Sep 02, 2026 · 8 min read
Australia's Privacy Bill Ends Consent as a Free Pass
On 31 August 2026 the Attorney-General's Department released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026. Its centrepiece asks a question no tick box can answer: was the data practice itself fair?
For thirty eight years, Australian privacy compliance has largely been an exercise in obtaining permission. Write the notice, surface the checkbox, log the consent, proceed. The second wave of reforms keeps the checkbox and takes away what it buys you: under the exposure draft, an organisation that collected information with textbook consent can still be in breach if the handling was not objectively fair and reasonable in the circumstances. Submissions close on 18 September 2026.
Key Takeaways
- The Attorney-General's Department opened consultation on the exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 on 31 August 2026, with submissions closing 18 September 2026.
- The bill introduces a fair and reasonable test: collection, use and disclosure must be objectively fair, reasonable and lawful, judged against reasonable expectations, transparency, minimisation, genuine choice and proportionality of harm.
- Where a child's information is involved, the child's best interests become a primary consideration in that test.
- The new right to erasure reaches only large digital platforms above roughly A$500 million group revenue or 2.5 million average Australian end users.
- Consent alone will no longer end the analysis, so an opt in checkbox on an email signup form stops being a complete defence for what happens to that address afterwards.
What Is the Fair and Reasonable Test?
The fair and reasonable test is a proposed obligation that data handling must be objectively fair, reasonable and lawful in the circumstances, assessed independently of whether the individual agreed to it. Writing in The Conversation, the test is framed as a shift of burden: the question is no longer whether you ticked the box, but whether the practice behind the box was defensible.
The factors an organisation would have to weigh:
- Reasonable expectations of the individual whose information it is.
- Transparency about what the organisation is actually doing.
- Minimisation: could the same purpose be achieved with less data?
- Genuine choice, as opposed to a flow engineered so refusing is impractical.
- Proportionality of the risk of harm against the benefit.
- The best interests of the child, as a primary consideration, wherever a child's information is in scope.
Practitioner summaries describe Australian Privacy Principles 3, 4 and 6 being consolidated into a single handling requirement. We have not read the operative section numbers in the draft text, so treat the exact drafting as unconfirmed.
How Is This Different From GDPR Fairness?
GDPR bolts fairness onto a lawful basis; Australia proposes to make fairness the basis. Under Article 5(1)(a) of the General Data Protection Regulation, a controller first picks a lawful basis from the Article 6 list, then processes lawfully, fairly and transparently. Fairness qualifies a gate you have already passed. In the Australian draft there is no menu of bases. There is one composite test, and it is the gate.
That distinction matters more than it sounds. European controllers have spent eight years arguing about which basis applies and very little about whether Article 5(1)(a) was satisfied on its own terms, because fairness has rarely been the operative hook in enforcement. Collapse the two and fairness is the only argument left. It is closer in spirit to the unfairness authority the US Federal Trade Commission exercises under Section 5, which we looked at when the FTC declined to ban personalised pricing and chose disclosure instead. One difference: the FTC's is enforcement discretion, Australia's would be a standing obligation.
What Else Is in the Exposure Draft?
The Attorney-General's Department consultation released the exposure draft alongside a consultation paper, and the package runs well past the headline test:
- A right to erasure, but a narrow one. Individuals could require destruction of information held by large digital platforms, with the threshold reported at group revenue of at least A$500 million or 2.5 million average Australian end users. That user figure is roughly one in eleven Australians, so it captures a very short list of companies and none of the mid sized senders filling your inbox.
- A reformed direct marketing regime replacing Australian Privacy Principle 7, with mandatory opt out mechanisms, a technology neutral definition of direct marketing, and rules for ad supported services and multi party advertising arrangements.
- Consent for data trading. Disclosing personal information for money, or for direct marketing, would require consent, with carve outs including services the individual requested.
- Seventy two hours to notify the Commissioner of an eligible data breach, replacing the current thirty day assessment window.
- A wider definition of personal information capturing inferences generated by AI systems, plus audio and video from wearables such as smart glasses. Biometric templates would require consent.
Announced the same day, separately from the bill, IDLock will let people block, unblock and monitor use of their passports and driver licences through the Document Verification Service, delivered via myGov to an early access cohort in 2026 before a national rollout in 2027.
