Tranche 2: The Privacy Act Finally Gets Fair (and Reasonable)
A woman in Launceston buys a maidenhair fern online. She types her name, her email and her street address, because the fern cannot find its own way up the Tamar. Two days later, the fern arrives, in a box so full of shredded paper that the fern seems to be the packing and the paper the product. That is the whole transaction, as far as she knows.
Then things start to happen. A week later, an ad for fern fertiliser follows her across three websites and into a news app. A garden tool company she has never heard of emails her by name. Her social feed recommends a humidity meter, a book called Ferns of the Southern Hemisphere and a membership to a plant society in Victoria. By the end of the month she is getting ads for a dehumidifier, which suggests that somewhere a model has decided the fern is thriving and her bathroom is not. She begins to suspect that the fern has an agent. Possibly a publicist. It certainly has a better social life than she does.
Sit down. Nobody is reading her mind, and the fern is not talking. Every one of those messages came from a data flow that somebody set up on purpose: a pixel on the checkout page, a customer list uploaded to an ad platform, a "partner" clause in a contract. Under the Privacy Act today, most of those flows can be made to comply with a privacy policy and an argument about "purpose". For many of them, the customer never has to agree to anything.
Today, that may start to change. On 31 August 2026, the Attorney-General, Michelle Rowland, released a consultation paper and draft legislation, the long-promised second tranche of Privacy Act reform. Her media release says the draft would stop businesses trading in personal information "without clear permission, meaning shopping habits, online interests or location data cannot be bought and sold behind Australians' backs". It also gives the reason: "almost four in five Australians report they have very little or no control over how their personal information is collected or used."
The draft has a plain name, the Privacy Amendment (Personal Data Protection) Bill 2026, and a big idea. It replaces three of the core privacy principles with one question: is this collection, use or disclosure fair and reasonable in the circumstances? Then it adds a consent gate at the two points where the government thinks consent matters most. One of those points is a new word, "trade", and the consultation paper says, in one short sentence, that it can include the pixels on your website.
So here is the plan. First, what landed today. Then we take the fair and reasonable test down from something you do every week without a name to the seven factors in the Bill. Then we follow the word "trade" to your tag manager. After a quick tour of the other changes, a (made-up) nursery owner in Launceston sorts her website's data flows into three baskets, and you can do the same before submissions close on 18 September.
Let's get into it.
Part 1: What Landed Today
This has been a long wait. I wrote about the Privacy Act Review, which came out in February 2023, and about the government's response later that year. The Review made 116 recommendations. As McCullough Robertson sets out in its summary today, the government agreed to 38 and agreed in principle to 68. A small set became law in the first tranche, the Privacy and Other Legislation Amendment Act 2024: higher penalties, new powers for the Office of the Australian Information Commissioner (OAIC) and a statutory tort for serious invasions of privacy. Everything difficult was left for "Tranche 2".
Tranche 2 is now a real document. The Attorney-General's Department's consultation page has two of them: a 58-page exposure draft of the Bill and a 42-page consultation paper. An exposure draft is a bill that has not gone to Parliament yet. The government publishes it so people can find the problems before it becomes law. The page says the Bill "remains subject to further consideration by government", and the draft's commencement table is empty.1
The consultation paper counts "roughly 40 proposals": 25 from the Privacy Act Review that strengthen protections, 5 more from the Review that simplify obligations, 4 new simplification measures and 7 measures for the OAIC. For anyone who collects data on a website, four changes matter most:
- APPs 3, 4 and 6 go. The rules for collecting personal information, for dealing with information you did not ask for, and for using and disclosing it are replaced by one new APP 3: collect, use or disclose only if it is "fair and reasonable in the circumstances" and lawful.
- A new APP 4 asks for consent in two places only: collecting sensitive information, and "trading" personal information.
- APP 5 notices get shorter. A notice must cover the fact and circumstances of the collection and the purposes, "in clear and plain language".
- APP 7 direct marketing is rewritten around an opt-out, with a new definition that covers audiences and cohorts.

Around those four sit wider definitions, a 72-hour deadline to report serious data breaches, new duties to know and destroy the data you hold, and a right to erasure against very large platforms. We will get to those. The fair and reasonable test comes first, because every other change is built on it.
