Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Privacy Act Tranche 2 Draft: 72-hour breach deadline, fair and reasonable test, what Australian businesses should do now

Author: Dan Briggs  |  Published: 7 September 2026  |  Reading time: 16 minutes

Executive summary

On 31 August 2026 the Attorney-General’s Department released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, the long-promised second tranche of Privacy Act reform. Submissions close on 18 September 2026. The draft contains roughly 40 proposals and, if passed in its current form, it would be the biggest change to how Australian businesses handle customer, patient, guest and donor data since the Australian Privacy Principles arrived in 2014.

Four proposals matter most to the businesses we support. First, a hard 72-hour deadline to notify the Information Commissioner once you have reasonable grounds to believe an eligible data breach has occurred, replacing the current “as soon as practicable” wording. Second, a new “fair and reasonable” test that replaces the collection, use and disclosure rules in APPs 3, 4 and 6, meaning consent alone will no longer justify what you do with personal information. Third, a much wider definition of personal information that expressly captures location data, behavioural data and information inferred by AI tools. Fourth, a security principle that expects you to destroy information you no longer need, not simply de-identify it, and to be able to prove your retention practices are working.

What the draft does not do is also important. It does not remove the $3 million small business exemption, despite what a number of widely shared articles claim. But if your firm became an AML/CTF reporting entity on 1 July 2026 (lawyers, conveyancers, accountants, real estate agents and dealers in high-value goods), you already lost that exemption, and this Bill is now your problem too.

Our view after reading the draft: the 72-hour clock is the proposal most likely to survive consultation unchanged, because it simply matches deadlines already in force under the Cyber Security Act 2024 and the SOCI Act. It is also the proposal most Australian SMBs are least equipped to meet, because meeting it depends on logging, backups and an incident plan that exist before the breach, not after. This whitepaper explains each proposal in plain terms, what it means for your business, and the practical steps worth taking now, whether or not you make a submission.

What was released on 31 August and why it matters

The Privacy Act 1988 has been under review since 2020. The Attorney-General’s Department published 116 reform proposals in February 2023. The first tranche, the Privacy and Other Legislation Amendment Act 2024, received Royal Assent on 10 December 2024 and delivered only a handful of them: a tiered civil penalty regime, a statutory tort for serious invasions of privacy (which commenced on 10 June 2025), a Children’s Online Privacy Code, and the automated decision-making transparency rules that take effect on 10 December 2026. We covered those last rules in Using AI to Make Decisions? You’ll Need to Say So in Your Privacy Policy by December.

The second tranche is the one that changes day-to-day data handling. According to Colin Biggers & Paisley’s analysis published 1 September 2026, the exposure draft contains 25 Privacy Act Review proposals that lift privacy protections, 5 that clarify or simplify obligations, 4 additional simplification measures and 7 measures aimed at making the OAIC more efficient. Clayton Utz describes the package as the most significant overhaul of Australian privacy law in more than a decade.

The timing is not accidental. According to the OAIC’s media release of 6 July 2026, the regulator received 1,205 data breach notifications in calendar year 2025, an 8 per cent increase on the 1,112 received in 2024 and the highest annual total since the Notifiable Data Breaches scheme began in 2018. Of those 1,205 notifications, 716 were attributed to malicious or criminal activity. Health service providers accounted for 225 notifications (19 per cent), followed by financial services (157), the Australian Government (118), business and professional associations (103), education (81) and legal, accounting and management services (81). The same release notes that the OAIC’s 2026 Australian Community Attitudes to Privacy Survey found 82 per cent of Australians are concerned about data breaches, up from 74 per cent in 2023.

That last figure is the political driver. Ministers see a public that is more worried about data breaches every year, and a scheme that still gives organisations an open-ended window to tell people. The draft Bill is the response.

It is an exposure draft, not law. It has not been introduced to Parliament. Provisions can and will change. But exposure drafts released after a six-year review process rarely get watered down in the direction businesses would prefer, and the core proposals have been signalled since the 2023 review report. Planning on the assumption that most of this becomes law during 2027 is the sensible position.

