Privacy reform is moving quickly
On 31 August 2026, the Australian Government released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026. It proposes major changes to the Privacy Act 1988 (Cth). The proposals are not yet law and may change after consultation.
The draft Bill would broaden key definitions, introduce a single “fair and reasonable” test for handling personal information, strengthen consent and data-security duties, tighten breach reporting, and create controller and processor concepts. It also targets risks linked to AI and other emerging technology.
- Wider coverage: more information, including some AI-generated inferences, may be treated as personal information.
- Fair and reasonable handling: consent alone may not make a data practice acceptable.
- Stronger consent: consent would need to be voluntary, informed, current, specific and unambiguous.
- Security and breach response: businesses may face clearer and faster response duties.
- New roles: controller and processor concepts may change how responsibility is shared between customers and suppliers.
What could your business lose?
Privacy risk is not limited to a regulator’s fine. Poor data practices can delay a sale, reduce the price of a business, trigger warranty or indemnity claims, and undermine trust with customers and suppliers.
A buyer may discover that customer data was collected under old notices, shared with service providers under weak contracts, or used to train an AI tool without a clear legal basis. The buyer may then require remediation before completion, seek a price reduction, demand a specific indemnity, or walk away.
Operational disruption can also be significant. A data breach may require urgent investigation, notification, customer communication and system changes. If contracts do not clearly allocate responsibility, the parties can spend critical time arguing about who must act and who must pay.