Australia · Privacy reform exposure draft

Australia’s privacy rules are changing. Are you ready?

Loyalty programs, adtech, AI profiles, customer lists, cloud systems and breach response could all be caught. If the proposal becomes law, weak consent, unexplained data sharing and poor retention controls may be far more difficult - and expensive - to defend.

· General information

A person using a laptop with digital identity, data and security graphics

Status of the proposal

Change is upon us.

The Australian Government released the exposure draft Privacy Amendment (Personal Data Protection) Bill 2026 and a consultation paper on 31 August 2026.

What this means for retailers

Routine digital retail practices could require a more defensible purpose, stronger choice and better evidence.

  • Loyalty and CRM: confirm which information is necessary for membership, which uses are optional and whether inferred profiles remain within customer expectations.
  • Websites and adtech: identify every tag, cookie, pixel, audience upload and server-side disclosure, including the recipient, purpose and legal basis.
  • Personalisation and AI: document what customer attributes are generated, how they influence offers or decisions and whether less information could achieve the purpose.
  • Apps and location: separate one-off service location from ongoing precise tracking and test whether collection settings give a genuine choice.
  • Marketing: connect email, SMS, social, display and behavioural advertising preferences so an opt-out can be actioned across relevant identifiers and channels.
  • Vendors: reconcile contracts, documented instructions, subprocessors, overseas access and the service’s actual data use.
  • Retention: map customer, transaction, complaint, CCTV, analytics and marketing data to a defensible retention and destruction rule.
  • Incidents: make sure ecommerce, stores, service providers and security teams can escalate an incident quickly enough for a 72-hour notification decision if the proposal becomes law.

What would change

The proposal would change the legal test, the information in scope and the controls around data use.

1. A new ‘fair and reasonable’ test

Much of APPs 3, 4 and 6 would be replaced by a single framework for collection, use and disclosure. Handling would need to be lawful and fair and reasonable in the circumstances.

The assessment would consider reasonable expectations, the entity’s functions and activities, transparency, data minimisation, genuine choice, the impact on the individual, proportionality and, where children are affected, the child’s best interests as a primary consideration. No single factor would decide the outcome.

A statement buried in a privacy policy would not, by itself, make an unexpected or excessive practice fair and reasonable.

2. More retail data could be ‘personal information’

The definition would change from information ‘about’ an individual to information that ‘relates to’ an identified or reasonably identifiable individual. The draft recognises that information may be generated or derived through data analysis, artificial intelligence or other technology.

Retailers should therefore look beyond names and contact details. Customer segments, predicted interests, shopping patterns, device-linked behaviour, loyalty insights and AI-generated profiles may be within scope where they have the required connection to an identifiable or reasonably identifiable person.

3. Consent would have to meet a higher standard

Consent would need to be voluntary, informed, current, specific and unambiguous. Bundled consent and interfaces that make consent difficult to refuse are unlikely to satisfy that test. Preselected settings and pre-ticked boxes would also be vulnerable.

Consent would not become the answer to every privacy question. A retailer would still need to assess whether the underlying collection, use or disclosure is fair and reasonable where that requirement applies.

4. Trading personal information would require consent

The proposal defines ‘trade’ broadly. It includes disclosures for money or other consideration and disclosures for direct marketing purposes, subject to specified carve-outs and exceptions.

The consultation paper says this may include customer-list transfers and disclosure of cookies or pixels in programmatic advertising processes. Retailers should not assume this is limited to the conventional sale of a database.

5. Direct marketing would include behavioural and audience targeting

The proposed definition covers advertising or marketing directed to a person using personal information, whether the person is targeted individually or as part of an audience, segment or cohort. The consultation paper gives targeted social media advertising and online behavioural advertising based on browsing history as examples.

The proposal does not require consent for every direct marketing communication. It would require a simple opt-out mechanism, reasonable steps to action an opt-out, and clear information about how to opt out. Separate consent requirements may still apply where the retailer trades personal information.

6. Some location and genomic data would become sensitive information

Genomic information and ‘precise geolocation tracking data’ would be added to the sensitive-information definition. The geolocation definition covers location within a radius of 500 metres that is collected and held by reference to the individual’s location over time. It is not directed at one-off or city-level location data.

7. Eligible data breach notification would move to 72 hours

An entity would need to notify the Information Commissioner within 72 hours after becoming aware of reasonable grounds to believe that an eligible data breach has occurred. If a complete statement is impossible or impracticable within that period, an incomplete statement could be lodged and supplemented as soon as practicable.

The separate obligation to assess a suspected eligible data breach within 30 days would remain. The draft would also add clearer duties to prepare for breaches and take reasonable steps to prevent or reduce harm.

8. Security, retention and de-identification would need ongoing evidence

APP entities would need to identify the personal information to which APP 11 applies, consider destruction before retaining no-longer-needed information in de-identified form, and regularly assess the effectiveness of security, destruction and de-identification measures.

