The Australian Government has released the 2026 Privacy Amendment exposure draft for public consultation, with submissions closing on 18 September 2026. If enacted in its current form, it would represent the most material change in a generation to how Australian businesses collect, use, retain and protect personal information.
This article separates three very different things: obligations already in force, changes already legislated but commencing later, and proposals in the Exposure Draft that are not yet law. Nothing in the Exposure Draft is currently binding.
This article provides general information and is not legal advice. Organisations should obtain advice relevant to their circumstances. Primary sources: the Attorney-General's Department privacy reform consultation, the consultation paper, the Government response to the Privacy Act Review, and the OAIC consultation on automated decision-making transparency.
What is changing in Australia's privacy laws?
The Privacy Act 1988 and the Australian Privacy Principles remain the law today. What the Government is consulting on is a substantial rewrite of the definitions, standards and enforcement settings that sit underneath them.
The most consequential proposal is a broader definition of personal information. The Exposure Draft moves from information being "about" an individual to information that "relates to" an identified or reasonably identifiable individual. That wording change looks small and is not. Under the proposed test, categories of data that many organisations currently treat as technical or operational could fall inside scope, including:
- device identifiers;
- behavioural information;
- location data;
- online activity and session data;
- profiling and audience segments;
- telemetry and diagnostic logs;
- AI-derived or inferred information.
For most Australian businesses the practical consequence is simple: the volume of data governed by privacy obligations would grow, often in systems owned by marketing, product and IT rather than legal.
The new fair and reasonable test
Under the Exposure Draft, collection, use and disclosure of personal information would increasingly need to satisfy a broader fair and reasonable standard, assessed objectively against what a reasonable person would expect.
Disclosure alone would no longer be a defence. Mentioning a use of data deep in a privacy policy does not automatically make that practice fair or reasonably expected, and consent would not cure a practice that fails the standard.
Callout — Fair and reasonable test. The privacy question is shifting from "Did we disclose this?" to "Can we justify doing this at all?"
Consent will need to be meaningful
The Exposure Draft proposes that, where consent is relied on, it must be voluntary, informed, current, specific and unambiguous.
If enacted, that has direct engineering consequences for:
- website and landing-page forms, including pre-ticked boxes and bundled consents;
- CRM systems that store a single undated "opted in" flag;
- marketing automation and lifecycle campaigns;
- customer portals, mobile applications and account sign-up flows;
- analytics, tracking and consent banners.
Practically, organisations need consent records that show what a person agreed to, when, and on what wording — not simply that a checkbox once existed.
Data minimisation becomes a business requirement
Minimisation is impossible without visibility. Before any policy decision, organisations need to answer six questions for each category of personal information:
- what do we collect;
- why do we collect it;
- where is it stored;
- who can access it;
- which third parties receive it;
- how long do we keep it.
In a typical Australian business, customer data is spread across Microsoft 365, SharePoint, Teams, CRM platforms, ERP systems, third-party SaaS applications, email mailboxes, laptops, file servers, backups, marketing systems and legacy applications that nobody has decommissioned. Our managed Microsoft 365 services and managed SharePoint work usually starts here, because a data map is the prerequisite for everything else.
Callout — Data minimisation. You cannot minimise, secure, retain or delete data you have never inventoried.
Stronger security expectations under APP 11
APP 11 already requires reasonable steps to protect personal information. The proposed reforms sharpen it: identify where personal information is held, implement proportionate technical and organisational controls, and regularly assess whether those controls are actually effective — not merely documented.
For a Microsoft-centric environment, that maps to concrete capability:
- Identity — Microsoft Entra ID, MFA, Conditional Access and privileged access management.
- Devices — Microsoft Intune for enrolment, compliance policies and encryption.
- Threat protection — Microsoft Defender, vulnerability management and patching.
- Monitoring — logging, retention of audit data and a managed security operations centre.
- Information protection — Microsoft Purview for classification, sensitivity labels, data loss prevention and retention.
- Response and recovery — tested incident response plus backup and recovery.
Independent frameworks help evidence effectiveness. Most organisations we work with align controls to the Essential Eight and, where commercially relevant, ISO 27001 — Mycelium 365's own certifications follow the same logic.
