Australia's Privacy Bill Targets AI Data
Coverage from White & Case, Dentons, and others

Australia's Attorney-General's Department has proposed a second package of Privacy Act reforms that would broaden personal information to include behavioral, precise-location and AI-generated data, while requiring organizations to show that collection, use and disclosure are fair and reasonable.
The bill would also strengthen breach notification, consent, retention and processor obligations and introduce limited erasure rights for large digital platforms. The package remains under consultation, with submissions due 18 September 2026, and retains several exemptions while omitting broader measures such as universal erasure and a direct individual action right.
If you read one thing
It provides the clearest broad overview of the proposed reforms across data scope, accountability, breach duties and targeted rights.
The evidence
It adds concrete evidence on the 72-hour breach rule, limited platform erasure rights and processor accountability.
Best explainer
It explains how the package shifts compliance toward fair data practices, governance, deletion rights and identity-credential control.
Broader data scope and fairness test
The proposed reforms would extend personal-information coverage to behavioral, precise-location, device-generated and AI-inferred data, while treating precise geolocation and genomic information as sensitive. Organizations would also need to demonstrate that collection, use and disclosure are fair and reasonable rather than relying solely on consent or privacy notices.
Stronger lifecycle and breach accountability
The package would tighten operational duties across the information lifecycle through a proposed 72-hour breach-notification deadline, stronger breach-response and retention expectations, and greater controller and processor accountability. Compliance would increasingly depend on documented governance, processor arrangements and information-management practices.
Targeted individual rights with structural limits
The reforms would strengthen individual control through stricter consent standards, sensitive-data and personal-information-trading consent requirements, targeted-advertising opt-outs and a limited erasure right. Erasure would primarily cover large digital platforms, leaving the proposed rights narrower than a universal deletion or direct-action regime.
72 hours
deadline for notifying the OAIC after reasonable grounds to believe an eligible data breach occurred
“Requiring notification to the Office of the Australian Information Commissioner within 72 hours of reasonable grounds to believe an eligible data breach occurred. Entities would also need breach-response systems and reasonable measures to contain harm and mitigate its effects.”
40 proposals
number of proposed privacy reforms
“The package contains 40 proposals and would substantially rewrite the Privacy Act 1988. Key changes include:”
30 days
maximum period for investigating suspected breaches
“Suspected breaches could be investigated for up to 30 days.”
2.5 million average monthly users
Australian users threshold for platform coverage
“The proposed erasure right would apply only to large digital platforms. Coverage would depend on a business group exceeding $500 million in gross revenue, including overseas revenue, or a platform having at least 2.5 million average monthly users in Australia.”
$500 million revenue
gross revenue threshold for a business group
“The proposed erasure right would apply only to large digital platforms. Coverage would depend on a business group exceeding $500 million in gross revenue, including overseas revenue, or a platform having at least 2.5 million average monthly users in Australia.”
The new articles reiterate the proposed reforms' broader data coverage, stronger consent and breach duties, retention rules, and platform accountability without evidencing a material change to the topic.
Previously
Australia's Attorney-General's Department has proposed a second package of Privacy Act reforms that would broaden personal information to include behavioral, precise-location and AI-generated data, while requiring organizations to show that collection, use and disclosure are fair and reasonable. The bill would also strengthen breach notification, consent, retention and processor obligations and introduce limited erasure rights for large digital platforms. The package remains under consultation, with submissions due 18 September 2026, and retains several exemptions while omitting broader measures such as universal erasure and a direct individual action right.
