Australia releases exposure draft legislation second tranche of Privacy Act reform, with the Attorney-General publishing the draft on 31 August 2026 and inviting written submissions until 18 September 2026. This tranche has been described as the most substantive package of privacy changes in decades, introducing a statutory fair and reasonable handling test, a right to erasure, new identity-protection measures, expanded enforcement and stronger individual rights. For in-house counsel, compliance officers, technology platforms and small and medium enterprises, the consultation window is short and the practical implications are significant. This article explains what has been released, who is affected, what the headline changes mean in operational terms, and how organisations can respond effectively before the deadline.
When Australia releases exposure draft legislation second tranche reforms of this magnitude, the practical stakes for regulated organisations rise sharply. An exposure draft is a version of proposed legislation released for public comment before a Bill is formally introduced to Parliament. It is not yet law, but it signals the Government’s policy intent and the likely shape of the eventual legislation. The Attorney-General’s Department released the draft on 31 August 2026 and set a submission deadline of 18 September 2026, giving stakeholders a concentrated period to identify drafting problems, unintended consequences and implementation concerns.
The current reform programme follows an earlier first tranche of amendments, enacted through the Privacy and Other Legislation Amendment Act 2024, that addressed a discrete set of priority measures. The second tranche is broader and more consequential, targeting structural elements that were deferred from the first round. Where tranche one delivered targeted fixes, tranche two proposes changes to core parts of the Privacy Act 1988 (Cth), the standard against which handling of personal information is judged, the individual rights available to Australians, and the enforcement architecture that backs those rights. This staged approach reflects the Government’s decision to legislate the less contentious measures first and reserve the more transformative reforms for a dedicated consultation.
The legislative pathway runs from exposure draft to Bill to Act. During the exposure-draft stage, the Government invites submissions, considers the feedback and may revise the drafting. The revised text is then introduced to Parliament as a Bill, where it typically passes through both Houses and is often referred to a parliamentary committee for further scrutiny and public hearings. Only after passage and Royal Assent does the reform become law, usually with transitional periods before key obligations commence. Because the exposure-draft comment period is an early and influential opportunity to shape the final text, organisations that wait for the Bill will generally have less leverage over the drafting.
The exposure draft Privacy Act package bundles several distinct reforms, each with implications for how organisations collect, use, secure and delete personal information. The summaries below identify the core of each change; the detailed analysis section that follows examines the operational and enforcement consequences in greater depth. Precise scope and thresholds should be confirmed against the exposure draft text.
The draft introduces a right for individuals to request deletion of their personal information in defined circumstances. This moves Australian law closer to comparable international rights and would require organisations to build processes for receiving, assessing and actioning erasure requests. As indicated in the exposure draft, the right is expected to be subject to thresholds and exceptions, for example, where retention is legally required or where deletion would prejudice a legitimate interest, so it is unlikely to be absolute.
The package addresses identity protection, reflecting concern about the harm caused by large-scale data breaches involving identity documents. Platforms and service providers that verify or hold identity information can expect measures directed at reducing the risk that compromised credentials are misused, alongside privacy-by-design expectations for how identity data is handled and secured.
A central reform is a new statutory requirement that the collection, use and disclosure of personal information be fair and reasonable in the circumstances. Under the current Privacy Act 1988 there is no equivalent standalone test. The proposed standard shifts part of the compliance analysis away from consent alone and toward an objective assessment of whether a particular data-handling practice is justifiable, regardless of whether the individual has technically agreed to it.
The exposure draft revisits the long-standing small business exemption, which has excused many smaller entities from the operation of core privacy obligations. Reform in this area would bring more organisations within scope. Businesses that have historically relied on the exemption should treat its potential removal or narrowing as a live risk and begin preparing for full compliance.