Why this is bigger than it looks
When the Productivity Commission put out its interim report a year ago, it proposed an "alternative" outcomes-based way to comply, next to the existing rules. Its final report, released on 19 December 2025, went further. As Johnson Winter Slattery summarised it in February, the Commission recommended one obligation "requiring entities to handle personal information in a manner that is 'fair and reasonable in the circumstances'", and "phasing out the existing APPs".
Today's draft meets the Commission about halfway. It keeps notice, direct marketing, security, access and the rest, but it replaces the three principles that decide whether you may touch the data at all. That is the core of the Act. Adam Ford of the IAPP calls the test possibly the most significant proposal in the package, and I agree with him.
Part 2: The House-Sitter Test
You already run a fair and reasonable test. You probably ran one the last time you went away.
You ask a friend to house-sit for a week. The instructions are short: water the ferns, feed the guinea pig, bring in the mail. You do not write a list of the things they may not do, because the list would never end. You trust them to know. When you come home, you check the house against a feeling, and that feeling has parts.
- Would you expect it? They made tea with your tea. Fine. They drank the aged oolong you were saving for a birthday. Less fine.2
- Is it connected to the job? They opened the mail to find the water bill. Fine, you asked them to handle the mail. They read your bank statements. Not connected to anything.
- Did they tell you? "I moved the fern to the bathroom, it looked dry" is a very different message from finding the fern in the bathroom and no note.
- Did they use more than they needed? They used the spare key. Fine. They had three more cut.
- Did you have a choice? "Can I have a friend over on Saturday?" is a question. A text on Saturday night that says "hope you don't mind" is not.
- What was the risk, and who got the benefit? They left the back door open for an hour while they watered the garden. Small risk, for your benefit. They rented your spare room to a stranger for the week. Big risk, for their benefit.
- Was anyone vulnerable involved? If your teenager was home too, you apply every test above more strictly.
That is a legal framework, even if nobody calls it one. It is a standard, not a rule. A rule decides the answer in advance ("be home by 10 pm"). A standard decides the answer afterwards, from the facts ("be home at a sensible hour"). My post on the Productivity Commission went through that difference in detail, with a speed sign and a foggy road. Tranche 2 now asks the Privacy Act to work like the house-sitter check.
How the Act does the same job today
The Privacy Act already has a sense of "what is the house-sitter allowed to do". It just writes it as a set of separate rules.
APP 3 controls collection. An organisation may collect personal information only if it is "reasonably necessary" for one of its functions or activities. The consultation paper says the new test keeps "the concepts of legitimacy, necessity and proportionality that underpin the current 'reasonably necessary' test". APP 4 tells you what to do with information you did not ask for. APP 6 controls use and disclosure: you may use the information for the purpose you collected it for (the primary purpose). For any other purpose (a secondary purpose), you need consent or one of a list of exceptions.
In practice, the purpose you wrote down at the start does a lot of work. Write a broad purpose into a privacy policy, and a lot of later uses become "primary". That is one way a fern order becomes a humidity meter ad.
The real mechanism: new APP 3 and its seven factors
Here is the core of the draft. New APP 3.1 says:
An APP entity must not collect personal information, or use or disclose personal information held by the APP entity, unless the collection, use or disclosure of the information is: (a) fair and reasonable in the circumstances; and (b) lawful.
APP 3.2 then lists the matters the entity "must have regard to". Line them up with the house-sitter:
- (a) Reasonable expectation: "whether a reasonable person would expect the collection, use or disclosure of the information in the circumstances". The oolong.
- (b) Functions or activities: whether it "relates to one or more of the APP entity's functions or activities". The water bill, not the bank statements.
- (c) Transparency "about the means and the purposes". The note about the fern.
- (d) Data minimisation: whether the purpose "could be met by collecting, using or disclosing less information, or information that is not personal information". The three spare keys.
- (e) Genuine choice for the individual. The Saturday question.
- (f) Impact and risk of harm, and whether it is "proportionate having regard to any benefits to the individual or the APP entity". The spare room.
- (g) Children: "the best interests of the child as a primary consideration". The teenager.
Three details in the consultation paper change how you should read that list.
First, no factor decides the answer alone. An entity "would not be required to satisfy every legislated factor", and "No single factor will determine whether a particular collection, use or disclosure is fair and reasonable." It is one judgement across all seven, like the one you make when you walk back into your house.
