On 31 August 2026, the Federal Government released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, the long-awaited second tranche of Privacy Act reform. Consultation closed on 18 September. The draft contains roughly 40 proposals, and several of them go straight to the heart of how Australian businesses collect customer data, build audiences and run digital advertising.

It’s a draft, not law, and details may change. But the direction is clear enough that it’s worth getting ready now. Here’s what marketers and business owners should know.

A new “fair and reasonable” test

The draft replaces the existing collection, use and disclosure rules with a single overarching test: your handling of personal information must be fair and reasonable in the circumstances. Law firm commentary describes seven legislated factors, including people’s reasonable expectations, transparency, data minimisation, genuine choice, and the impact on privacy, including impacts on children.

For marketers, the practical shift is this: ticking a consent box won’t automatically make a practice acceptable. You’ll need to be able to explain why the way you use data is something a customer would reasonably expect.

Broader definitions catch more marketing data

Under the draft, “personal information” would cover information that relates to an individual, not just information about them. Commentators note this is intended to capture data such as behaviour, preferences and location. The draft also:

  • treats precise geolocation tracking data and genomic information as sensitive information, with extra safeguards
  • treats inferences generated by AI as information that has been collected

If your ad targeting, CRM segments or lookalike audiences rely on behavioural data, location data or AI-generated predictions about customers, these changes are directly relevant.

Consent, trading data and direct marketing

Three proposals stand out for anyone running campaigns:

  • Tighter consent. Consent would need to be voluntary, informed, current, specific and unambiguous. Clayton Utz notes this effectively rules out pre-ticked boxes and bundled consent.
  • Consent before trading personal information. Organisations would need consent before “trading” personal information, which McCullough Robertson summarises as disclosures for consideration or for direct marketing purposes, with limited exceptions. That has obvious implications for list swaps, data partnerships and some audience-sharing arrangements.
  • A rebuilt direct marketing regime. The current direct marketing principle (APP 7) would be replaced with a simplified framework, including a technology-neutral definition of direct marketing, mandatory opt-out mechanisms, specific rules for ad-supported services, and clarification of multi-party advertising arrangements.

Other changes worth knowing about

  • 72-hour breach notification. Entities would need to notify the Information Commissioner within 72 hours of an eligible data breach.
  • Controllers and processors. Businesses would need to be clearer about roles with their service providers and document processing instructions in contracts. Think about your CRM, email platform, agency and any analytics tools.
  • Right to erasure for large digital platforms (those with $500 million-plus revenue or 2.5 million-plus Australian users).

What about small business?

This is the question we hear most. Many small businesses are currently exempt from the Privacy Act. According to LK Law’s analysis, removing the small business exemption is still under consideration rather than settled in this draft. So if you’re a smaller operator, you may not be caught immediately, but there are two good reasons not to ignore this:

  1. Your larger customers, partners and platforms will be caught, and they will push obligations down the chain through contracts.
  2. If the exemption is narrowed or removed later, you’ll want your data practices already in order.

What to do now

  1. Map your marketing data. List what you collect (forms, pixels, CRM, email, ecommerce), where it goes, and who you share it with.
  2. Audit your consent wording. Remove pre-ticked boxes and split bundled consents so people can agree to marketing separately from, say, completing a purchase.
  3. Review data-sharing arrangements. Any arrangement where you pass customer data to another party for their marketing, or receive it, should be reviewed against the “trading” proposal.
  4. Check your opt-outs. Make unsubscribing simple across email, SMS and any other channel.
  5. Tidy up your contracts. Make sure agreements with your agencies and software providers set out how they may use your customers’ data.
  6. Update your breach response plan with a 72-hour timeline in mind.
  7. Get legal advice on how the final legislation applies to your business once it’s introduced. This article is general information, not legal advice.

The businesses that come out of privacy reform well will be the ones that treat customer data as something earned, not just collected. If you’d like help reviewing your tracking, consent and CRM setup, the Big Digital team is always happy to have a chat.

Photo: FlyD on Unsplash

Sources