The reform programme has proposed strengthening enforcement, including through mechanisms that allow individuals to pursue remedies more directly, alongside enhanced regulatory powers. This would represent a shift from a framework that has relied predominantly on regulatory enforcement by the Office of the Australian Information Commissioner (OAIC), and it raises the litigation and financial exposure associated with non-compliance. A statutory tort for serious invasions of privacy was introduced through the 2024 amendments, and the second tranche builds on the broader enforcement direction of the reform programme.
Consistent with the reform programme’s attention to emerging technology, the package addresses automated decision-making. Organisations that use algorithmic or AI-driven systems to make or materially influence decisions about individuals can expect transparency and accountability expectations directed at those systems, reflecting concern about opacity and fairness in automated processing.
Determining scope is the first practical question every organisation should ask when Australia releases exposure draft legislation second tranche reforms of this breadth. The draft affects large entities already regulated under the Privacy Act 1988, but its reach extends further through changes to the small business exemption and technology-specific obligations.
The small business exemption has meant that a substantial number of entities below the relevant annual turnover threshold have sat outside the core privacy framework. Reform to this exemption would draw many of those entities in. Small businesses that hold significant volumes of personal information, operate in sensitive sectors or provide services to larger regulated organisations should assume they may lose the benefit of the exemption and plan accordingly. Even where an exemption is retained in some form, contractual flow-down obligations from larger customers frequently require smaller suppliers to meet privacy standards regardless of their statutory position.
Digital platforms, cloud providers and other large service providers face significant operational impact. These organisations process personal information at scale, verify identity, and often make automated decisions about users. New identity-protection measures, the fair and reasonable test and erasure rights all bear on platform operations, requiring changes to product design, data retention, and user-facing controls.
Organisations deploying AI and automated decision-making systems should map where those systems process personal information and where they produce decisions with a legal or similarly significant effect on individuals. The reforms are directed at transparency and accountability, so entities should be ready to explain, document and justify how automated systems use personal data, a task that is considerably easier to complete before, rather than after, the obligations commence.
The following analysis examines the likely operational, legal and enforcement consequences of the key reforms in the exposure draft Privacy Act package, with practical examples of what compliance may require. Final obligations will depend on the enacted text.
A workable right to erasure requires more than a policy statement. Organisations will need an intake channel for requests, a means of verifying the requester’s identity, and a defensible process for assessing whether an exception applies. Exceptions are likely to include legal retention obligations, ongoing legal proceedings, and public-interest considerations such as freedom of expression. Cross-border data flows add complexity: where personal information has been disclosed to overseas recipients or hosted in offshore infrastructure, organisations may need to be able to propagate a deletion request to those recipients and evidence that they have done so. Practical readiness means knowing where personal data resides, who holds copies, and how quickly it can be located and removed.
The interplay between erasure and public-interest or journalistic material will require careful judgment, and organisations should document the reasoning behind each decision to refuse or limit a request.
The fair and reasonable test introduces an objective standard that operates independently of consent. In practice this means an organisation cannot rely solely on a user having clicked “agree” to justify a data-handling practice; the practice itself must be defensible. Compliance evidence is likely to take the form of documented assessments that weigh the purpose of the processing, the sensitivity of the information, the reasonable expectations of the individual, and the proportionality of the data handling to the outcome sought.
Consider a retailer building detailed behavioural profiles from purchase history: under the proposed standard, the question is not merely whether the customer consented, but whether profiling of that depth is fair and reasonable given the customer’s expectations and the intrusiveness involved. Organisations should build a repeatable assessment methodology and retain the records that demonstrate their reasoning.
The identity-protection measures respond directly to the harm caused when identity credentials are exposed in a breach. For platforms and services that verify identity, this points toward stronger controls over how identity documents are collected, stored and reused, and toward mechanisms that limit the downstream misuse of compromised credentials. Privacy-by-design becomes central: minimising the retention of identity documents once verification is complete, encrypting identity data, and segregating high-risk information all reduce exposure. Organisations that collect identity documents as a matter of routine should reassess whether retention is genuinely necessary, and for how long.
Any expansion of the ways individuals can seek remedies changes the risk calculus. Under the current framework, enforcement flows largely through the OAIC, complemented by the statutory tort for serious invasions of privacy introduced in 2024. Broader avenues for individuals to seek remedies would increase both the volume of potential claims and the financial exposure attached to non-compliance. Combined with enhanced regulatory powers, the reforms make privacy compliance a board-level financial risk rather than a purely regulatory one. Organisations should establish a legal risk register capturing the areas of greatest exposure, high-volume data processing, sensitive information, and automated decision-making, and prepare for the possibility of both regulatory action and private litigation.
Data breach response sits at the intersection of these reforms. Australia’s Notifiable Data Breaches scheme already requires eligible data breaches to be reported to the OAIC and affected individuals. Stronger identity-protection measures and expanded individual rights heighten the consequences of a breach, and organisations should ensure their incident response plans, notification thresholds and timelines are current and tested. A breach that exposes identity documents or triggers a wave of erasure requests will test operational readiness in ways that a tabletop exercise conducted now can help anticipate.
Because Australia releases exposure draft legislation second tranche reforms with a submission deadline of 18 September 2026, the window for influencing the final drafting is short. Early engagement matters because the exposure-draft stage is when the Government is often most receptive to drafting changes; once a Bill is introduced, amendments can be harder to secure. A well-targeted submission that identifies a specific, evidenced problem with the drafting is generally more persuasive than a general expression of concern.
Submission strategy should be tailored to the audience:
Recommended submission topics include the scope and thresholds of the erasure right, the drafting of the exceptions that protect legitimate retention and public interest, the transition timetable for entities newly caught by changes to the small business exemption, and the calibration of penalties and individual remedies. An exemplar submission point might read: “We support the introduction of a right to erasure but recommend that the exceptions expressly preserve retention required to meet other legal obligations and to defend against legal claims, and that a minimum transition period apply before the obligation commences for entities newly brought within scope.” Organisations should coordinate with peak bodies where possible and file before the 18 September 2026 deadline.
Even though the reforms are not yet law, the practical work of preparation should begin now. The measures below are organised by timeframe.
Short term (0–30 days):
Medium term (30–120 days):
Organisations seeking structured support can request a tailored compliance review and a submission template from a senior privacy lawyer in the Global Law Experts network.
The table below summarises the key differences between the current Privacy Act 1988 and the tranche-two exposure draft. Precise thresholds and clause detail should be confirmed against the exposure draft text.
| Topic | Current Privacy Act 1988 | Exposure Draft (Tranche Two) |
|---|---|---|
| Small business exemption | Exemption for small businesses meeting the relevant criteria | Proposed changes to scope and threshold, bringing more entities into coverage |
| Right to erasure | Limited or sectoral rights only | Proposed new or expanded right for certain platforms and individuals, subject to exceptions |
| Fair and reasonable test | No standalone statutory test | Proposed statutory fair and reasonable handling standard |
| Individual remedies | Enforcement mostly by the OAIC; statutory tort for serious invasions of privacy (2024) | Proposed expansion of avenues for individuals to seek remedies |
| Penalties and enforcement | OAIC regulatory powers and civil penalties | Enhanced enforcement mechanisms proposed |
The fact that Australia releases exposure draft legislation second tranche reforms of this scale, released on 31 August 2026 with submissions closing on 18 September 2026, makes this a defining moment for privacy compliance in Australia. The consultation window is short, and the reforms reach core aspects of how organisations collect, use, secure and delete personal information, backed by stronger enforcement. Organisations should not wait for the Bill: begin a compliance gap analysis now, prepare a targeted submission, and brief senior leadership on the risk. To request a tailored compliance review, a submission template and expert guidance, connect with a senior Australian privacy lawyer in the Global Law Experts network.
posted 9 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 10 minutes ago
posted 18 minutes ago
No results available
Find the right Legal Expert for your business
Send welcome message