Second, the privacy policy loses its magic. On reasonable expectations, the paper says "a practice does not necessarily become reasonably expected simply because it is described in a collection notice or privacy policy". On transparency, it says an entity "is not automatically transparent simply because information is included in a privacy policy, particularly if the policy is lengthy or unclear". A clause on page nine does not make the spare room rental reasonable.
Third, the benefit test has a clear direction. The paper says: "Information handling is unlikely to be proportionate where there is a significant risk to individuals, and the entity is the primary beneficiary." And on genuine choice: "Choice will not be genuine where individuals are presented with 'take it or leave it' terms, would suffer detriment for refusing, or are influenced through the use of dark patterns."
There is one surprise, and it cuts the other way. The paper says there "would be no express requirement to obtain consent for unexpected or unrelated secondary uses". Consent stops being the general way to make a new use lawful. Instead, you must show that the new use passes the seven factors. Consent "may continue to be a mechanism that entities use to provide individuals with choice, but it will only be valuable if meaningful". The same applies in reverse: a tick box cannot rescue a use that fails the test. That is the Productivity Commission's "tick box" complaint, turned into draft law.
The IAPP's Adam Ford put the result in one line: "This reflects an emerging regulatory view that legality alone may not be sufficient." The draft says the same thing in its own structure. "Lawful" is paragraph (b). "Fair and reasonable" comes first.
How this compares with Europe
If you have worked with the GDPR, the fair and reasonable test will feel familiar and odd at the same time. Article 6 of the GDPR says processing is lawful "only if and to the extent that at least one of the following applies", and then lists six lawful bases: consent, contract, legal obligation, vital interests, public task and legitimate interests. You pick a door and justify it. The last door, legitimate interests, has its own balancing test: your interests against the person's rights.
The Australian draft has one door for everybody, and the balancing happens at that door. In my reading, it is closer to a legitimate interests test applied to everything than to the GDPR's list of six. It is also why the draft's "legal basis" question has only one answer for most of your data: pass the seven factors. Then there are the two places where the draft adds a second lock, and that is where your tag manager comes in.
Part 3: The Word That Matters Most Is "Trade"

Back to the house-sitter. Most of what they do is judged by feel. But some things you would never leave to feel. "Do not rent out the house" is a rule, even in the most relaxed arrangement. The draft does the same. It keeps a consent rule for two acts, in new APP 4:
4.1 An APP entity must not collect sensitive information that relates to an individual unless the individual has consented to the collection of the information.
4.2 An organisation that holds personal information that relates to an individual must not trade the information unless the individual has consented to the trading of the information.
APP 4.1 is mostly the rule you have today, with a longer list of sensitive information (more on that below). APP 4.2 is new. To see how far it reaches, you need three definitions, and they build on each other.
Step 1: what is a disclosure?
Today the Act does not define "disclose". The draft does: "an entity discloses personal information if the entity makes the personal information accessible to another person or body". The consultation paper adds that it is a disclosure "regardless of whether the entity retains a level of control over it", that it "does not require an intention to disclose", and that storage alone, including overseas, is not a disclosure unless someone else can access the data.
Think about what a tracking pixel does. When a page loads, it makes the visitor's browser send the platform a request with the page address and whatever events and identifiers you configured. Under this definition, that looks like you making personal information accessible to another body, if the data is personal information. That leads to the next definition.
Step 2: what is personal information now?
Today's Act asks whether information is "about" an identified or reasonably identifiable person. The draft asks whether it "relates to" one, and adds a note that reads like a list of what an ad platform receives:
An individual can be identified, or reasonably identifiable, even if the individual's name or legal identity is not known. This can be the case if, for example, information allows an individual to be recognised, singled out, or otherwise dealt with as a distinct individual in practice.
The examples in that note include "a pseudonym or identifier", "location data or geolocation data" and "characteristics, behaviours, traits, preferences or patterns of activity". A cookie ID with a browsing history attached fits that description easily. So does a hashed email.3 "Reasonably identifiable" also gets a definition: a person is reasonably identifiable if they "could be identified by combining the information or opinion with other information or opinions that are reasonably available".
The draft also widens "collects". An entity collects personal information "regardless of the source from which or means by which the information is collected", and the note says that includes "generating the information itself" or "deriving it from other information". The consultation paper says directly that "inferences drawn by AI-enabled technology about an individual would be considered collection". The model that decided the fern owner needs a dehumidifier has collected something about her.
None of this appears from nowhere. In June, the Privacy Commissioner found that Medmate and Monash IVF interfered with privacy through the tracking pixels on their websites. The OAIC said that tracking people on health websites and targeting them with ads on social media "amounts to a collection sensitive information for which the website provider must obtain users' consent". The Privacy Commissioner added that "9 in 10 Australians consider it neither fair nor reasonable to be targeted on the basis of their sensitive health data". Note the words "fair" and "reasonable". The draft writes that reasoning into the definitions, for every website, not only health sites.

Step 3: what is a trade?
Draft section 6FC says a disclosure of personal information by an organisation "is a trade of that information if the organisation discloses the information: (a) for money or other consideration; or (b) for the purposes of direct marketing."
Part (a) is what you would expect. "Consideration" has its contract-law meaning and, the paper says, covers "the transfer of shares, the exchange of customer lists, or other transfers of personal information for value". Selling a list is a trade. Swapping a list with a "partner" is also a trade.
Part (b) is the one to read twice. The paper says disclosure for direct marketing "is intended to be interpreted broadly and includes disclosures that support or inform direct marketing, even where marketing is not the sole purpose". Then comes the sentence that turns this into a website question:
For example, this may include disclosures of cookies or pixels in programmatic advertising processes.
"May" is doing some work there, and the OAIC will need to write guidance. But the direction is clear. A Meta Pixel or TikTok Pixel that sends page views and conversion events to the platform so that you can build audiences and target ads is a disclosure that supports direct marketing. Unless a carve-out applies, that is a trade. A trade needs consent.
There are four carve-outs. A disclosure is not a trade if:
- it is for the recipient to provide "a product or service that the individual requested from the recipient" (the paper adds, "including where the disclosing organisation receives a commission");
- it is incidental to someone taking over the business, and selling the data is not "a substantial purpose" of the deal;
- it goes to a processor acting for you, on your documented instructions;
- it is for preventing, detecting or dealing with fraud.

The processor carve-out is the one vendors will argue about. The draft sets up a controller and processor model, like the GDPR. A processor acts "in accordance with a controller's documented instructions" and only for the purposes in those instructions. Your email platform, sending your newsletter under your contract, is a clear processor. An ad platform that matches your pixel data to its own users and uses it to improve its own targeting is not, in my reading. The paper also says a platform "will generally be responsible for the opt-out requirement unless it is acting solely as a processor", so the government expects some platforms not to be processors.
Direct marketing without the trade
Now the other half. The draft defines direct marketing as advertising or marketing material sent to a person if they are "selected, identified or otherwise targeted (whether as an individual or as a member of a class)" using personal information about them. The paper says this includes "targeted social media advertising, and online behavioural advertising based on personal information, including browsing history", and that it "makes clear that direct marketing includes group-level targeting that relies on personal information". Audiences, segments and cohorts are in.
But direct marketing itself does not need consent. The paper says so plainly: "The framework does not require consent for direct marketing, but entities must obtain consent to trade personal information." New APP 7 asks for a "simple means" to opt out before you send anything, reasonable steps to act on the request, and opt-out information on every communication, "in clear and plain language".4
So the same customer list can fall into two baskets. Email your own customers through your email processor, and it is direct marketing: it needs an opt-out. Upload the same list to a social platform to target them, or people like them, and it is a disclosure for direct marketing: it needs consent first.
A note for small businesses
Most businesses with an annual turnover of $3 million or less are outside the Privacy Act today. There are exceptions, and one of them is trading. The OAIC's small business guidance says the Act covers a business that discloses personal information "for a benefit, service or advantage", such as selling or swapping a customer list, when it does so without consent and without legal authority.
The draft rewrites that exception so that it covers a business that "trades personal information", using the new definition of trade. My reading, and it is only a reading of a draft: disclosure for direct marketing becomes part of the small business test. A small online shop that sends customer data to an ad platform to target ads might then be "trading" and inside the Act, unless it has consent. I did not find any change to the part of the current law that keeps consented trading outside the Act, so consent looks like the thing that decides it. If you run a small business with a pixel, this is the part of the draft to ask your lawyer about, and possibly the part to write a submission about.
