By Chong Shao
IIS published our initial reflections on the Exposure Draft of the Privacy Amendment (Personal Data Protection) Bill 2026 (the ‘Exposure Draft’), shortly after its release. We saw much that was evolutionary rather than revolutionary, and welcomed the attempt to place greater responsibility on organisations to justify how they handle personal information. We also flagged a harder question: whether the new ‘fair and reasonable’ framework would, taken as a whole, provide stronger privacy protection than the APPs it would replace.
As we prepared our submission for the Attorney-General’s Department’s consultation – published here – our thinking has sharpened.
We remain supportive of the underlying objective of the privacy reforms. Privacy law should not depend too heavily on individuals protecting themselves through notices and consent mechanisms, and there is real value in requiring organisations to consider whether their information handling is substantively fair and reasonable. However, the Exposure Draft is making a significant structural change by replacing the established statutory constraints in APPs 3, 4 and 6 with a more discretionary balancing test. We unpack our concerns in the submission.
The implications may also extend well beyond the Privacy Act itself. The Children’s Online Privacy Code currently in development, the DATA Scheme under the Data Availability and Transparency Act 2022 and the Digital ID regime are just three examples of frameworks that rely, in different ways, on the existing APP architecture. Replacing core parts of that architecture will have consequences elsewhere. Those dependencies should be identified and worked through before the foundations are changed.