Australia's federal government released a landmark privacy exposure draft on August 31, 2026, that would create a world-first legal obligation for any company or government agency handling Australians' personal data to actively justify that collection as proportionate — even when the individual has already clicked "I agree." The Privacy Amendment (Personal Data Protection) Bill 2026 went public for consultation yesterday, closing a 38-year gap since the country's original Privacy Act 1988 was written before the web, smartphones, or social media existed. Public submissions are open through September 18, 2026, via the Attorney-General's Department consultation hub.

The bill's central mechanism is what legal scholars are calling a world-first: a "fair and reasonable" test that would displace Australia's current consent-based architecture with a multi-factor obligation. Under the proposed standard, an organization must satisfy a proportionality assessment covering whether a reasonable person would expect their data to be handled that way, whether the organization is transparent about its handling, whether the same purpose could be achieved with less data, whether the individual had a genuine and meaningful choice — not just the legal appearance of one — and whether the risk of harm to the person is outweighed by real benefits. Australian Privacy Commissioner Carly Kind, speaking before the bill's release, described the proposed test as one that diverges from a consent-based model and represents a new direction beyond what the EU's General Data Protection Regulation established.

The practical effect of that shift is structural: the consent form, which has served for decades as the legal shield behind which the surveillance economy's data-collection practices operate, would no longer be sufficient. Companies that gather behavioral data through terms-of-service agreements — and then use it for purposes their users would not recognize as proportionate — would be unable to point to the clicked checkbox as their justification. Attorney-General Michelle Rowland, whose portfolio also covers digital platform regulation, framed the stakes in unusually direct terms: Rowland on Australians' data control — "Australians expect their personal information to be protected, not exploited. Yet almost four in five Australians report they have very little or no control over how their personal information is collected or used."

What "Fair and Reasonable" Actually Requires

The test replaces three of the current Australian Privacy Principles — APPs 3, 4, and 6, which govern collection, unsolicited information, and use or disclosure respectively — with a unified, principles-based framework. Under the existing law, consent can be technically valid even when buried in a 500-word terms-of-service clause; the new standard under the exposure draft would require that consent be "voluntary, informed, current, specific and unambiguous" — and even valid consent would not end the legal inquiry, because the organization would still need to demonstrate that its handling of the data is fair and reasonable against all the relevant factors.

The bill's expanded definition of "personal information" also closes a gap that has become significant as AI inference has grown more sophisticated. Information that relates to an identifiable individual — a nickname, a device identifier, or a behavioral pattern — will qualify, regardless of whether a name is attached. More consequentially, inferences that artificial intelligence draws about an individual will be treated as collected personal information in the same way as data typed into a form. This forecloses the argument — already being developed in corporate data practice — that deriving sensitive conclusions from non-sensitive inputs amounts to collection of new information rather than use of existing data.

Precise location tracking has been added to the list of "sensitive information" requiring explicit consent to collect. The bill defines precision technically: a device that can pin a user's location to within 500 meters (1,640 feet) and tracks that position over time qualifies as collecting precise location data, regardless of whether the application describes itself as a navigation tool, a fitness tracker, or a retail loyalty program.

The 72-Hour Breach Clock

The bill replaces the current requirement to notify the Office of the Australian Information Commissioner of an eligible data breach "as soon as practicable" with a hard 72-hour breach notification deadline — matching the standard already embedded in Australia's broader cyber regulation framework and bringing the country's breach notification obligations into alignment with the EU's GDPR.

The practical weight of that change is carried by what the Optus and Medibank breaches exposed in 2022. Optus's breach, which exposed 9.8 million customer records — roughly a third of Australia's population — exposed names, dates of birth, home addresses, phone numbers, email contacts, and passport and driver's license numbers. Medibank's near-simultaneous breach reached 9.7 million records and included sensitive health data. Under the current "as soon as practicable" standard, both companies spent days in investigation before formal notification. A 72-hour clock would have forced earlier regulatory intervention and earlier public warning. Latitude Financial's 2023 breach — 14 million records, the largest in Australian history — and MediSecure's 2024 breach of 12.9 million prescription records followed the same pattern. The combined effect is that a meaningful proportion of Australia's adult population now has sensitive identity documents and health records in active circulation on criminal forums, a circumstance that faster breach notification alone cannot remedy but that faster notification could have partially mitigated.

Australia's first civil penalty under the Privacy Act — an AU$5.8 million (approximately $4.16 million USD) judgment against Australian Clinical Labs over its 2022 breach of 223,000 patient records — was handed down by the Federal Court in October 2025. The scale of that penalty illustrates exactly why the 72-hour clock matters operationally: faster notification to regulators produces faster regulatory engagement, and faster engagement means entities cannot spend weeks deciding whether a breach is "eligible" under the current framework.

Data Brokers in the Crosshairs

Beyond the headline mechanism, the bill contains what amounts to a structural assault on data brokerage practices that have operated in an Australian legal gray zone for decades. A proposed ban on personal information trading without permission would require that any disclosure of personal information for consideration — or for direct marketing purposes — obtain specific, granular consent rather than relying on bundled terms.

