Australia's Privacy Law Changes in 2026: What You Can Actually Do
A plain-English guide to Australia's 2026 privacy reforms: what is already law, what is only proposed, and how to use your rights with the OAIC today.
Published 2026-09-17 ยท Updated 2026-09-24
The short version
- Some changes are already law: you can sue for serious invasions of privacy, and from 10 December 2026 businesses must disclose automated decision-making in their privacy policies.
- The bigger changes in Tranche 2, including a "fair and reasonable" test, a right to erasure and 72-hour breach notification, are still only proposals with no start date.
- You can already ask any business covered by the Privacy Act what it holds on you, and complain to the OAIC if it will not answer.
- Using a different email alias for each business makes it far easier to prove who leaked your data when you exercise those rights.
The biggest shake-up in a generation, in pieces
Australia is partway through the most significant overhaul of its privacy law since the Privacy Act was written. The trouble is that it is arriving in pieces, with different start dates, and the headlines rarely say which parts are law and which are still on the drawing board.
The pressure behind it is easy to see. Breach notifications to the OAIC reached 1,205 in calendar 2025, the highest since the scheme started in 2018. The OAIC received 3,948 privacy complaints in 2025-26, up 73 percent. Data breaches are now the top perceived privacy risk for Australians, at 82 percent in 2026, and according to figures cited by the Privacy Commissioner, only 10 percent of Australians think organisations handle their data fairly.
This guide sorts the changes into three piles: what already applies, what is proposed, and what you can do with it this week.
What is already law
The first tranche of reform has passed Parliament. These are the parts that matter most to individuals.
You can sue for a serious invasion of privacy. A new statutory tort gives individuals a direct avenue to take action in court, rather than relying only on a complaint to the regulator. The bar is high, it is a court process, and anyone considering it should get legal advice first. But the right exists now, and that changes how seriously organisations have to take privacy.
Automated decisions must be disclosed from 10 December 2026. From that date, an organisation covered by the Privacy Act that uses personal information in automated decision-making that can affect your rights or interests must say so in its privacy policy, including the kinds of personal information used and the kinds of decisions made. The OAIC has said its guidance is on the verge of release but, at the time of writing, it has not been published.
A Children's Online Privacy Code must be registered by 10 December 2026. It will strengthen protections for anyone under 18 online, and a breach of the Code will be a breach of the Privacy Act.
More small businesses are covered. From 1 July 2026, real estate agents, lawyers, accountants, conveyancers and precious-metals dealers were brought into the Privacy Act regime through anti-money-laundering reforms, regardless of turnover. The OAIC estimates more than 100,000 small businesses were affected. These are exactly the businesses that hold your ID documents and financial details.
Under-16s are banned from ten social media platforms, and you cannot be forced to hand over government ID to prove your age. Platforms must offer alternatives. Since 11 September, eSafety can compel documents from platforms and seek penalties of up to $99 million. No platform has been fined yet.
What is only proposed: Tranche 2
On 31 August the Attorney-General released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026. It contains around 40 measures. Consultation closed on 18 September, the government wants the bill tabled before the end of the year, and no start date has been announced. The Productivity Commission has been publicly critical of several proposals, so the final bill may look different from the draft. None of what follows is law yet.
A "fair and reasonable" test. Described as a world first, it would require organisations to show that the way they collect, use and disclose your information is fair and reasonable, whether or not you ticked a consent box. A privacy notice would no longer be enough on its own.
A wider definition of personal information. Information that "relates to" you, not just information "about" you, bringing tracking, profiling and inferred data more clearly into scope.
A right to erasure. Organisations that qualify as large digital platforms would have to destroy personal information about you on request, subject to exceptions. How "large digital platform" is defined will decide how far that reaches.
Faster breach notification. Organisations would have 72 hours to notify the Commissioner of an eligible data breach, replacing the current 30-day assessment window.
Consent before sharing pixel data. Ad tech would need consent before sharing data from tracking pixels, the hidden code that reports your visits to other companies. The OAIC has already found that Medmate and Monash IVF interfered with privacy by collecting sensitive health information through pixels and using it for targeted advertising without consent.
New rules for new technology. The draft includes obligations aimed at AI, wearable cameras, connected vehicles and targeted advertising, categories the current Act barely addresses.
Digital ID, IDLock and your identity documents
Two identity changes sit alongside the Privacy Act. From 30 November 2026, private businesses can apply to join the Australian Government Digital ID System, either as accredited providers or as businesses that rely on it. It is co-regulated by the ACCC and the OAIC.
The second is IDLock, a service expected to sit inside myGov and let you block, unblock and monitor the use of your identity documents in the Document Verification Service. Early access is expected in late 2026, with national rollout reported for 2027. If your licence or passport has turned up in a breach, it is worth watching for.
How to ask a business what it holds on you
The most useful right you have today is not new at all. Under Australian Privacy Principle 12, you can ask any organisation covered by the Privacy Act for the personal information it holds about you. Under APP 13 you can ask it to correct anything that is wrong. Most complaints the OAIC receives are about how information is used or disclosed, and about access, so you would not be the first to ask.
Be honest with yourself about what to expect. Some organisations respond properly. Many send a partial answer, a pile of raw data that is hard to read, or nothing. That is the asymmetry privacy-minded people keep running into: a government agency generally has to produce your records when asked, while many private companies bury the request behind a contact form. Every request still counts. It is a small cost to them, and it creates the paper trail a regulator needs.
- Find the organisation's privacy policy and look for its privacy officer or privacy contact. Use that address, not general customer service.
- Put your request in writing. Say you are making a request under Australian Privacy Principle 12 for all personal information held about you, including where it came from and who it has been disclosed to.
- Give enough detail for them to find you, such as the email address, phone number or account number you used with them.
- Keep a copy and note the date. Organisations should respond within a reasonable period, which is generally taken to be 30 days. They cannot charge you for making the request.
- If what comes back is wrong, ask for a correction under APP 13. If you no longer want marketing, tell them to stop using your details for direct marketing.
How to complain to the OAIC
If an organisation ignores you, refuses without a good reason or mishandles your information, the Office of the Australian Information Commissioner is the next step. It is free, and you do not need a lawyer.
Expect it to take a while. The OAIC's caseload has risen sharply, and the Commissioner herself described the growing complaint queue as "a measure of systemic non-compliance, and of the failure of first-instance dispute resolution". That is not a reason to stay quiet. It is the reason regulators are asking for stronger powers.
- Complain to the organisation first, in writing, and give it 30 days to respond. The OAIC will generally ask whether you have done this.
- Gather your evidence: your original request, any replies, dates, and screenshots or emails showing how your information was used.
- Lodge a privacy complaint through the online form at oaic.gov.au. Explain what happened, which organisation was involved and what outcome you want.
- Complain promptly. The OAIC may decline complaints made more than 12 months after you became aware of the problem.
- If a data breach notice says your information was exposed, keep the notice. It is useful evidence for a complaint.
Government agencies are also covered by the Privacy Act, and you can request your own records from them under freedom of information laws.
Make leaks traceable before you need to prove them
The weakest point in any complaint is proving where your data came from. If spam, scam texts or a breach notice arrive, most people can only guess which of the dozens of businesses holding their details lost control of them.
Email aliases fix that. Give every business its own forwarding address, and when one starts attracting junk, you know exactly who leaked or sold it. That is concrete evidence for an access request or an OAIC complaint, and it lets you switch off that one address without changing anything else. SimpleLogin and addy.io both have free tiers that do this well. If you want to go further and move your main inbox to a provider that cannot read your mail, we keep a separate site, NoSpyEmail, that compares the handful of private email services that hold up.
Key dates for Australian privacy in 2026
Here is the timeline in one place. Dates marked as proposed may change.
- 1 July 2026: more than 100,000 small businesses in sectors such as real estate, law and accounting brought under the Privacy Act regime. In force.
- 11 September 2026: eSafety gains power to compel documents over the under-16 ban, with penalties of up to $99 million. In force.
- 18 September 2026: consultation on the Tranche 2 exposure draft closed.
- 30 November 2026: private businesses can apply to join the Australian Government Digital ID System.
- 10 December 2026: automated decision-making disclosure starts, and the Children's Online Privacy Code must be registered.
- Before the end of 2026: the government intends to table the Tranche 2 bill. Proposed, with no start date.
Frequently asked questions
What are the Privacy Act changes in Australia in 2026?
Tranche 1 is law: a right to sue for serious invasions of privacy, automated decision-making disclosure from 10 December 2026, and a Children's Online Privacy Code. Tranche 2, including the fair and reasonable test and right to erasure, is still a draft.
Do Australians have a right to be forgotten?
Not yet in general. The Tranche 2 draft proposes a right to erasure against large digital platforms, but it has not been passed and has no start date.
How do I find out what data a company holds on me in Australia?
Write to the company's privacy officer and request your personal information under Australian Privacy Principle 12. If it does not respond within about 30 days, you can complain to the OAIC.
Can I be forced to show government ID to use social media in Australia?
No. Platforms enforcing the under-16 ban must offer alternatives to government ID for proving your age.
When do Australian businesses have to report a data breach?
Currently they have up to 30 days to assess a suspected breach. The Tranche 2 draft proposes 72 hours to notify the Commissioner, but that is not yet law.
Ready to act on this?
We've reviewed the tools so you don't have to.