All insights
Industry newsSep 01, 2026Source: Australian Attorney-General's Department

Australia proposes privacy law reforms for AI and digital data

An Australian privacy team maps AI data collection, consent, and erasure evidence

Australia released draft legislation on August 31, 2026 for a second major stage of Privacy Act reform. The proposal would add a fair and reasonable test for handling personal information, strengthen consent, create a right to erasure in defined circumstances, and restrict trading in personal information without clear permission. The government explicitly links the package to risks from artificial intelligence and data-intensive devices such as smart glasses and connected vehicles.

The package is open for consultation until September 18. It is not enacted law. That status is central to the story: organizations do not yet have a new legal duty under this draft, but they can now see the direction and the evidence burden the government is considering.

What the Australian government proposed

The Attorney-General's media release identifies four headline measures:

The consultation package is broader than AI. It addresses privacy law across digital services and technologies. AI matters because many systems collect, infer, combine, or act on personal information at scale. The government cites connected vehicles and smart glasses as examples of technology that can continuously collect and process information.

The proposal follows the 2024 reform tranche. Existing automated decision-making transparency changes from that earlier law are scheduled to apply from December 10, 2026. The new exposure draft is a separate consultation and should not be described as already adding those duties.

Why the fair and reasonable test matters for AI systems

Consent alone can be a weak control when a service relies on a long privacy notice or bundles unrelated purposes into one choice. A fair and reasonable test would require a more objective assessment of the collection, use, and disclosure of personal information.

IAPP analysis says the draft would direct organizations to consider sensitivity, reasonable expectations, foreseeable harm, and whether the data practice is proportionate to its purpose. For an AI system, that assessment should cover the full operating chain:

Control questionEvidence to retain
What personal information enters the system?data inventory, source, classification, and collection context
What does the model infer or create?output categories, evaluation results, and known limitations
Which purpose authorizes the use?purpose statement, legal analysis, and product decision
Who receives the data or output?processors, tools, recipients, and transfer records
Can the use change over time?model version, prompt or policy change, and review trigger
Can a person exercise a right?request workflow, identity check, exceptions, and completion evidence

This is especially important for agents. An agent may retrieve personal information, combine it with other sources, decide what action to take, and send a result to another system. A privacy record that describes only the model misses the tools, connected data, and external effects.

What teams can do during consultation

Organizations do not need to pretend the draft is final to prepare well. A practical readiness review can remain explicitly provisional:

  1. Inventory AI data paths. Record models, agents, repositories, connected tools, personal-information categories, recipients, and owners.
  2. Separate collection from inference. Document what a person supplied and what the system inferred, scored, or generated.
  3. Test reasonable expectations. Ask whether a person would expect this specific use in this context, not merely whether a notice mentions AI.
  4. Link consent to purpose. Retain the exact notice, choice, scope, time, and withdrawal route where consent is relied upon.
  5. Design deletion workflows. Identify copies, derived records, model inputs, logs, backups, processors, and lawful exceptions.
  6. Version the assessment. Reopen it when data sources, models, tools, purposes, or recipient groups change.

Maetra's AI system inventory guidance helps connect systems to owners and data access. The AI compliance evidence checklist provides a structure for requirements, controls, evidence, and freshness.

What remains uncertain

The consultation may change before legislation reaches Parliament. Final scope, definitions, exemptions, enforcement details, and transition periods cannot be inferred from the media release alone. The government is asking regulated entities, civil society, academics, and other stakeholders how the measures should work in practice.

The proposed right to erasure is also not a promise that every record must always be deleted. Any final duty would depend on the enacted text, the organizations and data within scope, and any exceptions. The same caution applies to consent and data-trading restrictions.

Maetra analysis

The operational signal is stronger than a generic call for better privacy. The draft points toward evidence that can survive objective review: a known data path, a defined purpose, a proportionate use, an accountable owner, and a working route for individual rights.

For AI agents, that record should include capabilities and effects. Teams need to know which agent accessed which data, under what task, which tool it called, what left the system, and which policy version governed the action. That evidence supports privacy review now and makes later changes to law easier to map without reconstructing the system from scratch.

Sources

Australiaprivacy reformAI governancepersonal data
Australia proposes privacy law reforms for AI and digital data | Maetra Insights