Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Back To Home
Privacy Act Reforms

Introduction
Australia’s data protection framework is undergoing a structural redesign since the enactment of the Privacy Act 1988 (Cth). While the initial legislative tranche under the Privacy and Other Legislation Amendment Bill 2024 introduced targeted enforcement powers, higher corporate penalties, and a statutory tort for serious invasions of privacy, it deliberately left the day-to-day architecture of information handling untouched.
That deliberate restraint has ended with the release of the second reform wave by the Australian Government. Centred around the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 and an accompanying consultation paper from the Attorney-General's Department, this new package directly addresses how organisations collect, evaluate, and retain personal information. As highlighted in governance analyses of the second wave, these proposals represent a decisive shift from passive notice-and-consent routines toward active, objective institutional accountability.
Redefining the Baseline of the “Fair and Reasonable” Test
The centrepiece of the second wave is the dismantling of the traditional, mechanical rules governing collection and disclosure under Australian Privacy Principles (APPs) 3, 4, and 6. In their place, the proposed framework introduces an overarching requirement: organisations may only collect, use, or disclose personal information if doing so is fair and reasonable in the circumstances.
Crucially, this standard operates independently of consent. An organisation can no longer sanitise disproportionate tracking or unnecessary data harvesting simply by hiding broad disclosures inside lengthy, unread terms of service. To determine whether processing meets the fair-and-reasonable threshold, entities must weigh objective criteria, including the individual’s reasonable expectations, the necessity and proportionality of the processing relative to business functions, the degree of transparency provided, and the risk of adverse impact or harm. This fundamentally alters data governance by placing the burden of justified data collection squarely on the enterprise rather than the consumer.
Expanding the Perimeter of Personal Information
Alongside the fair-and-reasonable test, the proposals broaden the statutory perimeter of what qualifies as regulated information. Currently, the Act applies strictly to information “about” an individual. The proposed amendment aligns Australia with standards established under Article 4 of the EU GDPR by expanding the threshold to cover any information relating to an identified or reasonably identifiable individual.
This change brings modern digital telemetry into the scope of the Act. Behavioural profiles, IP address histories, tracking pixels, mobile advertising identifiers, and algorithmic inferences derived from artificial intelligence models will no longer escape regulation under the claim that they are mere technical metadata. Furthermore, the definition of “sensitive information” is formally updated to encompass precise geolocation tracking trails and genomic data, subjecting these telemetry streams to heightened consent and security safeguards.
Institutional Accountability: Controllers, Erasure, and Breach Deadlines
Beyond definitional shifts, the second wave restructures enterprise operational obligations in three keyways:
The proposals introduce an explicit legislative distinction between controllers (entities that determine the purpose and means of processing) and processors (service providers that process data strictly on documented instructions). This provides clear boundaries for liability across cloud supply chains, bringing Australia into harmony with global privacy architectures.
The draft creates a statutory right to erasure. While currently calibrated around large digital platforms meeting designated scale thresholds, this mechanism sets the legislative precedent for user-initiated data purges, compelling organisations to architect verifiable deletion pipelines across production environments and data lakes rather than relying on superficial logical flags.
The framework tightens regulatory breach reporting by replacing the ambiguous as soon as practicable threshold with a strict 72-hour notification deadline to the Office of the Australian Information Commissioner (OAIC) once an entity has reasonable grounds to believe an eligible data breach has occurred. This compressed timeline leaves no margin for administrative indecision, making continuous visibility over enterprise data flows an operational necessity.
The Compromises
While the second wave delivers significant structural modernisation, it also reflects targeted regulatory compromises. Broad exemptions that have long differentiated Australia from its international peers, most notably the blanket small business exemption for entities with an annual turnover under $3 million and the private-sector employee records exemption, remain deferred from this specific bill. Similarly, universal rights to erasure across every small enterprise and private rights of action in federal court were held back in favour of targeted, high-impact mechanisms.
Nevertheless, for medium and large enterprises, digital platforms, and technology-driven service providers, the direction of travel is unmistakable. Privacy compliance in Australia can no longer be treated as a static legal audit or a front-end consent banner; it requires continuous, defensible data lifecycle governance.
How Tsaaro Helps Organisations Navigate the Reforms
Adapting to an objective “fair and reasonable” regime requires more than legal interpretation; it demands end-to-end operational governance and institutional accountability. This is where Tsaaro serves as a strategic privacy partner:
Tsaaro assists enterprises in re-architecting their data practices by conducting comprehensive data mapping, privacy impact assessments, and vendor risk evaluations to ensure data handling meets evolving regulatory thresholds. By bridging the gap between legal mandates and technical operations, Tsaaro helps organisations implement robust data governance frameworks, operationalise data subject rights, and establish defensible breach response mechanisms aligned with OAIC standards. Through tailored advisory and continuous compliance oversight, Tsaaro transforms complex statutory obligations into resilient, audit-ready privacy programmes.
Conclusion
The second wave of Privacy Act reforms marks Australia’s definitive transition from tick-box compliance to substantive accountability. By establishing the fair-and-reasonable principle, broadening definitions of personal data, and mandating rapid incident responses, the reforms demand that organisations fundamentally justify how and why they handle data.
Organisations that rely on passive notice and consent will find their models increasingly fragile under this incoming regime. True readiness requires embedding privacy-by-design across the entire data engineering stack, ensuring that every record collected can withstand objective regulatory scrutiny from day one.
Want to stay ahead?
Reach out to the experts at Tsaaro today.
Talk to a Privacy Expert
Get a free 1:1 session on AI compliance, DPDPA readiness, or incident response planning.
Related articles