Data retention and deletion
Retaining information indefinitely increases privacy exposure and cyber risk at the same time: every record kept beyond its purpose is a record that can be breached, discovered or misused.
Common accumulation points include:
- dormant mailboxes belonging to departed staff;
- old SharePoint sites and Teams channels nobody owns;
- forgotten SaaS platforms still holding exported customer lists;
- legacy on-premises servers kept "just in case";
- redundant or duplicated CRM records;
- archived databases and long-tail backups.
Microsoft Purview retention policies, labels and disposition review, combined with information governance across Microsoft 365, allow retention rules to be enforced by the platform rather than by memory. Our cyber security services and managed IT services typically implement this alongside identity and device hardening.
Faster data breach response
The Exposure Draft proposes notifying the OAIC of an eligible data breach within 72 hours of becoming aware of it, materially shorter than the current assessment window. This is proposed legislation and may change before passage — but the operational capability it assumes takes months to build.
Callout — Proposed 72-hour breach notification. Under the Exposure Draft, eligible data breaches would be notifiable to the OAIC within 72 hours. Not yet law; timing and thresholds may change.
A documented and tested response process should cover incident declaration, containment, legal escalation, OAIC notification, identification of affected data and individuals, log preservation, supplier and vendor escalation, and customer communications. Detection and evidence collection are practical prerequisites, which is where security monitoring and a well-run helpdesk intersect: most incidents are first reported as an ordinary support ticket.
Marketing and customer data
The reforms would touch marketing operations more than most teams expect. Areas to review include email marketing and SMS, behavioural and targeted advertising, CRM segmentation, website analytics, data enrichment platforms and advertising platform audience uploads.
The core requirement is to understand how customer data moves between systems — which platform is the source of truth, which integrations copy data outward, and whether every destination is disclosed and justifiable.
Trading personal information
The Exposure Draft proposes that trading personal information — disclosing it for a benefit — would require consent. If enacted, that would have direct implications for data brokers, lead generation, purchased third-party marketing lists, customer enrichment services and advertising platforms that ingest customer data.
Organisations that buy or sell audience data should be mapping those flows now, including contractual warranties from suppliers about how their lists were assembled.
Right to erasure
The proposed right to erasure is not currently drafted as a universal, GDPR-style right to be forgotten for all Australian organisations. Under the Exposure Draft it is targeted primarily at large digital platforms that meet defined thresholds.
Existing APP 11.2 obligations to destroy or de-identify information no longer needed already apply to regulated entities. The sensible planning position is capability, not panic: be able to locate and delete an individual's data across your systems, because that capability supports retention, breach response and customer expectations regardless of how the erasure right is finalised.
Controllers and processors
The Exposure Draft proposes distinguishing controllers (who determine the purposes and means of processing) from processors (who process on a controller's instructions) — a concept familiar from GDPR but new to Australian statute.
This matters most to managed service providers, SaaS vendors, payroll companies, cloud providers, outsourced service providers and professional services firms. If enacted, contracts would need documented processing instructions, defined security responsibilities, sub-processor disclosure, breach notification timelines between the parties, and clear return-or-destroy obligations at exit.
Mycelium 365 already operates to documented security responsibilities across client environments, and this is a good reason to review supplier agreements as part of governance and compliance readiness.
What does this mean for Privacy Act regulated organisations?
A practical five-step readiness framework:
1. Map your data
Identify what personal information exists, in which systems, under whose ownership, and which third parties receive it.
2. Review collection practices
For each category, determine whether the information is genuinely required for a stated purpose — and stop collecting what is not.
3. Validate security controls
Confirm identity, device, data and monitoring controls are implemented and operating effectively, with evidence.
4. Establish retention and deletion policies
Define when data is retained, destroyed or de-identified, and enforce it through platform retention rather than manual process.
5. Test incident response
Run tabletop exercises and breach simulations against a 72-hour clock, including supplier escalation and customer communications.
What does this mean for currently non-regulated organisations?
The existing small business exemption has not simply been removed by the current Exposure Draft. Many small businesses remain outside parts of the Privacy Act framework, subject to the existing exceptions (health service providers, businesses trading in personal information, contracted service providers to the Commonwealth, credit reporting and related categories).
That is a statutory answer, not a commercial one. Privacy expectations increasingly flow through commercial relationships: enterprise customer contracts, supply-chain security requirements, cyber insurance underwriting, tender responses, ISO 27001 alignment, security questionnaires, government contracts and obligations passed down from regulated customers.
