Privacy reform is coming: Why businesses should act now, not after the Bill passes

0

The Attorney-General’s exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 would bring the most significant changes to the Privacy Act 1988 since the introduction of the Australian Privacy Principles, according to Holding Redlich General Counsel Lyn Nicholson.

In comments provided to MySecurity Media, Nicholson said the reform direction is clear even if the draft Bill changes during the parliamentary process, and warned organisations against waiting until legislation is finalised before beginning compliance work.

“While the Bill may change as it moves through Parliament, the direction of reform is clear. The proposed changes would expand obligations around consent, data handling, data security, data breaches and the retention and destruction of personal information.

“Importantly, organisations should not assume they can wait until the legislation is passed before taking action. Many of the proposed reforms would require operational and governance changes that could take time to implement.

“For example, the Bill introduces a new, codified standard for consent. For the first time, the Privacy Act would define what constitutes valid consent, requiring it to be voluntary, informed, current, specific and unambiguous. Pre-ticked boxes, bundled consents, and stale or generic consent language are unlikely to satisfy this standard. Every privacy collection statement, consent flow, cookie banner and marketing opt-in will need to be reviewed against this five-part test.

“The proposed reforms would also broaden the definition of personal information and introduce a new requirement for the collection, use and disclosure of personal information to be fair and reasonable. The Bill would also impose tougher obligations around data retention, destruction and ongoing compliance monitoring.

“The notifiable data breach scheme is also substantially rebuilt, with a requirement to notify the Privacy Commissioner of an eligible data breach within 72 hours, a significant shift from the current ‘as soon as practicable’ standard. For many organisations, the question will be whether their existing incident response plans and processes can meet that deadline.

“The Bill also creates a new privacy principle giving individuals the right to require large digital platforms to destroy their personal information on request, subject to limited exceptions. Qualifying platforms will need erasure request-handling processes, response-timeframe tracking and clear internal criteria for when an exception applies.

“Businesses that use the lead time before the reforms are finalised to assess gaps and begin planning will be better placed to manage implementation than those that wait for the final legislation.”

Share.