The 72-hour breach deadline: what changes and what stays

Under the current Notifiable Data Breaches scheme, an organisation that suspects a breach has up to 30 days to assess whether it is an “eligible data breach” (one likely to result in serious harm). Once it forms that view, it must notify the OAIC and affected individuals “as soon as practicable”. In practice, that second stage has stretched for weeks in many of the incidents we have seen, particularly where the organisation was still working out which records were touched.

The draft Bill keeps the 30-day assessment window but puts a hard limit on the second stage. Once an entity is aware of reasonable grounds to believe an eligible data breach has occurred, it must give the Commissioner a statement within 72 hours. As iTnews reported on 1 September 2026, the clock starts when the entity becomes aware that there are reasonable grounds to believe an eligible data breach has occurred. If a complete statement cannot be assembled in time, the entity can file an incomplete one, with a written notice identifying what is missing and why it was impossible or impracticable to supply. Filing nothing at all within 72 hours could attract an infringement notice or a compliance notice. Affected individuals must be notified at the same time where practicable, and must be told about material changes to previously reported information.

There is a second change buried in the same section that lawyers are flagging as more significant than the deadline. Today, taking remedial action that prevents serious harm is a way to avoid the notification obligation arising at all. The draft flips that into a positive duty: entities would be obliged to take reasonable steps to contain a breach and mitigate harm. Containment stops being a way out and becomes a legal requirement in its own right.

Why 72 hours is the number

The deadline is not new to Australian regulation. Under the Cyber Security Act 2024, businesses with annual turnover above $3 million must report a ransomware or cyber extortion payment to the Australian Signals Directorate within 72 hours of making it, with an education-first approach that ended on 31 December 2025 and full enforcement from 1 January 2026. We covered that in Ransomware Payment Reporting Is Now in Enforcement Mode. Critical infrastructure operators already face 72-hour windows under the Security of Critical Infrastructure Act 2018, and APRA-regulated entities have a 72-hour incident notification obligation under CPS 234. Europe’s GDPR has used 72 hours since 2018. The draft Bill simply brings the NDB scheme into line.

What this means for your business

Here is the pattern we see in the SMB incidents we handle, and it is the most important practical point in this whitepaper. The step that takes the longest in a breach response is almost never containment. Resetting passwords, revoking sessions and isolating a device is typically done within hours. The step that takes days or weeks is answering the question the notification statement actually asks: which records were accessed, by whom, and does that meet the serious harm threshold. If your Microsoft 365 tenant is on default audit settings, your file server has no access auditing turned on and your line-of-business application keeps no access log, that question can be unanswerable, and you will be filing an “incomplete statement” that says so in writing to the regulator.

That is the real cost of the 72-hour rule. It does not require you to be faster at fixing things. It requires you to have the evidence available to explain what happened, and that evidence has to be collected before the breach, not after.

Concretely, a business that can meet a 72-hour deadline has these things in place already: unified audit logging enabled across Microsoft 365 with retention beyond the default; mailbox auditing on every account; an inventory of where personal information actually lives (including the spreadsheet exports nobody admits to); an incident response plan with named decision-makers and their after-hours contact details; a pre-agreed relationship with an IT provider or incident responder who can pull logs at 2am; and a template notification statement that only needs the facts filled in. If you have all six, 72 hours is achievable. If you have none, it is not.

The fair and reasonable test: consent is no longer a complete answer

The centrepiece of the draft is a single new standard that replaces APPs 3, 4 and 6. Any collection, use or disclosure of personal information would have to be fair, reasonable and lawful in the circumstances, judged against a set of legislated factors: what a reasonable person would expect; the connection to your business’s functions; whether your notices would let a reasonable person understand why and how you handle their information; whether you are collecting only what you need; whether the individual has a genuine choice and meaningful alternatives; the potential impact on the individual and whether it is proportionate to the benefit; and, where children are involved, their best interests as a primary consideration.