Callout — Regulated vs non-regulated. Being outside the Privacy Act does not necessarily mean being outside your customer's privacy requirements.
Regulated vs non-regulated comparison
| Area | Privacy Act regulated organisation | Currently non-regulated organisation |
|---|---|---|
| Data inventory | Required in practice to meet APP 1 and APP 11; scope would broaden under the Exposure Draft (proposed) | Not a statutory obligation; commonly required by enterprise customers and insurers |
| Data minimisation | APP 3 applies now; a broader fair and reasonable test is proposed | Driven by contract and risk, not statute |
| Privacy policy | Mandatory under APP 1 | Good practice; often required in tenders |
| Cyber security controls | APP 11 now; effectiveness testing emphasised under the Exposure Draft (proposed) | Driven by customer contracts, insurance and Essential Eight expectations |
| Retention | APP 11.2 destruction or de-identification applies now | Contractual and risk-based |
| Breach response | Notifiable Data Breaches scheme applies now | No OAIC obligation; contractual notification clauses commonly apply |
| OAIC notification | Currently assessment-based; 72 hours proposed under the Exposure Draft | Not applicable unless an exception brings you into scope |
| Consent management | APP 3 and APP 7 now; voluntary, informed, current, specific and unambiguous consent proposed | Spam Act and Do Not Call obligations still apply to marketing |
| Direct marketing | APP 7 applies now | Spam Act 2003 and telemarketing rules apply regardless |
| Supplier governance | APP 8 for overseas disclosure; controller and processor duties proposed | Flows down through customer contracts |
| Automated decision-making | Privacy policy transparency requirements commence 10 December 2026 (legislated) | Not directly regulated; customer and sector expectations apply |
AI and privacy
AI does not simply read personal information — it generates and infers it. A summary, a risk score, a sentiment classification or a next-best-action recommendation can itself be personal information that "relates to" an identifiable individual under the proposed definition.
This applies to Microsoft Copilot, AI agents, CRM intelligence features, automated HR screening, profiling, automated decisioning and customer service AI. Two governance realities follow. First, Copilot inherits existing permissions: if SharePoint access is over-broad, AI will surface data faster than any human ever did. Second, AI outputs need the same classification, retention and access controls as source data.
Separately — and this is already legislated, not proposed — transparency requirements for automated decision-making are scheduled to commence on 10 December 2026, requiring applicable APP entities to disclose in their privacy policies the kinds of personal information used in computer programs that make, or substantially assist in making, decisions significantly affecting individuals. The OAIC has consulted on guidance for this.
Callout — AI and automated decisions. Legislated ADM transparency commences 10 December 2026. Broader AI-related privacy changes remain proposals under the Exposure Draft.
Practical preparation usually starts with an AI readiness assessment, permissions remediation across Microsoft 365, and AI strategy advisory to set governance before deployment.
Privacy is becoming a technology architecture issue
The conclusion for most Australian boards is that privacy can no longer be treated as a privacy-policy exercise with a legal owner and an annual review. If enacted, the reforms assume organisations can demonstrate what data they hold, justify why they hold it, prove controls work, delete on schedule and respond to a breach within days.
Policy only becomes real when the technology enforces it — through identity and access control, endpoint management, information classification, data loss prevention, retention, monitoring, AI governance and tested incident response. That is the substance of Mycelium 365's Security by Design approach: configure the Microsoft platform so that the compliant path is the default path, then evidence it.
Where a broader technology plan is needed, a technology roadmap or Fractional CIO engagement is usually the right vehicle, supported by Azure and managed IT services day to day.
Is your Microsoft environment ready for Australia's next privacy regime?
Most organisations already have many of the required capabilities available through Microsoft 365, Entra ID, Intune, Defender, Purview and Azure — but they are often not configured as an integrated privacy and security framework.
Mycelium 365 can help assess your current environment, identify privacy and security gaps and develop a practical roadmap aligned with your regulatory and commercial requirements.
This article provides general information and is not legal advice. Organisations should obtain advice relevant to their circumstances, and should monitor the Exposure Draft process — consultation closes 18 September 2026 and the final legislation may differ from the proposals described here.
