Privacy law
Privacy Act reforms in 2026: what's law, what's proposed and what it means for AI
Australia's privacy reforms are arriving in two stages. The 2024 amendments are law, with the last major change starting on 10 December 2026. The tranche 2 exposure draft is still a proposal. Here's how to tell them apart and what to do now if your organisation uses AI tools.
By the AusGPT team · Updated · 8 min read
General information only, not legal advice. Check the primary sources linked below, and get advice for your situation.
Australia's Privacy Act reforms are happening in two stages, and only the first is law. Tranche 1, the Privacy and Other Legislation Amendment Act 2024, received Royal Assent on 10 December 2024. Most of it started the next day, the statutory privacy tort started on 10 June 2025, and the automated decision-making transparency rules start on 10 December 2026. Tranche 2 is an exposure draft, the Privacy Amendment (Personal Data Protection) Bill 2026, released by the Attorney-General's Department on 31 August 2026. Consultation closed on 18 September 2026. The department says the Bill "remains subject to further consideration by government". It has to be introduced and passed by Parliament before any of it applies.
If your organisation uses AI tools, act on tranche 1 now and plan for tranche 2.
Law now vs proposed: the short version
| Change | Status (October 2026) | Starts |
|---|---|---|
| Security: APP 11 steps include "technical and organisational measures" | Law | 11 December 2024 |
| New civil penalty tiers, infringement and compliance notices | Law | 11 December 2024 |
| Doxxing offences in the Criminal Code | Law | 11 December 2024 |
| Statutory tort for serious invasions of privacy | Law | 10 June 2025 |
| Automated decision-making disclosures in privacy policies (APP 1.7 to 1.9) | Law | 10 December 2026 |
| Children's Online Privacy Code | OAIC must register it by 10 December 2026 | Not yet set |
| Fair and reasonable test, new definitions, 72-hour breach notice, controllers and processors, right to erasure | Proposed (exposure draft) | No date |
What tranche 1 changed
The 2024 Act has three schedules. Schedule 1 amends the Privacy Act, Schedule 2 adds the statutory tort and Schedule 3 adds doxxing offences to the Criminal Code. The parts most relevant to organisations:
Security (APP 11.3). APP 11 already required reasonable steps to protect personal information. A new APP 11.3 says those steps "include technical and organisational measures". For AI tools, that means access controls and approved tools, plus staff training and written rules.
Penalties and enforcement. Section 13G still covers serious interferences with privacy, and the Act now lists factors a court may consider, including the sensitivity of the information, the number of people affected, whether a child or person experiencing vulnerability was involved, and whether the entity failed to implement practices, procedures and systems to comply. A new section 13H creates a mid-tier civil penalty of up to 2,000 penalty units for an interference with privacy that isn't serious. Section 13K covers administrative breaches, such as not having a compliant privacy policy, with a maximum of 200 penalty units, and those can be dealt with by infringement notices and compliance notices. Courts can now also order an entity that contravened a civil penalty provision to compensate affected people or take steps to redress loss, and the Commissioner gained powers to run public inquiries and new monitoring and investigation powers.
Automated decisions (APP 1.7 to 1.9). From 10 December 2026, privacy policies must describe the kinds of personal information used, and the kinds of decisions made, by computer programs that make or substantially and directly help make decisions that could significantly affect people. The OAIC's September 2026 guidance treats generative AI and chatbots as computer programs. Our guide to APP 1.7 covers it in detail.
Children's Online Privacy Code. The Act requires the Information Commissioner to develop and register a code about online privacy for children within 24 months of Royal Assent. The OAIC released an exposure draft on 31 March 2026, consultation closed on 5 June 2026, and the OAIC says the code "must be finalised and registered by 10 December 2026". Its start date hasn't been announced.
Overseas data flows (APP 8.3). Regulations can now prescribe countries or binding schemes whose protections are "at least substantially similar" to the APPs. Disclosures to recipients covered by a prescribed country or scheme get a new pathway under APP 8. Check the current Privacy Regulation before relying on it.
