Viewing entries tagged
Notice and consent

Beyond notice and consent: Three reflections on Australia's privacy reforms

Comment

Beyond notice and consent: Three reflections on Australia's privacy reforms

By Malcolm Crompton and Chong Shao

The most significant update to the Privacy Act 1988 (Privacy Act) since the 2014 amendments has been unveiled by the Australian Government. It is coming amidst anxiety about emerging risks surrounding new technologies, including artificial intelligence and wearable devices such as smart glasses. Despite these specific concerns, the Privacy Amendment (Personal Data Protection) Bill 2026 (the ‘Exposure Draft’) is a technology-agnostic and principles-based upgrade to the ‘operating system’ of privacy regulation in Australia.

No doubt there will be a flurry of breakdowns and commentaries in the coming weeks (and IIS is sure to add our own contributions). Right now, we’d like to make three big picture observations, having witnessed various changes to the Privacy Act over the past quarter-century.

Many changes are evolutionary rather than revolutionary

Some of the more interesting things being proposed – including a broader definition of ‘personal information’; new rules for ‘trading’ of personal information; and an explicit definition of consent – are not completely new. For example:

  • Personal information has always extended beyond information associated with a person’s name; the new definition removes doubt, particularly in relation to technical and location data.

  • The Act already has a concept of ‘trading’ personal information (i.e., disclosing personal information for some benefit, service or advantage), buried in the small-business exemption. The Exposure Draft elevates it into a broader rule governing how organisations may trade personal information.

  • In the APP guidelines, the OAIC advises that consent must be voluntary, informed, current and specific. The Exposure Draft codifies these expectations and adds an explicit requirement that consent be unambiguous.

The new ‘fair and reasonable’ test is more complicated. On the surface, it brings together familiar concepts such as fairness, necessity and reasonable expectations. But the Exposure Draft does much more than add a new overarching safeguard: it replaces the existing APPs 3, 4 and 6 that have formed the core rules governing collection, use and disclosure of personal information, as well as substantially rewriting APP 5. That is a much more significant architectural change than the Privacy Act Review originally contemplated. IIS is still considering whether the new framework, taken as a whole, provides stronger or weaker protection than the one it replaces.

The ‘notice and consent’ model of privacy is finally dying, but …

Ever since Alan Westin’s seminal Privacy and Freedom in 1967, the way that we have thought about information privacy has been individualistic – tell people what is going on (notice) and give them choice over what occurs (consent). That thinking influenced the OECD Privacy Guidelines, which in turn became the basis of most privacy regimes around the world.

We now have decades of evidence that notice and consent works better in theory than in practice and has become even less effective in the digital age. ‘Consent fatigue’ – the sense of mental exhaustion and helplessness people feel from constantly having to read privacy notices, banners, pop-ups, and policies – is a real phenomenon.

The new APP 3 in the Exposure Draft marks a significant shift – APP entities must ensure that the collection, use and disclosure of personal information is fair and reasonable in the circumstances, having regard to seven factors [1]. Two of the factors (transparency and genuine choice) nod towards the existing regime, but they must be considered holistically alongside other factors such as reasonable expectations, relationship to an organisation’s function, privacy impact and data minimisation.

There is the potential – and we emphasise, only the potential – for this to be a genuine improvement for the protection of privacy while enabling organisations to achieve legitimate ends. However, our perennial observation is that ‘gaming the rules is one of the rules of the game’. The devil will be in the details of how this is operationalised – we have much more to say on this in future posts.

The stakes to privacy reform are high

The Exposure Draft is likely to mark the end of a reform journey that has been running for close to a decade – from the Productivity Commission’s 2017 Data Availability and Use report, through the ACCC’s 2019 Digital Platforms Inquiry, to the Privacy Act Review commenced in 2020 and finalised in 2023.

As privacy history buffs at IIS, we note that privacy law reform doesn’t come around very often. The Privacy Act has only undergone three major structural overhauls since it was enacted: the credit reporting provisions in 1990, the extension of the Act to the private sector in 2001, and the introduction of the Australian Privacy Principles in 2014 that replaced earlier sets of principles.

This may be the last serious opportunity to update the Privacy Act significantly for the next decade. The Attorney-General’s Department is currently taking submissions to ‘inform what the government considers when finalising reforms to strengthen privacy protections and ensure Australia’s privacy laws are fit for the digital age’.

Submissions are due in less than two weeks: 18 September! We encourage everyone to make their voices heard.


Here are a couple of questions worth pondering and answering:

  • Where might the proposed changes produce ambiguity, unintended consequences or disproportionate burdens when applied to real-world systems and business practices – and what would make them work better and be less ‘gameable’?

  • If this is the legislative settlement we may live with for the next decade, are there important gaps or unresolved issues that should be addressed now?


[1] The seven factors are:

(a) whether a reasonable person would expect the collection, use or disclosure in the circumstances;

(b) whether it relates to the entity’s functions or activities;

(c) how transparent the entity is about the means and purposes of the handling;

(d) whether the purpose could be achieved using less personal information, or information that is not personal information;

(e) whether the individual has genuine choice;

(f) the privacy impact and risk of harm, including whether these are proportionate to the benefits; and,

(g) where the individual is a child, the child’s best interests as a primary consideration.