That includes checking whether de-identified information remains de-identified, whether re-identification risks are being managed and whether continued retention is justified.

9. Controller and processor roles would affect technology contracts

The draft would recognise a controller-processor relationship where one APP entity acts for another APP entity in accordance with documented instructions and only for specified purposes. The controller would generally bear responsibility for APP compliance, while processors would remain directly responsible for APPs 1 and 11.

This is not a label that can simply be inserted into a contract. Retailers would need to check what each cloud, ecommerce, analytics, marketing and fulfilment provider actually does with the information and whether the documented instructions match the live service.

10. The proposed erasure right is limited

The new right would apply to ‘large digital platforms’, not to every retailer. A platform would need to fall within specified Online Safety Act service definitions and meet at least one threshold: group gross revenue of $500 million or more in the previous financial year, or an average of at least 2.5 million monthly Australian end users during that year. Regulations could also prescribe platforms or classes of platforms.

Requests would be subject to exceptions. Retailers should assess the definition and thresholds rather than assuming that every ecommerce website is covered.

Do not wait for the final law to discover that your data practices need major repair

Continue complying with the law that applies now, but test the proposal against the business now. Systems, contracts, consent journeys, advertising technology and retention controls can take months to change.

The practical lesson

Do not start with a privacy policy rewrite. Start with the live retail data journey.

A retailer cannot assess this proposal by reading its privacy policy alone. The practical questions sit in the systems and processes that collect, generate, combine, use and disclose customer information.

That includes websites, apps, loyalty programs, ecommerce accounts, customer service, delivery and returns, CCTV and in-store technology, analytics tags, advertising pixels, audience tools, data clean rooms, AI profiles, fraud systems, cloud platforms and third-party marketplaces.

If the business cannot identify what information moves through those systems, why it is needed, who receives it and how long it is retained, it will struggle to apply the proposed tests or demonstrate that its controls work.

What is not in the draft

Some earlier reform proposals have not been carried into this exposure draft.

The exposure draft does not contain provisions abolishing the general small-business operator exemption or the private-sector employee-records exemption. Those exemptions are already qualified, so a business should confirm whether it is actually outside the Act rather than relying only on turnover or the word ‘employee’.

The draft also does not create a general direct right of action for every Privacy Act breach and does not impose a new mandatory privacy impact assessment requirement on private-sector organisations for every high-risk activity. This does not remove existing complaint, regulator and penalty exposure or the separate statutory tort for serious invasions of privacy.

A proportionate privacy impact assessment can still be one of the most useful ways to test a new technology, customer-data use or vendor arrangement and document the reasoning.

What retailers should do now

Find the practices that would be hardest and most expensive to change.

  1. Confirm coverage. Identify the entities and activities currently covered by the Privacy Act and any exemptions or exceptions being relied on.
  2. Map the live data journey. Start with ecommerce, loyalty, apps, customer service, stores, delivery, adtech, marketplaces, AI tools and cloud providers.
  3. Record purpose and necessity. For each material practice, document why the information is needed, who benefits and whether a less privacy-invasive option could work.
  4. Audit consent and choice. Find bundled terms, pre-ticked settings, dark patterns, compulsory marketing choices and consent that no longer matches current practice.
  5. Test advertising disclosures. Identify cookies, pixels, audience tools and other disclosures that could fall within the proposed ‘trade’ definition.
  6. Connect opt-outs. Check whether preferences can be applied across campaigns, agencies, platforms, identifiers and devices.
  7. Shorten breach decision time. Update escalation, evidence collection, legal assessment and draft notification processes against the proposed 72-hour period.
  8. Strengthen retention and vendor controls. Set accountable review cycles and make documented instructions match the service that is actually delivered.
  9. Create a controlled change plan. Assign owners, priorities and monitoring triggers so the business can respond when the Bill changes or progresses.

How Watchdog can help

Turn the proposal into a practical retail readiness plan.

Watchdog can review the proposed reforms against your customer journey, data flows and current controls. We can help map systems and vendors, assess consent and adtech, test direct marketing and opt-out processes, review retention and incident readiness, identify priority gaps and prepare a practical submission or implementation plan.

Privacy reform readiness review

Tell us how your business collects and uses customer information and where the greatest uncertainty sits. We will help you identify what should be addressed now and what should be monitored as the Bill develops.

Official sources

Primary material used for this update.

Important information

Keep the proposal separate from the law that applies today.

This update is general information, not legal advice. It describes an exposure draft released for consultation and should not be treated as enacted law. The Privacy Act and other privacy, marketing, surveillance and consumer laws may already apply to current practices. The correct position depends on the entity, activity, information, technology and contractual arrangements. Obtain advice for your circumstances before acting.

The draft has not been introduced into or passed by Parliament. It has no commencement date. Its content may change following consultation and the parliamentary process.

Find the risk before it becomes an enforcement problem

Could your retail data practices survive the proposed test?

Watchdog can map the customer-data journey, expose the practices most likely to fail and give your business a clear order of action.