2 Sources
[1]
Australia is eyeing a world-first 'fair and reasonable' test for data collection and privacy
On Monday, the Australian government released draft legislation for the next big overhaul of the Privacy Act. The Privacy Amendment (Personal Data Protection) Bill 2026 is now out for public comment, together with a consultation paper. It is the second instalment (or "tranche") of privacy reform , and it is the one that matters most. The bill contains dozens of new measures, such as stronger consent requirements and a "right to be forgotten", but at its heart is a world-first test that could bypass many loopholes companies use to justify what they do with personal data. How we got here The Privacy Act was introduced in 1988, before the web, smartphones, and social media. The Attorney-General's Department spent three years reviewing it and reported in 2023 with more than 100 proposals for change. The government agreed with most of them, at least in principle. The first tranche of reforms became law in late 2024. These created a new right to sue for serious invasions of privacy. This "statutory tort" (a wrong you can take to court), tackled doxxing, and promised a children's online privacy code. Tranche one also included a requirement for privacy policies to disclose whether they use automated decision-making systems to make decisions that could reasonably be expected to significantly affect an individual's rights or interests. This will come into effect in December. This new bill is the main course of the reforms. It contains around 40 measures that, if enacted, will change how every business and government agency covered by the act handles our personal information. What's in it? The bill modernises the basic building blocks. "Personal information" will cover any information that relates to a person who can be identified, even without a name. A nickname, a device identifier or a pattern of behaviour can be enough. Inferences that artificial intelligence (AI) draws about you will count as "collected" information, just like details you type into a form. The list of "sensitive information" (the category that requires your consent to collect) will grow. It now includes precise location-tracking data. That means information from a device that pins you down to within 500 metres and follows you over time. Consent to data collection gets an upgrade. It must be voluntary, informed, current, specific and unambiguous. Pre-ticked boxes and design tricks will not cut it. There are other headline items. Companies will need your consent before they trade your personal information. Large digital platforms (those with A$500 million in revenue or 2.5 million Australian users a month) will have to delete your data on request, with some exceptions. This means a "right to be forgotten" for the first time in Australia. Also, data breaches will need to be reported to the regulator within 72 hours. The big idea is "fair and reasonable" The centrepiece of the draft legislation is deceptively simple. An organisation can only collect, use or disclose your personal information if doing so is "fair and reasonable" in the circumstances. This test is unique to Australia. Europe's privacy law asks whether an organisation has a legal basis for processing data. The United States mostly relies on notice and consent, which in practice means clicking "I agree" to terms nobody reads. The Australian test asks a different question: even if you ticked the box, was the data practice itself fair? That is the crucial point. Businesses cannot consent their way around it. A privacy policy buried in legal jargon will not save a practice that an ordinary person would never expect. The bill lists the factors that matter. They include what a reasonable person would expect, whether the organisation is transparent about what it is doing, and whether it could achieve its purpose with less data. An organisation must also consider whether the person has a genuine choice, and weigh the risk of harm against the benefits. Where children's information is involved, the best interests of the child must be a primary consideration. In effect, this shifts the burden of privacy protection from individuals onto organisations, moving Australia towards a digital duty of care in which those who profit from our data must actively look after the people it relates to. What about smart glasses? The government is openly worried about wearable technology. Smart glasses and earbuds with cameras and microphones can record people discreetly in public. The consultation paper asks whether the reforms go far enough to deal with this kind of technology. The bill helps in several ways. Video, audio and AI-generated inferences captured by smart glasses will clearly be personal information. Collecting biometric templates (such as mathematical maps of faces used for recognition) will also need consent. Companies deploying these devices will have to show their data handling is fair and reasonable. There is a gap, though. The Privacy Act generally does not allow an individual to take legal action. This is despite the 2023 review recommending that the act should provide a private right of action, and the government accepting this recommendation in principle. If a stranger films you with their glasses at a cafe, your main remedy is the statutory tort from the first tranche of reforms, and few people know it exists. It is also expensive to litigate. The consultation paper asks what else might be needed. What happens next The exposure draft is open for comment until September 18, and the final bill will follow once the feedback is in. Expect a fight. Business groups will worry about uncertainty in the fair and reasonable test, and privacy advocates will push for it to have teeth. The direction, however, is clear. Australia is betting that fairness, not fine print, should decide what happens to our personal information.
[2]
Tech giants are trying to obliterate privacy. Australia has a rare chance to take back part of their power | Lizzie O'Shea
