Productivity Over Privacy? The Commission's Outcomes Gambit

Published Category: Data Privacy 32 min read 6,398 words by James Nicholson

You are buying a kettle online. It is a good kettle. It has a temperature dial, which matters, because green tea scorched at 100 degrees tastes like a lawn clipping's revenge. You add it to the cart, type your address and reach the last screen, where a small box waits for you: I have read and agree to the Privacy Policy.

You have not read the Privacy Policy. Nobody has read the Privacy Policy. But let's say that today, for once, you decide to be the model citizen the law imagines. You open it. The Australian Competition and Consumer Commission found that a typical privacy policy runs to 6,876 words and takes about 29 minutes to read. Fine. That is one cup of tea and a biscuit. Then you remember that the same research put the total at nearly 46 hours a month, if you read every policy you meet. That is a working week, every month, spent reading documents written so that nobody will read them. Over a year, that is more than twelve working weeks spent on cookie clauses. You start to wonder whether the kettle comes with a policy of its own, and whether the policy has a policy.

You tick the box. You were always going to tick the box.

Nobody expects you to read it, and that is the point. The box does not measure whether you understood anything. It measures whether a box exists and whether it was ticked. On 5 August 2025, the Productivity Commission put that problem at the centre of its interim report, Harnessing data and digital technology. It said some parts of the Privacy Act can make consent and notification a "tick box" exercise, "where businesses comply with the letter of the law but not the spirit of it". Its answer is a second way to comply: an outcomes-based track, where you prove that you protected people, instead of proving that you followed the steps.

The stakes are not small. The Commission counts about 277,000 firms that the Act affects, and it estimates the direct privacy costs of the 10,000 with turnover of $50 million or more at about $2 billion a year. It also lands in the middle of a queue. The government has been promising a second tranche of Privacy Act reforms for a long time, and as of August 2025, nobody outside Canberra has seen a draft.

So I want to take the two words everyone is suddenly using, "rules" and "outcomes", and find out what they mean in practice. We will start at a speed sign, drive to Montana (which tried this on its highways, with results), visit a building site and a financial adviser, then sit with a made-up data manager in Hobart as she complies both ways.

Kettle on. Let's get into it.

Part 1: What the Commission Actually Proposed

The Productivity Commission is the federal government's independent adviser on economic policy. This interim report is the third of five productivity inquiries, and it covers four areas: artificial intelligence, access to data, privacy regulation and digital financial reporting. The third one changes how you would comply with the Privacy Act.1

The two recommendations that matter are short. Draft recommendation 3.1 reads:

The Australian Government should amend the Privacy Act 1988 (Cth) to provide an alternative compliance pathway that enables regulated entities to fulfil their privacy obligations by meeting criteria that are targeted at outcomes, rather than controls-based rules.

Draft recommendation 3.2 is blunter: do not introduce a "right to erasure", because it "would impose a high compliance burden on regulated entities, with uncertain privacy benefits for individuals".

Two days later, the Commission put the first of those on X, in slightly plainer words:

We recommend Govt amend the Privacy Act for an alternative compliance pathway for firms to fulfil their obligations whilst protecting the privacy of individuals.

Share your feedback on how an outcomes-based obligation could work and be enforced: https://engage.pc.gov.au/page/make-a-submission

(8/11)

— Productivity Commission (@ozprodcom), 7 August 2025 on X

Note the word "alternative". The Commission does not propose to delete the Australian Privacy Principles (APPs), the 13 rules at the core of the Act. It proposes to add a second road next to them. In its words, this would create a "dual track" regime: "one outcomes-based track (designed to provide flexibility for regulated entities) and one more prescriptive track (designed to provide regulated entities with greater certainty about their privacy obligations)". Each business would choose.

Why the Commission thinks the current road is broken

The argument in chapter 3 has two halves, and they point at the same problem from opposite sides.

The first half is about cost to business. The Commission says that the Act is flexible overall, but some requirements "focus too much on specific controls (that is, prescribing certain actions or procedures) rather than outcomes". It also heard about over-compliance, where businesses do more than the law asks, sometimes by choice and sometimes because they do not understand the law. Its example is businesses that seek consent when they do not need it, "leading to heightened costs for businesses and creating unnecessary hurdles for consumers".

The second half is about protection for people, and this part should interest anyone who has ever ticked the kettle box. The Commission quotes research from the Consumer Policy Research Centre, from a survey of 1,000 Australians: "only 7% of consumers agree that companies give consumers real choices to protect their privacy online", and 52% find it time-consuming to protect their privacy online. Commissioner Julie Abramson put it this way when the report came out: "To use a product or service, consumers are often asked to acknowledge lengthy, complex privacy policies that few have the time to read."

So the claim is that the controls cost business money and fail to protect people. If that is true, a second road makes sense. If it is only half true, the second road could be a way round the protections.

What the outcome would be

The Commission's preliminary view is that the outcome should be a best interest obligation: when a business decides how to handle personal information, it "would be required to prioritise the privacy interests of individuals". It also lists two weaker options, and it illustrates all three with a diagram I did not expect to find in a government report: a water spill.

  • Act in the best interest: mop up the spill.
  • Have regard to the best interest: consider mopping up the spill.
  • Duty of care: put up a sign warning people about the spill.

Then it does the same for a data breach: lock the person's account, consider locking the account, or notify people about the breach. I have read this figure several times, and each time I picture a regulator standing in a puddle, holding a report that says "considered".2

The water spill is more useful than it looks. After something goes wrong, each option asks a different question: did you fix it, did you think about fixing it, or did you warn people? Those are three very different standards.

The Commission wants feedback by 15 September 2025, with a final report due later in the year. It asks whether to build the pathway as a defence, a safe harbour or "deemed-to-comply standards", which duty to use and how to enforce it. To answer those questions, we need to go down a level, to what "rules" and "outcomes" really are.

Part 2: Rules and Standards, From the Speed Sign Down

You already use both kinds of law every day, probably on the drive to work.

The first kind is on a pole: a round sign with a red border and "60" in the middle. You know what it asks of you before you do anything. The police officer's job afterwards is only to measure: were you over 60 or not? The second kind is less visible. You know that you must drive at a speed that suits the conditions, so on a foggy night in the Derwent Valley you drive at 40, even on a 100 road. Nobody gave you a number for fog. You are expected to work it out, and if something goes wrong, someone else will decide afterwards whether you worked it out correctly.

Naming the difference

Lawyers call the first kind a rule and the second a standard. In 1992, the Harvard law professor Louis Kaplow wrote a paper that is still the reference point for this, Rules versus Standards: An Economic Analysis. His definition is refreshingly narrow. The only difference that matters is when the law gets its content: "whether the law is given content ex ante or ex post". Before you act, or after.

He uses a speed example too. A rule "might prohibit 'driving in excess of 55 miles per hour on expressways'". A standard "might prohibit 'driving at an excessive speed on expressways'". With the rule, somebody decided the answer in advance and wrote it down. With the standard, somebody decides the answer later, in your case, with your facts.

That gives Kaplow his central trade-off: "Rules typically are more costly than standards to create, whereas standards tend to be more costly for individuals to interpret when deciding how to act and for an adjudicator to apply to past conduct." A rule is expensive once, at the start. A standard is cheaper to write and more expensive every time someone uses it.

Hold on to that sentence, because it explains most of the fight over the Commission's proposal. The outcomes track does not remove the cost of deciding what good privacy looks like. It moves that cost from Parliament to each business, and then to the regulator and the courts afterwards.

Two questions, not one

Regulators have their own words for a similar split. The Commission uses controls-based (or inputs-based) regulation for rules that "prescribe or proscribe certain actions or procedures", and outcomes-based regulation for rules that "require entities to achieve certain outcomes". So far, that is Kaplow's rule and standard with the labels changed.

But the Commission adds a second question, and I think this is the most useful thing in the chapter. How much choice does the law give you about how you comply? That is flexible against prescriptive, and it is a separate axis. Put the two together and you get a grid with four boxes. The Commission fills each box with an example.

A two-by-two grid. The columns are controls-based and outcomes-based; the rows are flexible and prescriptive. Flexible and controls: 'You must have a privacy policy.' Flexible and outcomes, highlighted: 'Your data practices must protect the privacy interests of individuals.' Prescriptive and controls: 'You must have a privacy policy that covers disclosure practices.' Prescriptive and outcomes: '80% of individuals must be happy with your data practices.'
Fig. 1 — Two questions, not one. Redrawn from Productivity Commission, Harnessing data and digital technology, Interim report, Box 3.4, 5 August 2025.

The bottom-right box is my favourite: "80% of individuals must be happy with your data practices." That is an outcome, and it is also completely prescriptive. It tells you exactly what number to hit. It is also, I suspect, a rule nobody would survive. (Imagine the survey. Imagine the survey's privacy policy.)

The grid shows why "we want outcomes, not rules" is not one request. You can have a flexible rule (APP 1 says you must have a privacy policy, and the Commission notes the policy "can contain whatever the regulated entity considers appropriate"), or a very rigid outcome. The Commission's proposed track sits in the top-right box: a broad outcome, with complete freedom about how you get there.

Where the Privacy Act already sits

Here is the part that the headlines skip. The Privacy Act is not a pure rule book now. It is already a mix, and the Commission says so.

On the controls side, the Commission names APPs 5 and 6. The OAIC summarises them as the rules for when "an APP entity that collects personal information must tell an individual about certain matters" (APP 5), and "the circumstances in which an APP entity may use or disclose personal information that it holds" (APP 6). These are the notice and consent machinery, and the kettle box lives here.

On the outcomes side, the Commission names APP 10. In the OAIC's summary, an entity "must take reasonable steps to ensure the personal information it collects is accurate, up to date and complete". Squire Patton Boggs, in a sharp response on 14 August, adds APP 11, which requires "reasonable steps" to protect information from misuse. "Reasonable steps" is a standard in Kaplow's sense. Nobody tells you in advance which steps are reasonable.

And even APP 6, the most rule-like of them, has a standard hiding inside it. You may use information for a secondary purpose if the person would reasonably expect it and the purpose is related. The OAIC's guidelines describe that test as "an objective one that has regard to what a reasonable person, who is properly informed, would expect in the circumstances". Then they add a line that I think is the key to this whole debate: "It is the responsibility of the APP entity to be able to justify its conduct."

Remember that line. It is already the law, and it tells you what an outcomes track would ask for, only more so.

Part 3: Montana Tried It on the Highway

If you want to see what happens when a standard has nothing underneath it, Montana ran the experiment for you.

A Bruegel-style winter road across open plains where a cart speeds past a puzzled constable holding a blank wooden sign, while three judges on a hay cart argue over a scroll and a laptop glows on a fence post.
Fig. 2 — Nobody could say what the sign should read, generated by OpenAI GPT Image.

After the United States repealed its national speed limit in 1995, Montana did not replace it with a number for daytime driving on its rural highways. Instead, as Montana Public Radio tells it, the law said drivers had to drive at speeds that were "reasonable and prudent". The actual statute, § 61-8-303(1), is a lovely example of a pure outcomes standard. It requires a speed "no greater than is reasonable and proper under the conditions existing at the point of operation, taking into account the amount and character of traffic, condition of brakes, weight of vehicle, grade and width of highway, condition of surface, and freedom of obstruction to the view ahead".

Every factor there is sensible. If the Commission's best interest obligation were a traffic law, it would look something like this.

Mr Stanko's Sunday drive

On a Sunday morning, 10 March 1996, a man named Rudy Stanko drove west on Montana State Highway 200 at a steady 85 miles per hour (about 137 km/h). A highway patrol officer followed him for about eight miles. The court record says "the roadway itself was bare and dry, there were no adverse weather conditions, and the incident occurred during daylight hours". The officer also said the road was narrow, had no shoulders, and was "broken up by an occasional frost heave". He gave Stanko a ticket for driving at an unreasonable speed.

Stanko took the ticket to the Montana Supreme Court and argued that the law was too vague to obey. Here is the moment that decided the case. The officer "gave no opinion what would have been a reasonable speed". So the judges asked the state's Attorney General, the chief law enforcement officer of Montana, what speed would have been reasonable and prudent at that place. His answer: "I cannot give you a number that would have been reasonable and prudent at that-it ultimately may come down to a question to be determined by the jury."

If you have ever asked a regulator "so what exactly do you want us to do?", that answer may feel familiar.

On 23 December 1998, a divided court struck the speed provision down as void for vagueness. Justice Terry Trieweiler wrote that the basic rule "not only permits, but requires the kind of arbitrary and discriminatory enforcement" that due process exists to prevent, and that it "impermissibly delegates the basic public policy of how fast is too fast on Montana's highways" to "policemen, judges, and juries".3 In 1999, the legislature took the hint and set a daytime limit of 75 miles per hour. Years later, Trieweiler summed up the problem in one line: "The problem was that nobody knew what the actual limitations on their speed would be."

What Montana teaches, and what it does not

I do not want to push the analogy too far. Stanko was a criminal case, and a civil privacy duty in Australia would be judged differently. Nobody is proposing to jail a marketing manager for an unreasonable email campaign.

But the mechanism transfers exactly, and it is Kaplow's. A pure standard is cheap to write and expensive to apply. In Montana, the cost landed on the driver (who had to guess), the officer (who had to judge) and the court (who had to decide, case by case, what "reasonable" meant).

That is the question the Privacy Commissioner asked about the Commission's proposal. In an opinion piece in the Australian Financial Review on 14 August, Carly Kind wrote that "it is hard to imagine how an organisation could demonstrate to a regulator that it was acting in the best interests of individuals without affording them the basic controls and protections currently enshrined in the Privacy Act". Her example was a GP using an AI scribe. Under a best interest defence, she argued, "your GP would not have to ask your permission to use an AI scribe, or even tell you they were using it, if they could establish it was in your best interests to do so". Her verdict on the system was blunt: "at its best, unworkable".

Squire Patton Boggs made the practical version of the same point. The proposal resembles the "legitimate interests" basis in Article 6(1)(f) of the GDPR, and in Europe, regulators strongly recommend that organisations write down the balancing test they did. An Australian business on the outcomes track "would also need to document their compliance", which "could lead to the same 'excessive regulatory burden' that the pathway is intended to reduce".

So the outcomes track asks you to be your own Attorney General, on every decision. You must know what the reasonable speed was, and you must be able to show the court your working.

Part 4: Two Tracks Already Running in Australia

The Commission's best argument is that dual-track regimes are not a thought experiment. Australia already runs several. The Commission lists work health and safety, electrical equipment standards and financial advice. I want to look at two: the building code, which is not on the Commission's list, and financial advice, which is. One shows how the idea can work well and the other shows how it can quietly fail.

A Flemish-style village crossroads where a robed clerk stands under a two-armed signpost; down one road villagers queue while a scribe ticks boxes in a ledger, down the other a judge inspects a finished cottage, and an open laptop rests on a milestone.
Fig. 3 — Two roads to the same cottage, generated by OpenAI GPT Image.

The building code: a recipe book and a test kitchen

If you have ever renovated a bathroom in Hobart, you have met a dual-track regime, whether or not you knew it. The National Construction Code (NCC) is built on Performance Requirements, which say what a building must achieve (it must not fall down, it must resist fire for long enough and so on). The code is clear that these "are the only NCC technical provisions that must be satisfied". Those are the outcomes.

There are two ways to meet them. You can follow the Deemed-to-Satisfy (DTS) Provisions, which the code's own explanation calls prescriptive, "like a recipe book": use this material, this thickness, this spacing. A solution that follows them "is deemed to have met the Performance Requirements". Or you can build a Performance Solution, which you design yourself and must prove meets the requirements, or is "at least equivalent to the Deemed-to-Satisfy Provisions".

The interesting part is what that second road costs. Under clause A2G2 of the 2022 edition, a Performance Solution needs a performance-based design brief prepared with the stakeholders, an analysis, an evaluation of the results against agreed acceptance criteria, and a final report that records the requirements, methods, steps, confirmation of compliance and any limits. The flexible road is not the easy road. It is the road with more paperwork, done by specialists, before anyone builds anything.

That is the model working well, for three reasons. The outcomes are specific and testable. The recipe book is complete enough to be a real alternative. And the proof on the flexible road is made before the building goes up, not after the ceiling falls in.

Financial advice: when the harbour swallows the lighthouse

The second example is financial advice, from the Commission's own list. Before 2012, conflicts of interest in advice were managed mostly by disclosure: tell the client about the commission, and let them decide. The Commission quotes a parliamentary committee's view of how that went: the documents were "so inaccessible that they are probably not read at all by most people". (If that sounds like the kettle box, it should.) So in 2012, advisers got a best interest duty: they must act in the best interests of their clients.

The law also provides a safe harbour. Section 961B(2) of the Corporations Act lists seven steps, and an adviser who follows them is taken to have met the duty. On paper, it is the perfect dual track: a broad outcome, plus a recipe that is deemed to satisfy it.

Now read the footnote to the Commission's own box. The Quality of Advice Review found that, in practice, "financial advisers focus[ed] more on the safe harbour steps than the primary duty", and for that reason it recommended that the safe harbour be removed.4

A Flemish harbour where dozens of small boats crowd into a tiny walled harbour while a harbourmaster ticks a long list, and a distant lighthouse on a headland is ignored; one sailor holds up a tablet.
Fig. 4 — Everyone in the harbour, nobody at the lighthouse, generated by OpenAI GPT Image.

That is the failure mode, and it is in the Commission's own evidence. When one track is a checklist and the other is a judgement, people pick the checklist, and the outcome becomes a thing they no longer think about. Allens predicted the same for privacy on 11 August. Under a safe harbour design, they wrote, it is "difficult to see organisations not falling back on traditional compliance requirements".

Which way round the tracks go

This is where the Commission's design choice matters. It sets out three options.

  • (a) The defence model. The APPs stay as the main road. A business that does not meet every APP "to the letter" can use the outcomes obligation as a defence, to show it still complied.
  • (b) The safe harbour model. The outcomes obligation becomes the general rule for everyone, and the APPs become a "deemed to satisfy" recipe. This is the NCC and financial advice design.
  • (c) The single pathway. Replace the controls entirely with outcomes, supported by guidance and codes.
Three stacked options. (a) Defence, marked as the Commission's preference: the existing APPs are the main path, and showing you met the outcome is the fallback. (b) Safe harbour: the outcomes obligation is the main path, and following the prescribed controls is deemed to comply. (c) Single pathway: the outcomes obligation is the only path, helped by guidance and codes. A note says (a) and (b) are the same two tracks, swapped.
Fig. 5 — Three ways to build it. Redrawn from Productivity Commission, Harnessing data and digital technology, Interim report, Figure 3.1, 5 August 2025.

The Commission says (a) and (b) "are inversions of each other", and it prefers the defence model, because it needs smaller changes to the Act. It rejects (b) partly because the APPs "are a mix of principles and controls-based requirements", so they could not work as a recipe book in their current form. That is an honest admission, and it matters: the NCC works because its recipe book is complete. The APPs are not.

Now look again at the preferred option. In the defence model, when do you use the outcomes track? Only when you have not met the APPs, and someone has noticed. The defence is something you raise after the event, in front of the regulator. In Kaplow's terms, it is the most ex post design available. It is Montana, with the Attorney General replaced by your own privacy team.

That is why I call it a gambit. It asks each business to bet that, if challenged, it can prove it acted in people's best interests. Allens thinks the bar may be higher than it looks: the duty "appears to impose a higher standard than both the existing law or the proposed Tranche 2 changes". They also warn that "by creating a dual-track approach, the existing limitations remain open to exploitation". Both can be true. The duty could be a high bar for a careful business and a hiding place for a careless one, and only the evidence tells them apart.

Part 5: Meanwhile, in the Queue for Tranche 2

To see why the timing irritated people, you need the history. I wrote about the Privacy Act Review when it came out in 2023, and about the government's response later that year. The Review made 116 recommendations. A small number became law in the first tranche, the Privacy and Other Legislation Amendment Act 2024, which received Royal Assent on 10 December 2024.

As MinterEllison summarised it, that Act gave the OAIC new powers to issue infringement notices and compliance notices. It clarified that the "reasonable steps" to secure personal information include "technical and organisational measures". It created a statutory cause of action for serious invasions of privacy, to start by 10 June 2025. And it set 10 December 2026 as the start date for new transparency duties about automated decisions.

The rest, the bigger changes, were left for a second tranche. The Commission's report lists what it expected that tranche to include: privacy impact assessments for high-risk activities (including automated decisions), a "fair and reasonable" test for collection, use and disclosure, removal of the small business exemption and a broader definition of "personal information".

As of August 2025, that second tranche has a promise and no text. On 20 July, the Attorney-General, Michelle Rowland, told Sky News, "Well, this is the second tranche of privacy reforms." She added: "we will not have our privacy reforms dictated by multinational tech giants who are trying to assert that you can either have innovation or you can have privacy protection, but not both. I reject that completely." As Chris Brinkworth noted in Mi3, she "did not unveil a draft bill, a consultation paper or even a timetable".

Two weeks later, the Commission's report argued that parts of that tranche would make things worse. A section heading says it directly: "Proposed reforms risk entrenching existing problems." Mi3 reported that Meta's submission to the inquiry had argued against privacy changes that would stop it training its AI on personal information from its platforms.

What the Commission did and did not say about Tranche 2

This is where it pays to read carefully, because the coverage has been looser than the report. The Commission made one direct recommendation against a Tranche 2 item: no right to erasure. Its argument leans on the European experience, where firms rated the right to be forgotten the hardest GDPR obligation to implement, and on a point Telstra made in 2020: APP 11 already requires an entity to destroy or de-identify information it no longer needs.

It did not recommend pausing the rest. It said further reforms "should be undertaken with a degree of caution", with "a critical eye trained on the practical impacts". Squire Patton Boggs, whose headline asks whether reforms are "on pause", is careful to add that "the Report does not go so far as to make this recommendation".5

The Commission also drew a distinction that is easy to miss. The Review's "fair and reasonable" test would add a new standard on top of the APPs: "that proposal would impose additional requirements", whereas the Commission's pathway would create "alternative requirements". One adds an outcomes test to the rules. The other offers an outcomes test instead of the rules. That is the real fork in the road, and it is why the privacy world reacted as it did.

A side road: text and data mining

The same report opened a second argument, about copyright. It asked whether Australia should add a fair dealing exception for text and data mining (TDM), which would cover analysis of machine-read material, including training AI models. The Commission said the exception "would not be a 'blank cheque'", because the use would still have to be fair.

The reaction was fast. As Herbert Smith Freehills Kramer set out on 22 August, APRA AMCOS and NATSIMO said a TDM exception would "legitimise digital piracy under guise of productivity", and the Treasurer told ABC's 7.30 that the government did not "have any plans to change or weaken" copyright arrangements. It is not a privacy question, but it has the same shape: a flexible standard ("fair") in place of permission asked in advance. Somebody has to decide what "fair" means, and if nobody decides before, a court will decide after.

Part 6: Priya Runs Both Tracks

Rules and outcomes are easy to argue about in the abstract. So let's give them to a person.

Meet Priya. She is the data manager for a mid-sized online homewares shop in Hobart. (She is made up. Hobart is real, and on a clear winter morning it is excellent.) The shop has a loyalty programme with about 80,000 members, and the marketing team has an idea: use each member's purchase history to send personalised emails, and train a small recommendation model on the data. Priya's job is to make it lawful. We will run her through the current rules first, then through a hypothetical best interest defence, and see what each one leaves on file.

Monday: the rules track

On the rules track, Priya works through the APPs one by one.

  1. Collection (APP 3). The shop already collects purchase history to run the loyalty programme. Priya checks that the new use does not need any new data. It does not.
  2. Use for a new purpose (APP 6). Personalised emails and a recommendation model are secondary purposes. Priya asks whether a member would reasonably expect this, and whether it is related to why the data was collected. She decides that recommendations based on your own purchases are related to a loyalty programme. She writes down why.
  3. Notice (APP 5). She checks the collection notice that members saw when they joined. It mentions "personalised offers", so she updates it to mention the recommendation model, in plain words, near the top.
  4. Privacy policy (APP 1). She updates the policy to match. She knows nobody will read it.
  5. Security (APP 11). She checks who can access the training data, removes names and email addresses from the model's copy, and sets a retention period for the training set.

At the end of Monday, her file holds: a record of the purpose assessment, a changed notice, a changed policy, an access list and a retention setting. If the OAIC asks, she can point to each APP and show a document.

Wednesday: the outcomes track

Now imagine the Commission's defence exists. The marketing team, excited, asks whether they can skip the notice update and the policy change, since "it's in the customer's interest anyway". Priya is careful. She knows the defence only helps if she can prove the outcome. So she asks what she would need to show a regulator if a member complained.

  1. What is the individual's privacy interest here? Purchase history can reveal a lot. A member who buys a baby monitor, then a breast pump, has told the shop something personal. Priya decides that the model must not infer or target health or pregnancy, and she writes that as a design rule.
  2. Does the member benefit? Better recommendations, fewer irrelevant emails. That is a benefit. But she also needs to show that the member was not harmed or surprised. That brings her straight back to telling members, which is the notice she was asked to skip.
  3. Is the data the minimum needed? She removes names and email addresses from the training copy. That is the same step as Monday.
  4. Is it secure? Access list and retention period. Same as Monday.
  5. Can the member stop it? She adds a clear opt-out from personalised emails. That is new, and it is good.
  6. Can she prove all of this later? She writes a short assessment that records each decision, the date and who approved it.

At the end of Wednesday, her file holds: a written assessment of the member's interests, a design rule about sensitive inferences, a minimised dataset, an access list, a retention setting, an opt-out and the notice update she ended up keeping anyway.

Friday: compare the files

Put the two files side by side, and most of the contents match: the same security, the same minimisation, the same purpose assessment under a different name. The outcomes track added two good things (a limit on sensitive inferences and an opt-out) and removed almost nothing, because every control she wanted to skip turned out to be part of her evidence.

The one thing that changed is where the risk sits. On the rules track, if Priya follows each APP, she can show compliance whatever the outcome. On the outcomes track, she is safe only if a regulator, looking back after a complaint, agrees with her judgement about the member's best interests. She has become the Attorney General of Highway 200, and she had better know the number.

When the marketing lead asks why the outcomes track took longer, Priya shows him the two files and says one sentence: "The outcome is only as good as the evidence." He goes to make a cup of tea. It is the right response to a well-kept file.

What to Do This Week

You do not need to know which track wins to start. The Commission's final report is due later in 2025, Tranche 2 has no bill yet, and the right to erasure may or may not survive. But the controls below matter under any of those outcomes, because they are what you would point to on the rules track and what you would need as evidence on the outcomes track.

  1. Map your personal information. List each system that holds personal information, what it holds, why, and who can access it. You cannot show an outcome for data you cannot find.
  2. Write down the purpose of each collection, at the time you decide it. The OAIC already says "it is the responsibility of the APP entity to be able to justify its conduct". A two-line purpose record written today is worth more than a long justification written after a complaint.
  3. Test your secondary uses against the "reasonable person" standard. For each new use of existing data, ask whether a properly informed person would expect it. If you need a paragraph to explain why they would, they probably would not.
  4. Minimise and delete. Remove fields you do not use. Set retention periods and apply them. APP 11 already requires you to destroy or de-identify information you no longer need, and the Commission quoted that duty when it argued against a right to erasure.
  5. Check security as "technical and organisational measures". Since December 2024, that phrase is in the Act's security duty. Technical: access control, encryption, logging. Organisational: who approves access, training, what happens when someone leaves. In the second half of 2024, the OAIC received 595 data breach notifications, and 69% came from malicious or criminal attacks. Every outcome test will start with whether you kept the data safe.
  6. Run a privacy impact assessment for high-risk uses. Profiling, AI training, sensitive information, automated decisions. PIAs were in the expected Tranche 2 list, and a PIA is the natural form of evidence for an outcomes defence. It does both jobs.
  7. Fix your notices for humans. Put the two or three things a person would care about at the top of the collection notice. The long policy can stay for the lawyers. (If you want a refresher on what good consent looks like in practice, I covered it in Consent Management: The What and Why.)
  8. Remove consent you do not need. The Commission found businesses seeking consent when the law does not require it. Unnecessary consent adds cost, adds fatigue and teaches people to tick boxes. Ask for consent where it is required or where it gives a real choice.
  9. Have your say. Submissions on the interim report close on 15 September 2025. Specific answers from people who do the work are useful.

Final Thoughts

Think back to the kettle and the little box that nobody reads. The Commission is right that the box proves very little. A ticked box is a record that a control happened, not that anyone was protected.

But an outcomes track does not make the box's job disappear. It hands that job to you, and asks you to prove, possibly years later, that you did right by the person on the other side of the checkout. Montana learnt what happens when nobody can say in advance what "reasonable" means. Financial advisers showed what happens when a checklist sits next to a duty: people climb into the checklist and stay there. The building code shows the version that works, where the flexible road demands more evidence, earlier, and not less.

So whichever track the Commission lands on, and whatever Tranche 2 finally contains, the useful work is the same. Know what data you hold. Write down why you hold it. Keep it safe, keep it small, and delete it when you are done. Those are the controls under the rules track, and they are the evidence under the outcomes track. Start with the map and the purpose record this week.

Now, if you'll excuse me, my kettle has reached 80 degrees, and the green tea is not going to wait for Tranche 2.

Notes

  1. Squire Patton Boggs noted that the report came out "in the small hours" of 5 August, and the Commission's X thread promoting it followed on 7 August. In Tasmania, the small hours are when the possums hold their council meetings, so the report at least had an audience. ↩

  2. The Commission labels the scenarios as "illustrative of what sorts of actions may be sufficient to meet the relevant duty or obligation". So "notify individuals about the breach" is its example of a duty of care, not a full legal test. ↩

  3. The court was split. One dissenting justice pointed out that the provision had been Montana law since 1955, and another argued that driving at 85 miles per hour on that road, with its hills and frost heaves, was clearly unreasonable, so Stanko had no standing to challenge the law's vagueness. ↩

  4. The Commission cites the Quality of Advice Review as Levy 2022, page 86, in the footnote to Box 3.6 of the interim report. The review looked at how financial advice is regulated in Australia. ↩

  5. The Squire Patton Boggs piece lists "Pause Tranche 2 changes" as its third point, then qualifies it in the first line. It reads the report's scepticism about the cost-benefit analysis as a signal, not as a formal recommendation. ↩

end of article · 6,398 words · 26 August 2025

James Nicholson, smiling, in round tortoiseshell glasses and a white T-shirt.

James Nicholson

James is a technology consultant in Hobart, Tasmania, and runs NEOBADGER. He works where technology, regulation and the people organisations serve meet: AI harnesses, development, data and compliance.

The story

Further reading

3 more articles on Data Privacy.