What the Draft Does Not Do
The small business exemption survives. Practitioner summaries agree that the exemption for operators under the A$3 million turnover threshold, the most contested carve out of the first wave, is not proposed for repeal in this tranche. We could not confirm that from the bill text, so it is reported rather than verified.
Nor could we verify new civil penalty tiers in the second wave. The enforcement architecture already in force came from the first wave, passed in September 2024: a top tier reaching A$50 million for serious or repeated interference with privacy, a mid tier, a low tier, and infringement notices the OAIC can issue without going to court. The statutory tort for serious invasions of privacy commenced on 10 June 2025, letting individuals sue directly. A fairness test lands on top of that machinery, not in place of it.
One more gap. The 2023 Privacy Act Review Report proposed an unqualified right to opt out of targeted advertising, and we could not settle whether the draft carries it across as a standalone right or folds it into the direct marketing regime. Anyone whose business depends on the answer should read the draft, not the coverage.
What This Means for Your Inbox
Email is the channel where the gap between what people agreed to and what actually happens is widest, so a fairness standard bites hardest there. Someone who enters an address to download a whitepaper has consented to receiving the whitepaper. Whether they consented to a pixel logging the timestamp of every open, the device and the approximate location is a separate question, and the test makes it one the sender has to answer.
Run the factors against open tracking and the analysis gets uncomfortable. Reasonable expectations: most people do not know a one pixel image is reporting back. Transparency: open tracking is rarely disclosed anywhere a recipient would look. Minimisation: aggregate deliverability metrics achieve most of the commercial purpose without a per recipient behavioural log. Proportionality: the benefit is campaign optimisation, and the data reveals when a named individual is awake and where. None of that means the bill bans tracking pixels. It means consent stops being the end of the conversation.
The direction of travel is the opposite of Europe's. Italy's regulator tightened the consent gate in April 2026 when the Garante required prior consent for pixels measuring open rates. Australia is asking whether the gate does any work at all. A sender who satisfies Italy by adding a consent banner has done nothing for an Australian fairness test if the tracking behind the banner is disproportionate. And because the draft treats AI generated inferences as personal information, profiles built from open and click logs are squarely in scope, the same identifiability question the EDPB raised about whether tracking identifiers are really anonymous.
What Should You Do Before 18 September?
If you handle Australian personal information, the consultation window is the cheapest moment to influence the drafting, and the department has asked for concise submissions of around 1,000 words. Steps that hold regardless of the final text:
- Inventory what consent alone justifies. Anything where the only answer to "why is this lawful" is "they agreed" is the exposure.
- Write the fairness argument down now, per data flow, against the six factors. A process based regime rewards documentation you already have and punishes reconstructions made under investigation.
- Audit the marketing stack. Open tracking, click redirection, enrichment vendors and any disclosure of addresses for money are the flows most likely to fail proportionality.
- Test consent flows for genuine choice. Pre ticked boxes and designs that make refusal harder than acceptance are called out explicitly.
- Rehearse a 72 hour breach clock against your real escalation path, not the one in the policy document.
For individuals, the first wave already gave you more than most people use. Australia has spent two years legislating here, from the statutory tort through to the social media age restrictions and the surveillance they require, and the pattern holds: obligations keep moving onto the organisations holding the data.
Will It Actually Pass?
History suggests speed: the first wave went from introduction to passage in under three months in 2024, as the IAPP noted. What is different is that a fairness test imposes a cost no compliance team can absorb by writing a longer notice. It requires deciding not to do things, which is why the fight will concentrate on two words, "objectively" and "proportionate". If the test survives the Senate roughly intact, Australia will have the first general privacy statute where consent is evidence rather than authorisation.
Sources: Attorney-General's Department: Privacy Reform, consultation on exposure draft legislation; IAPP: Australia publishes initial proposals for second wave of Privacy Act reforms; The Conversation: Australia is eyeing a world first fair and reasonable test for data collection and privacy; Attorney-General's media release: new identity protection service IDLock; OAIC: Statutory tort for serious invasions of privacy. Provisions described as reported are drawn from published practitioner summaries of the exposure draft rather than the bill text, and are flagged as such above.