The bill, published on Monday by the Attorney-General’s Department, is the second and most consequential tranche of privacy reform following the 2023 Privacy Act Review, which made more than 100 proposals for change. The first tranche, enacted in late 2024, created a statutory tort for serious invasions of privacy and required privacy policies to disclose automated decision-making systems.
The centrepiece of the new legislation is a requirement that organisations can only collect, use or disclose personal information if doing so is ‘fair and reasonable in the circumstances’. This test is designed to bypass existing loopholes that have allowed broad data practices under vague consent.
The bill modernises key definitions. ‘Personal information’ will cover any data relating to an identifiable person, including nicknames, device identifiers, or behavioural patterns. Inferences drawn by artificial intelligence will also count as ‘collected’ information. The list of ‘sensitive information’ – which requires explicit consent – will now include precise location-tracking data, defined as information that pins a device to within 500 metres and tracks movement over time.
Consent must be voluntary, informed, current, specific, and unambiguous. Pre-ticked boxes and dark patterns will no longer be acceptable. Companies will need specific consent before trading personal data.
For the first time in Australia, the bill introduces a ‘right to be forgotten’, applying to large digital platforms – those with A$500 million in annual revenue or 2.5 million monthly Australian users. Such platforms must delete a user’s data on request, subject to limited exceptions.
Data breach notification requirements will be tightened: organisations must report breaches to the regulator within 72 hours.
The bill contains around 40 measures in total. The government is seeking submissions as part of the consultation process before the legislation proceeds to parliament.