The practical consequence, as Colin Biggers & Paisley puts it, is that consent stops being a complete answer. Today, a business that gets a customer to tick a box can point to that tick. Under the draft, the business also has to be able to justify the handling itself. A hotel that asks for a date of birth, passport number and next-of-kin details for a one-night stay would need to explain why each item is necessary. A recruitment firm that keeps every applicant’s CV indefinitely “in case a role comes up” would struggle with the data minimisation factor.

Consent itself gets a statutory definition. It must be voluntary, informed, current, specific and unambiguous, all five at once. Pre-ticked boxes will not do. Bundled consent, where one tick covers marketing, profiling and sharing with partners, will not do. Consent obtained years ago and relied on since will not do, because it is no longer “current”. Enrolment forms, app permissions, loyalty sign-ups and membership applications will need reviewing, and many will need re-papering.

A separate “consent to trade” rule would require consent before disclosing personal information for money or other consideration for direct marketing purposes, with carve-outs for services the individual has requested, mergers and acquisitions, and controller-to-processor disclosures. Direct marketing is defined broadly enough to include disclosures via cookies and tracking pixels, which follows the Privacy Commissioner’s pixel determinations earlier in 2026.

What this means for your business

For most of our clients, the fair and reasonable test is a form-and-process problem more than a technology problem. The work is to list every point where you collect personal information (website forms, booking systems, intake questionnaires, CRM imports, event registrations, donation pages), write down why you collect each field, and remove the fields you cannot justify. That exercise usually shrinks the data footprint noticeably, which in turn shrinks the blast radius of a future breach. It is one of the few compliance tasks that also directly reduces cyber risk.

Wider definitions: location, behaviour and AI inferences

The draft rewrites several definitions that sit underneath everything else.

Personal information would cover information that “relates to” an individual, not just information “about” them, and would use an objective “reasonably identifiable” test. Information that lets someone be singled out (a device identifier, a pseudonymous customer ID, a pattern of behaviour) counts even if their name is unknown. Sensitive information would expand to include genomic information, biometric templates and precise geolocation tracking data, defined as location within 500 metres tracked over time. Workforce tracking apps, fleet telematics that identify drivers, and access-control systems using fingerprints or faces move into the consent-required category.

Collection would expressly capture AI-generated and derived data. If your CRM’s AI assistant infers that a client is likely going through a divorce, or your booking system scores a guest as high-risk, those inferences become personal information you have “collected” and must handle under the full set of obligations. Disclosure would be defined as making information accessible to another person or body, which Clayton Utz notes raises a real question about whether storing data with a cloud provider continues to fall outside the definition of a disclosure.

De-identification would no longer be treated as a fixed state. Whether information is de-identified depends on context, and organisations would need to manage the foreseeable risk that it can be re-identified over time.

What this means for your business

Two things. First, your data map is wrong, or will be. Almost every organisation we assess has a reasonable idea of where names, emails and payment details sit, and almost none has thought about the inferred fields their software generates, the location history in their fleet or field-service tools, or the biometric templates in their door-access system. Second, if you are rolling out Copilot, ChatGPT or any AI assistant across the business, the outputs of those tools about your customers are now inside the regulated perimeter. That is a governance conversation to have before the rollout, not after.

Destruction, retention and the new security principle

APP 11 currently requires reasonable steps to protect personal information and to destroy or de-identify it when no longer needed. The draft tightens both halves. Entities would need to consider destroying, not merely de-identifying, information they no longer need; be able to identify that information; and regularly evaluate whether their security and retention measures are actually working. Retention in de-identified form would remain permitted for research and statistical purposes, but a blanket policy of de-identifying everything rather than deleting it is unlikely to survive.

This lands on top of the existing penalty regime. Since the December 2024 amendments, a serious interference with privacy carries a maximum civil penalty for a body corporate of the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover during the breach period, according to DLA Piper’s summary of the Act. A non-serious interference carries up to $3.3 million, and a new low tier of up to $330,000 applies to specific administrative failures such as not having a compliant privacy policy, enforceable by infringement notice without going to court.

What this means for your business

Retention is where IT and legal have to work together, and where most businesses have simply never made a decision. The shared drive contains client files from 2011. The old practice management system was “kept for reference” after migration. Backups are retained forever because nobody set a policy. Every one of those is personal information you hold, and under the draft you would need to justify holding it. A defensible retention schedule, applied by Microsoft Purview retention policies and enforced on the file server and in backups, is the technical control that turns a policy into evidence. It also removes the data that makes a ransomware incident notifiable in the first place. Our earlier piece on the Quest Apartment Hotels breach is a case in point: the exposed database held guest records from before June 2025 that the business had no ongoing need for.

Controllers, processors and your cloud contracts

For the first time, Australian law would formally distinguish between a “controller” (the organisation that decides why and how personal information is handled) and a “processor” (one that handles it on the controller’s behalf). A processor acting within documented written instructions would be exempt from the APPs other than APP 1 (open and transparent management) and APP 11 (security), and its acts would be treated as the controller’s. A processor that steps outside those instructions would be directly liable.

This mirrors the European model and is broadly good news for businesses that use outsourced providers, including managed IT providers like us, because it clarifies who is responsible for what. The catch is the phrase “documented written instructions”. To get the benefit, your contracts with your IT provider, your payroll bureau, your cloud software vendors and your marketing agency will need to state what they are permitted to do with the personal information you give them. Most SMB supplier agreements do not.

What this means for your business

Pull out your current contracts with anyone who touches customer, patient, guest, member or donor data. If they do not contain data-handling terms, they will need them. This is also a useful moment to check whether those suppliers hold data offshore, whether they have their own breach notification commitments to you (with a timeframe that lets you meet your 72 hours), and whether they can actually produce access logs on request.

What is not in the draft

Two things are worth stating plainly because the opposite is being widely reported.

The small business exemption stays. The exposure draft does not propose to repeal the exemption for businesses with annual turnover of $3 million or less, and it does not repeal the employee records exemption. Colin Biggers & Paisley makes the point directly: entities planning on the basis that these will be removed should treat that as stated government policy, not proposed law. We have seen several articles from IT and legal marketing sites asserting that the $3 million exemption ends on 10 December 2026. That date is the commencement of the tranche 1 automated decision-making rules, which is a different thing entirely. If you have been told the exemption is gone, the source is confused.

Smart glasses and wearables are not specifically regulated. The consultation paper acknowledges community concern about devices that can record discreetly, but it does not propose banning them, and it confirms that individuals acting in a personal capacity remain outside the Privacy Act. Businesses that collect personal information through wearables, however, are covered by the ordinary rules, including the consent requirement for biometric templates.

The right to erasure is also far narrower than the headlines suggest. It would apply only to large digital platforms covered by the Online Safety Act 2021 that have $500 million or more in gross revenue or 2.5 million or more average monthly Australian end users. Banks, telcos, retailers, data brokers and every SMB fall outside it.

Who is caught: professional services, hospitality and not-for-profits

Professional services

This is the group for which the draft matters most, and the reason is a change that has already happened. As Helios Salinger explained in March 2026, from 1 July 2026 the Anti-Money Laundering and Counter-Terrorism Financing Act extends to lawyers, conveyancers, accountants, real estate professionals and dealers in high-value goods. Reporting entities under that Act are excluded from the small business exemption regardless of turnover. The OAIC estimated the change would bring more than 100,000 small businesses under the Privacy Act for the first time. Those firms have now been fully regulated for just over two months, many without knowing it, and every proposal in this draft will apply to them. The OAIC’s own figures show legal, accounting and management services reported 81 breaches in 2025 before that expansion took effect.

The nature of the data makes it worse. A conveyancer holds identity documents, bank details and contract prices. An accountant holds tax file numbers, income and family structures. A financial planner holds everything. These are exactly the records that meet the “serious harm” threshold, which means almost any unauthorised access is a notifiable breach with a 72-hour clock.

