Written by: Haim Ravia, Dotan Hammer
The Australian Attorney-General has released a consultation paper accompanying the draft Privacy Amendment (Personal Data Protection) Bill 2026, a proposal to reform the Australian Privacy Act. The package comprises approximately 40 proposals: 25 that strengthen privacy safeguards, 5 that clarify and simplify existing obligations, 4 further measures reducing unnecessary compliance burdens, and 7 measures intended to enhance the efficiency of the Office of the Australian Information Commissioner. Emerging technologies are addressed expressly, including wearable surveillance devices and connected vehicles.
Schedule 1 of the draft Bill modernizes the foundational concepts of the Privacy Act 1988, including personal information, sensitive information, de-identification, consent and disclosure. Schedule 2 contains the structural change: it replaces the existing layered obligations with a single “fair and reasonable” test for the collection, use and disclosure of personal information, supported by legislated factors including the individual’s reasonable expectations, data minimization and genuine choice. This is a deliberate shift away from consent as the organizing principle of the current statute.
Schedule 3 strengthens data breach requirements, including a 72-hour notification period to the Information Commissioner aligned with Australia’s critical infrastructure framework. Schedule 4 introduces access exceptions where compliance is technically impossible and creates a right of erasure exercisable against large digital platforms meeting specified revenue or user thresholds — a platform-specific right without a direct analogue in the GDPR. Schedule 5 consolidates the currently fragmented health and medical research exceptions into a unified framework aligned with the Australian National Statement on Ethical Conduct in Human Research.
Click here to read the Australian Attorney-General’s consultation paper proposing to reform the Australian Privacy Ac