Part 4: The Rest of the Package, Quickly
The rest of the package is narrower, but several changes will reach work your team does every week.
Consent gets a definition
Today the Act says consent can be express or implied, and not much more. The draft says consent "must be all of the following: (a) voluntary; (b) informed; (c) current; (d) specific; (e) unambiguous." The consultation paper explains each one. Bundled consent and interfaces "that make it unreasonably difficult for an individual to avoid giving consent" are probably not voluntary. Pre-ticked boxes "would likely not be sufficient". Consent can still be implied "where it can be clearly inferred from the individual's conduct and the purpose of the consent is obvious from the context". If your cookie banner has one "Accept" button and a "Settings" link in small grey text, read this section of the paper twice.
Sensitive information grows
The sensitive information list gets two additions. One is genomic information. The other will matter to anyone with an app: precise geolocation tracking data. The draft defines it as personal information from a device that identifies a person's location "within a radius of 500 metres" and "is collected and held by reference to the individual's location over time". The paper says it does not cover "one-off disclosures of location information" or "less precise location data (for example city location)". A store finder that asks for your location once is not in scope. An app that logs where you are every hour is.
The draft also answers an old question: when do you "collect" sensitive information that you could derive from ordinary data? The answer is that you do not collect it just because it is possible to derive it. You collect it when you derive and record it, or when you use it as sensitive information.5
Data breaches get a 72-hour clock
Today, after an entity believes it has had an eligible data breach (one likely to cause serious harm), it must give the Commissioner a statement "as soon as practicable". The draft replaces that with "within 72 hours". The paper says 72 hours matches the critical infrastructure and cyber security reporting laws. The 30-day period to assess a suspected breach stays. If you cannot complete the statement in 72 hours, you may send an incomplete one and explain what is missing and why.
Two new duties come with the clock, and they apply to any "data breach", even one below the serious harm test. Entities must have "practices, procedures and systems" to respond, and must take reasonable steps to reduce harm "as soon as practicable" after they suspect a breach: disable compromised accounts, contain the access, tell people how to protect themselves.
APP 11: know what you hold
APP 11 already says you must protect personal information and destroy or de-identify it when you no longer need it. The draft adds three duties. You must be able to identify the personal information you hold. For information you no longer need, you must first consider whether to destroy it, before you choose to de-identify it. And you must regularly assess whether your security, destruction and de-identification measures work. The paper also says de-identification "is not a static condition". Data that was anonymous last year may not be anonymous after someone releases a new dataset.
For analytics teams, the first duty is the one to plan for. It includes the event tables in your warehouse, the exports in someone's downloads folder and the audiences in three ad accounts.
Erasure, for the very large
The draft creates a right to erasure, but only against large digital platforms. A large digital platform is an organisation that provides a social media service, a relevant electronic service or a designated internet service (the categories in the Online Safety Act 2021) and meets one of two tests: gross revenue of "at least $500 million" across its business group in the previous financial year, or at least 2.5 million end users, which the consultation paper describes as an average of 2.5 million monthly end users in Australia. On request, it must destroy the personal information it holds about a person, unless an exception applies, and tell them the outcome in writing.
Rowland said that "Breaches of privacy can be tens of millions of dollars", as the ABC reported, so the platforms have reason to take the right seriously. It is also narrow, and not everybody is happy about that. The ABC reported that Greens senator David Shoebridge criticised the limit to platforms "with $500 million or more in revenue, or 2.5 million monthly users". For most businesses reading this, the erasure right will not apply. The APP 11 destruction duty will.
What is not in the draft
It is also worth knowing what I did not find. I searched the draft for the other big recommendations from the Privacy Act Review: removing the small business exemption, changing the employee records exemption, mandatory privacy impact assessments and a direct right of action for individuals. None of them appear. The consultation paper also describes OAIC measures (for example, a 60-day deadline to answer privacy complaints) that are not yet drafted. These may come later, or not at all.
