Australia Law – Holding Redlich Counsel Outlines Effect of Privacy Law Changes

Holdingredlich

The Attorney-General’s exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 proposes the most significant changes to the Privacy Act 1988 since the Australian Privacy Principles were introduced, according to Holding Redlich General Counsel Lyn Nicholson.

In the below commentary, Lyn outlines some of the key reforms and why organisations should start preparing now rather than wait for the legislation to be finalised.

“While the Bill may change as it moves through Parliament, the direction of reform is clear. The proposed changes would expand obligations around consent, data handling, data security, data breaches and the retention and destruction of personal information.

“Importantly, organisations should not assume they can wait until the legislation is passed before taking action. Many of the proposed reforms would require operational and governance changes that could take time to implement.

“For example, the Bill introduces a new, codified standard for consent. For the first time, the Privacy Act would define what constitutes valid consent, requiring it to be voluntary, informed, current, specific and unambiguous. Pre-ticked boxes, bundled consents, and stale or generic consent language are unlikely to satisfy this standard. Every privacy collection statement, consent flow, cookie banner and marketing opt-in will need to be reviewed against this five-part test.

“The proposed reforms would also broaden the definition of personal information and introduce a new requirement for the collection, use and disclosure of personal information to be fair and reasonable. The Bill would also impose tougher obligations around data retention, destruction and ongoing compliance monitoring.

“The notifiable data breach scheme is also substantially rebuilt, with a requirement to notify the Privacy Commissioner of an eligible data breach within 72 hours, a significant shift from the current ‘as soon as practicable’ standard. For many organisations, the question will be whether their existing incident response plans and processes can meet that deadline.

“The Bill also creates a new privacy principle giving individuals the right to require large digital platforms to destroy their personal information on request, subject to limited exceptions. Qualifying platforms will need erasure request-handling processes, response-timeframe tracking and clear internal criteria for when an exception applies.

“Businesses that use the lead time before the reforms are finalised to assess gaps and begin planning will be better placed to manage implementation than those that wait for the final legislation.”

Leave a Comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Scroll to Top