Australia Australia news media bargaining code

Australia's Second Privacy Act Rewrite Trades Consent for a 'Fair and Reasonable' Test — and Puts the Burden on Business

Rowland's exposure draft adds a fairness standard, erasure rights and a controller/processor regime; consultation closes Sept 18.

Australia's Privacy Act, Tranche Two People of Internet Research · Australia $500M Erasure right revenue threshold Right of erasure applies only to p… 72 hours Breach notification deadline New hard deadline to notify the OA… 18 days Consultation window length Exposure draft released Aug 31, su… June 2025 Tranche one tort commenced Statutory tort for serious invasio… peopleofinternet.com
Australia's Privacy Act, Tranche Two People of Internet Research · Australia $500M Erasure right revenue threshold 72 hours Breach notification dea… 18 days Consultation window length June 2025 Tranche one tort commenced peopleofinternet.com

Key Takeaways

A second, sharper draft

On August 31, 2026, Attorney-General Michelle Rowland released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, the second tranche of Australia's overhaul of the Privacy Act 1988. It is more consequential than the first. Tranche one, the Privacy and Other Legislation Amendment Act 2024, gave Australians a statutory tort for serious invasions of privacy — a reform that only took effect on 10 June 2025, just over a year before this second draft landed. Tranche two goes after the operating model of the data economy itself: how companies decide what they may collect, what large platforms owe users who want their data gone, and who is liable when a vendor mishandles it. Consultation on the exposure draft closes September 18, 2026.

What actually changes

The centerpiece is a 'fair and reasonable' test that would replace the current consent-and-notice architecture (Australian Privacy Principles 3, 4 and 6) with a single, judged-after-the-fact standard. Under the draft, entities must weigh factors including reasonable expectations, data minimisation, proportionality to purpose, transparency and genuine choice before collecting or using personal information — not simply obtain consent and disclose a privacy policy, according to analysis from Corrs Chambers Westgarth. Consent stops being a safe harbor; it becomes one input into an objective test a court or the OAIC can second-guess later.

The draft also creates a right of erasure, but a narrow one: it applies only to large digital platforms meeting a $500 million group-revenue threshold, 2.5 million average monthly Australian users, or platforms specifically prescribed by regulation — not to the broader economy of small and mid-sized data handlers, per the same analysis. A new controller/processor framework, modelled on the EU's GDPR, would let processors who act strictly on a controller's documented instructions offload most compliance liability upward, while breach-notification duties tighten to a hard 72-hour deadline for alerting the OAIC once an eligible breach is identified — down from the current 30-day assessment window that dominates today's practice.

The case for it

The strongest argument for the fair-and-reasonable test is that consent-based privacy law has manifestly failed to constrain data practices anyone would call reasonable. Sprawling privacy policies that few users read, pre-ticked boxes, and 'consent' extracted as a condition of using an essential service have let companies do almost anything with personal data as long as it was disclosed somewhere in the fine print. An objective fairness backstop — the kind courts already apply in unconscionable-conduct law — closes that gap without banning any specific business model outright. The erasure right, similarly, responds to a genuine asymmetry: once a handful of dominant platforms hold a comprehensive profile of a user, walking away from the service does nothing to make that data disappear. And a 72-hour breach clock matches Australia's own recent experience — the Optus and Medibank breaches showed how costly slow, uncertain notification can be for both consumers and companies scrambling to respond.

Why the design still needs scrutiny

The risk is that 'fair and reasonable' becomes a floating standard that only gets defined through enforcement actions and litigation years after businesses have built products around today's rules. A consent framework, whatever its flaws, tells a company in advance what it must do to comply. A totality-of-circumstances test tells a company only that a regulator or judge will decide later whether what it did was acceptable — a genuine cost for smaller Australian firms and startups that cannot retain the legal teams multinational platforms can. The government has partly recognised this by scoping the erasure right to large platforms rather than the whole economy, which is the right instinct: erasure obligations at internet-wide scale would have hit thousands of small businesses with compliance costs disproportionate to any actual privacy harm they pose. That same proportionality logic should extend to the fair-and-reasonable test — through safe-harbor guidance, phased enforcement, or a genuine small-business threshold — rather than applying one open-ended standard uniformly from a corner store's loyalty program to a hyperscale ad platform.

The controller/processor split is the most defensible piece of the package: it imports a workable, decade-tested EU concept rather than inventing an Australian-specific liability regime, and it correctly leaves processors who follow documented instructions largely off the hook. Get the fairness test's implementation guidance right during this consultation window, and Australia will have modernised its privacy law without freezing out the smaller innovators the framework claims to protect. Get it wrong, and 'fair and reasonable' becomes another compliance line item only the largest platforms can comfortably absorb — the opposite of what proportionate regulation is supposed to achieve.

Sources & Citations

  1. AG's Department – Privacy Reform Consultation
  2. OAIC – Statutory Tort for Serious Invasions of Privacy
  3. Corrs Chambers Westgarth analysis
  4. IAPP – Australia's second wave of Privacy Act reforms