[codicts-css-switcher id=”346″]

Global Law Experts Logo
australia privacy act reform

Australia’s Privacy Act Reform: the “second Tranche” and What It Means for Dispute Resolution

By Global Law Experts
– posted 1 hour ago

This article explains the key legal and practical implications of the Australian Government’s ongoing Privacy Act reform program, in particular the anticipated “second tranche” of changes, summarises the proposed measures, sets out short-term compliance steps for businesses, and outlines how organisations can engage with consultation processes.

The Privacy Act reform program marks the most significant overhaul of the Privacy Act 1988 (Cth) in decades. The first tranche of reforms was enacted through the Privacy and Other Legislation Amendment Act 2024 (Cth), and the Australian Government has signalled that further, more structural reforms, commonly described as the “second tranche”, remain under development and consultation. These changes carry consequences for how organisations collect, use and protect personal information. For dispute resolution practitioners and in-house counsel, the reform program signals a meaningful shift in litigation and enforcement risk, particularly through a statutory tort for serious invasions of privacy (introduced in 2024) and further proposed measures such as a broader direct right of action and expanded regulator powers.

Businesses that begin preparing now will be better placed to manage exposure and to shape the final legislation.

Executive summary, what the reforms change and why they matter

The Privacy Act reform program is broad in scope. It re-frames baseline obligations around a positive standard of conduct, opens pathways for individuals to seek redress, and strengthens the enforcement toolkit available to the regulator. Taken together, these measures move privacy from a compliance-and-notification model towards a proactive, accountability-based regime, with real dispute consequences for organisations that fall short.

Key takeaways

  • Small business exemption reform. The exemption that has historically excluded many small businesses from the Act has been flagged by government for review, which could draw more organisations into the framework and increase their potential exposure to disputes and enforcement.
  • “Fair and reasonable” handling standard. A proposed positive obligation that personal information handling be fair and reasonable would apply across collection, use and disclosure, creating a new benchmark against which conduct can be measured, and challenged.
  • Statutory tort and direct rights of action. A statutory tort for serious invasions of privacy has already been legislated (commencing in 2025), and further direct rights of action for privacy breaches remain under consideration, expanding the litigation landscape beyond regulator-led enforcement.
  • Expanded regulator powers. The Office of the Australian Information Commissioner (OAIC) has gained enhanced investigatory and enforcement capabilities, with further powers under consideration, sharpening the consequences of non-compliance.
  • Higher penalties. The 2024 amendments introduced a tiered civil penalty regime for interferences with privacy, and the reform trajectory continues to point to stronger enforcement pathways.
  • Application and commencement issues. Transitional and application questions, including how obligations phase in, will materially affect how organisations plan compliance.

Who should read this

This analysis is aimed at small and medium businesses assessing whether they may lose the benefit of the current exemption, regulated entities already subject to the Act, and legal counsel advising on litigation, enforcement and contractual risk. Anyone responsible for data governance, board reporting or dispute readiness should treat the reform program as a planning trigger rather than a distant policy debate.

Context and legislative background

The Privacy Act 1988 (Cth) has been the cornerstone of federal privacy regulation for more than three decades. It established the Australian Privacy Principles and the office of the regulator, but it was drafted for an earlier technological era and has been amended incrementally rather than comprehensively. The current reform program follows the Attorney-General’s Department’s Privacy Act Review Report (released in early 2023) and the Government’s response (released in September 2023), which agreed or agreed-in-principle to a large number of proposals. It also draws on earlier analysis by the Australian Law Reform Commission on serious invasions of privacy in the digital era. The Government has chosen to modernise the Act in stages rather than in a single sweeping Bill.

Quick timeline: 1988 to the current reforms

The Act commenced operation in 1988 (with the private-sector provisions added later) and has been amended repeatedly, most notably to introduce credit reporting reforms, the Notifiable Data Breaches scheme (2018), and successive updates to the Australian Privacy Principles. The Privacy Act Review Report in 2023 set the agenda for the current reforms. The first tranche was enacted as the Privacy and Other Legislation Amendment Act 2024 (Cth). Further reforms addressing more contested structural proposals are expected to follow.

What an exposure draft is and how consultation fits in

An exposure draft is a draft of proposed legislation released for public consultation before a Bill is formally introduced to Parliament. It gives affected parties an opportunity to test the drafting, identify unintended consequences and propose amendments. Critically, an exposure draft does not change the law. Provisions become binding only if a Bill is introduced, passes both Houses of Parliament and receives Royal Assent. Where the Government releases exposure draft materials or consultation papers for the next stage of reform, the consultation window is the mechanism through which businesses can influence the final shape of the legislation. Organisations should confirm current consultation timeframes directly with the Attorney-General’s Department.

The reform program, key changes in plain language

For each major reform item below, it is helpful to understand what the current law provides, what is proposed, and the practical impact. Proposed measures should be read alongside the existing statutory text on the Federal Register of Legislation to appreciate the scope of change.

Small business exemption, scope and thresholds

Under the Privacy Act as it currently stands, many businesses with limited annual turnover fall outside the Act’s core obligations because of the small business exemption. The reform program proposes to review and potentially remove or narrow this carve-out. The practical impact is that organisations previously outside the regime may need to comply with the full suite of privacy obligations, including notice, access, correction and security requirements. For a business that has never maintained a formal privacy program, this would represent a substantial operational and governance uplift.

Fair and reasonable handling, the proposed test and its operational meaning

The current framework relies heavily on notice and consent. The reform proposals contemplate a positive obligation that the collection, use and disclosure of personal information be fair and reasonable in the circumstances. This is significant because it would shift responsibility onto organisations to justify their handling of data proactively, rather than relying on the fact that an individual clicked “agree”. In practice, organisations would need to be able to demonstrate that each material data-handling decision was proportionate and defensible.

Statutory tort and direct rights of action, who can sue and available remedies

Historically, enforcement was largely channelled through the regulator. The Privacy and Other Legislation Amendment Act 2024 (Cth) introduced a statutory tort for serious invasions of privacy, giving individuals a cause of action in certain circumstances (commencing in 2025). Further direct rights of action for interferences with privacy under the Act itself remain under consideration in the reform program. This is among the most consequential changes from a dispute resolution perspective, because it opens the door to individual and potentially grouped claims.

The precise causes of action, standing requirements, limitation periods and available remedies should be verified against the legislation and any exposure draft text as reform progresses, but the direction of travel is clear: privacy breaches will increasingly be litigated, not merely investigated.

Enforcement and penalties, regulator powers and court proceedings

The reforms strengthen the OAIC’s enforcement posture. The 2024 amendments introduced additional enforcement mechanisms and a tiered civil penalty framework, including lower-tier and mid-tier penalties for interferences with privacy alongside the existing serious or repeated interference penalty. Further enhancements to investigatory and enforcement powers are under consideration. For risk teams, this means that a privacy failure that might once have resulted in an inquiry could now attract significant financial penalties and, in serious cases, court proceedings.

Cross-border transfers and international implications

Modern privacy regimes increasingly emphasise individual control and the accountability of organisations that send data offshore. Where reforms strengthen obligations around cross-border transfers, including mechanisms to recognise countries with substantially similar protections, organisations that rely on overseas cloud providers, offshore processing or multinational data flows will need to review their contractual and technical safeguards. Aligning Australian practice more closely with international standards also has implications for businesses that operate across jurisdictions.

Small business exemption, implications and thresholds

The proposed change to the small business exemption is arguably the reform with the widest reach, because it could convert a large population of previously exempt entities into regulated ones. Consultation is the moment for affected businesses to explain the practical cost and effort of compliance.

