Two Overdue Changes, and a Boundary Drawn in the Wrong Place
The Attorney-General’s Department released the Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026 on 31 August. iTnews led with the 72-hour breach reporting deadline, and it is the change most organisations will feel first. Alongside it sits a right to erasure, a single fair and reasonable test replacing a tangle of collection, use and disclosure obligations, and roughly forty proposals in total.
Both headline changes are the right direction. “As soon as practicable” was never a deadline, and Australians have had no mechanism to compel destruction of information held about them. Neither is a small piece of work to implement, and neither should be argued against.
The problem is not what the reform does. It is where it stops.
The Erasure Right Is Scoped by Service Type, Not by Risk
The right to erasure binds only a “large digital platform”. To qualify, an organisation must provide a social media service, relevant electronic service or designated internet service as defined in the Online Safety Act 2021, and then clear either a $500 million group gross revenue test or an average of 2.5 million monthly Australian end users.
Read that in order. The size threshold is the second test. The first is whether you operate a service that the Online Safety Act recognises. A credit reporting body does not. Neither does a data broker, a bank, a telco or a retailer. They are not carved out by an exemption clause — there is no clause. They sit outside the definition before the size test is ever applied.
The consequence is worth stating plainly. Optus, Medibank and Latitude are the breaches that produced the political appetite for this reform. None of the three would be subject to the erasure right it introduces.
There is a regulation-making power to prescribe additional platforms, and the consultation paper is explicit about its purpose: to capture services that “collect significant amounts of personal information and present heightened privacy risks”. That is the correct test, and it is immediately narrowed by the next sentence — a platform may only be prescribed if it falls within the Online Safety Act definitions. The escape hatch opens into the same room. A data broker assembling a file on every adult in the country cannot be brought in by regulation at any level of risk, because it does not operate the right kind of service.
Whatever the drafting rationale, the effect is that the reform locates privacy risk in a category of business rather than in a category of data. The information a credit reporting body holds is more sensitive, harder to change and more damaging when exposed than most of what sits on a social platform. It is the holding that creates the exposure, not the industry classification of the holder.
The Same Pattern, Twice More
The 2023 Privacy Act Review identified two exemptions as the largest gaps in the Act’s coverage: the small business exemption for operators under $3 million turnover, and the employee records exemption.
Neither appears in this package. Across roughly forty proposals — twenty-five uplifting protections, five clarifying obligations, four simplifying them, seven improving the regulator — the two structural exclusions go untouched. Every Australian’s employment file remains outside the Act. A very large number of organisations handling customer data remain outside it entirely, on a turnover threshold that has not moved since 2001.
Three years after the Review, the pattern is consistent enough to plan around: obligations are being strengthened for entities already inside the perimeter, and the perimeter is not moving. The reasonable inference is that it is not going to move soon.
The 72-Hour Clock Starts When You Decide It Starts
The deadline is real, and it is not the number boards should be focused on.
The obligation is to notify the Commissioner within 72 hours of becoming aware of reasonable grounds to believe that an eligible data breach has occurred. The existing 30-day window to assess a suspected breach survives unchanged; the consultation paper says so directly. Two stages remain, and the hard limit attaches to the second one.
That means the clock is started by a judgement call your organisation makes internally. Somebody decides that suspicion has become belief. Until that decision is made, the 72 hours has not begun, and the assessment period is the one running.
Every organisation should therefore be able to answer three questions before this commences. Who holds the authority to conclude that reasonable grounds to believe exist? What evidence do they need in front of them to make that call? Where is the decision and its timing recorded?
If those answers do not exist, the failure mode is predictable and it is not a missed deadline. It is a regulator asking, after the fact, why belief was reached on day nineteen when the material supporting it was available on day three. A 72-hour obligation hung off an undocumented internal judgement is an invitation to reconstruct that judgement in hindsight, and hindsight is not a friendly forum.
Where a complete statement cannot be assembled in time, an incomplete one may be filed with written notice of what is missing and why. Filing nothing at all attracts an infringement or compliance notice. In practice the reform rewards organisations that can scope an incident quickly and penalises those that cannot — which is a capability question, not a legal one.
The Obligation That Does Apply Across the Board
Buried in the data security schedule is the change with the widest reach, and it has drawn almost no coverage.
The Bill would require every entity to take reasonable steps to implement practices, procedures and systems that enable it to respond effectively to data breaches. The consultation paper names the compliance measure explicitly: maintaining, regularly reviewing and testing a breach response plan. Failure to comply is an interference with the privacy of an individual in its own right.
A separate obligation requires reasonable steps to mitigate harm from the moment there are grounds to suspect a breach, and it is ongoing as understanding of the incident develops.
Read those together and the effect is that untested response capability becomes independently enforceable. Not enforceable when a breach is mishandled — enforceable because the capability was never built. That applies to every APP entity, with no service-category gate and no size threshold above the existing small business line.
It is, in other words, the across-the-board obligation. It is simply not the one making headlines.
What to Do With the Next Two Weeks
Submissions close on 18 September, and concise ones are encouraged. If your organisation holds sensitive personal information but does not operate an Online Safety Act service, you have a direct interest in whether the erasure right is scoped by risk or by category, and a short submission saying so is worth more than a long one filed later.
The commencement table in the exposure draft is blank. There is no date to plan against, which is the usual argument for waiting. It is a poor one here. Documented breach-decision authority and a tested response plan are the two things the reform will require of everyone regardless of where the perimeter finally lands, and neither depends on the drafting being settled.
The scope debate is worth having. Losing it changes very little about what you should already be able to do.