Key quotes:

The next phase of Australian privacy reform has arrived with [the draft] proposing around 40 changes to the Privacy Act. This signals a major shift towards greater accountability, stronger data security obligations for organisations and enhanced rights for individuals.

Submissions are currently open and close on 18 September 2026.

Summary of proposals:

expanding “sensitive information” to include new categories such as precise geolocation tracking data and genomic information

strengthening the requirements for valid consent by requiring it to be voluntary, informed, current, specific and unambiguous.

Requires organisations to obtain consent before collecting sensitive information or trading personal information, unless a specified exception applies.

a simplified direct marketing framework, including a technology-neutral definition of direct marketing, mandatory opt-out mechanisms, and specific rules for ad-supported services and clarifies multi-party advertising arrangements.

Introduces a right for individuals to request the destruction of personal information held by large digital platforms, unless an exception applies.

Eligible data breaches must be notified to the Information Commissioner within 72 hours

Introduces a controller and processor model that allocates primary responsibility for privacy compliance to the controller, aligning Australia’s privacy framework more closely with international privacy regimes such as the GDPR and UK GDPR.

Strengthens the OAIC’s complaint-handling, investigation and enforcement powers, including enhanced information-gathering powers, representative complaint management and enforcement of privacy complaint obligations.

Full draft can be read here