Australia is eyeing a world‑first ‘fair and reasonable’ test for data collection and privacy

The Conversation

Rob Nicholls Senior Research Associate in Media and Communications, University of Sydney. September 1, 2026 2.06pm AEST

On Monday, the Australian government released draft legislation for the next big overhaul of the Privacy Act.

The Privacy Amendment (Personal Data Protection) Bill 2026 is now out for public comment, together with a consultation paper. It is the second instalment (or “tranche”) of privacy reform , and it is the one that matters most.

The bill contains dozens of new measures, such as stronger consent requirements and a “right to be forgotten”, but at its heart is a world-first test that could bypass many loopholes companies use to justify what they do with personal data.

How we got here

The Privacy Act was introduced in 1988, before the web, smartphones, and social media. The Attorney-General’s Department spent three years reviewing it and reported in 2023 with more than 100 proposals for change. The government agreed with most of them, at least in principle.

The first tranche of reforms became law in late 2024. These created a new right to sue for serious invasions of privacy. This “statutory tort” (a wrong you can take to court), tackled doxxing, and promised a children’s online privacy code.

Tranche one also included a requirement for privacy policies to disclose whether they use automated decision-making systems to make decisions that could reasonably be expected to significantly affect an individual’s rights or interests. This will come into effect in December.

This new bill is the main course of the reforms. It contains around 40 measures that, if enacted, will change how every business and government agency covered by the act handles our personal information.

What’s in it?

The bill modernises the basic building blocks. “Personal information” will cover any information that relates to a person who can be identified, even without a name. A nickname, a device identifier or a pattern of behaviour can be enough. Inferences that artificial intelligence (AI) draws about you will count as “collected” information, just like details you type into a form.

The list of “sensitive information” (the category that requires your consent to collect) will grow. It now includes precise location-tracking data. That means information from a device that pins you down to within 500 metres and follows you over time.

Consent to data collection gets an upgrade. It must be voluntary, informed, current, specific and unambiguous. Pre-ticked boxes and design tricks will not cut it.

There are other headline items. Companies will need your consent before they trade your personal information. Large digital platforms (those with A$500 million in revenue or 2.5 million Australian users a month) will have to delete your data on request, with some exceptions. This means a “right to be forgotten” for the first time in Australia. Also, data breaches will need to be reported to the regulator within 72 hours.

The big idea is “fair and reasonable”

The centrepiece of the draft legislation is deceptively simple. An organisation can only collect, use or disclose your personal information if doing so is “fair and reasonable” in the circumstances.

This test is unique to Australia. Europe’s privacy law asks whether an organisation has a legal basis for processing data. The United States mostly relies on notice and consent, which in practice means clicking “I agree” to terms nobody reads.

The Australian test asks a different question: even if you ticked the box, was the data practice itself fair?

That is the crucial point. Businesses cannot consent their way around it. A privacy policy buried in legal jargon will not save a practice that an ordinary person would never expect.

The bill lists the factors that matter. They include what a reasonable person would expect, whether the organisation is transparent about what it is doing, and whether it could achieve its purpose with less data.

An organisation must also consider whether the person has a genuine choice, and weigh the risk of harm against the benefits. Where children’s information is involved, the best interests of the child must be a primary consideration.

In effect, this shifts the burden of privacy protection from individuals onto organisations, moving Australia towards a digital duty of care in which those who profit from our data must actively look after the people it relates to.

What about smart glasses?

The government is openly worried about wearable technology. Smart glasses and earbuds with cameras and microphones can record people discreetly in public. The consultation paper asks whether the reforms go far enough to deal with this kind of technology.

The bill helps in several ways. Video, audio and AI-generated inferences captured by smart glasses will clearly be personal information. Collecting biometric templates (such as mathematical maps of faces used for recognition) will also need consent. Companies deploying these devices will have to show their data handling is fair and reasonable.

There is a gap, though. The Privacy Act generally does not allow an individual to take legal action. This is despite the 2023 review recommending that the act should provide a private right of action, and the government accepting this recommendation in principle.

If a stranger films you with their glasses at a cafe, your main remedy is the statutory tort from the first tranche of reforms, and few people know it exists. It is also expensive to litigate. The consultation paper asks what else might be needed.

What happens next

The exposure draft is open for comment until September 18, and the final bill will follow once the feedback is in.

Expect a fight. Business groups will worry about uncertainty in the fair and reasonable test, and privacy advocates will push for it to have teeth.

The direction, however, is clear. Australia is betting that fairness, not fine print, should decide what happens to our personal information.

To read the full article click here.

Share this article

More News

Newsrooms unite to defend trusted journalism in AI age

Australians are being urged to look beyond the headline and understand how journalism is made as news organisations confront a rapidly changing information landscape dominated by social media algorithms and AI.

How to tame your feed

It was great getting a sense of the deep ethnographic research Agata has undertaken and the links between digital literacy and digital empowerment. What I took away from the conversation was a sense that the algorithms that drive our feeds are not just code, they have a shape and form that evolves based on our interactions. While I would put myself in an ‘algorithms are bad’ camp, I find more people I speak with saying they like their algorithm, it makes their life easier, they just want it to do its work without all the slop and noise. This is where the business models behind the social media platforms come in and left to their own devices, will serve copy to maximise time on screen through extreme content. Counteracting that with hacks like conscious engagement could change our online experiences for the better.

Five things to understand about how the OpenAI hack unfolded

The Albanese government is scrambling to answer questions about national security and the dangers posed by artificial intelligence following revelations that a rogue AI agent deployed by OpenAI hacked sensitive Australian data, including aggregate Medicare records. Social media platforms would have to ask users, through prompts that appear from time to time, whether they want to keep a personalised, algorithm-driven feed or instead see mostly the accounts they have chosen to follow.

TV in Australia turns 70. What’s next?

As the nation celebrates seven decades of broadcast television, the industry also confronts questions about the future in an increasingly digital world. For more on this, we spoke with Dr Timothy Koskie, a post-doctoral research associate at The University of Sydney’s Centre for AI Trust and Governance.