← Insights / Compliance

Australia's Privacy Amendment Bill 2026: erasure rights, controller/processor framework, and 18 September submission deadline

Australia's Attorney-General Michelle Rowland released the exposure draft of the *Privacy Amendment (Personal Data Protection) Bill 2026* on 31 August 2026, opening a three-week public consultation window that closes on 18 September. For international professional services firms and global enterpris

Compliance 5 September 2026 6 min read

Australia's Privacy Amendment Bill 2026: What International Businesses Need to Know Before 18 September

Australia's Attorney-General Michelle Rowland released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 on 31 August 2026, opening a three-week public consultation window that closes on 18 September. For international professional services firms and global enterprises that handle Australian personal data, this is not a distant regulatory development to monitor from afar. The draft legislation introduces structural changes to how personal information must be collected, used, stored, and erased — and several of its provisions have direct implications for organisations headquartered well outside Australia.

This briefing sets out what the Bill proposes, where the obligations fall, and what businesses with cross-border data flows should be doing now.


The Bill introduces a new 'fair and reasonable' test for the collection and use of personal information. This shifts the compliance baseline from a procedural question — did you obtain consent or identify a lawful basis? — to a substantive one: would a reasonable person consider this collection or use fair in the circumstances?

This framing will be familiar to organisations already operating under the UK GDPR's legitimate interests balancing test or the EU's broader proportionality requirements, but it is not identical. The Australian version is context-specific and not tied to a closed list of lawful bases. In practice, it means that businesses collecting personal data from Australian individuals will need to conduct documented assessments of whether their data practices are genuinely justifiable, not merely technically permitted.

For multinationals running standardised global data collection processes, this test creates a localisation pressure. A consent mechanism or data use policy that satisfies one jurisdiction's requirements may not clear Australia's 'fair and reasonable' threshold without adjustment.


The Bill tightens consent requirements, moving closer to the granular, informed, and specific standards that GDPR-experienced organisations will recognise. Bundled or pre-ticked consent mechanisms will face greater scrutiny. Where consent is the chosen mechanism, it must be freely given, clearly expressed, and capable of being withdrawn without detriment.

For businesses that rely on consent as a primary lawful basis for processing Australian personal data — particularly in marketing, analytics, or data-sharing contexts — existing consent architectures will need review. Organisations that have already overhauled their consent frameworks for GDPR or similar regimes will have a head start, but direct comparison is insufficient. Australian law has its own regulatory context, and assumptions of equivalence carry compliance risk.


Right of Erasure: Targeted at Large Digital Platforms

The Bill introduces a right of erasure, but its initial scope is deliberately narrow. The right is targeted at large digital platforms rather than applied universally across all data controllers. This mirrors a pattern seen in other jurisdictions where erasure obligations are phased in, beginning with high-volume consumer-facing platforms before broader extension.

International businesses operating consumer-facing digital services in Australia — particularly those meeting scale thresholds that qualify them as large digital platforms — should treat this as an immediate compliance concern, not a future consideration. The infrastructure required to honour erasure requests reliably, particularly across distributed systems or where data has been shared with downstream processors, takes time to build and test.

Organisations that have already implemented erasure workflows under GDPR Article 17 should audit whether those workflows extend to Australian data subjects and whether the definitional boundaries under the new Bill align with their existing processes.


Controller/Processor Framework: A Significant Structural Change

One of the most consequential reforms in the Bill is the introduction of a statutory controller/processor framework. Australia's Privacy Act has historically lacked this distinction, placing obligations on 'APP entities' without differentiating between those who determine the purposes of processing and those who act on another's instructions.

The new framework brings Australia broadly into line with GDPR architecture, creating clearer accountability chains and — critically — direct obligations on processors, not just controllers. For international businesses operating as data processors for Australian clients, or running shared service centres that process Australian personal data on behalf of group entities, this is a material change.

Existing data processing agreements will need to be reviewed against the new framework. Contractual provisions that were sufficient under the previous APP entity model may no longer allocate responsibility correctly. Processors who have previously operated at arm's length from Australian privacy obligations will now face direct regulatory exposure.

This also has implications for outsourcing arrangements. Professional services firms acting as processors — in IT, finance, HR, legal, or consulting functions — should anticipate that Australian clients will begin requesting updated data processing agreements that reflect the new statutory framework, likely before the legislation is finalised.


IDLock and Digital Identity Protection

The Bill introduces a new digital identity protection service called IDLock, designed to help individuals protect their identity data and respond to fraud. The service sits alongside the Bill's enhanced data breach and fraud management obligations, which strengthen existing notification requirements and introduce more robust expectations around breach response.

For businesses subject to Australian notifiable data breach obligations, the enhanced framework increases the stakes of non-compliance. Breach response plans should be reviewed to ensure they reflect the updated obligations, including any changes to notification timelines and the categories of information that trigger mandatory reporting.


What the Bill Does Not Do: AI and Automated Decision-Making

It is worth being explicit about scope. Despite significant industry interest in AI-specific regulation, the Bill does not introduce dedicated rules for AI systems or algorithmic decision-making. The one AI-adjacent measure — automated decision-making transparency obligations — is carried over from the existing reform agenda and is set to commence on 10 December 2026.

This means that Australian AI compliance obligations, at least for now, remain relatively limited compared to the EU AI Act's requirements. Businesses operating across both jurisdictions should not conflate the two frameworks. Australia's automated decision-making transparency obligations are narrower in scope and different in structure from the EU's risk-tiered approach.


The 18 September Deadline: Why It Matters

The public consultation window closes on 18 September 2026 — less than three weeks from the exposure draft's release. For businesses with significant exposure to Australian privacy law, this is a short window to prepare a considered submission, particularly where the controller/processor framework or the erasure right may create operational complications.

Submissions are an opportunity to shape the final legislation, clarify ambiguous provisions, and flag practical implementation challenges before the Bill is introduced to Parliament. Organisations that have navigated GDPR implementation cycles will understand the value of engaging early, when legislative text is still malleable.


Act Now, Not After Royal Assent

Australia's Privacy Amendment Bill 2026 represents a substantive alignment with international data protection norms. For multinational organisations, that alignment is broadly welcome — but it creates immediate work. Controller/processor frameworks require contractual restructuring. Erasure rights require technical infrastructure. Consent standards require policy review. Each of these takes time that post-enactment compliance timelines may not allow.

Ops Intel works with international professional services firms and global enterprises to map regulatory obligations across jurisdictions, identify gaps in existing compliance programmes, and build frameworks that hold up under scrutiny — before regulators come looking.

If Australia's Privacy Amendment Bill creates questions about your organisation's data compliance posture, contact Ops Intel today to arrange a compliance assessment.

Follow us in Google

See Ops Intel first when AI rules change

One click tells Google you want our compliance briefings near the top of your results — and marks us as a preferred source inside Google's AI answers. It applies to your Google account only, and you can undo it any time.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit