Post

Australia's privacy reforms: what is changing and when

Australia’s privacy reforms now involve several different timelines. Some changes are already law, others have a December milestone, and the latest package remains an exposure draft. School leaders need to separate those categories to decide what requires action now.

The Attorney-General’s Department opened consultation on the Privacy Amendment (Personal Data Protection) Bill 2026 on 31 August. Submissions close on 18 September 2026, and the proposals remain subject to government consideration. Consultation details.

This article explains the reform position. Its companion, How independent schools should govern technology approvals, sets out a practical process for turning supplier assessments into school decisions.

Status checked on 12 September 2026. Lead photo by Philipp Katzenberger on Unsplash.

What has happened, and what comes next

DevelopmentPosition as at 12 September 2026
First reform legislationParliament passed the Privacy and Other Legislation Amendment Act 2024 in November 2024, including the framework for a statutory privacy tort and the Children’s Online Privacy Code. Attorney-General’s Department.
Serious invasions of privacyThe statutory tort commenced on 10 June 2025, providing an additional avenue for redress through the courts. OAIC explanation.
Automated decision transparencyNew privacy-policy obligations commence on 10 December 2026 for covered automated decision making. OAIC issues paper.
Children’s Online Privacy CodeThe OAIC must register the final Code by 10 December 2026. Registration and the commencement of obligations are separate matters. OAIC consultation page.
The 2026 exposure draftConsultation is open. The draft commencement table contains no dates, so this package has no settled start date. Exposure draft, clause 2.

Independent schools should also establish their existing obligations. The OAIC says private schools are usually covered by the Privacy Act, including through turnover, related organisations or providing health services and holding health information. First aid and medication support can be relevant. Government schools generally operate under different arrangements. OAIC guidance on children and education.

December deserves its own preparation

The automated-decision provisions concern programs that use personal information to make, or substantially and directly contribute to making, decisions expected to significantly affect a person’s rights or interests. Privacy policies must describe relevant categories of information and decisions. A human making the final decision does not automatically exclude the process. OAIC issues paper, pp. 12–15 and 25–26.

I would begin by finding systems that score or recommend outcomes for admissions, scholarships, student interventions or recruitment. Those are review examples; whether the obligation applies depends on the actual process and statutory threshold. System owners will need to explain how software contributes before a privacy-policy update can accurately describe it.

The Children’s Online Privacy Code needs separate attention. Its scope concerns specified online service providers likely to be accessed by children, with exceptions. Schools should assess their activities and suppliers against the final instrument and its transition arrangements. Having students alone does not settle coverage. OAIC background.

What the new exposure draft proposes

Fair and reasonable information handling

The draft would replace several collection, use and disclosure rules with a fair, reasonable and lawful handling requirement, subject to exceptions. Factors include expectations, transparency, minimisation, choice and proportional harm. Children’s best interests would be a primary consideration. Exposure draft, Schedule 2.

For schools, my starting question would be whether each information request is justified by the activity. A broad enrolment consent should never end that assessment, particularly where students have little practical choice about participation.

The proposed personal-information definition includes information relating to identifiable people, with identifiers and behavioural patterns among its examples. Collection includes generating or deriving information. Defined precise geolocation tracking would become sensitive information. Exposure draft, Schedule 1.

Consent would expressly need to be voluntary, informed, current, specific and unambiguous. Sensitive-information collection would generally continue to require consent, with exceptions. White & Case analysis.

I would include learning profiles, device identifiers and app telemetry in school reviews alongside names and contact details. Removing a name may leave other information that identifies the student.

Ethernet and fibre cables connected to network equipment The proposed changes would affect operational preparation as well as privacy documentation.

A tighter breach-notification timetable

The proposal would give entities 72 hours to notify the Information Commissioner once they become aware of reasonable grounds to believe an eligible data breach has occurred. The existing requirement to take reasonable steps to complete a suspected eligible breach assessment within 30 days remains. Preparedness and harm-mitigation duties would also be strengthened. Consultation paper, Schedule 3.

That trigger matters. An initial technical alert and awareness of grounds to believe an eligible breach occurred are different stages. Notification to affected people has its own requirements. Staff need prompt escalation pathways, while those assessing the incident need supplier cooperation and access to decision-makers.

Responsibility for outsourced processing

The processor proposal applies where both parties are Australian Privacy Principle entities. A provider handling information under a controller’s written instructions could receive an exception from certain obligations, with relevant responsibility resting on the controller. Processors retain direct APP 1 and APP 11 duties; conduct outside instructions falls outside the exception. Consultation paper, Schedule 6.

Schools would need to understand each provider’s role in the particular activity. Contracts should establish permitted handling, including whether the supplier uses information for its own analytics, advertising or AI training.

Information holdings, security and disposal

Proposed APP 11 changes would require identification of relevant personal information, consideration of destruction when no longer needed, and regular evaluation of compliance. Legally required retention is protected. Exposure draft, Schedule 3.

Preparation should connect the records policy to actual systems, exports and supplier accounts. Schools will need to account for applicable education, child-safety and other retention requirements when deciding what can be removed.

What remains unsettled

The proposed erasure right targets large digital platforms. It is not a general right to demand deletion of every school record. Broader removal of the small-business and employee-records exemptions is outside this package. White & Case analysis.

A proposed 60-day complaint-response requirement is among measures still being developed in the consultation paper, rather than fully expressed in the exposure draft. Consultation paper, pp. 38–40.

Schools can use the consultation to explain implementation issues such as supplier contracts, record retention and the time needed to review existing systems. Meanwhile, leadership can assign an owner to the December preparation and start the technology assessment and approval work that already supports sound privacy governance.


References

Government reform documents

Attorney-General’s Department. (2026, August 31). Privacy reform: Consultation on exposure draft legislation [Closes 18 September 2026].

Attorney-General’s Department. (2026). Exposure draft: Privacy Amendment (Personal Data Protection) Bill 2026 [Draft legislation]. Accessible Word version.

Attorney-General’s Department. (2026). Privacy reform: Consultation paper, particularly Schedules 3 and 6 and pp. 38–40.

Attorney-General’s Department. (n.d.). Privacy [Reform overview]. Accessed 12 September 2026.

Regulator guidance

Office of the Australian Information Commissioner. (2025, June 19). Statutory tort for serious invasions of privacy.

Office of the Australian Information Commissioner. (2026, May). Automated decision-making transparency obligation (APP 1): Issues paper.

Office of the Australian Information Commissioner. (2026). Draft Children’s Online Privacy Code: Consultation for industry, civil society, academia; and OAIC releases exposure draft of the Children’s Online Privacy Code.

Office of the Australian Information Commissioner. (n.d.). Children and young people. Accessed 12 September 2026.

Boyle, N., Kermond, C., & Moore, A. (2026, September 8). Australia privacy update: Proposed privacy law reform. White & Case LLP.

This post is licensed under CC BY-NC-ND 4.0 by the author.