Comment

Privacy Act review: A closer look at the fair and reasonable test

Privacy Act review: A closer look at the fair and reasonable test

By Natasha Roberts

In this post, we take a closer look at the ‘fair and reasonable test’ – a proposal in the recent review of the Privacy Act 1988 (Cth) (Privacy Act) which the Government ‘accepted in principle’. In our view, the introduction of a fair and reasonable test to the Privacy Act is welcome and has the potential to rebalance the Privacy Act away from personal responsibility (‘Well, you consented so it’s on you if your privacy was impacted’) and towards organisational responsibility (‘We, the organisation, agree to handle this personal information fairly and reasonably’).

What was the problem the Review was trying to address?

Notice and consent have become less effective over time

Notice and consent are often held up as critical elements of privacy law. They are there to ensure transparency and individual choice when it comes to the handling of personal information. Under Australian Privacy Principle (APP) 5, individuals must be told certain information when their personal information is collected including the purpose of collection (notice) and must, in most cases, under APP 6 be asked for permission before the information is used or disclosed for secondary or unrelated purposes (consent).

There’s no doubt that notice and consent will continue to play an important role in the Privacy Act. Indeed, privacy laws the world over include notice and consent as baseline principles. The problem is that over time, notice and consent have become less effective to about the same degree that personal information handling has become more complex and privacy-invasive.

Information handling has become more invasive over time

When the Privacy Act was first introduced in 1988, we lived in a largely paper-based world in which data handling was constrained by practical limitations like the inability to make use of large amounts of hardcopy information and the expense of storing it. There was no information economy in the sense we understand today. And there was no incentive for organisations to collect excess amounts of personal information or to repurpose the information for other (profit-raising) activities. It is possibly for this reason that the Privacy Act contains virtually no restriction on the ‘primary purposes’ for which organisations may use and disclose personal information.

You can see how today – in an environment that rewards data innovation, accumulation and reuse – personal information handling may expand into increasingly privacy-invasive areas – areas that were unanticipated in 1988 or indeed even in 2012 when the APPs were introduced to replace earlier principles.

This creates two pain points for privacy law

The first pain point is that the legislation has inadequate brakes available for unethical or privacy-invasive data handling activities. It simply did not need those brakes before. If an organisation collects personal information for the primary purpose of profiling children and selling such information to other businesses, for example, APP 6 would seem to permit this. Submissions to the Privacy Act review also pointed out that organisations have significant discretion in determining whether a collection is ‘reasonably necessary’ for their functions and activities under APP 3.

The second pain point is that data handling has become much more complex in recent decades and this has significant implications for the operation of informed consent. How can an individual be adequately informed if you need a degree in data science to fully grasp what is going to happen to your information? In other comparable settings, we do not expect individuals to have subject-matter expertise. We do not, for example, demand that airline passengers read lengthy statements about aeronautics and safety testing and then ‘consent’ to fly on a certain type of aircraft. Of course, passengers should not have to bear risk or responsibility for aircraft safety. Nor should they have the ‘choice’ to fly on risky, poorly-maintained aircraft. We are at a point now where the same principles should apply to data handling.

You might think that the difficulty of obtaining informed consent in these circumstances would cause a natural shift away from reliance on consent for data processing. Well, you would be wrong. As data processing has become more complex, consent notices have become prevalent, along with being longer and more technical.

Thankfully the Privacy Act Review Report recognised this, noting that ‘where digital innovation is exponentially increasing the amount of personal information and sources from which it is collected, it is not reasonable that individuals should bear primary responsibility for ensuring that they do not experience harm as a result of an entity’s information-handling practices.’ It also noted that ‘the diversity, change and novelty in digital information-handling practices may mean that individuals do not appreciate the scale, or even the existence, of privacy risks.’

How did the Review propose to address this problem?

Enter the fair and reasonable test

To address these obvious shortcomings in the current regulatory approach, the Review Report proposed that the Privacy Act be amended to introduce a requirement that the collection, use and disclosure of personal information be fair and reasonable in the circumstances. In applying this ‘fair and reasonable test,’ the Review Report proposed that certain matters be taken into account, including:

  • Whether an individual would reasonably expect the personal information to be collected, used or disclosed in the circumstances

  • The kind, sensitivity and amount of personal information being collected, used or disclosed

  • Whether the collection, use or disclosure is reasonably necessary for the functions and activities of the organisation or is reasonably necessary or directly related for the functions and activities of the agency

  • The risk of unjustified adverse impact or harm

  • Whether the impact on privacy is proportionate to the benefit

  • If the personal information relates to a child, whether the collection, use or disclosure of the personal information is in the best interests of the child, and

  • The objects of the Act.

Perhaps, most importantly, the Review Report specifically proposed that the fair and reasonable test apply irrespective of whether consent has been obtained. Our hope is that, in the future, it will be harder for individuals to ‘consent away’ their rights to fair and reasonable information handling.

What are the key takeaways for my organisation?

Privacy law reform is still ongoing, therefore this in an area on which to maintain a watching brief. That said, there is nothing to stop you from reviewing the bullets listed above and assessing your personal information handling activities against those standards. We suggest:

  • Maintaining a watching brief on privacy law reform to see how the fair and reasonable test is implemented in practice.

  • Engaging in consultation processes associated with Privacy Act reform – the Government has committed to further consultation on the fair and reasonable test and there is likely to be opportunities to comment on bill exposure drafts.

  • Taking the time to review the fair and reasonable factors listed above to see how they apply to your information handling practices – aside from anything else, they offer a baseline for fair and reasonable collection, use and disclosure of personal information.

  • Considering the fair and reasonable factors listed above in any privacy impact assessment or product development process.