Savira
Reference

Privacy Act reform tracker: what has changed and what's next

A plain English tracker of Privacy Act reform: what has already commenced, what starts on 10 December 2026, and what is still only a draft.

Compliance updatesReviewed 30 August 20266 min read

Privacy Act reform keeps getting announced, which makes it hard to tell what is actually law. Here is the short version. The first tranche passed in December 2024 and most of it is already in force. Two more pieces start on 10 December 2026. The second tranche is still only a draft bill, out for consultation until 18 September 2026, and the small business exemption has not been removed.

If you run a small or medium business, the useful question is which changes already bind you and which are still someone's proposal. This tracker splits them, with the dates.

What has already commenced

December 2024: bigger penalties and a new infringement notice power. The Privacy and Other Legislation Amendment Act 2024 (Cth) added a mid-tier civil penalty for interferences with privacy that are not serious, plus a low-level penalty for specific administrative breaches with infringement notices attached. That is the change behind the OAIC's privacy policy compliance sweep, where the regulator points to penalties of up to $66,000. In practice it means the OAIC no longer has to reserve action for catastrophes.

December 2024: doxxing became a criminal offence. New offences in the Criminal Code cover the malicious release of someone's personal data.

December 2024: security obligations spelled out. APP 11 now expressly refers to technical and organisational measures, so things like access controls, encryption and staff training are named rather than implied.

10 June 2025: the statutory tort commenced. People can now sue directly for a serious invasion of privacy, either intrusion into seclusion or misuse of information. It runs alongside the complaints process rather than replacing it, and the OAIC has no direct role in it.

January 2026: the OAIC started checking without being asked. Its first compliance sweep is reviewing about 60 privacy policies across six sectors that collect details face to face. You do not need to have had a breach to come under scrutiny.

1 July 2026: a large group of small businesses came under the Privacy Act. This one came through the anti-money laundering reforms, not the privacy reforms, and it caught a lot of people by surprise. Real estate professionals, lawyers, conveyancers, accountants, trust and company service providers, and dealers in precious metals and stones became reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). Where you provide one of those designated services, the Privacy Act applies to the personal information you handle for it, whatever your turnover. The OAIC has published specific guidance for reporting entities, including advice not to keep copies of full identity documents.

What is coming, and when

10 December 2026: automated decisions go in your privacy policy

If you use a computer program to make, or substantially help make, decisions that could significantly affect someone's rights or interests, your privacy policy will have to say so. It needs to cover the kinds of personal information used and the kinds of decisions made that way.

"Computer program" is broad. It is not limited to artificial intelligence, so a rules-based screening tool or a scoring spreadsheet can be caught. The work is mapping where those tools sit in your business, which takes longer than the writing does. Our guide to what a privacy policy has to include covers the rest of the page this sits on.

10 December 2026: the Children's Online Privacy Code

The OAIC has to finalise and register the code by that date. It applies to online services likely to be accessed by children, including social media services, messaging and games with chat, and services that let users access content. The OAIC released an exposure draft on 31 March 2026 and consulted until 5 June 2026, receiving 135 written submissions. The registration deadline is fixed, but the date the code itself starts applying has not been settled.

Still a draft: the second tranche

On 31 August 2026 the Attorney-General's Department released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, along with a consultation paper covering roughly 40 proposals. Submissions close on Friday 18 September 2026, and the department has asked for about 1,000 words. Nothing in it is law, and the department has said the bill remains subject to further consideration by government.

What the draft second tranche would change

  • A fair and reasonable test. Collection, use and disclosure would have to be fair and reasonable in the circumstances, whether or not you got consent. Consent would stop being a complete answer.

  • A wider definition of personal information. The test would shift from information "about" someone to information that "relates to" an identified or reasonably identifiable individual, which brings Australia closer to the European position.

  • Consent for some direct marketing disclosures. The consultation paper names cookie and pixel disclosures in programmatic advertising as the kind of conduct in scope.

  • Precise location as sensitive information. A new category keyed to a radius of 500 metres.

  • A right to erasure on large platforms. Limited to platforms above a revenue or user threshold, not a general right for everyone.

Just as useful is what the draft leaves out. It does not remove the small business exemption or the employee records exemption, and it does not introduce a universal right to erasure, mandatory privacy impact assessments or a direct right of action. Those were all in the Privacy Act Review and none of them are in this draft.

What to do at each stage

1. Sort what applies to you now from what does not

If you are a reporting entity under the anti-money laundering rules, you are covered today and that is the priority. If your only exposure is the second tranche, you have time.

2. Book the December work now

Automated decision-making disclosures and the children's code both land on 10 December 2026. Map your automated tools first, then write. Doing it the other way round produces a policy that describes systems you do not have.

3. Read your privacy policy against what you actually do

This is the cheapest thing on the list and it is what the regulator is currently checking. Every tool that touches customer data, every supplier, every overseas transfer.

4. Have a say, or at least a look

Submissions on the draft bill close on 18 September 2026. Even if you do not write one, the consultation paper is a fair preview of where this is heading.

Common questions

Has the small business exemption been removed?

No. It survived the first tranche and it is not in the draft second tranche either. That said, more small businesses are covered than the $3 million turnover figure suggests, including health service providers and, since 1 July 2026, businesses providing designated services under the anti-money laundering rules.

When will the second tranche become law?

There is no date. The consultation closes on 18 September 2026 and the government has signalled it wants to introduce legislation before the end of the year, but a bill still has to pass both houses and would almost certainly come with a transition period.

Do I need to do anything about automated decision-making if I only use a spreadsheet?

Possibly. The test is whether a computer program makes, or substantially and directly helps make, a decision that could significantly affect someone's rights or interests, not whether the tool is clever. A manual judgement informed by your own notes is different from a formula that produces the outcome.

Does the Children's Online Privacy Code apply to an ordinary business website?

Only if the service falls within the categories in the code and is likely to be accessed by children or is primarily concerned with children's activities. A trades business website is unlikely to be caught. A game, an app or a service aimed at families is a different question, and worth checking properly once the final code is registered.

This is general information, not legal advice. Every business handles information a bit differently, so if you're not sure how this applies to yours, it's worth checking with a lawyer or privacy adviser.

Source: Privacy Reform - Consultation on Exposure Draft legislation, Attorney-General's Department, opened 31 August 2026, closes 18 September 2026.

Privacy Reform - Consultation on Exposure Draft legislation

Published 31 August 2026

Source: Office of the Australian Information Commissioner website – www.oaic.gov.au © Commonwealth of Australia, licensed under CC BY 4.0. This summary is Savira's own and is not endorsed by the OAIC.

© Savira 2026. All rights reserved.
ABN 53 273 071 022PO Box 2045, Hornsby Westfield NSW 1635