Hospitality

Venues, hotels and hospitality groups above the $3 million threshold are already regulated, and the draft hits them in three places: the fair and reasonable test on guest data collection (why do you need a licence scan for a table booking?); precise geolocation data if your app or Wi-Fi tracks movement; and third-party processors, because almost every venue runs its booking, loyalty, POS and Wi-Fi through outside providers. The Quest breach earlier this year came through a supplier. Under the draft, your contracts with those suppliers need documented instructions and your breach plan needs to assume the incident will start somewhere you do not control.

Not-for-profits

Charities and NFPs with turnover above $3 million are regulated now, and those providing health services are regulated at any size. Donor databases, beneficiary case notes and volunteer records are all personal information, and beneficiary data in particular is often sensitive information (health, disability, financial hardship). The draft’s emphasis on retention, destruction and the best interests of children will be felt hardest here, because NFPs tend to keep records for a long time and often work with young people. We wrote about the current obligations in Protecting Beneficiary Data: What Australian NFPs Must Know Under the Privacy Act; the draft raises the bar on every point in that article.

The Central West and Northern Beaches angle

We support a lot of firms in Orange, Bathurst and Dubbo, and the July AML/CTF change has been the single most common privacy question from that region this year. The reason is structural. Regional professional services firms are more likely to sit under the $3 million threshold, so many have never had to think about the Privacy Act at all. They also tend to run older, on-premises practice management systems, have a smaller pool of local IT support, and rely on a handful of long-serving staff who hold most of the process knowledge in their heads. None of that is a criticism; it is simply the environment. It does mean that a 72-hour notification deadline is a bigger lift for a three-partner conveyancing practice in Bathurst than for a national firm with a security team, because the practice has to build the logging, the plan and the supplier relationships from scratch.

The practical advice for regional firms is to sequence the work. Get Microsoft 365 auditing and multi-factor authentication right first, because they cost nothing beyond time and cover the most likely breach scenario (a compromised mailbox). Then write the incident plan, including who you call and what their after-hours number is. Then do the data inventory and retention clean-up over the following quarter. Trying to do all of it at once, with limited local IT capacity, is how nothing gets done.

On the Northern Beaches, the picture is different. Brookvale, Dee Why and Manly have a dense cluster of hospitality venues and allied health practices, and the issue there is data collected through third parties: booking platforms, loyalty apps, guest Wi-Fi, online intake forms. Those businesses generally have modern cloud systems, so the logging problem is smaller. The exposure is in supplier contracts and in over-collection. A venue that scans a driver’s licence for a Friday-night booking is holding a document it does not need, through a supplier whose data-handling terms it has probably never read. The draft’s fair and reasonable test and processor provisions are aimed squarely at that arrangement.

Action table: what to do in the next 90 days

Nothing in the draft is law yet, and the consultation closes on 18 September 2026. But every item below is worth doing regardless, because each one either reduces the chance of a notifiable breach or makes one survivable. The table is ordered by the sequence we recommend.

Priority Action Why it matters under the draft Bill Owner
1 Confirm whether the Privacy Act applies to you now. Check turnover against the $3 million threshold, and check whether you became an AML/CTF reporting entity on 1 July 2026 or provide health services. If you are covered, every proposal applies. If you are not, the draft does not change that, despite what you may have read. Principal / CFO
2 Enable unified audit logging and mailbox auditing across Microsoft 365, and confirm retention is long enough to cover a breach discovered months later. The 72-hour statement has to say what was accessed. Without logs, you cannot. IT provider
3 Enforce phishing-resistant MFA on every account, including shared mailboxes and service accounts. Compromised credentials remain the most common cause of the breaches we see and the OAIC reports. IT provider
4 Write or update a one-page incident response plan: who decides, who to call (after hours), what the first six hours look like, and a template notification statement. 72 hours from awareness leaves no time to work out roles during the incident. Principal + IT provider
5 Inventory every point where personal information is collected and every system where it is stored, including exports, backups and AI-generated fields. The fair and reasonable test and the wider definitions both depend on knowing what you hold and why. Operations manager
6 Remove fields you cannot justify from forms, booking systems and intake questionnaires. Data minimisation is a legislated factor. Less data is also less to lose. Operations manager
7 Set a written retention schedule and apply it technically (Purview retention policies, file server clean-up, backup expiry). The draft expects destruction, not indefinite de-identified storage, and evidence that the policy is working. Principal + IT provider
8 Review consent mechanisms: remove pre-ticked boxes, unbundle marketing consent, and plan to refresh consents older than a few years. Consent must be voluntary, informed, current, specific and unambiguous. Marketing / admin
9 Add data-handling clauses to supplier contracts: documented processing instructions, breach notification to you within 24 hours, log access on request, data location. Processor protections only apply where instructions are documented. Your 72 hours starts even if the breach is at a supplier. Principal / legal
10 Consider a short submission to the consultation by 18 September 2026, particularly on transition periods. The draft is silent on a grace period. Small businesses have the most to gain from asking for one. Principal

