Australia’s Privacy Reforms: What Your Business Contracts Need Now

Australia’s proposed privacy reforms could change how businesses collect, use, share and protect personal information. Businesses should review their commercial contracts, data practices and AI arrangements now, before the proposals become law.

The draft Bill is a warning that privacy compliance is becoming a core commercial issue. Businesses that understand their data and strengthen their contracts now will be better placed to manage regulatory change, protect transaction value and adopt AI with confidence. 

Privacy reform is moving quickly

On 31 August 2026, the Australian Government released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026. It proposes major changes to the Privacy Act 1988 (Cth). The proposals are not yet law and may change after consultation. 

The draft Bill would broaden key definitions, introduce a single “fair and reasonable” test for handling personal information, strengthen consent and data-security duties, tighten breach reporting, and create controller and processor concepts. It also targets risks linked to AI and other emerging technology. 

  • Wider coverage: more information, including some AI-generated inferences, may be treated as personal information. 
  • Fair and reasonable handling: consent alone may not make a data practice acceptable. 
  • Stronger consent: consent would need to be voluntary, informed, current, specific and unambiguous. 
  • Security and breach response: businesses may face clearer and faster response duties. 
  • New roles: controller and processor concepts may change how responsibility is shared between customers and suppliers. 

What could your business lose?

Privacy risk is not limited to a regulator’s fine. Poor data practices can delay a sale, reduce the price of a business, trigger warranty or indemnity claims, and undermine trust with customers and suppliers. 

A buyer may discover that customer data was collected under old notices, shared with service providers under weak contracts, or used to train an AI tool without a clear legal basis. The buyer may then require remediation before completion, seek a price reduction, demand a specific indemnity, or walk away. 

Operational disruption can also be significant. A data breach may require urgent investigation, notification, customer communication and system changes. If contracts do not clearly allocate responsibility, the parties can spend critical time arguing about who must act and who must pay.

The key message: do not wait for the law to change

Businesses should review their data map and key contracts now. The aim is to understand what personal information enters the business, why it is used, where it is stored, who receives it and when it is deleted. 

Priority contract terms include: 

  • the purpose for which data may be collected and used; 
  • ownership and permitted use of customer, employee and derived data; 
  • whether data may be used to train, test or improve AI systems; 
  • minimum security controls and audit rights; 
  • subcontractor approval and flow-down obligations; 
  • cross-border storage and disclosure; 
  • breach reporting timeframes and cooperation duties; 
  • data return, deletion and transition support when the contract ends; and 
  • warranties, indemnities and liability caps for privacy breaches. 

A common commercial scenario

A business appoints a cloud software provider to manage customer enquiries. The provider sends data overseas, uses subcontractors and offers an AI feature that analyses messages. The contract says little about how the AI feature uses the data or whether the provider can retain it to improve its model. 

Under the proposed framework, that arrangement may raise questions about fairness, transparency, consent, security and the parties’ respective roles. Even under the current law, the business should understand what personal information is submitted to the tool, what outputs it creates and who can access the information. 

The safer approach is to complete privacy and security due diligence before signing. The contract should then set clear limits on data use, require suitable safeguards, impose prompt incident reporting, and give the customer practical rights if the provider fails to comply. 

How we help

We help businesses prepare for privacy change without losing sight of commercial outcomes.  

We can: 

  • review privacy, data-sharing, SaaS, outsourcing and AI contracts; 
  • identify gaps in data rights, security duties and risk allocation; 
  • prepare privacy and cyber due-diligence questions for acquisitions; 
  • draft warranties, indemnities, conditions precedent and remediation plans; 
  • update customer and supplier terms so they reflect how data is actually used; and 
  • help respond to privacy incidents and disputes. 

Business Lawyers for Sydney and Newcastle

Need Answers Fast? Contact Us Today

The information in this article is not legal advice and is intended to provide commentary and general information only. It should not be relied upon or used as a definitive or complete statement of the relevant law. You should obtain formal legal advice specific to your particular circumstance. Liability limited by a scheme approved under Professional Standards Legislation.

Author
Partner
Accredited Specialist (Business Law)