'Pervert glasses' are selling out, tick-a-box consent is broken and the spectre of surveillance is invading all aspects of our lives A mere five years after the government first started talking about it, new changes have finally been proposed for the Privacy Act. They could not be more overdue and urgent. 'Pervert glasses' are selling out at Kmart, facial recognition technology is proliferating in our everyday environments, and microtargeting for advertising has filled our algorithms with nonsense and toxic junk. Privacy reform is hugely popular: 93% of Australians say protecting personal information is important to them, and 87% say they are more concerned about their privacy than they were five years ago. But it is practically impossible for us to take personal responsibility for our data footprint, especially in the age of AI. Tick-a-box consent is a broken model. Australians rate protecting our personal information as their number one priority for AI regulation. Granting strong legal protections over personal information is one of the most important and impactful ways to reshape technology in the interests of the many, not the few. Data-extractive business models give rise to all sorts of negative downstream consequences, such as extremist and misleading content, addictive algorithms and careless product design. Privacy law has the capacity to target reform at the source of the problem - the collection, use and storage of personal information. This is far more effective than playing whack-a-mole with the latest exploitative or harmful product built by some avaricious tech bro who has been encouraged by our permissive regulatory environment. Australia's privacy laws remain woefully out of date, with the majority having been drafted four decades ago. This latest tranche of reform, if implemented, will be a highly significant improvement, bringing us closer to similar jurisdictions such as Europe and California. At the centre is a fair and reasonable test. This shifts the onus away from individuals to make impossible decisions about consenting to endless terms and conditions, instead posing the question to companies: are you collecting and using this information in a way that is fair and reasonable? Interestingly, the government has also opted to introduce certain provisions around the right to erasure. Giving individuals the right to request that data be deleted is hugely important in a context where many people have experienced a data breach involving information they may have shared years before, including with companies they no longer use. It's also important if you have a particular reason for wanting to delete: for example, you are managing a problem with gambling, and you don't want that industry or marketing companies to know that about you. There are some carve-outs and limitations in the current proposal, but this next little while offers a great opportunity to convince the government to tighten these up. While this exposure draft is a welcome step, the government needs to do more. Well-designed rules mean nothing if they are not enforced. The regulator, the Office of the Australian Information Commissioner, is under-resourced and outmatched in size compared to the corporations it supervises. The benefit of a flexible and technology-neutral rule such as the fair-and-reasonable test will include that it can adapt to community expectations over time and specific situations - but only if we allow people the right to enforce it directly in court. Courts have a really important role to play in interpreting and applying the rules: Meta's recent US$17bn settlement serves as a case in point. Cases brought by people harmed by these companies allow evidence to come to light that can shape effective rule-making by our governments. Perhaps most importantly, they send a chill through boardrooms of companies that have to date banked on escaping the scrutiny of regulators. This is a problem for another important policy: the digital duty of care. It's a great idea but it also has to be enforced for it to be meaningful. At present, it would be very difficult for an Australian to sue Meta in the way that has been done in the US, even though the harms we experience are the same. It's not even clear that the improvements Meta has committed to making as a result of that case will be also made to their Australian service. Such a perverse outcome can be addressed if the government makes it plain that both courts and regulators have a role to play in enforcing privacy rights and the digital duty of care. The other key concern is the spectre of surveillance creeping into all aspects of our lives. Facial recognition technology is highly invasive and almost entirely unregulated in Australia and, while some aspects of these reforms might touch on this tech, we really need specific rules for such significant technologies. There are pre-existing proposals we could introduce immediately, which are in line with rules in other comparable countries. Privacy reform may seem wonkish or a lost cause but, in reality, it's one of the best tools we have to take back power from big tech and creepy companies. This proposal is a great first step but it can't be the only one.
Share
Copy Link
Australia released draft legislation to modernize the 1988 Privacy Act with a world-first fair and reasonable test for data collection. The reforms introduce stricter consent requirements, a right to be forgotten for large platforms, and shift privacy protection burden from individuals to organizations amid growing concerns over invasive technologies like smart glasses.
The Australian government released draft legislation on Monday for the Privacy Amendment (Personal Data Protection) Bill 2026, marking the most significant overhaul of the nation's outdated privacy laws
1
. At the heart of these Australia privacy reforms sits a world-first fair and reasonable test for data collection that could fundamentally reshape how organizations handle personal information. The bill, now open for public comment alongside a consultation paper, represents the second and most critical tranche of privacy reform following initial changes enacted in late 20241
.The urgency of these reforms cannot be overstated. Australia's privacy laws remain woefully outdated, with the majority having been drafted four decades ago when the Privacy Act was first introduced in 1988, before the web, smartphones, and social media existed
1
2
. The Attorney-General's Department spent three years reviewing the act and reported in 2023 with more than 100 proposals for change, with the government agreeing to most of them in principle1
.The centrepiece of the draft legislation is deceptively simple yet revolutionary in approach. Organizations can only collect, use or disclose personal information if doing so is fair and reasonable in the circumstances
1
. This test is unique to Australia and differs fundamentally from approaches in Europe and the United States. While Europe's privacy law asks whether an organization has a legal basis for processing data and the US mostly relies on notice and consent, the Australian test asks whether the data practice itself is fair, even if users ticked the consent box1
.Businesses cannot consent their way around this requirement. A privacy policy buried in legal jargon will not save a practice that an ordinary person would never expect
1
. The bill lists specific factors that matter, including what a reasonable person would expect, whether the organization is transparent, and whether it could achieve its purpose with less data. Organizations must also consider whether the person has genuine choice and weigh the risk of harm against benefits. Where children's information is involved, the best interests of the child must be a primary consideration1
.This approach shifts the burden of privacy protection from individuals onto organizations, moving Australia towards a digital duty of care in which those who profit from data must actively look after the people it relates to
1
. As Lizzie O'Shea notes, this shifts the onus away from individuals to make impossible decisions about consenting to endless terms and conditions2
.The bill modernizes fundamental building blocks of personal data protection. Personal information will cover any information that relates to a person who can be identified, even without a name. A nickname, device identifier or pattern of behaviour can be enough
1
. Critically, AI-generated inferences that artificial intelligence draws about individuals will count as collected information, just like details typed into a form1
.The list of sensitive information requiring consent to collect will grow to include precise location-tracking data, defined as information from a device that pins someone down to within 500 metres and follows them over time
1
. Consent itself gets an upgrade under the stricter consent requirements. It must be voluntary, informed, current, specific and unambiguous. Pre-ticked boxes and design tricks will not cut it1
. Companies will need consent before they trade personal information1
.For the first time in Australia, the reforms introduce a right to be forgotten. Large digital platforms with A$500 million in revenue or 2.5 million Australian users a month will have to delete data on request, with some exceptions
1
. Giving individuals the right to request data deletion is hugely important in a context where many people have experienced data breaches involving information they may have shared years before, including with companies they no longer use2
. This right also matters for those managing specific problems, such as gambling, who don't want that industry or marketing companies to retain that information2
.Additionally, data breaches will need to be reported to the regulator within 72 hours
1
, a significant tightening of accountability measures that addresses the unchecked power of tech giants.Related Stories
The government is openly worried about wearable technology, particularly smart glasses and earbuds with cameras and microphones that can record people discreetly in public
1
. The consultation paper asks whether the reforms go far enough to deal with this kind of technology. The bill helps in several ways. Video, audio and AI-generated inferences captured by smart glasses will clearly be personal information. Collecting biometric templates, such as mathematical maps of faces used for facial recognition, will also need consent1
.The concern is timely given that pervert glasses are selling out at Kmart, facial recognition technology is proliferating in everyday environments, and microtargeting for advertising has filled algorithms with nonsense and toxic content
2
. Privacy reform is hugely popular, with 93% of Australians saying protecting personal information is important to them, and 87% saying they are more concerned about their privacy than they were five years ago2
.While the exposure draft represents a welcome step to modernize the 1988 Privacy Act, significant concerns remain about enforcement. The regulator, the Office of the Australian Information Commissioner, is under-resourced and outmatched in size compared to the corporations it supervises
2
. Well-designed rules mean nothing if they are not enforced. The benefit of a flexible and technology-neutral rule such as the fair and reasonable test will include that it can adapt to community expectations over time and specific situations, but only if people have the right to enforce it directly in court2
.Meta's recent US$17bn settlement serves as a case in point. At present, it would be very difficult for an Australian to sue Meta in the way that has been done in the US, even though the harms experienced are the same. It's not even clear that the improvements Meta has committed to making as a result of that case will also be made to their Australian service
2
. This perverse outcome can be addressed if the government makes it plain that both courts and regulators have a role to play in enforcing privacy rights and the digital duty of care2
.Another key concern is the spectre of surveillance creeping into all aspects of life. Facial recognition is highly invasive and almost entirely unregulated in Australia, and while some aspects of these reforms might touch on this technology, specific rules for such significant technologies are needed
2
. The reforms, if implemented, will bring Australia closer to similar jurisdictions such as Europe and California, addressing algorithmic toxicity and data-extractive business models that give rise to extremist and misleading content, addictive algorithms and careless product design2
.Summarized by
Navi
[1]
22 Apr 2026•Policy and Regulation

18 Oct 2024•Policy and Regulation

11 Sept 2024

1
Technology

2
Policy and Regulation

3
Technology
