Helios Salinger

  • About
    • About Salinger Privacy – now Helios Salinger
    • Meet our team
    • Work with us
    • Videos, Podcasts and Media Mentions
    • Privacy Awareness Week
  • Consulting
    • Overview – Our Consulting Services
    • Privacy Impact Assessment
    • Privacy Maturity Assessment
    • Privacy by Design advice
    • Privacy Compliance and Gap Analysis
    • Algorithmic Impact Assessment
    • Re-identification Risk Assessment
    • Data ethics
    • Privacy Helpdesk
  • Training
    • Overview – Our Training Services
    • Privacy Compliance Training
    • Privacy Professionals Training
    • All Online Modules
    • Training Calendar
    • Public Courses and Workshops
    • In-house Privacy Training and Workshops
    • Webinars
    • IAPP Certifications
    • Training Advisory Services
    • Login
  • Resources
    • Overview – Our Resources
    • THE PRIVACY PULSE
    • Privacy Act Reforms
    • Compliance Kits
    • Resources on key privacy topics
    • Free Handbook
    • Newsletter
    • Login
  • Case Study
  • Blog
  • Calendar
  • Contact
  • Compliance Kits
    • For Business & Non-profits
    • For Peak Bodies
    • For Australian Government
    • For NSW Public Sector
    • For VIC Public Sector
    • For QLD Public Sector
    • For WA Public Sector
    • Login

Privacy law reform: weaving threads for a harmonious whole

September 7, 2026, Anna Johnston

Privacy reforms are on their way; here’s what you need to know.

On 31 August, Attorney General Michelle Rowland released an exposure draft Bill to reform the federal Privacy Act. She also released a consultation paper to accompany the Bill. This is the next stage in the long-running review of the Privacy Act which commenced in 2018, and which has already been through multiple public submission stages. 

While the Attorney General is calling for feedback on this draft exposure Bill, by setting a submission period of only a couple of weeks, she is sending a signal that she is ready to roll, so we could see the final Bill tabled in Parliament before the year’s end.

Now I don’t expect you to feel sorry for me, dear reader, but the timing of the exposure draft Bill’s release has somewhat interrupted my otherwise delightful holiday in Türkiye. While not offering as much relaxation as consuming a trashy legal thriller while sipping a cocktail by the hotel pool, reviewing the contents of the Bill has nonetheless proven an enjoyable experience.

In fact, my travels have provided me with the perfect metaphor to appreciate the draft Bill and its impacts. 

Having watched a demonstration of the creation of a traditional Turkish kilim rug, it occurs to me that the impact of these reforms, if passed, will provide us with a kilim: a thing of beauty, both visually harmonious and useful. Focusing on just one or two elements is not the way to look at this reform package; instead you need to step back and appreciate the overall pattern being created.

Kilims are created through the interlacing of warp and weft. The warp is the set of vertical threads lined up neatly within a frame. The weft brings the rug to life, as coloured skeins of wool are threaded horizontally, in and out of the warp, to create the pattern. Traditional kilims are painstakingly slow to create, but once complete, with all loose ends neatly knotted off, they should last for decades.

In much the same way, privacy jurisprudence is created slowly, with input from two directions, within a frame. Policy intent provides the frame. Legislation is the warp, while over time the Privacy Commissioner and courts provide the weft of colour, through case law, OAIC guidance and determinations. 

While we already have an existing rug in the form of the Privacy Act 1988, it is now terribly worn, and showing holes in places. The environment has changed since the old rug was created, and the 1988 design no longer suits our decor. Australians deserve a new rug.

The draft Bill released by the Attorney General, and the accompanying Consultation Paper which sets out the policy intent, will set us well on our way to creating a new rug. Recent OAIC determinations and guidance are ready and waiting, to complete the pattern. (And yes, just like creating a traditional kilim, it has been painstakingly slow to get us to this point.) But once these reforms have been passed and commenced, loose ends will have been tied off, and the rug will be complete. The end result should be harmonious and practical, for decades to come.

Few surprises 

The Bill does what it says on the box – by which I mean what the accompanying Consultation Paper describes as the intention: “to deliver three key outcomes: better privacy protections for Australians, greater certainty for businesses and other entities, and a stronger and more efficient privacy regulator”.

The general direction of the Bill is also much as expected, with most of the reform proposals previously flagged as part of the formal review of the Act. Also, many of the amendments are consistent with past guidance and determinations from the regulator, such that the overall effect of the Bill is to clearly set out in statute what successive Commissioners have said about how the existing Act should be interpreted in practice. It also feels like the legislative drafters have been busy tying up a bunch of loose threads, with sensible changes to definitions, and the addition of explanatory notes throughout.

