  • Re-test data you treat as de-identified against the idea that it could be combined with other reasonably available information.
  • Record who owns each data set and how long it is kept.

Days 31 to 60: fix the contracts and the consent

  • Review supplier contracts for documented processing instructions, security duties, breach notification timing and sub-processor terms.
  • Review consent mechanisms and collection notices against the proposed standard: voluntary, informed, current, specific and unambiguous.
  • Identify any activity that could count as trading personal information or direct marketing, and check the consent behind it.
  • Run the seven factors against your three or four highest-risk uses of data and write down the reasoning.

Days 61 to 90: rehearse the breach

  • Update the breach playbook so that the decision point for "reasonable grounds" has a named owner and a target measured in hours, not days.
  • Prepare a template for an initial, incomplete notification.
  • Run a tabletop exercise that includes a supplier-caused incident, and measure the elapsed time to a notification decision.
  • Report the results, and the remaining gaps, to your risk committee or board.

Key takeaways

  • The Privacy Amendment (Personal Data Protection) Bill 2026 is an exposure draft released on 31 August 2026. It may change, and no commencement date has been announced.
  • The proposed fair and reasonable test applies even where consent has been given, so documented reasoning about purpose, data minimisation and impact would matter as much as notices.
  • A wider definition of personal information could bring analytics, telemetry and AI-derived data into scope.
  • The controller and processor model leaves most liability with the controller, which makes vendor contracts a privacy control.
  • A 72-hour OAIC notification window would leave little room for slow triage, and the 30-day assessment period for suspected breaches is reported to remain.
  • The draft does not touch the small business or employee records exemptions.
  • Data mapping, contract review, consent review and a rehearsed breach playbook are worth doing now. Seek legal advice for your specific position.

CyberCorp's GRC specialists help Australian organisations turn proposed privacy obligations into practical controls, from data mapping and supplier reviews to breach response readiness. Schedule a GRC Assessment to see where your organisation stands, or learn more about our Compliance Assurance services.

Back to Insights