Part 5: Mereana Sorts Her Nursery's Website

Mereana (made up, as far as I know) runs the website for a plant nursery in Launceston. It is the nursery that sent the maidenhair fern. The business turns over about $8 million a year, so it is inside the Act already. Mereana has read the draft, she has a pot of tea, and she has three baskets. On the bench in front of her: every data flow on the website, one tag per flow.
- Basket 1, fair and reasonable only: the flow must pass the seven factors. No consent gate.
- Basket 2, consent first: sensitive information, or a trade.
- Basket 3, opt-out: direct marketing that is not a trade.
Some flows go in two baskets. That is fine. The baskets are about which extra rule applies. The fair and reasonable test applies to everything.
Monday: the checkout
The checkout collects name, email, phone, delivery address and payment. The address goes to the courier, and the card goes to the payment provider.
- Order data, stored by the nursery: Basket 1. The customer expects it, it relates to the business and it is needed to deliver the fern.
- Address to the courier: a disclosure, but the customer asked for delivery. It fits the "requested service" carve-out, and the courier is also close to a processor. Basket 1.
- Card to the payment provider: the same reasoning, and possibly the fraud carve-out as well. Basket 1.
- A "plant care quiz" that asks about the customer's allergies: allergy information is health information, which is sensitive. It needs consent, and the paper's "strictly necessary" exception does not help, because the quiz is optional and it feeds marketing. Basket 2. Mereana writes a note to ask whether the quiz needs the question at all. That is factor (d).
Tuesday: analytics
The site runs GA4, with Google Signals turned off, and a heatmap tool that records clicks on product pages.
- GA4, used only to measure the site: a disclosure to Google. If Google acts only as the nursery's processor under its terms, and the data is not used for ads, it is not a trade. Mereana marks the vendor terms as something to check, and puts the tag in Basket 1 for now. It must still pass the seven factors. Do customers expect it? The paper says a privacy policy is not enough to make a practice expected, so she plans a clear line in the banner and the notice.
- GA4 linked to Google Ads, with remarketing audiences: now the same data supports direct marketing. Basket 2.
- The heatmap tool: the vendor stores recordings only for the nursery. Basket 1. Factor (d) asks whether it needs every session, so she sets it to a sample and masks form fields.
Wednesday: advertising
This is the long day.
- Meta Pixel with page views, "add to cart" and purchase events, and advanced matching on: the pixel makes behaviour and a hashed email accessible to Meta, for ad targeting and measurement. This is the paper's example. Basket 2, with consent before the pixel fires, because a consent collected after the data has left does not gate anything.6
- Google Ads conversion tag with enhanced conversions: hashed customer data to Google, for ad measurement and optimisation. Basket 2.
- Customer list upload to Meta for a "Custom Audience" and a lookalike audience: a disclosure for direct marketing. The lookalike is group-level targeting that relies on personal information. Basket 2.
- Ads on Meta shown to "people in Tasmania aged 35 to 65 interested in gardening": Meta does the targeting with its own data. The nursery discloses nothing. It is not the nursery's trade, although the ad may still be direct marketing by the platform. Mereana puts it on the table next to the baskets, with a note for Meta's problem pile.
Thursday: email and partners
- Monthly newsletter to customers who signed up, sent through the email platform: direct marketing, with the email platform as a processor. Basket 3. Every email needs a working unsubscribe link, and the Spam Act still applies alongside the Privacy Act.7
- The "garden partners" arrangement: the nursery shares its list of new customers with a garden tool company each quarter, and gets a 10% referral fee on sales. That is disclosure for consideration, and it is for direct marketing. Basket 2, twice over. This is the garden tool email that surprised our fern owner in the opening. Mereana's note says "stop, or ask".
- Click and collect store finder that asks for location once: not precise geolocation tracking data, because it is not held over time. Basket 1.
Friday: compare the baskets
By Friday afternoon, the baskets look like this. Basket 1 holds the checkout, the courier, the payment provider, measurement-only analytics, the sampled heatmap and the store finder. Basket 3 holds the newsletter. Basket 2 holds the allergy quiz, the Meta Pixel, the Google Ads tags, the customer list upload, remarketing audiences and the partner list.
Basket 2 is where the new work is. Every one of those flows needs a consent that is voluntary, informed, current, specific and unambiguous, collected before the data leaves. For the tags, that means a consent tool that holds them until the visitor says yes, with separate choices, not one "Accept all". I wrote about how a consent signal travels through a tag last year, in the Google consent mode post. That mechanism is the same one Mereana will need here.
