Australia's Privacy Act Reforms: what organisations, boards and executives need to know

What has changed?

The Australian Government has released the Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026, representing the second major tranche of reforms to Australia's privacy framework. The Bill is currently proposed legislation, not law, with consultation open until 18 September 2026. The direction of reform is important in that privacy regulation would meaningfully move beyond whether an organisation has an appropriate privacy policy or has obtained consent, towards whether its collection, use, retention, protection, and sharing of personal information are objectively fair, reasonable, and appropriately governed.

Key proposed reforms include:

  • Fair and reasonable use of personal information

  • Organisations would need to demonstrate that the collection, use and disclosure of personal information is fair and reasonable in the circumstances. Excessive data collection or unexpected secondary uses could therefore be problematic, notwithstanding disclosure or consent.

  • Stronger standards for consent

  • Consent is intended to be voluntary, informed, current, specific and unambiguous. This may call into question consent mechanisms embedded in opaque terms or effectively imposed on a take-it-or-leave-it basis.

  • Restrictions on trading personal information

  • Stronger controls would apply to buying, selling, or otherwise trading information, such as individuals' interests, behaviours, and location data, without clear permission.

  • Broader treatment of digital information

  • The reforms seek to modernise the concept of personal information for a technology environment in which behavioural, inferred and device-generated information can identify or reveal information about individuals.

  • Stronger data breach requirements

  • The Exposure Draft would introduce a 72-hour deadline for notifying the OAIC of an eligible data breach once the relevant threshold is met, materially compressing regulatory response timeframes. The current Privacy Act instead requires notification as soon as practicable following an eligible breach.

  • A (focused) right to erasure

  • Individuals would be able to request the deletion of their personal information from certain large digital platforms.

The precise application of the reforms will – of course – continue to depend on the final legislation and whether an organisation is within the scope of the Privacy Act.

What does this mean for Boards and risk managers?

From a broad cyber and incident-response risk perspective, the proposed 72-hour notification requirement increases the importance of rapid incident detection, escalation, and decision-making. An organisation needs to be able to determine quickly what occurred, what information was affected, the likely consequences for individuals, and which regulators, customers, and other stakeholders require notification. Incident-response plans should therefore be operational and tested, rather than simply documented.

From a data and technology risk perspective, the reforms in their current state reinforce the rhetoric that Privacy risk increasingly begins before a cyber incident occurs. Organisations should understand what personal information they collect, why they collect it, where it is held, which third parties can access it, how long it is retained and how it is ultimately destroyed or de-identified.

Importantly, this is distinct from much of the traditional cyber-risk discussion, which has understandably focused on resilience, preparedness, and incident response once an event occurs. Those capabilities remain critical – and the proposed 72-hour notification timeframe makes them more so – but the reforms place increased emphasis on the decisions made before an incident ever happens, whether information should have been collected in the first place, whether its use remains appropriate, whether access is sufficiently controlled and whether there is a legitimate reason to continue retaining it.

The reforms, therefore, reinforce the value of data minimisation and lifecycle governance. Information that an organisation does not reasonably need to collect or retain not only creates a privacy risk but also increases the potential severity, complexity, and cost of a future cyber incident.

D&O/directors' duties

Privacy and cyber risk are increasingly an enterprise governance issue. ASIC has expressly stated that Boards should ensure cyber risks are adequately addressed within the organisation's risk-management framework and has warned that failing to address cyber security or relevant disclosure and reporting obligations adequately may constitute a breach of directors' duties.

For directors, the issue is therefore not an expectation that every incident can be prevented. Rather, the Board should be able to demonstrate informed oversight, appropriate investment and challenge, clear accountability and reasonable preparedness for foreseeable privacy, cyber and data risks.

From a data perspective, this increasingly raises a broader governance question: how much meaningful focus from the Board and management is being applied to the information the organisation holds and the risks it creates? Directors should consider whether they are sufficiently informed about what personal information the organisation collects and retains, the purposes for which it is used, its material data dependencies and third parties, and whether the organisation is investing appropriately in the people, systems and governance required to manage those exposures. As with cybersecurity more broadly, effective oversight does not require directors to become technical specialists, but it does require sufficient understanding to ask informed questions, challenge management, and satisfy themselves that material risks are being appropriately managed.

Where does insurance fit?

Cyber insurance can provide an important financial and operational backstop should an incident occur, including well-established access to a specialist incident-response ecosystem. In the context of the proposed reforms, that capability potentially becomes even more relevant – particularly where an organisation may need to investigate, triage and make regulatory decisions within a 72-hour notification timeframe.

Without insurance, an organisation seeking to replicate the same capability itself would need to identify and diligence appropriate specialists, establish individual retainers and commercial arrangements, ensure availability, determine escalation protocols and then coordinate those parties during an incident. An appropriately designed cyber insurance program can establish much of this ecosystem in advance and provide a known pathway for accessing and coordinating it when time is critical. Cyber insurance can therefore form part of incident-response preparedness and broader cyber-risk posture, rather than being viewed as a mechanism for transferring financial loss.

Further, insurer underwriting and policy-placement processes can also provide a useful external reference point for prevailing cyber-risk controls and market expectations. However, they should complement – rather than replace – an organisation's own governance and risk-management framework.

Future outlook

Although the proposed reforms remain subject to consultation, the message is clear: privacy compliance is becoming less about ticking regulatory boxes and more about responsible data stewardship. Organisations that take a proactive approach to reviewing their privacy practices today will be better equipped to manage risk and maintain trust in the years ahead.

The contents of this publication are provided for general information only. Lockton arranges the insurance and is not the insurer. While the content contributors have taken reasonable care in compiling the information presented, we do not warrant that the information is correct. The contents of this publication are not intended as a legal commentary or advice and should not be relied on in that way. It is not intended to be interpreted as advice on which you should rely and may not necessarily be suitable for you. You must obtain professional or specialist advice before taking, or refraining from, any action based on the content in this publication.

© 2026 Lockton Companies Australia Pty Ltd.