Interestingly, the consultation paper also asks for feedback on topics where the policy direction is still a work in process: what else (if anything) is required to address the privacy issues arising from emerging technologies, such as connected vehicles and this month’s hot topic, smart glasses.

However overall there are not many surprises. Not a lot has changed in the nature of the proposed amendments from the set of reform proposals contained in the government’s final report in 2023.

What has changed is public sentiment, which is finally catching up to the arguments made by privacy advocates for years: that online tracking, profiling and targeting are driving a range of digital harms. The latest ACAPS results show that 78% of Australians don’t feel like they have real control over how their personal information is collected and used.

And where public sentiment goes, the pollies will surely follow. Not that long ago people like me talking about ‘algorithmic harms’ drew blank stares from politicians, but now they are falling over themselves to regulate Big Tech and online services. The PM is talking about allowing people to ‘block algorithms’ on social media, while a wide spectrum of MPs from the Greens to independent Senator Pocock and the Coalition are saying that the draft Bill doesn’t go far enough to protect privacy.

Meaningful privacy reform finally has political momentum behind it. Lobbyists hired by big businesses to push back against the reforms: save your breath. (Though it would appear that the small business lobby has successfully persuaded the government not to abolish the current exemption for small businesses just yet. This is a significant hole in the rug being created, which still needs fixing.)

The high-level view

So let’s take a high-level look at some of the different elements in the draft Bill. The Consultation Paper offers an excellent plain language outline of the proposed amendments, so I won’t rehash all the changes here. Instead, let’s step back and look at some emerging themes.

Pragmatic balancing acts

You can see the delicate dance that the Attorney General must perform, in order to satisfy the expectations of the Australian community to uplift privacy protections, without unduly burdening businesses in the process. Some of the solutions in the draft Bill demonstrate some nifty footwork from the policy-makers to resolve concerns raised during the Act Review process.

For example, the proposed new right to erasure will only apply to large digital platforms, rather than all regulated entities. That’s a smart compromise, delivering meaningful privacy protections where they matter, without creating a nightmare for everyone else.

Along similar lines, a new exception to the right of access will be created, in which an entity may refuse access if providing access is technically impossible or infeasible.

Navigating the core rules governing data flows will also become easier, with APPs 3 and 4 (collection) and 6 (use and disclosure) to be replaced with a single principle. Rules for direct marketing should also become clearer.

A processor and controller distinction will also be introduced. So long as both entities are regulated under the Privacy Act, an entity which is only handling personal information at the behest of another can be considered a ‘processor’. Processors only need to comply with APP 1 (transparency and accountability) and 11 (data security), while their ‘controller’ client remains liable for compliance with all APPs including the new ‘fair and reasonable’ test.

And, as mentioned, the Bill does nothing to abolish the current small business exemption. This is a missed opportunity.

Adieu ‘notice and consent’, hello ‘fair and reasonable’

The approach taken by some businesses to using and abusing our personal information could be summarised as ‘we gave you notice (somewhere you probably didn’t see it) and therefore we (will claim to) have your consent to do what we want with your data’.

The ‘notice and consent’ model of privacy regulation is ineffective and unfair. While successive Privacy Commissioners have pointed out in case determinations and written guidance that consent must be voluntary, informed, specific and current, bad practices remain.

This Bill provides the final nail in the coffin for the notice and consent model. Instead, almost all data handling practices must pass a ‘fair and reasonable’ test. (There are some public interest exceptions, which will be much as they exist now.) This new ‘fair and reasonable’ test will be applied with reference to a non-exhaustive list of factors to be considered, with the OAIC expected to flesh out more detail over time.

The Bill also makes clear that Privacy Policies and collection notices are not, by themselves, sufficient to justify data handling practices that may otherwise fall short of the new test. Offering customers a lengthy Privacy Policy which buries the devil in the detail will not serve to authorise said devilish data dealings, if they would not pass the ‘fair and reasonable’ pub test anyway. The Flight Centre ‘design jam’ showed us that simply including something in the Privacy Policy does not on its own permit the handling of that data.

As the Consultation Paper notes, “Transparency and reasonable expectations are related but distinct”: “While information handling is less likely to be reasonably expected if the individual is unaware of it, a practice does not necessarily become reasonably expected simply because it is described in a collection notice or privacy policy.”

On top of the ‘fair and reasonable’ test, some practices will also require consent to first be obtained, such as the collection of certain sensitive categories of data (the list of which will be expanded to also include genomic data and geolocation tracking data), and the trading of personal information.

A new definition of consent will also clarify that in order to be legally valid, the purported consent must be voluntary, informed, specific, current – and unambiguous.