Our view

We think three things about this draft.

The 72-hour deadline will pass largely as drafted. It aligns with four other Australian regimes and with GDPR, the regulator has publicly said breach notifications are at a record high, and public concern is at 82 per cent. There is no constituency arguing for a longer window. Businesses should treat it as settled and build for it.

The fair and reasonable test will be argued over, but the direction will not change. Larger businesses will push for narrower factors and a clearer safe harbour for consent. Some of that will succeed. But the principle that you must be able to justify what you collect, not just get a tick for it, has been government policy since the 2023 review response and will be in the final Bill in some form.

The gap between the businesses that can comply and those that cannot is almost entirely a logging and planning gap, not a legal one. A firm with audit logs, MFA, a retention policy and a written incident plan will find the 72-hour rule demanding but manageable. A firm without them will find it impossible, and will be writing to the regulator to explain why. The difference between the two is a few weeks of IT work that also happens to be the same work that prevents most breaches in the first place. That is the case for starting now rather than waiting for Royal Assent.

If you would like a straight answer on where your business sits, we offer a fixed-scope privacy readiness review covering Microsoft 365 audit and MFA configuration, a data inventory, a retention baseline and a one-page incident plan. Call 1300 425 548 or contact All IT Services and we will book a time with one of our Sydney, Central West, Brisbane or Melbourne teams.

Frequently asked questions

Is the Privacy Amendment (Personal Data Protection) Bill 2026 law yet?

No. It was released as an exposure draft for consultation on 31 August 2026, with submissions closing on 18 September 2026. It has not been introduced to Parliament and the provisions may change. Most commentators expect a Bill to be introduced after the consultation, with passage and commencement likely during 2027, although no dates have been announced.

Does the draft remove the $3 million small business exemption?

No. The exposure draft does not propose to repeal the small business exemption or the employee records exemption. However, the exemption does not apply to health service providers or to reporting entities under the AML/CTF Act, and from 1 July 2026 that Act extends to lawyers, conveyancers, accountants, real estate agents and dealers in high-value goods. Firms in those industries are covered by the Privacy Act regardless of turnover.

When does the 72-hour clock start under the proposed rules?

The clock starts when your organisation becomes aware that there are reasonable grounds to believe an eligible data breach has occurred. The existing 30-day window to assess a suspected breach remains. Once the assessment concludes that an eligible breach has occurred, you would have 72 hours to give the Information Commissioner a statement, and you can file an incomplete statement with a written explanation if full details are not yet available.

What is the biggest technical change we should make first?

Turn on unified audit logging and mailbox auditing in Microsoft 365, confirm the retention period covers a breach discovered months after it began, and enforce multi-factor authentication on every account. In the incidents we handle, the slowest part of a response is working out which records were accessed, and that is impossible without logs. These two changes cost nothing beyond time and address the most common breach scenario.

What penalties apply if we get it wrong?

Under the penalty tiers introduced in December 2024, a serious interference with privacy carries a maximum civil penalty for a company of the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover during the breach period. A non-serious interference carries up to $3.3 million, and a lower tier of up to $330,000 applies to specific administrative failures such as not having a compliant privacy policy. Under the draft, failing to file any statement within 72 hours could attract an infringement notice or a compliance notice.