Australia's privacy reforms push boundaries with new AI and identity protections

Australia has unveiled a comprehensive second wave of privacy reform proposals, introducing stricter obligations on organisations handling personal data, expanding user rights, and addressing emerging risks posed by AI, wearable devices, and cyber threats.

Australia has unveiled a second round of privacy reform proposals, setting out draft legislation and a consultation paper that would significantly expand the obligations on organisations handling personal information. The package, released by the Attorney-General’s Department, is aimed at modernising the Privacy Act for the digital age and is open for comment until 18 September 2026, with submissions invited from businesses, charities, consumer groups, legal specialists and privacy advocates. According to the government’s consultation materials and ministerial announcement, the reforms are intended to address new risks created by artificial intelligence, wearable devices and large-scale data processing.

At the centre of the draft is a proposed fair and reasonable test for the collection, use and disclosure of personal information. That would go beyond a narrow reliance on consent forms and privacy notices, requiring organisations to show that their data practices are objectively justified in the circumstances. The consultation paper says relevant factors would include the sensitivity of the information, people’s reasonable expectations, the risk of harm and whether the data use is proportionate to its purpose. In practical terms, that could have wide implications for advertising technology, analytics platforms, AI systems and other high-volume data operations.

The draft package also includes a proposed right to erasure, which would allow Australians to seek deletion of certain personal information when it is no longer needed or when they no longer want it retained. Industry reporting has said this right would apply to large platforms, including search engines, social media services, messaging apps, gaming services and AI platforms that meet specified revenue or user thresholds. The policy direction is consistent with a broader shift towards treating privacy as an ongoing relationship, rather than a one-off notice and consent exercise.

Identity protection is another major theme. The government has also proposed an IDLock initiative intended to give individuals more visibility and control over identity credentials such as passports and driving licences. That comes after a series of major cyber incidents in Australia have sharpened political and public attention on the links between privacy, cybersecurity and fraud prevention. Officials are presenting the measure as part of a wider effort to give people practical tools to manage how identity data is used and shared.

The second tranche builds on earlier privacy changes passed in September 2024, which strengthened enforcement powers for the Office of the Australian Information Commissioner, enabled an OAIC-drafted Children’s Online Privacy Code, added transparency requirements for automated decisions and created a new statutory tort for serious invasions of privacy. The latest proposals suggest regulators are moving towards a more demanding model in which organisations must demonstrate strong governance, documented decision-making and privacy-by-design controls, rather than simply relying on compliance paperwork after the fact.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.