Her last note is about Basket 1. Each flow there still needs a short written reason against the seven factors. If the OAIC ever asks, "we thought it was fine" is a weak answer, and "here is what we considered" is a good one.
What to Do This Week
The draft will change before it reaches Parliament, and it has no start date. But the work below is useful under today's law too.
- List every data flow that leaves your website or app. Tag manager, hard-coded scripts, server-side tags, audience uploads, data-sharing clauses in contracts. For each one, write down the recipient and what it does with the data. You cannot sort what you have not listed.
- Run the three questions on each flow. Is it made accessible to another body? Is it for money, other consideration or direct marketing? Does a carve-out apply? If you cannot answer the processor question for a vendor, read its terms, and look for words like "our own purposes" or "improve our products".
- Mark the sensitive flows. Health, precise location over time, and anything a model derives about religion, sexuality or health. These need consent now, and after the pixel determinations in June, the OAIC has shown it will act.
- Write the seven-factor note for the flows that stay in Basket 1. One paragraph each. Expectation, connection, transparency, minimisation, choice, risk and benefit, children.
- Test your consent banner against the five words. Is "No" as easy as "Yes"? Is each purpose separate? Do the tags wait for the answer? Is anything pre-ticked?
- Check your breach plan against 72 hours. Who decides that a breach is "eligible"? Who writes the statement to the Commissioner? Can you do it on a Saturday?
- Decide whether to make a submission. Submissions close on 18 September 2026, and the department asks for about 1,000 words. If the trade definition, the small business change or the processor carve-out would hurt or help your business, this is the time to say so, with a real example.
Final Thoughts
Back to the fern owner in Launceston. Under the draft, most of what happened to her would need a different start. The fern still arrives, because delivery is fair, reasonable and requested. The newsletter can still come, with an unsubscribe link. But the pixel on the checkout page, the list sent to the tool company and the lookalike audience built from her order would each need her "yes" first, and a "yes" that means something: separate, clear and easy to refuse.
The one takeaway is this. The draft does not ask "did you tell them?" as its first question any more. It asks "was it fair?", and then, for trades and sensitive data, "did they agree?". The first question is a judgement. The second is a gate. Your job is to know which of your data flows face which one.
So this week, list the flows and sort them into baskets, and if the draft gets something wrong for your business, tell the department before 18 September. The Bill has a blank commencement table and a lot of consultation ahead. It will change. The basic shape, one test and two gates, probably will not.
The house-sitter will be home soon, the ferns are watered and nobody rented out the spare room. Now, if you'll excuse me, I think my tea is ready.
Notes
-
The commencement table in the draft has four numbered rows and no text in any of them. For a document that is about when things happen to your data, it is quite restful to read. ↩
-
Drinking a saved oolong without asking is a recognised category of harm in any serious tea household. The Privacy Act does not recognise it yet. Perhaps in Tranche 3. ↩
-
A hashed email is an email address run through a one-way function such as SHA-256, so it looks like a long string of random characters. Ad platforms use the hash to match a person to an account, because the same email always gives the same hash. That is exactly what "singled out" means. ↩
-
The draft has a separate clause for ad-supported services, the platforms that earn money from the ads they show. If a user opts out, such a platform may offer its service on different terms, as long as those terms give "a genuine choice to continue to use the service without receiving direct marketing communications". The consultation paper links it to "consent or pay" guidance in the UK and the EU. ↩
-
The consultation paper's example is good. A meal order for a halal meal is not sensitive information just because you could infer religion from it. If you later use the order to infer religious belief and send marketing about a religious festival, you have collected sensitive information at that point, and you need consent. ↩
-
The OAIC's determinations about Medmate and Monash IVF were published on 24 June 2026, under the current Act. They concern health information, which is already sensitive. The draft goes further, because the trade gate does not depend on the page being about health. ↩
-
New APP 7.7 says the direct marketing principle does not apply "to the extent that" the Spam Act, the Do Not Call Register Act or parts of the Interactive Gambling Act apply. The paper says the rest of the Privacy Act, including the fair and reasonable test, still applies to the data behind those messages. ↩


