Privacy Act Tranche 2: What the Draft Bill Means for Australian Businesses
10 October 2026 · Compliance365
On 31 August 2026 the Attorney-General's Department released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, the second tranche of Privacy Act reforms, with a consultation paper. Consultation closed on 18 September 2026.
It is not law. The Government has said it intends to introduce the Bill before the end of 2026, and the final text may change. This post covers what the draft proposes and what is worth doing now, whatever the final wording.
The main proposals
A “fair and reasonable” test for everything you do with personal information
The draft replaces the current collection, use and disclosure principles (APPs 3, 4 and 6) with a single test: collection, use and disclosure must be fair and reasonable, judged against a list of factors set out in the Act. Commentators describe this as the biggest change in the draft. “It’s in our privacy policy” or “they ticked the box” stops being enough on its own; the handling itself has to be fair.
Consent that means something
Where consent is needed, the draft requires it to be voluntary, informed, current, specific and unambiguous. Bundled consents (“by using this site you agree to everything”) and consents collected years ago for another purpose are unlikely to meet that standard. Separate consent requirements apply to collecting sensitive information and to trading personal information.
A 72-hour breach statement to the OAIC
Today, an organisation that suspects an eligible data breach has up to 30 days to assess it. The draft adds a requirement to give the OAIC a statement within 72 hours of having reasonable grounds to believe an eligible breach has occurred. An incomplete statement can be given first, with the full details as soon as practicable. Missing the deadline would be a civil penalty contravention.
Other changes in the draft
- Sensitive information would expressly include precise geolocation tracking data and genomic information.
- Direct marketing (APP 7) would be replaced with a simpler, technology-neutral regime, with an opt-out on every communication.
- A right to erasure is included, but summaries of the draft say it applies only to large digital platforms.
What the draft does not change
Two things many businesses were watching are not in the draft:
- The small business exemption stays. Businesses with annual turnover of $3 million or less remain outside the Act, unless they are already covered for another reason (health service providers, for example).
- The employee records exemption stays. Private sector employers remain outside the Act for their own employee records.
There are also no commencement dates or transition periods in the draft yet. Commentators note that many of the new requirements would apply to personal information you already hold, not only to what you collect after the law starts.
Don’t confuse this with 10 December 2026
A separate change from the first tranche (the 2024 amendments) does start on 10 December 2026: privacy policies must explain when computer programs make, or substantially and directly inform, decisions that significantly affect people. That is already law. We cover it in Automated decisions and your privacy policy.
What to prepare now
Whatever the final Bill says, these steps help today and line up with the draft:
- Know what personal information you hold, where, and why. A record of processing activities (RoPA) is the foundation for a fair-and-reasonable assessment. See what a good RoPA looks like.
- Review how you collect consent. List where you rely on it, and flag bundled, pre-ticked or very old consents.
- Rehearse a 72-hour breach statement. Decide who drafts it, who approves it and what it contains. Run a tabletop exercise against the clock.
- Check marketing opt-outs work on every channel and are actioned promptly.
- Treat the exemptions as current law, not a plan. If you sit under the $3 million threshold, the draft doesn’t change that, but your larger customers will still ask how you handle their data.
If you want a structured way to do this, ISO 27701 adds a privacy management system to ISO 27001 and covers most of the groundwork. See our Privacy Act readiness guide and ISO 27701 service.
Sources
- Attorney-General’s Department, Exposure draft: Privacy Amendment (Personal Data Protection) Bill 2026
- Gilbert + Tobin, One giant leap: Tranche 2 of Privacy Act reform (exemptions unchanged, no transition dates, applies to information already held)
- Johnson Winter Slattery, Second tranche of Australian Privacy Act reform (72-hour statement, direct marketing)
- HSF Kramer, The draft tranche 2 Privacy Act reforms (intended introduction before the end of 2026)
- McCullough Robertson, Privacy Act reforms: tranche 2 proposals
This is general information, not legal advice. Last reviewed 10 October 2026.
Found this useful? Get the ISO/Privacy/AI readiness checklists.
Browse resources