Australia Unveils World-First Fair and Reasonable Test to Reshape Data Collection and Privacy

2 Sources

Share

Australia released draft legislation to modernize the 1988 Privacy Act with a world-first fair and reasonable test for data collection. The reforms introduce stricter consent requirements, a right to be forgotten for large platforms, and shift privacy protection burden from individuals to organizations amid growing concerns over invasive technologies like smart glasses.

Australia Introduces World-First Privacy Framework

The Australian government released draft legislation on Monday for the Privacy Amendment (Personal Data Protection) Bill 2026, marking the most significant overhaul of the nation's outdated privacy laws

1

. At the heart of these Australia privacy reforms sits a world-first fair and reasonable test for data collection that could fundamentally reshape how organizations handle personal information. The bill, now open for public comment alongside a consultation paper, represents the second and most critical tranche of privacy reform following initial changes enacted in late 2024

1

.

The urgency of these reforms cannot be overstated. Australia's privacy laws remain woefully outdated, with the majority having been drafted four decades ago when the Privacy Act was first introduced in 1988, before the web, smartphones, and social media existed

1

2

. The Attorney-General's Department spent three years reviewing the act and reported in 2023 with more than 100 proposals for change, with the government agreeing to most of them in principle

1

.

The Fair and Reasonable Test Shifts Power Dynamics

The centrepiece of the draft legislation is deceptively simple yet revolutionary in approach. Organizations can only collect, use or disclose personal information if doing so is fair and reasonable in the circumstances

1

. This test is unique to Australia and differs fundamentally from approaches in Europe and the United States. While Europe's privacy law asks whether an organization has a legal basis for processing data and the US mostly relies on notice and consent, the Australian test asks whether the data practice itself is fair, even if users ticked the consent box

1

.

Businesses cannot consent their way around this requirement. A privacy policy buried in legal jargon will not save a practice that an ordinary person would never expect

1

. The bill lists specific factors that matter, including what a reasonable person would expect, whether the organization is transparent, and whether it could achieve its purpose with less data. Organizations must also consider whether the person has genuine choice and weigh the risk of harm against benefits. Where children's information is involved, the best interests of the child must be a primary consideration

1

.

This approach shifts the burden of privacy protection from individuals onto organizations, moving Australia towards a digital duty of care in which those who profit from data must actively look after the people it relates to

1

. As Lizzie O'Shea notes, this shifts the onus away from individuals to make impossible decisions about consenting to endless terms and conditions

2

.

Stricter Consent Requirements and Expanded Definitions

The bill modernizes fundamental building blocks of personal data protection. Personal information will cover any information that relates to a person who can be identified, even without a name. A nickname, device identifier or pattern of behaviour can be enough

1

. Critically, AI-generated inferences that artificial intelligence draws about individuals will count as collected information, just like details typed into a form

1

.

The list of sensitive information requiring consent to collect will grow to include precise location-tracking data, defined as information from a device that pins someone down to within 500 metres and follows them over time

1

. Consent itself gets an upgrade under the stricter consent requirements. It must be voluntary, informed, current, specific and unambiguous. Pre-ticked boxes and design tricks will not cut it

1

. Companies will need consent before they trade personal information

1

.

Right to Be Forgotten for Major Platforms

For the first time in Australia, the reforms introduce a right to be forgotten. Large digital platforms with A$500 million in revenue or 2.5 million Australian users a month will have to delete data on request, with some exceptions

1

. Giving individuals the right to request data deletion is hugely important in a context where many people have experienced data breaches involving information they may have shared years before, including with companies they no longer use

2

. This right also matters for those managing specific problems, such as gambling, who don't want that industry or marketing companies to retain that information

2

.

Additionally, data breaches will need to be reported to the regulator within 72 hours

1

, a significant tightening of accountability measures that addresses the unchecked power of tech giants.

Tackling Invasive Technologies Like Smart Glasses

The government is openly worried about wearable technology, particularly smart glasses and earbuds with cameras and microphones that can record people discreetly in public

1

. The consultation paper asks whether the reforms go far enough to deal with this kind of technology. The bill helps in several ways. Video, audio and AI-generated inferences captured by smart glasses will clearly be personal information. Collecting biometric templates, such as mathematical maps of faces used for facial recognition, will also need consent

1

.

The concern is timely given that pervert glasses are selling out at Kmart, facial recognition technology is proliferating in everyday environments, and microtargeting for advertising has filled algorithms with nonsense and toxic content

2

. Privacy reform is hugely popular, with 93% of Australians saying protecting personal information is important to them, and 87% saying they are more concerned about their privacy than they were five years ago

2

.

Critical Gaps in Enforcement and Regulation

While the exposure draft represents a welcome step to modernize the 1988 Privacy Act, significant concerns remain about enforcement. The regulator, the Office of the Australian Information Commissioner, is under-resourced and outmatched in size compared to the corporations it supervises

2

. Well-designed rules mean nothing if they are not enforced. The benefit of a flexible and technology-neutral rule such as the fair and reasonable test will include that it can adapt to community expectations over time and specific situations, but only if people have the right to enforce it directly in court

2

.

Meta's recent US$17bn settlement serves as a case in point. At present, it would be very difficult for an Australian to sue Meta in the way that has been done in the US, even though the harms experienced are the same. It's not even clear that the improvements Meta has committed to making as a result of that case will also be made to their Australian service

2

. This perverse outcome can be addressed if the government makes it plain that both courts and regulators have a role to play in enforcing privacy rights and the digital duty of care

2

.

Another key concern is the spectre of surveillance creeping into all aspects of life. Facial recognition is highly invasive and almost entirely unregulated in Australia, and while some aspects of these reforms might touch on this technology, specific rules for such significant technologies are needed

2

. The reforms, if implemented, will bring Australia closer to similar jurisdictions such as Europe and California, addressing algorithmic toxicity and data-extractive business models that give rise to extremist and misleading content, addictive algorithms and careless product design

2

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved