Tranche 2 privacy reforms unveiled: the proposals and their practical implications

We can now see how privacy regulation is likely to change in the next few years - and the changes will be significant indeed.

The Federal Government has released a consultation paper for the so-called “Tranche 2” privacy reforms, together with a draft Bill titled the Privacy Amendment (Personal Data Protection) Bill 2026 (Cth) (the Bill) to implement these reforms.

No immediate action is required unless you want to make a submission on the draft Bill: there is a very short timeframe until 18 September for that. A commencement date or general transition period have not yet been proposed.

Tranche 2 is the second set of changes arising from the review of the Privacy Act 1988 (Cth) (the Privacy Act) that commenced back in 2020 and which delivered its report in early 2023. The Tranche 1 reforms were implemented by the Privacy and Other Legislation Amendment Act 2024 (Cth).     

Most of the proposed reforms in the Bill flow from the review of the Privacy Act.

In this article we summarise the main changes put forward in the Tranche 2 reforms and discuss some of the possible implications for businesses.

Core definitions

Personal information. Information would be personal information if it “relates to”, rather than is “about”, an identified or reasonably identifiable individual. The connection cannot be merely tenuous, remote, incidental or trivial. An individual could be identifiable even if their name or legal identity is unknown, including where they can be singled out or treated as a distinct person. A definition of reasonably identifiable would be included - this depends on information available to the entity, technical feasibility, cost, effort and controls against re-identification.

Practical implication: Cookie identifiers, device identifiers, customer reference numbers and pseudonymous profiles may be personal information even if the business cannot attach a legal name to them.

Sensitive information. The definition of sensitive information would add genomic information and “precise geolocation tracking data”. The latter means information generated or derived from technology that identifies a person’s location within 500 metres and is held by reference to location over time. A one-off location disclosure is not intended to be captured.

Practical implication: Businesses using continuous location information may need consent and sensitive-information controls even where they previously treated the information as ordinary telemetry.

De-identified information. Information would be de-identified only where, in the circumstances, it no longer relates to an identified or reasonably identifiable individual. De-identification would not be a permanent status.

Practical implication: An organisation cannot rely indefinitely on a one-off de-identification exercise. It may need to reassess re-identification risk as its data holdings and available technologies change.

Collection. An entity would collect information when it includes the information in a record or generally available publication, regardless of its source or how it was obtained. That would expressly cover information obtained from third parties and public sources, as well as information that is derived by processes such as data analysis and artificial intelligence. Special timing rules would apply to inferred sensitive information. If ordinary information is collected for a purpose involving its use as sensitive information, the sensitive information is collected at that point. Otherwise, collection occurs when the inference is first recorded, used or disclosed as sensitive information.

Practical implication: Data inventories will need to record model outputs and derived attributes, not just data received from customers.

Disclosure. Personal information would be disclosed when it is made accessible to another person or body, whether or not the disclosing entity retains control of it. Mere transmission or offshore storage would not itself be disclosure unless another person or body can access the information.

Practical implication: Contractual control over a recipient will no longer necessarily support an argument that no disclosure has occurred. Access permissions and actual system access will matter.

Consent. Consent to the use or disclosure of personal information would have to be voluntary, informed, current, specific and unambiguous. Bundled consents, undefined future purposes, pre-ticked boxes and interfaces that obstruct refusal are unlikely to qualify. Consent could still be implied where the person’s conduct is clear and the purpose is obvious.

Practical implication: Businesses will need evidence of the precise purpose and information covered by each consent, as well as a process to identify when a material change makes an earlier consent stale.

Fair and reasonable test

The current rules dealing separately with solicited collection, unsolicited information, and use and disclosure would largely be replaced by a single rule.

Collection, use and disclosure would have to be lawful, fair and reasonable in the circumstances, unless a permitted general or health situation applies or the handling is required or authorised by law. Giving notice or obtaining consent would not, by itself, make the handling fair and reasonable.

The assessment of what is fair and reasonable would require consideration of:

  • a reasonable person’s expectations, assessed objectively in the context of the relationship and relevant community standards;

  • the connection with the entity’s functions or activities, including whether there is a clear link between the handling and what the entity does;

  • transparency, including whether a reasonable person could understand why and how their information is being handled;

  • data minimisation, including whether the purpose could be achieved using less, less sensitive, de-identified or no personal information;

  • genuine choice, including whether the individual has meaningful and accessible options without unreasonable detriment;

  • impact and proportionality, balancing the likely benefits against the risk and severity of harm to the individual; and

  • for information relating to a child, the child’s best interests, which must be given significant weight as a primary consideration.

No factor is conclusive. A practice will not become fair and reasonable simply because it is described in a privacy policy or the person consented to it.

The reforms would remove current separate requirements to collect directly from an individual, distinguish solicited from unsolicited information and obtain consent for unexpected secondary uses. Those matters would instead form part of the overall assessment.

Practical implication: A privacy notice or consent will no longer be enough to demonstrate compliance. Businesses are likely to need documented assessments showing the purpose, expected benefits, possible harm, alternatives and safeguards for material information-handling activities.

Consent would be required for sensitive information and data trading

An organisation would need consent to collect sensitive information or to trade personal information, unless an exception applies. Collection, use or disclosure would still have to satisfy the fair and reasonable test even where valid consent has been obtained.

Trading personal information. Trading would include disclosure for money or other consideration and disclosure for direct marketing purposes. It may capture transfers of customer lists and disclosures through cookies or pixels used in programmatic advertising. Four activities would be carved out:

  • disclosure necessary to provide a product or service requested by the individual;

  • disclosure incidental to a business sale or acquisition;

  • disclosure to a processor acting under a controller’s documented instructions; and

  • disclosure necessary to prevent, detect, investigate or remedy unlawful activity or serious fraud-related misconduct.

Practical implication: Organisations should identify all arrangements in which personal information is disclosed for value or to support direct marketing, including advertising technology, data matching and referral arrangements.

Publicly available sensitive information. Consent would not be required to collect sensitive information from a publicly available document, including some publicly accessible social media material, but the collection must still be fair and reasonable.

Practical implication: Public availability is not a general licence for scraping or profiling. The purpose, scale and reasonable expectations of affected people will remain relevant.

Strictly necessary services. Consent would not be required where sensitive information is strictly necessary to provide a product or service explicitly requested by the person and there is no less intrusive way to provide it. Its use would be confined to that service and not permitted for direct marketing. A narrower protective test will apply to children.

Practical implication: The exception may assist essential and support services, but “strictly necessary” is a demanding threshold. Convenience or personalisation is unlikely to be enough.

Privacy collection notices would be shorter, but more exact

The prescribed content would be reduced to the fact and circumstances of collection and the purposes for which the entity intends to use or disclose the information. Notices would have to be clear, concise and current, without excessive, vague or irrelevant material. They would need updating when methods or purposes change.

Practical implication: Organisations may be able to shorten notices, but generic purpose statements will carry more risk. Product-specific or layered notices may be needed where collection practices differ.

The serious wrongdoing exception would expand

Permitted General Situation 2 currently allows an entity to collect, use or disclose personal information where it has reason to suspect unlawful activity or misconduct of a serious nature relating to its functions or activities, and reasonably believes the handling is necessary to take appropriate action.

The proposal would replace “misconduct of a serious nature” with the broader concept of “wrongdoing of a serious nature”. This could cover conduct outside an employment, professional or official context, including financial abuse or the misuse of an enduring power of attorney. The existing requirements for suspicion, connection and necessity would remain.

Practical implication: Financial institutions may have clearer grounds to use or disclose information when investigating customer exploitation, including wrongdoing by someone acting in a private capacity.

Direct marketing would cover audience-based advertising

Australian Privacy Principle (APP) 7 would be replaced by a technology-neutral regime covering marketing directed to an individual using personal information, including targeting as part of an audience, segment or cohort. Emails, texts, calls, targeted social advertising and behavioural advertising could all be captured.

The organisation making the communication would have to provide a simple opt-out, explain the opt-out in each communication and take reasonable steps to give effect to it. In multi-party arrangements, a platform would generally bear the obligation unless acting solely as a processor.

An ad-supported service could offer different terms after an opt-out, but only if the person has a genuine choice to continue without direct marketing. Dark patterns or illusory alternatives would not qualify.

Practical implication: Organisations may need systems that recognise and apply a person’s opt-out across different accounts, devices and advertising identifiers. Responsibility for handling opt-outs should also be clear in arrangements with platforms and advertising agencies.

Data breach obligations would start earlier

The reforms would distinguish between a “data breach” and an “eligible data breach”. Obligations to respond to a data breach and prevent or reduce harm would apply even if the breach was not likely to cause serious harm, while the serious-harm threshold would continue to determine whether notification is required.

Entities would have to maintain reasonable practices, procedures and systems for effective breach response. They would also have an ongoing obligation to take reasonable steps to prevent or reduce harm from actual or suspected breaches.

An eligible data breach would still require likely serious harm. Once an entity has reasonable grounds to believe one has occurred, it would have 72 hours to notify the OAIC. The existing 30-day assessment period would remain where there are only grounds to suspect a breach.

An incomplete notice could be submitted where a complete notice is impossible or impracticable within 72 hours. Missing information, material changes and material corrections would then have to be provided as soon as practicable. Individuals would also receive relevant updates. The OAIC could direct an entity to provide a complete statement and notify affected people.

Practical implication: Incident teams will need separate “suspect” and “believe” decision points, a 72-hour reporting process, and the ability to notify before the forensic investigation is complete.

APP 11 would impose active data governance

An entity would have to know what personal information it holds. When information is no longer needed, it would first have to consider destruction before deciding to retain it in de-identified form. It would also have to assess regularly whether its security, destruction and de-identification controls remain effective.

Practical implication: A retention policy without an accurate data inventory and evidence of disposal will not be enough. Periodic security and re-identification reviews will be required.

Access and erasure rights would change

APP 12 currently requires an entity, on request, to give an individual access to personal information it holds about them, subject to specified grounds for refusal. The proposal would add a new ground for refusal where, despite the entity taking reasonable steps, providing access remains unreasonable or impracticable because it is technically impossible or infeasible. The entity could rely on the new exception only to the extent necessary. If some information can be provided, it must still provide access to that information. Deliberately designing a system so that information cannot be retrieved would also be unlikely to satisfy the requirement to take reasonable steps.

Practical implication: Legacy-system limitations may support a partial refusal, but businesses will need evidence of the steps taken and must provide accessible information that is not covered by the exception.

A new erasure right would apply only to large digital platforms. A platform would generally qualify if its corporate group had at least $500 million in gross annual revenue or the platform averaged 2.5 million Australian monthly end users. It would have to destroy personal information on request and give written reasons for any refusal.

Exceptions would cover specified public and legal interests, information strictly necessary for an ongoing service, technical impossibility or infeasibility, frivolous or vexatious requests and information held solely as a processor.

Practical implication: In-scope platforms will need identity verification, data discovery, deletion and decision-recording processes that reach across the corporate group and technical environment.

Controllers and processors would have different responsibilities

A processor would be an APP entity handling information for another APP entity under documented instructions and only for the specified purposes.

The processor would remain directly responsible for APP 1, which concerns open and transparent privacy management, and APP 11, which concerns data security, retention and disposal. For the other APPs, conduct within the controller’s documented instructions would generally be attributed to the controller.

A processor acting outside the instructions would remain responsible for its own conduct.

Practical implication: A generic services agreement will not be enough. Instructions must state the permitted purposes, and contracts should deal with security, deviations, assistance, deletion, audit and incident reporting.

The OAIC would receive wider powers

The reforms would strengthen the powers and efficiency of the Office of the Australian Information Commissioner (OAIC). The changes include a clearer early dispute-resolution process, stronger complaint-management and enforcement powers, improved handling of representative complaints, broader investigation powers and clearer rules governing information-gathering notices. The OAIC would also be able to assess privacy protections used by social media platforms for age-assurance purposes and provide Ministers with information about ongoing investigations.

Practical implication: Taken together, the changes would give the OAIC more effective tools to manage complaints, investigate possible breaches and secure enforcement outcomes.

Research exceptions would be consolidated

The separate health and medical research exceptions would be replaced by one exception for human research by organisations and agencies. The research would need to be reviewed, approved and monitored under the National Statement on Ethical Conduct in Human Research and comply with OAIC guidelines. For qualifying research, consent would not have to be current or specific.

Practical implication: The change may make non-medical research easier, but ethics approval and compliance with the future OAIC guidelines will become central controls.

Emerging-technology rules remain open

The Tranche 2 consultation paper asks whether the proposed definitions and general rules adequately deal with artificial intelligence, smart glasses, other wearable surveillance technology and connected vehicles. It does not yet propose a separate detailed regime for those technologies.

Practical implication: Businesses using these technologies should not assume that the absence of technology-specific rules means no change. Generated inferences, precise location information, covert collection and the fair and reasonable test may already bring the main risks within the proposed framework.

Get in touch if you would like to discuss how the Tranche 2 privacy reforms may affect your business.

 

Next
Next

Financial Services and Credit Monthly Update August 2026