Which businesses are affected

Businesses that have historically relied on the exemption, including many owner-operated enterprises, franchises and service providers, should assess whether they would be brought within the Act. Entities already handling health or other sensitive information may find that a change simply formalises obligations they should arguably have been meeting, while those with limited data-handling may face a genuinely new compliance burden. A prudent assumption during consultation is that the exemption may narrow, and to prepare accordingly.

Contracting and procurement implications

Larger organisations frequently contract with small suppliers who currently sit outside the Act. If those suppliers become regulated, contractual data-handling clauses, warranties, indemnities and audit rights will need to be revisited. Procurement teams should begin mapping which vendors would be affected, because gaps in the contractual chain are a common source of downstream disputes when a breach occurs.

Fair and reasonable handling, operationalising the standard

A fair and reasonable handling standard is deliberately principles-based, which gives organisations flexibility but also uncertainty. The task for compliance teams is to translate an open-textured legal standard into concrete, evidenced practice.

Practical steps to evidence fair and reasonable handling

Organisations should build a defensible record around each significant data-handling activity. Privacy impact assessments, documented balancing exercises, data minimisation decisions and retention limits all help demonstrate that a handling decision was proportionate. Where a business collects more data than it strictly needs, retains it indefinitely, or repurposes it without a clear justification, it exposes itself to an argument that its conduct was neither fair nor reasonable, precisely the kind of allegation that could underpin a complaint or claim.

Recordkeeping and demonstrable decision-making

A recurring theme across the reform is accountability. It is not enough to make good decisions; organisations must be able to show that they did. That means maintaining contemporaneous records of privacy assessments, approvals and the reasoning behind data-handling choices. In any future dispute, the quality of this documentation will often determine whether an organisation can defend its position.

Direct rights of action, litigation landscape and dispute risk

From a dispute resolution standpoint, the expansion of individual rights of action, including the new statutory tort for serious invasions of privacy, is the reform most likely to change day-to-day legal practice. It transforms privacy from a predominantly regulatory matter into a source of private litigation.

Likely claims and typical remedies

Where individuals can bring proceedings directly, the natural consequence is a rise in claims following high-profile data breaches or systemic mishandling. Remedies may include damages, and the aggregation of many similarly affected individuals raises the prospect of class action exposure. Organisations that hold large volumes of personal data should model this risk now, because the financial exposure from grouped claims can rival or exceed a regulatory penalty. The specific remedies and any limits should be confirmed against the legislation and any exposure draft as text is finalised.

How dispute resolution clauses and ADR will interact with direct rights of action

The emergence of direct claims makes early dispute management more important than ever. Well-drafted complaints-handling processes, internal escalation procedures and access to mediation can resolve grievances before they harden into litigation. Alternative dispute resolution, including mediation and structured settlement, will be central to managing volume claims cost-effectively. Organisations should also review whether and how contractual dispute resolution mechanisms operate alongside statutory rights, recognising that statutory causes of action may not be readily displaced by private agreement.

Enforcement, OAIC powers, penalties and cross-agency coordination

The reforms sharpen the regulator’s teeth. Understanding the trajectory of the OAIC’s enforcement powers is essential to accurate risk modelling, because the difference between the previous and current regimes is not marginal.

Enforcement pathway: investigation to determination to court

The typical enforcement pathway moves from complaint or own-motion inquiry, through investigation and determination, and, where warranted, to court proceedings for civil penalties. Enhanced powers mean the regulator can investigate more effectively and escalate more readily. The OAIC also increasingly coordinates with other regulators, so a single incident may attract attention across multiple agencies. Organisations should prepare for the possibility of parallel scrutiny and ensure their incident response contemplates regulatory engagement from the outset.

What increased penalties mean for risk modelling

Higher civil penalties change the calculus for boards. Privacy risk can no longer be treated as a minor operational matter; it belongs in enterprise risk registers alongside other material exposures. Insurance cover should be reviewed to confirm whether privacy penalties and defence costs are addressed (noting that civil penalties are commonly uninsurable as a matter of public policy), and boards should receive regular reporting on the organisation’s privacy posture.