Clarifying and strengthening the scope of the Act

The definition of ‘personal information’ will be amended much as previously flagged, including by the addition of an explanatory note. This amendment will clarify that an individual will be considered reasonably identifiable (and thus the data in question will constitute “personal information”, the handling of which is regulated under the Act) even if the name or legal identity of the individual is not known. Identifiability means that a person can be “recognised, singled out or otherwise treated as a distinct individual in practice”.

With this reform, entities conducting tracking, profiling and targeting at the individual level should no longer be able to argue that their data is out of scope of regulation just because they don’t know anyone’s real name. This reform is great news for anyone who cares about the protection of their privacy, or who is keen to wrest back some degree of control from our algorithmic overlords.

Tying up loose ends

The Bill imports into statute form many elements developed over time through case law and OAIC guidance. These include:

  • Generating or inferring information or opinion will constitute a ‘collection’
  • A collection of data which could in theory incidentally include or imply sensitive category data will only need to meet the stricter test for collecting sensitive information at the point in time when the risk is being realised (e.g. when the inference is being drawn and used)
  • Allowing a third party to access data is a ‘disclosure’, no matter where the data is located or the third party resides
  • De-identification is a temporary state, heavily dependent on both the treatment of the data and the environment in which it is held.

Support for public interest research 

The rationalisation of the current two exemptions for research (each of which has proven problematic in their own way) is very welcome.

In addition, the Bill takes a novel approach to defining consent in the context of research. For human research projects that are ethically reviewed, approved and monitored in accordance with the National Statement on Ethical Conduct in Human Research, consent would not be required to satisfy the ‘current’ or ‘specific’ elements of the definition of consent”.

This will help to resolve difficulties many of our public sector clients have faced when they wish to create sources of immense public value for future researchers, such as tissue biobanks and enduring data assets. (I am talking here about the types of research which help to better prevent, diagnose or treat disease, or which tackle policy challenges in fields like early childhood development, education or social wellbeing). The specific research projects which will draw on these rich assets for decades into the future cannot be known in advance, so gaining an individual’s consent to include their information or bio sample in an enduring data asset or biobank can only ever be for unspecified projects and open-ended in time.

Act fast on data breaches

The timeframe for notifying the OAIC about an eligible data breach will be dramatically slashed to 72 hours. Regulated entities should manage this compliance complexity with a well established and tested Data Breach Response Plan.

What’s next

Submissions on the Consultation Paper will close on 18 September. Parliament next sits the week commencing 12 October. Nothing is guaranteed in politics, but it is conceivable that this Bill could be law before the end of the year.

What is unclear is how these reforms will work with a separate policy proposal to introduce a ‘digital duty of care’, details of which the government has said will be released in October.

And what’s missing is any mention of the abolition of the small business exemption. Should we expect a Tranche 3 in due course?

Where to find out more

Keep an eye on our privacy reforms resource page for the latest developments. And see our fast guide for busy people: The Privacy Act in a Nutshell. This Executive Briefing Paper offers a concise explanation of how the Privacy Act works right now, alongside an explanation of what might change. 

Photograph © Anna Johnston

Filed Under: Blog, Privacy Act Reform

If you enjoyed this blog, subscribe to our newsletter to receive more privacy insights and news every month.

Privacy Compliance Kits

Recent Posts

  • Privacy law reform: weaving threads for a harmonious whole
  • Tick and flick: what ’I agree’ really means to Australians in 2026
  • Inching towards individuation: OAIC decision on pixels broadens scope of the Privacy Act
  • How dark patterns can land you in hot water: new case offers lessons for all
  • How to sniff out the landmines that can ruin your AI project
  • Privacy reforms to impact over 100,000 small businesses
  • The view from the summit: trust and hope, caution and concern, and plenty of hard work
  • Is identifiability in the eye of the beholder?  EU case tests limits of pseudonymisation
  • Mind the gap: when legal permission is not enough to ensure compliance
  • Why “Don’t worry it’s de-identified” should (still) be a red flag when considering privacy risk

Archive

  • 2026
  • 2025
  • 2024
  • 2023
  • 2022
  • 2021
  • 2020
  • 2019
  • 2018
  • 2017
  • 2016
  • 2015

Search

Helios Salinger can help you navigate the complexity of the regulatory environment, and ensure the trust of your customers.

CONTACT US

T: 02 9043 2632
Level 37, 180 George Street
Sydney NSW 2000
Email Enquiry

© Helios Salinger Pty Ltd
ACN 655 748 593
ABN 59 655 748 593

Our Privacy Policy

Terms of Engagement

Subscribe to our newsletter.

These details will be added to our mailing list to receive the Helios Salinger eNews and Product News newsletters. You can unsubscribe or adjust your preferences at any time, from the bottom of any newsletter.