Australia Privacy Law Changes: What You Can Do
Privacy in Australia is changing faster in 2026 than it has in decades. Some rules already apply, others are proposals.
The Office of the Australian Information Commissioner (OAIC) oversees the Privacy Act 1988 and the 13 Australian Privacy Principles. On top of the Act are rules you can rely on today, and a new draft bill that Parliament has not yet passed.
On 31 August 2026 the Australian Government released the Privacy Amendment (Personal Data Protection) Bill 2026 as an exposure draft with a consultation paper. Anyone can comment until 18 September 2026
Quick answer: You already have rights to access, correct and complain about personal information under the Privacy Act. Since 10 June 2025 you can also sue for a serious, intentional or reckless invasions of privacy. From 10 December 2026, many organisations must state in their privacy policy when a computer system (i.e. AI) uses your personal information to make significant decisions about you, and a Children’s Online Privacy Code is required to be registered. A right to erasure, IDLock, a “fair and reasonable” collection test, and extra AI rules are still proposals.
What already applies in Australia
-> Privacy Act 1988 and the 13 Australian Privacy Principles – ongoing. Many organisations must collect fairly, store securely, and tell you why they want your information. The OAIC has investigative powers if they do not. Health services in Australia are covered even if they are small. Many other businesses under $3 million turnover still sit outside the federal Act.
-> Notifiable Data Breaches scheme – ongoing. If a serious breach is likely to harm you, the organisation must tell you and the OAIC. There is no 72-hour deadline in Australian law.
-> Stronger OAIC powers and higher penalties – since 11 December 2024. The regulator has more tools when organisations break the rules.
-> Statutory tort for serious invasions of privacy – since 10 June 2025. You can take someone to court if they intentionally or recklessly invade your privacy in a serious way.
-> Social media minimum age – since 10 December 2025. Age-restricted platforms must take reasonable steps to keep Australians under 16 off those services.
Locked-in for 10 December 2026
The following changes are already legislated here in Australia, and are not part of the new draft bill:
-> Automated decisions. If a bank, insurer, employer, health service or government agency uses a computer program to make, or substantially help make a decision that could significantly affect your rights – it must say so in its privacy policy. The policy must describe the kinds of personal information collected and used, and the decisions involved. This is more of a notice rule, not a ban on AI systems. If a decision about you looks machine-made and wrong – ask whether a computer was involved and request a human to review it.
-> Children’s Online Privacy Code. The OAIC must register this code by 10 December 2026. It will add extra rules for many online services that children are likely to use, including limits on targeted advertising. It sits next to the under-16 social media restriction. It does not, by itself, make a device private (phone or PC). Parents still need tight permissions and, where the risk is high – a device that is not built to track.
Proposed (not law yet)
The 31 August 2026 package is an exposure draft plus a consultation paper. You cannot enforce these items until an Act is passed and a start date is set.
-> Right to erasure. You will be able to ask large digital platforms – such as social media and search companies – to destroy personal information they hold about you. News organisations publishing news articles would be exempt. This would not be a “delete me from every retailer and data broker” right. Timeframes, exceptions and enforcement are still being consulted on.
-> IDLock. A planned myGov tool to block, unblock and monitor use of a driver liscence or passport when those documents are used to verify you online. It builds on the Credential Protection Register (2022) which the government says has already blocked more than 830,000 fraudulent checks. A small trial is expected later in 2026. A wider myGov rollout is planned for 2027. IDLock is aimed at identity crime, and it does not stop apps, your phone or PC from collecting behavioural data.
-> Fair and reasonable collection, and stronger consent. The draft would stop organisations relying on a buried tick-box to collect more than they need, or to use your information for a purpose you would never expect. Trading personal information would need clearer permissions.
-> AI training and smart glasses. The draft and consultation paper aim to tighten rules on using the personal information of Australians to train AI, and use of wearable cameras that can record without a clear signal. eSafety have advised harms from covert recording are already happening. An import ban on some smart glasses has been discussed in public, however is not part of the draft bill.
Why the gap still matters
The 2026 OAIC community survey (1,504 adults in March) found that 93% of Australians say protecting personal information is important, 87% are more concerned than 5 years ago, and 78% feel they have little or no real control. 93% say using data collected for a service to train AI is not fair. 93% also support a legal right to request deletion.
That is why the draft exists and is also why waiting for the draft is not a solid plan.
A future right to ask a platform to delete an account still does not stop:
- a stock Android or iPhone collecting and sending your personal data in the background
- apps collecting location, contacts and/or sensor data after you tap Allow
- AU telcos keeping certain metadata for 2 years
- AI systems training on data that has already left your device.
What you can do this week
We recommend these in order, with each step standing on its own:
- Lock email, myGov and internet banking first. These 3 accounts can reset everything else. Use a unique, strong password for each. Turn on two-factor authentication (2FA) – using an authenticator app or a passkey. Avoid SMS codes if the service offers an app or passkey instead. A password manager such as Proton Pass makes this relatively simple. This and other free options can be found in our Privacy Hub with 150+ tools to improve your privacy, security and anonymity.