Making a submission, how organisations should respond to consultation

Consultation timeframes on Privacy Act reform can be compressed, so organisations should be ready to engage promptly when exposure draft or consultation materials are released. A focused, evidence-based submission carries far more weight than a general expression of concern. Submissions are administered through the Attorney-General’s Department; organisations should verify current consultation dates on the Department’s website.

Practical submission checklist

  • Identify who should sign. Ensure the submission is authorised at an appropriate level and reflects the organisation’s considered position.
  • Secure legal input early. Engage advisers to test the drafting against your operations and to frame technical points precisely.
  • Provide concrete impact evidence. Quantify compliance costs, implementation timeframes and operational consequences rather than asserting them.
  • Propose specific drafting. Suggested wording is more persuasive than abstract objection.
  • Address transition. Explain what commencement and phasing arrangements would allow realistic compliance.

Tips to ensure your submission is considered

Clear asks travel furthest. A submission that isolates a small number of high-priority issues, articulates the problem, sets out the practical impact and proposes a workable alternative is more likely to influence the final Bill than a lengthy document covering every provision. The Law Council of Australia and other peak bodies also publish submissions, and reviewing the concerns raised by professional bodies can help sharpen your own contribution.

Immediate compliance actions, what to start now

Waiting for further reforms to pass before acting would leave many organisations exposed, particularly given the measures already legislated in 2024. Because the direction of reform is now visible, sensible preparation can begin immediately and will reduce both enforcement and litigation risk.

30/60/90 day compliance playbook

  1. First 30 days. Map your personal information holdings, confirm whether a small business exemption change would affect you, and review your privacy notices and consent mechanisms for obvious gaps.
  2. By 60 days. Conduct privacy impact assessments on high-risk processing, review vendor and supplier contracts, and refresh your incident response and breach-notification procedures.
  3. By 90 days. Deliver staff training, tighten data retention and minimisation practices, review insurance cover, and establish regular board reporting on privacy risk.

Evidence and controls to reduce litigation risk

The controls that reduce regulatory exposure are largely the same as those that defend against private claims: documented decision-making, proportionate data handling, robust security, and a demonstrable culture of accountability. Building this evidence base now means that if a dispute arises, the organisation can point to a contemporaneous record of responsible conduct.

Dispute resolution strategies and practical scenarios

A dispute resolution lens helps organisations anticipate how the reforms could translate into real conflict, and how to mitigate it. The following two scenarios illustrate the practical stakes.

Scenario 1, SMB data breach and exemption dispute

A small services business that previously relied on the exemption suffers a breach after a reform narrowing the exemption commences. It has no privacy program, no breach-response plan and limited records of its data-handling decisions. It faces regulatory scrutiny and complaints from affected individuals, and its larger clients invoke contractual warranties. Early preparation, a privacy policy, a documented breach-response process and clean vendor contracts, would have substantially reduced both the regulatory and contractual exposure.

Scenario 2, direct action by an individual claiming damages

Following a systemic mishandling of personal information, an individual brings a direct claim, and others in a similar position consider joining. The organisation’s ability to defend itself turns on the records it can produce: did it assess the risks, minimise the data, and act proportionately? Where those records exist, early mediation may resolve the matter efficiently. Where they do not, the organisation faces a costly and public dispute. This scenario underscores why demonstrable compliance is the most effective litigation shield.