The bill simultaneously tightens the conditions for consent across the board. Pre-ticked boxes, bundled consent arrangements — where agreeing to one thing implies agreement to another — and vague or obscured opt-in mechanisms would be prohibited. Consent must be active, granular, and clearly separated from other terms.

The surveillance economy's legal architecture rests, in large part, on the fiction that a user who checks "I agree" to a 47-page privacy policy has meaningfully consented to having their behavioral data sold to parties they have never heard of, aggregated with data from other sources, and used to build profiles their original consent form did not describe. The combination of the fair-and-reasonable test and the trading ban directly targets that fiction. Companies in the ad-tech supply chain that collect Australian users' data, aggregate it, and pass it downstream will need to demonstrate that each transaction in that chain meets the new standard — not just the point of initial collection.

Right to Erasure: Significant but Narrow

The bill introduces a right to erasure — the "right to be forgotten" — for the first time in Australian law, but in a form substantially narrower than what privacy advocates sought and narrower than EU GDPR Article 17. The right would apply only to "large digital platforms": services covered by the Online Safety Act 2021 that meet either an AU$500 million (approximately $358 million USD) gross revenue threshold or an average of 2.5 million monthly Australian end users.

Platforms that meet the threshold must destroy personal information on request, provide written notice identifying what was destroyed, specify exceptions relied upon, and advise the individual on how to lodge a complaint if dissatisfied. Exceptions to the right are broad: law enforcement purposes, information required by law or court order, requests that are technically impossible, and situations where retention is necessary for the provision of a service the individual continues to use.

The result is a two-tier privacy landscape. Users of the largest platforms — Meta, Alphabet, TikTok, and their equivalents — will have an erasure mechanism. Users of smaller platforms, data brokers, and the broader ecosystem of services below the threshold will not.

Smart Glasses, Connected Cars, and AI Inference

The bill arrives explicitly targeting technologies that did not exist when the Privacy Act was written. The accompanying consultation paper flags concerns about smart glasses and AI-enabled earbuds — wearable devices that can discreetly record audio and video of bystanders who have no awareness they are being captured. In early 2026, a scandal emerged over Meta's Ray-Ban AI glasses, in which contractors in Kenya had reviewed intimate footage recorded by the devices to train the AI system — footage whose subjects had not consented to any such use. The bill's expanded definition of personal information would expressly capture video, audio, and AI-generated inferences from such devices, requiring that their collection meet the fair-and-reasonable standard.

Connected and autonomous vehicles present a similar challenge. Modern vehicles continuously collect location data, driving behavior, and environmental information — including, as a 2023 Mozilla Foundation analysis found, data about a driver's health, immigration status, and sexual activity drawn from connected phones. The Privacy Act's 1988 language was not designed to reach this category of continuous, ambient data collection. The bill's reformulation of "personal information" from "information about" to "information that relates to" an individual directly addresses it.

What the Test Does Not Guarantee

The "fair and reasonable" standard's flexibility is simultaneously its most novel feature and its most significant limitation. Unlike the GDPR's prescriptive framework — which names specific lawful bases for processing, specifies maximum storage periods, and provides relatively clear compliance benchmarks — the fair-and-reasonable test is principles-based, meaning its operative meaning will be built through litigation and regulatory determinations over time.

Australian Privacy Commissioner Carly Kind has described this as a feature: a principles-based test is harder to game than prescriptive rules, because companies cannot satisfy it by engineering technical compliance while violating its spirit. That assessment is plausible in the long run. In the short run, however, the first few years of the test's operation will require courts to construct what "reasonable expectations" means in a digital economy — a process that, in the EU, took the GDPR more than five years to begin producing reliable precedent for. During that construction period, well-resourced companies with skilled legal teams will be better positioned than individual complainants or the OAIC to shape the emerging standard.

How Australia Now Compares to the GDPR

The bill moves Australia meaningfully closer to GDPR standards on several dimensions — particularly the 72-hour breach notification window and the embedding of data minimization in the fair-and-reasonable test's factor list. The controller/processor model proposed in the bill, which allocates primary compliance responsibility to the data controller, mirrors the GDPR's core structural distinction.

Notable gaps remain. The GDPR's Article 22 creates a right not to be subject to decisions made solely through automated processing; the Australian approach remains transparency-based under Tranche 1 (which requires disclosure of automated decision-making in privacy policies from December 10, 2026) rather than rights-based. The GDPR requires the appointment of a Data Protection Officer in many circumstances; no equivalent mandatory obligation appears in the current draft. The Australian bill does not include any provision equivalent to the GDPR's explicit cross-border adequacy framework, though a whitelist mechanism for prescribed jurisdictions exists under Tranche 1 (as of September 2026, no countries have been prescribed).

What Australia's bill does offer that the GDPR does not is the fair-and-reasonable test itself. The GDPR's six lawful bases for processing personal data — including "legitimate interests" — have been extensively gamed by companies claiming that their interest in monetizing user data constitutes a legitimate basis. The Australian test would require that data use be not just legally based but actively justifiable as proportionate, transparent, and minimized — a higher and more subjective bar.

The Small Business Question

One of the most consequential structural questions the bill leaves open is the AU$3 million (approximately $2.15 million USD) annual turnover exemption that currently shields the majority of Australian businesses from Privacy Act obligations entirely. The 2023 Privacy Act Review recommended removing the exemption, which would bring an estimated 2.3 to 2.5 million additional businesses — approximately 95% of all Australian businesses — under the Act's full scope for the first time. The Albanese government agreed with the recommendation in principle; the bill addresses this threshold, though the final mechanism remains subject to consultation.

The Productivity Commission has publicly raised compliance burden reservations for small businesses. The OAIC, meanwhile, has stated that the exemption is "no longer appropriate in light of the privacy risks posed by entities of all sizes" — language that reflects the documented reality that data breaches at companies below the current threshold have caused harm at scale, and that small businesses collecting health data, biometric access records, and financial details are not obviously less capable of misusing that data than larger ones.

Australia is already an outlier among comparable common-law jurisdictions: the UK, Canada, New Zealand, Ireland, and South Africa all apply privacy laws regardless of business size.

Rowland's Reform Portfolio

The bill is the latest element in a coordinated digital regulation program driven by AG Rowland, who also serves as Communications Minister — an unusual double portfolio that has placed her at the center of both privacy and online safety reform. She introduced the Social Media Minimum Age Act 2024, which enacted Australia's ban on social media for users under 16, as well as the Cyber Security Act 2024, which established mandatory cyber incident reporting obligations for critical infrastructure. The interconnection of those reforms is not incidental: a country that requires platforms to verify users' ages generates new biometric and identity data streams; a country that requires breach reporting for critical infrastructure generates new disclosure obligations; and a country that introduces a fair-and-reasonable test for all personal data handling creates an overarching framework that governs what happens to the data those other laws require to be collected.

What Happens Next

Submissions close September 18, 2026, via the Attorney-General's Department Consultation Hub. The government has invited responses from businesses, academics, community organizations, and members of the public. If enacted in the current form — which is not certain, given the Productivity Commission's reservations and the scope of industry pushback expected on both the fair-and-reasonable test and the small business exemption — the bill would represent the most substantial rewrite of Australian privacy law since 1988, and would establish one genuinely novel global standard: the first national law to make "I clicked agree" legally insufficient as a justification for data collection.


Frequently Asked Questions

What is Australia's "fair and reasonable" test, and how is it different from consent?

Under Australia's current law — and under the GDPR's "legitimate interests" basis — a company can often justify data collection by pointing to a form you signed or a terms-of-service clause you clicked. The proposed fair-and-reasonable test adds a layer that consent alone cannot satisfy: the company must independently demonstrate that its data handling is proportionate, transparent, minimized to what is necessary, and aligned with what a reasonable person would expect. The test is specifically designed to close the loophole in which legal consent forms provide cover for data uses that users would not recognize or accept if they understood them. Australia's Australia's fair-and-reasonable framework full details and the five-factor assessment that organizations must satisfy.

Does Australia's right to erasure work the same way as Europe's GDPR right to be forgotten?

No — Australia's proposed right is considerably narrower. The GDPR's Article 17 applies across the EU economy to any data controller. Australia's bill limits the right to "large digital platforms" — services meeting either an AU$500 million (approximately $358 million USD) revenue threshold or 2.5 million monthly Australian users. Users of platforms below those thresholds, and users of data brokers and aggregators, would have no erasure right under the bill as currently drafted. If you use a smaller platform, social network, or specialized service that collects detailed personal data, the bill as written does not give you a direct mechanism to demand deletion from that organization.

Will the fair and reasonable test immediately protect Australians, or will it take years for courts to define what it means?

Potentially both — and the gap between those two statements matters. If enacted, the test would be law from its commencement date, meaning the OAIC could investigate and enforce against organizations whose data practices are obviously disproportionate from day one. However, the test's principles-based nature means that the full scope of what "fair and reasonable" requires — particularly in gray areas like behavioral advertising, AI inference, and data broker supply chains — will be built through regulatory determinations and court decisions over years. The EU's comparable implementation of the GDPR's "legitimate interests" basis took more than five years to produce reliable precedent. Australian organizations with well-resourced legal teams are better positioned than individual complainants to shape that emerging standard. The test is a structural improvement over the current consent-loophole architecture; it is not a switch that flips all harmful data practices off on the day of enactment.

How does the bill affect businesses that are currently exempt from Australia's Privacy Act?

Australia currently exempts businesses with annual turnover below AU$3 million (approximately $2.15 million USD) from most Privacy Act obligations. The bill addresses the scope of this exemption, though the final mechanism remains subject to consultation. If the exemption is fully removed — as the government agreed in principle after the 2023 Privacy Act Review — approximately 2.3 to 2.5 million additional businesses would become subject to all 13 Australian Privacy Principles for the first time. That would be the largest single expansion of Australia's privacy framework in the Act's history. Separately, small businesses providing designated services under Australia's anti-money-laundering and counter-terrorism financing regime have already been brought under the Privacy Act from July 1, 2026, regardless of turnover. The Australia privacy small business obligations are covered in detail by BizTechLawyers' July 2026 analysis.

Originally published on Tech Times