Australian Privacy Reforms: ‘Fair and Reasonable’ – But Not Necessarily ‘Easy
Updated: 2 hours ago

Australian businesses (or at least the privacy community) are all a flutter about Tranche 2 of the reforms to the Privacy Act 1988 (Cth), so I will be chewing over the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 for the next few days.
For me, one of the most important elements of the Bill is the ‘fair and reasonable’ test, which I consider the cornerstone of the current reforms.
The current requirement under Australian Privacy Principle 3 is that APP entities may only collect personal information that is “reasonably necessary for, or directly related to, one or more of the entity’s functions or activities”. This is quite a broad authorisation – but it is focused on the entity’s needs, rather than the individual’s choices, rights or wellbeing.
The Bill proposes that APP 3 require that collection, use or disclosure of personal information be not only lawful, but “fair and reasonable in the circumstances”. What is fair and reasonable will depend on several factors including:
Reasonable expectations: Whether a reasonable person would expect the collection, use or disclosure in the circumstances.
Functions and activities: Whether the collection, use or disclosure relates to the entity’s functions or activities – as in the current APP 3.
Transparency: Whether the APP entity has been transparent about collection, use or disclosure.
Minimisation and privacy by design: Whether the APP entity could achieve the purpose of the collection, use or disclosure with less personal information, or non-personal information.
Genuine choice: Whether the individual is given an actual, genuine choice about how their personal information is used.
Impacts: The impacts on the privacy of the individual, any risk of harm, and whether that risk is proportionate to any benefit to the individual.
Best interests (of the child): If the individual is a child, their best interests should be a primary consideration.
Per the Consultation Paper, no single factor will determine whether a practice is ‘fair and reasonable’ – it will be a holistic determination.
Needless to say, if passed, this test will require a signficant reshaping of how personal information is handled by government agencies and private sector businesses in Australia. A few consequences stand out:
Handling practices must be considered, deliberate and thought through: It’s long been the complaint of the privacy officer - “you can’t collect it just in case”. The revised APP 3 underlines this point – if you are collecting and handling PI, you need to have a lawful and specific purpose in mind, and that purpose needs to be fair and reasonable to boot. However, the big data and now large model paradigms of the last 10 years have promoted bad data hygiene, resulting in rampant overcollection and overretention. Further, the Bill proposes to expand the definition of personal information – from information ’about’ an individual, to information that ‘relates to’ an individual. Data-driven methodologies may be put in an uncomfortable position – where is the data coming from? Are users aware? Entities engaging in digital and online advertising, data broking, and analysis-driven activities – including the training of AI processes in the form of large language and machine learning models - will need to consider their positions carefully.
Privacy Policies – and privacy messaging in general - will need to be rethought: You cannot create reasonable expectation without transparency – so we need to ensure that public facing messaging is accurately communicating why we are handling personal information. However, we also need to ensure that users consume and are able to consume this messaging. We can’t just throw a 5000 word policy at people and claim we have informed them – we already know that the vast majority of users won’t read that policy, and many users would be unable to understand it anyway. We need to be smarter about providing privacy messaging in consumable ways, and at appropriate times – such as short form policies, policy summaries, plain language, translations and just-in-time messaging. This isn’t a new issue – privacy professionals have been banging on about this for years, but it may become far more urgent.
Bundled consents will need to be identified and remediated: You cannot give genuine choice if you are forcing users to agree to multiple purposes in a single action. This is currently common practice – if you want to use our service, you accept that we will also do another 20 things with your data. That will have to change – we will have to provide a lot more granular functionality to enable users to make genuine choices about their data. Note that the Bill also amends the definition of consent - "voluntary, informed, current, specific and unambiguous" - so bundled consents would likely be invalid in any case.
Defensibility: How can we demonstrate that certain handling practices are ‘fair and reasonable’? Not just that we were transparent about need for our functions and activities, but that we considered the impacts on the individuals, risks, compliance, and minimisation and alternative methods. This sounds suspiciously like our old friend, the Privacy Impact Assessment. This of course, is not the only way to ensure defensibility. But fortune favours the prepared. It would be very helpful to those organisations concerned about regulatory scrutiny to assess key processes, functions, and services, and document compliance and defensible postures.
So now what?
Australia is proposing a significant shift in its privacy regime, explicitly aimed at dealing with the new wave of technology including data collection, survelliance, machine learning, LLMs and automation.
The Attorney General’s Department is still accepting submissions until 18 September 2026. If you feel like your business is going to be adversely affected, it’s time to start typing.
In my view, most of what is proposed in the fair and reasonable test was already considered best practice, and is in line with the regulator’s current and long-standing expectations. The difference is, the expansion of the defintion of personal information will capture activities currently operating in the 'wild west' of AI and data analysis, and there will now be greater legislative, and presumably enforcement, weight behind it. Big tech and heavy data users are likely to find themselves in the regulator's sights.
There is significant political capital being applied to get this legislation passed (and not before time, considering it’s been in the works since 2020). Therefore, my advice is - don’t wait. Start getting your collection practices, privacy policies and consent flows into defensible shape now, rather than waiting for the Bill to pass. Get the assessments rolling on your key processes and services, and make the changes to improve privacy outcomes.
If you’re concerned on how to approach the pending reforms, please reach out to us.