Comparison table, current Privacy Act vs the reform direction

Topic Privacy Act 1988 (pre-2024 position) Reform direction (legislated 2024 and/or proposed) Practical impact
Small business exemption Many small businesses excluded from core obligations Proposed for review, potential narrowing or removal More organisations may be brought into the regime; governance uplift required
Standard of handling Reliance on notice and consent Proposed positive “fair and reasonable” handling obligation Organisations would need to justify handling proactively and keep records
Rights of individuals Enforcement largely regulator-led Statutory tort for serious invasions of privacy legislated (2024); broader direct rights under consideration Increased litigation and potential class action exposure
Regulator (OAIC) powers Existing investigatory and enforcement powers Enhanced powers legislated in 2024; further powers under consideration Greater likelihood of investigation and escalation
Penalties Serious or repeated interference penalty framework Tiered civil penalty regime introduced in 2024 Higher financial stakes; board-level risk management needed
Commencement In force 2024 measures commencing progressively; further measures subject to enactment Timing and phasing will shape compliance planning

Next steps and timeline, what to watch

The Attorney-General’s Department continues to develop the next stage of reforms informed by consultation. Where exposure draft or consultation materials are released, the Department considers feedback and finalises drafting before a Bill is introduced to Parliament. The usual legislative process then applies: debate, potential committee scrutiny, amendment and passage through both Houses before Royal Assent. Industry observers expect that the substance of any broader direct right of action, the small business exemption and the penalty framework will attract significant attention. Organisations should monitor the Parliament of Australia website for introduced legislation and the OAIC and Attorney-General’s Department websites for guidance and consultation updates, and track any transitional provisions closely, as commencement timing will drive compliance deadlines.

How Global Law Experts can help

As the Privacy Act reform program advances, organisations face a narrowing window to influence future reforms and a longer road to compliance with measures already legislated. Global Law Experts can assist with tailored consultation submissions, dispute resolution planning, litigation readiness assessments and practical privacy compliance uplift. For guidance from a Dispute Resolution expert, contact the Global Law Experts team to discuss how the reforms affect your organisation and what to prioritise now.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Jim Harrowell at Hunt & Hunt Lawyers, a member of the Global Law Experts network.

Sources

  1. Attorney-General’s Department (Australia)
  2. Office of the Australian Information Commissioner (OAIC)
  3. Federal Register of Legislation, Privacy Act 1988 (Cth)
  4. Parliament of Australia, Bills & Legislation
  5. Australian Law Reform Commission, Serious Invasions of Privacy in the Digital Era (ALRC Report 123)
  6. Law Council of Australia

FAQs

What is the “second tranche” of Privacy Act reform?
The Government legislated a first tranche of reforms through the Privacy and Other Legislation Amendment Act 2024 (Cth). The “second tranche” refers to further, more structural reforms, including proposals such as a broader direct right of action, changes to the small business exemption and a “fair and reasonable” handling standard, that remain under development and consultation. Organisations should confirm current consultation timeframes with the Attorney-General’s Department.
No. An exposure draft is a consultation document. The proposed provisions become law only if a Bill is introduced to Parliament, passes both Houses and receives Royal Assent.
The reform program proposes to review and potentially narrow or remove the exemption, meaning more small businesses could fall within the Act’s obligations. Affected businesses should assess their data holdings and begin building a privacy program.
Where introduced, it would require documented, proportionate decision-making around the collection, use, disclosure and retention of personal information. Organisations should adopt privacy impact assessments and maintain evidence of their handling decisions.
A statutory tort for serious invasions of privacy, legislated in 2024, allows individuals to bring proceedings in certain circumstances. Broader direct rights of action under the Act remain under consideration. The specific causes of action, standing and limits should be verified against the legislation and any exposure draft text.
The 2024 amendments introduced a tiered civil penalty regime and enhanced enforcement powers for the OAIC. Organisations should assess their potential exposure and elevate privacy within their enterprise risk framework now. Current penalty amounts should be confirmed against the legislation and OAIC guidance.
Prepare a focused submission that sets out the practical impact, quantifies compliance costs and proposes specific drafting changes. In parallel, prioritise urgent controls that reduce enforcement and litigation risk now.
mediation act 2023
By Global Law Experts

posted 1 hour ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Australia’s Privacy Act Reform: the “second Tranche” and What It Means for Dispute Resolution

Send welcome message

Custom Message