Australia's Privacy Laws Are Changing (Again). Here's What Your Business Actually Needs to Know

If you run a business in Australia, you've probably heard that privacy law reform has been "coming" for years. It has. And now it's arriving in stages. Some of it has already become law, while others are still in the works, but they are close enough that smart businesses are preparing early.

Prevention is always better than cure, especially when it comes to privacy compliance. Here's where things stand as of September 2026 and what it means for the privacy policy on your website right now. 

Key Takeaways

  • Some privacy law changes are already in force, including a new doxxing offence, a statutory tort, stronger OAIC powers, and an expanded "reasonable steps" security standard.

  • From 10 December 2026, privacy policies must disclose automated decision-making that significantly affects a person's rights, alongside the new Children's Online Privacy Code.

  • A "fair and reasonable" test for handling personal information is proposed under Tranche 2, but it isn't law yet.

What's changing in Australian privacy law right now? 

Australian privacy law is changing in two stages. Tranche 1, the Privacy and Other Legislation Amendment Act 2024, is already law and mostly in effect. Two reforms stemming from this act will be in effect by 10 December 2026. Tranche 2 is a 2026 Exposure Draft Bill, the Privacy Amendment (Personal Data Protection) Bill 2026, with around 40 proposals. It isn't law yet; submissions close on 18 September 2026, and it could still change before Parliament introduces it. 

What's already law under Australia's 2024 privacy reforms? 

Since the Privacy and Other Legislation Amendment Act 2024 came into force, several key changes already apply. A new doxxing offence and a statutory tort for serious invasions of privacy now give individuals a direct legal right to sue over privacy breaches. The OAIC (Office of the Australian Information Commissioner) also has stronger enforcement powers, including civil penalties and compliance notices. Additionally, businesses must take "reasonable steps" to secure personal information, covering both technical and organisational measures. 

This means the OAIC can move straight to a civil penalty or a compliance notice, without first running a full investigation and formal determination. For a business, that shortens the runway between a complaint landing and the real consequences that follow. And "reasonable steps" now expressly covers organisational measures too, so a firewall or encryption alone won't cut it. You'll also need policies, training and governance behind your data security. 

What are the two reforms that will take effect from December 2026? 

From 10 December 2026, two privacy reforms take effect. Privacy policies must disclose where a business uses personal information in automated decision-making that could significantly affect someone's rights or interests, such as credit scoring, algorithmic pricing, or automated application rejections. The Children's Online Privacy Code also comes into force on the same date, aimed at social media, gaming, and ed-tech platforms likely to be accessed by children, rather than most commercial or property businesses.

The use of personal information in automated decision-making isn't limited to obvious AI tools. It can include any automated process your business uses that meaningfully affects another person, especially if you're in a property business handling confidential information on tenants or buyers. Even if a human is involved, it still counts if they aren't actively exercising judgement; they're just rubber-stamping what the system decides.

What's proposed in Australia's Tranche 2 privacy reforms? 

The Exposure Draft Bill would replace Australia's Privacy Act rules on collecting, using and disclosing personal information (APPs 3, 4 and 6) with a new "fair and reasonable" test. Instead of following a checklist, businesses would weigh factors like reasonable expectations, business purpose, transparency, and impact on the individual. In practice, this shifts privacy compliance from "Did we follow the rule?" to "Can we justify this decision?", making documentation far more important.

Other proposed changes worth watching:

  • Consent gets a formal definition. It would need to be voluntary, informed, current, specific and unambiguous, which would make pre-ticked boxes, bundled consents and "take it or leave it" terms much harder to rely on.

  • A new concept of "trading" personal information would require consent whenever personal information is disclosed for money or for direct marketing purposes, subject to some carve-outs.

  • Direct marketing rules would be simplified but tightened. A technology-neutral definition would cover everything from email to targeted social advertising, with a mandatory simple opt-out.

  • Data breach response gets faster and more structured. There's a proposed 72-hour deadline to notify the OAIC of an eligible data breach and a new positive obligation to actually have breach-response systems in place before something goes wrong, not just a plan for what to do after.

  • A right to erasure, but only for "large digital platforms" (very roughly, revenue over $500 million or more than 2.5 million monthly Australian users). Unless you're a major platform operator, this one is unlikely to apply directly to you, though it's a useful trend to be aware of if you're a smaller platform hoping to scale.

What can you do as an Australian business to prepare for the privacy reforms? 

This reform is unfolding in two stages, so we'd recommend a response that reflects both.

  1. Get the automated decision-making clause sorted well before December 2026. This is a firm legal obligation with a fixed deadline, not a proposal.

  2. Begin reviewing your privacy policy against the direction of the "fair and reasonable" test, even though it isn't law yet. Businesses that already document why they collect and use information, not just that they do, will have a much easier transition once Tranche 2 passes.

We've put together a practical checklist to help you work through both, which you can download below. And if you'd like a proper review of your privacy policy against where the law is heading, that's exactly the kind of thing we're here for.

This article is general information only and doesn't constitute legal advice. If you'd like advice tailored to your business, get in touch with our team.


About the Author: Erin Vassallo

Erin Vassallo is the Principal Solicitor and founder of Law Team, a values-led law firm with a strong reputation across New South Wales and Queensland. With over two decades of experience in commercial, construction, and property development law, Erin is a trusted advisor to developers, landowners, and business owners navigating complex projects and legal risk.

Her hands-on experience includes joint ventures, structuring development deals, contract negotiation, risk mitigation, and project governance across residential, commercial, and mixed-use developments. Erin holds qualifications in law, political science, mediation, and disruptive strategy (Harvard Business School) and is the founder of Certified BCorp Law Team, committed to ethical business practices and social impact.

Frequently Asked Questions

Previous
Previous

Automated Decision-Making Disclosure: Why Every Business Should Audit Its Systems Before December 2026 

Next
Next

Getting Paid, Not Chasing Paid: How the Security of Payment Act Actually Works