Menu

Privacy Act reform draft proposes a 72-hour breach deadline and reaches AI inferences

Comingwave team · 7 minute read · published

An office manager stands beside open filing drawers and a laptop, sorting customer records in a tidy office.

The Australian Government released a draft of its next round of Privacy Act reform on 31 August 2026. The Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026 and a consultation paper are open for comment until Friday 18 September 2026. The package would tighten how organisations collect, use, secure and delete personal information, set a 72-hour deadline for reporting eligible data breaches to the regulator, and treat inferences drawn by AI tools as a collection of personal information. The draft does not repeal the small business exemption, but small and medium businesses should still read it closely.

This article is general information for business owners and managers, not legal advice.

What the Attorney-General's Department released

The Attorney-General's Department opened its consultation on the exposure draft legislation on 31 August 2026. The department says the reforms are meant to strengthen privacy protections and help tackle emerging risks from new technologies, including artificial intelligence and wearable devices such as smart glasses, while giving regulated entities greater certainty.

Two points about status are worth keeping in mind. This is a draft for consultation, not a Bill before Parliament. The department states that the Bill "remains subject to further consideration by government". Submissions must be uploaded by Friday 18 September 2026, and the department encourages concise submissions of around 1,000 words.

According to the consultation paper, the package contains roughly 40 proposals: 25 from the Privacy Act Review that uplift privacy protections, 5 from the Review that clarify and simplify obligations, 4 additional simplification measures, and 7 additional measures to improve the efficiency of the regulator, the Office of the Australian Information Commissioner (OAIC).

The main proposals in plain terms

A single "fair and reasonable" test

The paper proposes replacing several existing collection, use and disclosure rules with one principle: personal information may only be handled where that is fair and reasonable in the circumstances. Organisations would weigh a list of factors set out in the law, including data minimisation, whether the person has a genuine choice, and whether the impact on the person is proportionate to the benefit. No single factor decides the question.

Updated definitions, including for AI

Personal information would become information that "relates to" an identified or reasonably identifiable individual, instead of information "about" them. The definition of "collects" would cover information generated or derived through data analysis, artificial intelligence or other technological processes. The paper says this is intended to make sure inferences drawn about a person by AI-enabled technology count as a collection under the Act.

Two categories would be added to sensitive information: genomic information, and precise geolocation tracking data, defined as data that identifies a person's location to within a radius of 500 metres and is held by reference to their location over time.

Consent and direct marketing

Consent would need to be voluntary, informed, current, specific and unambiguous. The direct marketing rules would be rewritten: the paper says the framework does not require consent for direct marketing itself, but an organisation would need consent to trade personal information, and each marketing communication would need to tell the person how to opt out.

Data breaches and security

This is the part most likely to change day-to-day operations. The draft would require an organisation to give the Information Commissioner a statement within 72 hours of becoming aware of reasonable grounds to believe an eligible data breach has occurred. Organisations that only suspect a breach would still need to take all reasonable steps to complete their assessment within 30 days. There would also be express duties to have practices and systems for responding to breaches, and to take reasonable steps to reduce harm as soon as practicable.

On security, organisations would need to be able to identify the personal information they hold, consider destroying information they no longer need, and regularly assess whether their security measures still work.

Processors and erasure

The draft introduces the roles of controller and processor. Where one organisation handles personal information on behalf of another under documented instructions, primary responsibility would generally sit with the organisation that decides the purpose. Processors would stay directly responsible for transparency (APP 1) and security (APP 11). A new right to request erasure would apply only to large digital platforms; one of the tests is a business group with more than $500 million in gross revenue in the previous financial year.

Is a small business covered?

The OAIC's guidance for small business explains the current position: most small businesses, meaning those with an annual turnover of $3 million or less, are not covered by the Privacy Act, but some are. Regardless of turnover, the Act covers a business that is, among other things, a health service provider, one that trades in personal information, or a contractor providing services under a Commonwealth contract.

The exposure draft does not repeal that exemption. It does amend the wording of the exemption provision that deals with trading in personal information, so a small business that buys, sells or swaps customer lists should read that part of the draft with its adviser.

There are three reasons a business under the threshold should still pay attention:

  • Your customers may be covered. If you handle personal information for a larger client, the controller and processor model means that client will want documented instructions and evidence of your security.
  • Growth changes your status. The OAIC's checklist asks whether turnover has exceeded $3 million in any financial year since 2002.
  • The draft can change. The Bill is still being considered, and the department is collecting feedback on how the measures would work in practice.

What an SME can do now

ProposalPractical questionSensible first step
Identify the personal information you holdCould you list every system that stores customer or staff details?Build a simple data register: system, what it holds, who can access it, how long it is kept
72-hour breach statementWho decides, and who writes to the OAIC, if the owner is on leave?Write a one-page breach response plan and test it once
Consider destructionAre old quotes, applicant CVs and closed customer files still sitting in shared drives?Set retention periods and delete what is no longer needed
AI inferences count as collectionDo any tools score, profile or segment customers or job applicants?Add AI tools to the register and note what personal information staff enter
Consent to trade, clearer opt-outsDo you share or receive marketing lists?Check where each list came from and that every email has a working opt-out
Controller and processor rolesDo suppliers handle personal information for you, or you for clients?Review contracts for written instructions on purpose and security

None of these steps depends on the final wording of the Bill.

Comingwave is a technology company that provides cyber security, business systems and integrations and IT consulting to small and medium businesses. Mapping where customer data sits across a CRM, an accounting package and shared drives is the kind of work we do. To talk through your systems, you can request a quote.

Key takeaways

  • The exposure draft and consultation paper were released on 31 August 2026; submissions close on 18 September 2026.
  • It is a draft. The department says the Bill remains subject to further consideration by government.
  • Headline proposals include a fair and reasonable test, a 72-hour breach statement, stronger security and deletion duties, and new definitions that reach AI-derived inferences.
  • The small business exemption is not repealed in the draft, but many small businesses are already covered or work for clients who are.
  • A data register, a breach plan and a retention rule are useful whatever the final law says.

Frequently asked questions

Is the Personal Data Protection Bill law yet?

No. It is an exposure draft released for consultation on 31 August 2026. The Attorney-General's Department says it remains subject to further consideration by government.

Does the draft remove the small business exemption from the Privacy Act?

No. The draft does not repeal the exemption for businesses with an annual turnover of $3 million or less, though it amends wording about trading in personal information.

What would the 72-hour data breach rule require?

An organisation would need to give the Information Commissioner a statement within 72 hours of becoming aware of reasonable grounds to believe an eligible data breach has occurred.

How does the draft deal with AI?

The definition of collection would cover personal information generated or derived by artificial intelligence, so inferences an AI tool draws about a person would be treated as collected information.

Can a small business make a submission?

Yes. The department welcomes feedback from all interested stakeholders, including industry and individuals, and submissions must be uploaded by Friday 18 September 2026.

Need help with your business technology?

Tell us what you need. We reply within one business day.

Get a free quote