Statutory tort. Schedule 2 creates a cause of action for serious invasions of privacy, by intrusion upon seclusion or misuse of information. It started on 10 June 2025 and, unlike most of the Privacy Act, can apply to individuals as well as organisations.
Other changes. Ministerial eligible data breach declarations allow information sharing to reduce harm after a breach, and a new objects clause recognises the public interest in protecting privacy. The Minister can also direct the Commissioner to develop APP codes.
What the tranche 2 exposure draft proposes
The consultation paper describes roughly 40 proposals: 25 Privacy Act Review proposals that strengthen protections, 5 that clarify and simplify, 4 further simplification measures and 7 measures to make the OAIC more efficient. The main ones:
A fair and reasonable test replacing APPs 3, 4 and 6. Draft APP 3.1 says an APP entity must not collect, use or disclose personal information unless it is "(a) fair and reasonable in the circumstances; and (b) lawful." Draft APP 3.2 lists the matters to consider:
- whether a reasonable person would expect it
- whether it relates to the entity's functions or activities
- whether the entity is transparent about the means and purposes
- whether the purpose could be met with less information, or with information that isn't personal information
- whether the individual has genuine choice
- the impact on privacy and any risk of harm, and whether that is proportionate to the benefits
- for children, the best interests of the child as a primary consideration.
Consent would still be required to collect sensitive information and to "trade" personal information. Trading includes disclosures for direct marketing, which the paper says may include cookies or pixels in programmatic advertising.
New definitions. Personal information would be information that "relates to" an identified or reasonably identifiable individual. "Collects" would cover information generated or derived "through means such as data analysis, artificial intelligence or other technological processes", and the paper says inferences drawn by AI about an individual would count as collection. "Disclosure" would mean making personal information accessible to another person or body. Merely transmitting or storing it, including overseas, wouldn't count unless it becomes accessible to someone else. Consent would have to be voluntary, informed, current, specific and unambiguous. Precise geolocation tracking data and genomic information would become sensitive information.
Controllers and processors. Where one APP entity handles personal information on another's documented instructions, the processor would generally not breach the APPs (other than APP 1 and APP 11) and responsibility would sit with the controller. This would only apply where both are APP entities and the processor stays within the instructions.
Data breaches. Entities would have to give the Commissioner a statement within 72 hours of becoming aware of reasonable grounds to believe an eligible data breach has happened. They would also have express duties to contain breaches, mitigate harm and maintain practices, procedures and systems to respond.
Security and retention. APP 11 would require entities to be able to identify the personal information they hold and to consider destruction before de-identifying information they no longer need. They would also have to regularly assess how well their security and destruction measures work.
Other measures. A right to erasure would apply only to large digital platforms, meaning broadly those with $500 million or more in group revenue or 2.5 million average monthly Australian users. The draft also simplifies collection notices, rewrites the direct marketing rules and adds research exceptions. A complaints process would generally require people to raise concerns with the entity first, with entities responding within 60 days.
What's not in it. The exposure draft doesn't remove the small business exemption or the employee records exemption. Its commencement table is blank, and the consultation paper says transitional and commencement provisions will be added once settled.
What this means for organisations using AI tools
Most AI risk under the Privacy Act comes from ordinary staff use: pasting client details into a chat tool, uploading documents for summarising, or letting an AI tool help decide something about a person. Tranche 1 already covers all of these, and tranche 2 would make some obligations more explicit.
| AI practice | Under current law | If the draft passes as released |
|---|---|---|
| Staff paste personal information into an AI tool | APP 6 use and disclosure rules apply. The OAIC recommends not entering personal information into publicly available generative AI tools. | Must be fair and reasonable. Making information accessible to the vendor is a disclosure unless a processor arrangement applies. |
| AI infers or generates information about a person | The OAIC already treats this as collection under APP 3. | Expressly "collection", including derived sensitive information. |
| AI informs significant decisions about people | APP 1.7 disclosures from 10 December 2026 | Unchanged, plus the fair and reasonable factors |
| AI vendor stores prompts and files | APP 11 security, including technical and organisational measures | Regular evaluation of security and destruction measures |
| AI tool involved in a breach | Statement to the Commissioner "as soon as practicable" (section 26WK) | Statement to the Commissioner within 72 hours |
What to do now
- List the AI tools your people use, including free and personal accounts, and what information goes into each.
- Check vendor terms and settings: whether inputs are used for training, where data is stored and processed, how long it is kept and who can access it. The OAIC's AI product guidance suggests turning off features that would disclose personal information, or not using the product.
- Write an AI use policy that says which tools are approved and what information may go into them. Back it with training and checks, as the OAIC recommends.
- Prepare your APP 1.7 disclosures before 10 December 2026 for any software or AI that makes or substantially informs significant decisions about people.
- Document technical and organisational measures for AI tools under APP 11: single sign-on where available, access removal for departing staff, retention settings and an approved-tool list.
- Rehearse your breach response. A 72-hour reporting window is only a proposal, but a tested data breach response plan is useful now.
- Look at your AI contracts. If the controller and processor model passes, you'll want documented instructions that limit what a vendor can do with your data.
- Start thinking in "fair and reasonable" terms: reasonable expectations, data minimisation and proportionality. These factors already reflect good practice under the current APPs.
Data location is one part of the picture. Keeping prompts and documents in Australia doesn't replace these steps, but it can simplify the cross-border questions in your assessments and the questions clients ask.
Use Claude with data stored and processed in Australia
AusGPT gives your team Claude AI with conversations and documents stored and processed in Australia. $29 per user per month, with a free trial.
Keep an eye on
- whether the Bill is introduced to Parliament, and in what form
- the final Children's Online Privacy Code and its commencement date
- further OAIC guidance on automated decisions and AI
- any regulations prescribing countries or schemes under APP 8.3.
We'll update this page as the reforms progress. Check the Attorney-General's Department consultation page and the OAIC for the latest position.
Sources
- Federal Register of Legislation: Privacy and Other Legislation Amendment Act 2024 (No. 128, 2024)
- Federal Register of Legislation: Privacy Act 1988 (Compilation No. 104, 4 June 2026)
- Attorney-General's Department: Privacy Reform, Consultation on Exposure Draft legislation (31 August to 18 September 2026)
- Attorney-General's Department: Exposure Draft, Privacy Amendment (Personal Data Protection) Bill 2026
- Attorney-General's Department: Privacy Reform Consultation Paper
- OAIC: Children's Online Privacy Code
- OAIC: APP Guidelines Chapter 1, APP 1 (automated decisions, updated 30 September 2026)
- OAIC: Guidance on privacy and the use of commercially available AI products
Frequently asked questions
- Has Privacy Act tranche 2 been passed?
- No. As of October 2026, tranche 2 is an exposure draft, the Privacy Amendment (Personal Data Protection) Bill 2026, released for consultation on 31 August 2026. Consultation closed on 18 September 2026 and the Attorney-General's Department says the Bill remains subject to further consideration by government. It must be introduced and passed by Parliament before it becomes law.
- What Privacy Act changes take effect in 2026?
- The automated decision-making transparency rules (APP 1.7 to 1.9) start on 10 December 2026. The OAIC must also finalise and register the Children's Online Privacy Code by 10 December 2026. Most other tranche 1 changes started on 11 December 2024, and the statutory tort for serious invasions of privacy started on 10 June 2025.
- Would tranche 2 remove the small business exemption?
- The exposure draft does not remove the small business exemption or the employee records exemption. Most businesses with an annual turnover of $3 million or less remain outside the Privacy Act unless an exception applies.
- How would tranche 2 affect AI tools specifically?
- The draft would treat personal information generated or derived by AI as collected, define disclosure as making information accessible to another person or body, replace APPs 3, 4 and 6 with a fair and reasonable test, and introduce a controller and processor framework. Each affects how organisations choose and configure AI tools.
- When would tranche 2 start?
- There is no date yet. The exposure draft leaves its commencement table blank, and the consultation paper says further transitional and commencement provisions will be added once settled.
Keep reading
Secure AI for your team, processed in Australia
Claude AI, document chat and voice dictation, with your data stored and processed in Australia. $29 per user per month.