By Malcolm Crompton and Chong Shao
The most significant update to the Privacy Act 1988 (Privacy Act) since the 2014 amendments has been unveiled by the Australian Government. It is coming amidst anxiety about emerging risks surrounding new technologies, including artificial intelligence and wearable devices such as smart glasses. Despite these specific concerns, the Privacy Amendment (Personal Data Protection) Bill 2026 (the ‘Exposure Draft’) is a technology-agnostic and principles-based upgrade to the ‘operating system’ of privacy regulation in Australia.
No doubt there will be a flurry of breakdowns and commentaries in the coming weeks (and IIS is sure to add our own contributions). Right now, we’d like to make three big picture observations, having witnessed various changes to the Privacy Act over the past quarter-century.
Many changes are evolutionary rather than revolutionary
Some of the more interesting things being proposed – including a broader definition of ‘personal information’; new rules for ‘trading’ of personal information; and an explicit definition of consent – are not completely new. For example:
Personal information has always extended beyond information associated with a person’s name; the new definition removes doubt, particularly in relation to technical and location data.
The Act already has a concept of ‘trading’ personal information (i.e., disclosing personal information for some benefit, service or advantage), buried in the small-business exemption. The Exposure Draft elevates it into a broader rule governing how organisations may trade personal information.
In the APP guidelines, the OAIC advises that consent must be voluntary, informed, current and specific. The Exposure Draft codifies these expectations and adds an explicit requirement that consent be unambiguous.
The new ‘fair and reasonable’ test is more complicated. On the surface, it brings together familiar concepts such as fairness, necessity and reasonable expectations. But the Exposure Draft does much more than add a new overarching safeguard: it replaces the existing APPs 3, 4 and 6 that have formed the core rules governing collection, use and disclosure of personal information, as well as substantially rewriting APP 5. That is a much more significant architectural change than the Privacy Act Review originally contemplated. IIS is still considering whether the new framework, taken as a whole, provides stronger or weaker protection than the one it replaces.
The ‘notice and consent’ model of privacy is finally dying, but …
Ever since Alan Westin’s seminal Privacy and Freedom in 1967, the way that we have thought about information privacy has been individualistic – tell people what is going on (notice) and give them choice over what occurs (consent). That thinking influenced the OECD Privacy Guidelines, which in turn became the basis of most privacy regimes around the world.
We now have decades of evidence that notice and consent works better in theory than in practice and has become even less effective in the digital age. ‘Consent fatigue’ – the sense of mental exhaustion and helplessness people feel from constantly having to read privacy notices, banners, pop-ups, and policies – is a real phenomenon.
The new APP 3 in the Exposure Draft marks a significant shift – APP entities must ensure that the collection, use and disclosure of personal information is fair and reasonable in the circumstances, having regard to seven factors [1]. Two of the factors (transparency and genuine choice) nod towards the existing regime, but they must be considered holistically alongside other factors such as reasonable expectations, relationship to an organisation’s function, privacy impact and data minimisation.
There is the potential – and we emphasise, only the potential – for this to be a genuine improvement for the protection of privacy while enabling organisations to achieve legitimate ends. However, our perennial observation is that ‘gaming the rules is one of the rules of the game’. The devil will be in the details of how this is operationalised – we have much more to say on this in future posts.
The stakes to privacy reform are high
The Exposure Draft is likely to mark the end of a reform journey that has been running for close to a decade – from the Productivity Commission’s 2017 Data Availability and Use report, through the ACCC’s 2019 Digital Platforms Inquiry, to the Privacy Act Review commenced in 2020 and finalised in 2023.
As privacy history buffs at IIS, we note that privacy law reform doesn’t come around very often. The Privacy Act has only undergone three major structural overhauls since it was enacted: the credit reporting provisions in 1990, the extension of the Act to the private sector in 2001, and the introduction of the Australian Privacy Principles in 2014 that replaced earlier sets of principles.
This may be the last serious opportunity to update the Privacy Act significantly for the next decade. The Attorney-General’s Department is currently taking submissions to ‘inform what the government considers when finalising reforms to strengthen privacy protections and ensure Australia’s privacy laws are fit for the digital age’.
Submissions are due in less than two weeks: 18 September! We encourage everyone to make their voices heard.
Here are a couple of questions worth pondering and answering:
Where might the proposed changes produce ambiguity, unintended consequences or disproportionate burdens when applied to real-world systems and business practices – and what would make them work better and be less ‘gameable’?
If this is the legislative settlement we may live with for the next decade, are there important gaps or unresolved issues that should be addressed now?
[1] The seven factors are:
(a) whether a reasonable person would expect the collection, use or disclosure in the circumstances;
(b) whether it relates to the entity’s functions or activities;
(c) how transparent the entity is about the means and purposes of the handling;
(d) whether the purpose could be achieved using less personal information, or information that is not personal information;
(e) whether the individual has genuine choice;
(f) the privacy impact and risk of harm, including whether these are proportionate to the benefits; and,
(g) where the individual is a child, the child’s best interests as a primary consideration.