A Fair and Reasonable Test Would Reach Across Data Use
One of the most consequential proposals is a single fair and reasonable test governing the collection, use, and disclosure of personal information.
The assessment would look at factors including an individual’s reasonable expectations, the relationship between the processing and the organisation’s activities, transparency, data minimisation, genuine choice, impacts on individuals, proportionality, and the best interests of children where relevant.
The practical effect reaches further than privacy notices. An organisation might describe a secondary use of customer data in its privacy policy, yet transparency alone would not establish that the use is fair and reasonable. Teams would also need to consider whether an individual would reasonably expect the activity, whether the organisation needs that amount of information, what choice the person had, and whether a less privacy-invasive approach achieves the same purpose.
For organisations, that creates a stronger connection between policy decisions and the underlying data map. Assessing an activity requires visibility into its purpose, data categories, systems, users, downstream disclosures, and associated risks.
Consent Would Need to Demonstrate Genuine Choice
The proposed definition of consent would require it to be voluntary, informed, current, specific, and unambiguous.
The consultation provides useful signals about what that means in digital experiences. Bundled consent and interfaces that make refusal unreasonably difficult would weigh against voluntariness. Preselected settings and pre-ticked boxes would likely fall short of an unambiguous choice. Consent for undefined future uses would conflict with the requirement for specificity.
The proposal therefore shifts attention toward how consent works through the full customer experience.
Privacy and digital teams would need to understand which processing purposes require consent, how those purposes appear to the individual, where the resulting choice is recorded, and whether changes in data use require the organisation to revisit that choice.
A related proposal would require consent before an organisation trades personal information, subject to specified exceptions. The proposed definition reaches disclosures for monetary or other consideration and disclosures supporting direct marketing, including certain uses of cookies or pixels in programmatic advertising.
That connection between consent, data sharing, and marketing makes purpose-level governance especially relevant.
Personal Information Would Cover More Modern Data Practices
The proposal would amend the definition of personal information from information “about” an individual to information that “relates to” an identified or reasonably identifiable individual.
The consultation explains that information might relate to someone through their activities, characteristics, behaviour, movements, preferences, or interactions. Identifiability would also account for information that identifies someone when combined with other information reasonably available to the entity.
This becomes especially relevant for AI and connected technologies. The proposed definition of collection expressly addresses information generated or derived through data analysis, artificial intelligence, or other technological processes. The consultation also discusses smart glasses, connected vehicles, and AI-generated inferences as areas where existing privacy concepts need to work in contemporary technical environments.
Privacy inventories therefore need to account for information organisations generate from existing data, alongside information collected directly from individuals.
Sensitive information would also expand to include precise geolocation tracking data and genomic information, while the consultation highlights biometric templates in the context of emerging technologies.
Privacy Rights and Data Retention Move Closer Together
The proposed reforms would introduce a right to erasure for individuals using large digital platforms.
The right would apply to qualifying platforms meeting specified revenue or Australian user thresholds. Those platforms would need to destroy personal information following a valid request unless an exception applies, then provide written notice explaining the outcome.
At the same time, proposed changes to APP 11 would place greater emphasis on identifying personal information and evaluating whether information that is no longer needed should be destroyed rather than retained in de-identified form.
Together, these proposals connect individual rights with broader data lifecycle governance.
An erasure workflow depends on knowing where personal information sits. A retention decision depends on knowing why it remains necessary. De-identification requires continued assessment of whether re-identification remains reasonably possible as technology and available information change.
That makes data discovery, processing inventories, retention controls, and privacy request workflows closely related parts of the same operating model.
Breach Response Would Face a Clearer Clock
The proposed amendments to Australia’s Notifiable Data Breaches scheme would introduce a 72-hour period for notifying the Information Commissioner after an organisation becomes aware of reasonable grounds to believe that an eligible data breach has occurred.
Where completing the full statement within that period is impossible or impracticable, the organisation would submit an incomplete statement and provide missing information later.
The proposals also establish a positive obligation to take reasonable steps to contain breaches and reduce harm, alongside requirements for practices, procedures, and systems that support effective response.
For privacy and security teams, readiness therefore depends on the path from detection to legal assessment, escalation, notification, remediation, and evidence. The timeline matters, but the operating process behind it determines whether the organisation reaches the right decision and records its actions as the incident develops.
AI and Wearables Make Privacy Governance a Cross-Functional Issue
The consultation gives emerging technologies a prominent role. The Government is specifically seeking feedback on whether the proposed definitions and safeguards adequately address technologies such as smart glasses and whether the definition of collection remains flexible enough for information generated through new technologies.
That brings privacy governance closer to AI, product, security, and data governance teams.
An AI system might derive information about an individual from existing data. A wearable device might continuously collect location, audio, video, or biometric information. A connected service might create new behavioural insights from several data sources.
Understanding those activities requires an inventory of systems and data uses, clear ownership, privacy risk assessment, and documentation that links technical behaviour with the purposes and safeguards approved by the organisation.
What Organisations Should Do During the Consultation Stage
The proposals remain subject to further consideration, so the current task is assessment rather than wholesale redesign.
Privacy teams should identify where the proposals would create the greatest operational impact across existing programs. The fair and reasonable test points toward reviewing high-volume and higher-risk processing activities. The consent provisions warrant examining current consent language and choice architecture. Proposed erasure and security changes place attention on data visibility, retention, rights workflows, and incident response. AI and wearable technology proposals make inventories of emerging technology use increasingly relevant.
These activities span several parts of the privacy program. OneTrust Privacy Automation supports processing inventories, privacy risk assessments, rights workflows, and compliance documentation. Consent & Preferences supports the governance of consent and individual choices across digital experiences. Incident Management supports structured breach assessment and response, while AI Governance connects AI inventories, ownership, assessments, and supporting evidence.
The common requirement across each area is operational visibility. Teams need to connect regulatory interpretation with the systems, data, decisions, and owners responsible for putting it into practice.
Preparing for the Next Stage of Australia’s Privacy Reform
Australia’s consultation asks a practical question: how should stronger privacy protections work inside modern organisations and digital services?
The answer will continue to develop after submissions close on September 18, 2026. Privacy teams still have useful work to do now. Mapping the proposals against existing processing activities provides a clearer view of where future change would affect consent, data governance, individual rights, security, AI, and internal ownership.
Explore OneTrust’s Australian Privacy Act Compliance Solutions for further guidance on managing privacy requirements and operational readiness as Australia’s reform process progresses.
Key Questions About Australia’s 2026 Privacy Reform Consultation