- Download your data from big platforms, then close accounts not in use. Google, Meta (Facebook and Instagram), Apple and Microsoft all have a “download your data” or a “privacy dashboard” page. Save that file somewhere safe (i.e. offline). Then delete shopping, forum and “free trial” accounts you no longer need and request for the deletion of your data. You already have the right to close an account you control.
- Cut what those platforms collect. Turn off AI training, ad personalisation and activity history where the settings exists. For everyday browsing, use options like Brave with add-ons like uBlock Origin. For searches, use Startpage, DuckDuckGo or Brave Search. That reduces new tracking even while old data is still sitting on a company’s servers.
- Check the 5-10 apps you actually open. On your phone: go to Settings → Apps → Permissions. If maps, a torch or a shopping app still works without location, microphone or contacts, switch those off. Delete anything you have not opened in 90 days. Always try to use an alias email instead of your “main” email.
- Treat your licence and passport as gold. Do not upload photos of them to a random app or “verify now” link. IDLock is not live yet. Random texts asking you to “confirm your ID” are typically scams until you check and validate the organisation’s real website yourself.
- Do not paste tax, health or family files into an AI tool. Photos, voice notes and other personal documents uploaded to many consumer AI tools can be used to improve that tool and beyond. Keep sensitive files on your own, secure privacy devices – preferrably offline.
- Look at the phone itself, not just the apps. Permission screens sit on top of a phone’s operating system. Stock Android and iOS still sends your personal data in the background. A professionally configured Privacy Phone running GrapheneOS, and a Privacy Laptop where you work or bank, can cut that layer. Major Australian networks and most banking apps still work when the phone is professionally configured.
Common Questions
What are the new privacy laws in Australia in 2026?
- Already in force: the statutory privacy tort (from 10 June 2025) and the under-16 social media rule (from 10 December 2025).
- From 10 December 2026, automated-decision notices and the Children’s Online Privacy Code take effect.
- The right to erasure, IDLock, the fair and reasonable test and extra AI rules are in an exposure draft with consultation closing 18 September 2026 (Parliament has not passed that draft).
Is there a right to erasure in Australia?
Not yet as a general legal right against every organisation. The draft would let you ask large social media and search companies to destroy personal information they hold about you. News publishers would be exempt. Until an Act is passed, consider closing accounts you control and use each platform’s own delete tools.
What is IDLock?
A proposed myGov tool to block and monitor use of your Australian licence or passport when they are used to verify you online. A small trial is expected later in 2026. A wider rollout is planned for 2027. It is aimed at identity theft. It does not stop apps or your phone collecting personal data.
When do automated decision-making rules start?
10 December 2026. Covered organisations must then describe relevant automated decisions in their privacy policy – the kinds of personal information used, and the kinds of decisions involved. That is a notice rule, not a ban on AI. If a decision about you looks machine-made and wrong, ask whether a computer was involved and request a human to review.
What is the “fair and reasonable” test?
It is in the draft bill, not current law. The idea is that an organisation could no longer collect or use your information just because you ticked a long terms and conditions box. Collection and use would also have to be fair and reasonable in the circumstances. Trading personal information would need clearer permissions. None of that can be enforced until Parliament passes it.
Can I sue for a privacy breach?
In serious cases, yes – if someone intentionally or recklessly invaded your privacy. For most mishandling (i.e. a leaked mailing list), complain to the organisation first, then escalate to the OAIC.
Does the Privacy Act cover every business?
No. Health services are covered even if they are small. Many other businesses under $3 million turnover still sit outside the federal Act. State and territory rules can still apply. When in doubt, complain to the organisation in writing and keep a copy for records.
Do these reforms mean I no longer need a privacy phone?
No. The reforms mainly govern what organisations may do after they already have your data. A hardened private phone reduces how much is sent in the first place.

Who enforces privacy law in Australia?
The OAIC for the Privacy Act, Courts for the statutory tort, and eSafety for online safety harms.
Where do I complain?
Best practice would be to write to the organisation first. Then use oaic.gov.au. This article is educational, not legal advice.
Can I comment on the draft?
Yes. Public consultation on the exposure draft is open until 18 September 2026 on the Attorney-General’s Department consultation page.
Final Thoughts
The 2026 reforms give Australians more formal control than they had in 2024: a path to court in serious cases, clearer notice when an automated system helps decide something important, extra rules for children’s services, and if passed – a platform deletion right and IDLock.
They still leave a hole. Normal phones and some default apps are designed as surveillance tools that keep collecting – even when your phone is idle.
Use the rights that already exist, comment on the draft if you want to, then reduce what your devices give away while Parliament works.
[Last updated: 4 September 2026. This page will be revised as the exposure draft moves through consultation and Parliament. Educational only – not legal advice.]
Want to go further?
-> Explore 150+ Privacy Tools vetted by our Pros
-> See Privacy Phones
Your personal data is extremely valuable.