Australia Unveils World-First ‘Fair and Reasonable’ Test in Major Privacy Overhaul

Draft legislation proposes stronger consent, a right to be forgotten, and 72-hour breach reporting as part of the second tranche of Privacy Act reforms.

edit
By LineZotpaper
Published
Read Time2 min
The Australian government has released draft legislation for a sweeping overhaul of the Privacy Act, introducing a world-first ‘fair and reasonable’ test that could close many loopholes companies use to justify data collection. The Privacy Amendment (Personal Data Protection) Bill 2026, now open for public comment, also strengthens consent requirements, expands the definition of personal information, and creates a right to be forgotten for large digital platforms.

The bill, published on Monday by the Attorney-General’s Department, is the second and most consequential tranche of privacy reform following the 2023 Privacy Act Review, which made more than 100 proposals for change. The first tranche, enacted in late 2024, created a statutory tort for serious invasions of privacy and required privacy policies to disclose automated decision-making systems.

The centrepiece of the new legislation is a requirement that organisations can only collect, use or disclose personal information if doing so is ‘fair and reasonable in the circumstances’. This test is designed to bypass existing loopholes that have allowed broad data practices under vague consent.

The bill modernises key definitions. ‘Personal information’ will cover any data relating to an identifiable person, including nicknames, device identifiers, or behavioural patterns. Inferences drawn by artificial intelligence will also count as ‘collected’ information. The list of ‘sensitive information’ – which requires explicit consent – will now include precise location-tracking data, defined as information that pins a device to within 500 metres and tracks movement over time.

Consent must be voluntary, informed, current, specific, and unambiguous. Pre-ticked boxes and dark patterns will no longer be acceptable. Companies will need specific consent before trading personal data.

For the first time in Australia, the bill introduces a ‘right to be forgotten’, applying to large digital platforms – those with A$500 million in annual revenue or 2.5 million monthly Australian users. Such platforms must delete a user’s data on request, subject to limited exceptions.

Data breach notification requirements will be tightened: organisations must report breaches to the regulator within 72 hours.

The bill contains around 40 measures in total. The government is seeking submissions as part of the consultation process before the legislation proceeds to parliament.

§

Analysis

Why This Matters

  • The ‘fair and reasonable’ test is a novel legal standard that could reshape how every business and government agency handles personal data in Australia.
  • Stronger consent rules and the right to be forgotten give individuals more control over their information, particularly on large digital platforms.
  • If enacted, Australia’s approach could influence privacy regulation globally, as the first jurisdiction to adopt a standalone ‘fair and reasonable’ requirement.

Background

The Privacy Act was enacted in 1988, before the rise of the internet, smartphones, and social media. In 2023, the Attorney-General’s Department released a review with over 100 recommendations for reform, most of which the government accepted in principle. The first tranche of reforms became law in late 2024, establishing a right to sue for serious invasions of privacy and a children’s online privacy code. The new bill represents the main substantive overhaul, targeting the ways companies collect, use, and share personal data in the modern digital economy.

Key Perspectives

Privacy advocates and consumer groups: The reforms are a long-overdue update that closes loopholes and gives Australians meaningful control over their personal data, especially from large tech platforms. Business and industry groups: While many support clearer rules, the compliance burden of the new test, expanded definitions, and 72-hour breach reporting may be significant, particularly for small and medium enterprises. Some may argue the ‘fair and reasonable’ standard lacks precise guidance. Critics and skeptics: Enforcement will be key; without strong regulatory resources and penalties, the new rights could prove difficult to exercise. The definition of ‘large digital platforms’ may create gaps that allow some companies to avoid the right to be forgotten.

What to Watch

  • Outcomes of the public consultation process, which will test industry acceptance and highlight potential implementation challenges.
  • The parliamentary timeline – whether the bill passes before the next federal election or faces delays.
  • How the Office of the Australian Information Commissioner (OAIC) prepares to enforce the new obligations, including the resourcing of its enforcement capacity.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.