Australia’s privacy reform is back in the spotlight: What businesses need to know about the 2026 exposure draft
Australia’s privacy reform agenda remains firmly in focus following the release of the Australian Government’s Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026 and accompanying Consultation Paper. The exposure draft contains a number of significant proposals that could require businesses to review and update their policies and processes.
The proposed reforms represent the next major tranche of Australia’s Privacy Act reform, and if enacted in their current form, would introduce significant changes to how organisations collect, use, disclose, secure and ultimately dispose of personal information.
While the proposed reforms are not yet law, they signal a significant shift in how Australian organisations will be expected to handle personal information.
Which privacy law changes could affect your business?
Key proposals contained in the exposure draft include:
- a new “fair and reasonable” standard for handling personal information;
- stronger requirements around consent;
- increased focus on data minimisation and destruction;
- tougher data breach notification obligations, including a proposed 72-hour timeframe;
- greater regulation of data trading and sharing;
- new considerations around AI, tracking and inferred personal information; and
- stronger rights for individuals in relation to their data.
Submissions on the exposure draft are currently being sought. If passed, this would signal a significant change in Australia’s privacy framework since the introduction of the Australian Privacy Principles and could require businesses to make substantial changes to their privacy policies and practices.
While the changes are significant, they are intended to deliver three key outcomes:
- Better privacy protections for Australians;
- Greater certainty for businesses and other entities; and
- A stronger and more efficient privacy regulator.
For many businesses, the challenge will not be understanding the proposed reforms themselves, but understanding what they mean in practice.
How can businesses prepare for Australia’s privacy reforms?
Businesses should consider whether they can confidently answer the following questions:
- What personal information they hold;
- Where it is stored;
- Who has access to it;
- Who they share it with;
- How long they retain it; and
- What happens when something goes wrong.
If the answer to any of these questions is not clear, now is a good time to talk to our privacy experts.
Businesses should not wait for the legislation to change before they start preparing.
Macpherson Kelley’s Privacy team will continue to monitor the progress of the exposure draft and the consultation process. In the meantime, we can help businesses understand the proposed reforms, identify potential gaps and start preparing before the changes become a compliance obligation.
The information contained in this article is general in nature and cannot be relied on as legal advice nor does it create an engagement. Please contact one of our lawyers listed above for advice about your specific situation.
more
insights
stay up to date with our news & insights
Australia’s privacy reform is back in the spotlight: What businesses need to know about the 2026 exposure draft
Australia’s privacy reform agenda remains firmly in focus following the release of the Australian Government’s Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026 and accompanying Consultation Paper. The exposure draft contains a number of significant proposals that could require businesses to review and update their policies and processes.
The proposed reforms represent the next major tranche of Australia’s Privacy Act reform, and if enacted in their current form, would introduce significant changes to how organisations collect, use, disclose, secure and ultimately dispose of personal information.
While the proposed reforms are not yet law, they signal a significant shift in how Australian organisations will be expected to handle personal information.
Which privacy law changes could affect your business?
Key proposals contained in the exposure draft include:
- a new “fair and reasonable” standard for handling personal information;
- stronger requirements around consent;
- increased focus on data minimisation and destruction;
- tougher data breach notification obligations, including a proposed 72-hour timeframe;
- greater regulation of data trading and sharing;
- new considerations around AI, tracking and inferred personal information; and
- stronger rights for individuals in relation to their data.
Submissions on the exposure draft are currently being sought. If passed, this would signal a significant change in Australia’s privacy framework since the introduction of the Australian Privacy Principles and could require businesses to make substantial changes to their privacy policies and practices.
While the changes are significant, they are intended to deliver three key outcomes:
- Better privacy protections for Australians;
- Greater certainty for businesses and other entities; and
- A stronger and more efficient privacy regulator.
For many businesses, the challenge will not be understanding the proposed reforms themselves, but understanding what they mean in practice.
How can businesses prepare for Australia’s privacy reforms?
Businesses should consider whether they can confidently answer the following questions:
- What personal information they hold;
- Where it is stored;
- Who has access to it;
- Who they share it with;
- How long they retain it; and
- What happens when something goes wrong.
If the answer to any of these questions is not clear, now is a good time to talk to our privacy experts.
Businesses should not wait for the legislation to change before they start preparing.
Macpherson Kelley’s Privacy team will continue to monitor the progress of the exposure draft and the consultation process. In the meantime, we can help businesses understand the proposed reforms, identify potential gaps and start preparing before the changes become a compliance obligation.