Skip to content
CyberByteSecurity
ArticlePrivacy reform 7 min read

Privacy Act reform: what's changing for 2026 and what to do

Written by Muhammad Gulzar, Founder & Principal Security Consultant

Principal Security Consultant · Enterprise & government experience · 15+ years across IT, cloud & cyber

Australia's Privacy Act reforms are landing in stages. A clear summary of what's already in force, what the second tranche is expected to bring, and the practical steps to get ready.

Australia's privacy law is in the middle of its biggest overhaul in decades, and it's landing in stages. The first tranche — the Privacy and Other Legislation Amendment Act 2024 — is largely in force, and a second, broader tranche is being progressed through 2026. Here's what has changed, what's coming, and the practical steps that get you ready.

What's already in force

  • A statutory tort for serious invasions of privacy (in effect since 2025) — individuals can now sue for serious breaches.
  • Stronger enforcement powers and a tiered penalty regime for the regulator (the OAIC).
  • New privacy-policy transparency requirements for certain automated decisions by APP entities commence on 10 December 2026 — so the time to prepare is now. Information current as at 24 July 2026.

What the second tranche is expected to bring

  • A 'fair and reasonable' test governing how personal information is collected and used.
  • Possible removal of the small-business and employee-records exemptions, bringing many more organisations fully into scope.
  • GDPR-style individual rights — such as a right to erasure — and a broader definition of 'personal information'.

What to do now

You don't need to wait for the final detail. Map what personal information you hold and where it lives; update your privacy policy and consent flows; review any automated decisions that materially affect people; and bring your security baseline (MFA, access control, tested backups) to a defensible standard — because taking 'reasonable steps' to protect personal information is already enforceable. Doing this now turns a looming compliance deadline into a routine update rather than a fire drill.

Request a scoping call

Talk to a senior advisor — not a salesperson.

A 20-minute scoping call: tell us what's prompting this, and we'll tell you the smallest credible engagement that solves it. Fixed price for the agreed scope, no obligation.

  • 15+ years across IT, cloud & cyber
  • Enterprise & government experience
  • Principal consultant-led delivery
  • Independent & Australian-owned
  • Melbourne-based · Australia-wide