On 18 September 2026, the AICD provided a submission to the Attorney-General’s Department (Department) on the consultation paper and exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 (Exposure Draft), which proposes significant amendments to the Privacy Act 1988 (Privacy Act).
The AICD supports reforms that modernise Australia’s privacy framework to reflect a digital economy, but considers that the Exposure Draft does not appropriately achieve these objectives. We remain concerned that there is no clear policy or public benefit case for many of the proposed reforms, and that the benefits and harms being addressed have not been adequately demonstrated. We also highlighted the significant compliance costs and implementation challenges the package would create for organisations.
We therefore recommended that the Department pause progression of the Exposure Draft and undertake further targeted consultation with business, community organisations and privacy experts before introducing legislation to Parliament.
The key points in our submission were:
Policy process and regulatory impact: We expressed significant concerns about the consultation process, including the two-and-a-half-week consultation period for a package of reforms that would fundamentally reshape Australia’s privacy framework. On this basis, we recommended that the Department pause progression of the Exposure Draft, undertake further consultation on key proposals and publish a comprehensive impact analysis covering the costs, benefits and productivity implications of all reforms before legislation is introduced to Parliament.
Definitions of personal information and consent: We supported in principle updating the definitions of personal information and consent to reflect modern digital environments. However, the proposed changes would substantially expand the scope of information captured by the Privacy Act and have significant operational consequences for entities. We therefore recommended a minimum 24-month implementation period supported by detailed guidance from the Office of the Australian Information Commissioner (OAIC) to support compliance .
Fair and reasonable test: We supported outcomes-based privacy regulation in principle, but raised concerns that the proposed ‘fair and reasonable’ test would create uncertainty, duplication and inconsistency by operating alongside existing Privacy Act obligations. Instead, we considered that the Productivity Commission’s proposal for an overarching outcomes-based privacy duty would be a more effective approach. At a minimum, our view is that comprehensive OAIC guidance would be required to support implementation.
Direct marketing and trading of information: We noted that direct marketing can provide important benefits to consumers and support competition, innovation and customer choice. We expressed concern that the cumulative effect of the proposed reforms, including new consent requirements and expanded definitions, could create substantial compliance costs and uncertainty, particularly in relation to online advertising, acquisitions and the transfer of information within corporate groups. We recommended greater clarity on how the trading of information provisions would operate in practice.
Data security and breach reporting: While supporting modernisation of the Notifiable Data Breaches scheme in principle, we cautioned against reforms that would increase complexity and duplication in cyber incident reporting. We opposed requirements for entities to provide incomplete notifications before they have sufficient visibility of an incident, and recommended greater flexibility in notifying affected individuals. We also emphasised the need for better coordination between regulators and alignment with broader cyber security reporting obligations.
Right to erasure on large digital platforms: We welcomed the decision to limit the proposed right to erasure to large digital platforms rather than applying it economy-wide, but recommended further refinement to ensure the obligation does not inadvertently capture entities beyond its intended scope.
Commencement, guidance and statutory review: We also recommended that any reforms be supported by a minimum 24-month commencement period, comprehensive OAIC guidance, a regulatory implementation roadmap, and a statutory review three years after commencement to assess effectiveness, unintended consequences and opportunities for improvement.
Latest news
Already a member?
Login to view this content