02 Sep 2026

Privacy Reform: What Practitioners Should Be Watching Before 18 September

Australia’s privacy landscape could be set for another significant shift, with the Australian Government releasing draft legislation and a consultation paper on 31 August 2026 aimed at modernising and strengthening the nation’s privacy laws.

Privacy Reform.png

On 31 August 2026, the Attorney-General's Department released a consultation paper and exposure draft - the Privacy Amendment (Personal Data Protection) Bill 2026 - as the next stage of reform to modernise the Privacy Act 1988 for the digital age. Submissions close Friday 18 September 2026, and the Department is encouraging concise submissions of around 1,000 words.

For members working across records, information governance, data governance and security, this consultation matters beyond the legal detail. Reform of this scale asks a practical question that sits squarely in our domain: can organisations actually do what the law will require of them?

What the reforms are responding to?

The package responds to growing privacy risks, including those associated with artificial intelligence, wearable surveillance technologies such as smart glasses and connected vehicles. The reforms aim to strengthen protections around collection, use, retention and an individual's ability to exercise their rights over their own information.

The scale of the package is significant - the consultation paper says the package includes roughly 40 proposals, comprising recommendations from the 2023 Privacy Act Review and additional measures. Central to the draft is a proposed “fair and reasonable” test for the collection, use and disclosure of personal information. Consent would not, by itself, make information handling fair and reasonable.

Why this is an information governance issue, not just a legal one?

Legislation sets the requirement. Whether an organisation can meet it depends on operational capability that legal teams alone cannot deliver. Some of the questions this consultation should prompt within your organisation:

  • Data inventory and lineage - Do you know what personal information you hold, where it resides, and how it moves between systems? Stronger accountability obligations are difficult to meet without this baseline.
  • Purpose and disclosure history - Can you demonstrate why information was collected, how it has been used, and who it has been shared with, across the full retention period - not just at the point of collection?
  • Consistent retention and destruction - Can retention and destruction requirements be applied consistently across the fragmented systems most organisations actually run, or only in the systems that were designed with this in mind?
  • Rights-response capability - Can you locate and act on information when an individual exercises existing access or correction rights? If your organisation is a large digital platform, could you also respond to the proposed right to erasure within a workable timeframe?
  • AI visibility - Can you identify when AI systems generate or use personal information, particularly where that use was not part of the original collection purpose?

Most of these are familiar information governance questions. What may change is the consequence of not being able to answer them.

The consultation is genuinely open on implementation?

The Department has specifically invited feedback on how the proposed measures would operate in practice - not only whether the policy intent is right, but whether the mechanics are workable. That is an invitation practitioners are well placed to respond to. Legislators can specify a right; they cannot specify, from outside an organisation, whether the systems and processes exist to deliver it. That translation work - from legal obligation to operational control - is where our expertise sits.

What we'd encourage members to do:

  • Read the exposure draft and consultation paper, available via the Attorney-General's Department consultation hub.
  • Consider making a submission, individually or through your organisation, focused on implementation and operational feasibility rather than policy position alone.
  • If you are contributing to an internal or peak-body submission, ground it in what you have actually observed trying to operationalise similar obligations under the current Act - that practical evidence is what strengthens a submission.

RIMPA Global is reviewing the proposed reforms and their implications for records and information management practice.  Members with practical experience of implementing privacy rights, managing personal information across multiple systems or governing AI-generated information are invited to share implementation issues that should inform RIMPA Global’s response.  

The consultation closes 18 September 2026

Visit the Privacy Reform page to review the draft Privacy Reforms or have your say!