---
title: "Australia’s 2026 Privacy Reform: What Customer-Data Teams Need to Do Now"
id: "96879"
type: "post"
slug: "australias-2026-privacy-reform-what-customer-data-teams-need-to-do-now"
published_at: "2026-09-18T05:15:28+00:00"
modified_at: "2026-09-21T01:41:59+00:00"
url: "https://tealium.com/blog/data-governance-privacy/australias-2026-privacy-reform-what-customer-data-teams-need-to-do-now/"
markdown_url: "https://tealium.com/blog/data-governance-privacy/australias-2026-privacy-reform-what-customer-data-teams-need-to-do-now.md"
excerpt: "The proposed changes go beyond consent banners. Here is what the 2026 exposure draft means for your data operations, and the practical steps to take while the legislation is finalised. Australia's privacy framework is facing its most significant overhaul in..."
taxonomy_category:
  - "Data Governance &amp; Privacy"
---

Data Governance & Privacy

# Australia’s 2026 Privacy Reform: What Customer-Data Teams Need to Do Now

Tim TillSeptember 17, 2026

## The proposed changes go beyond consent banners. Here is what the 2026 exposure draft means for your data operations, and the practical steps to take while the legislation is finalised.

Australia's privacy framework is facing its most significant overhaul in more than a decade. The Attorney-General's Department has released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, signalling a material shift in how customer data must be collected, used and governed. The legislation is not yet final, but organisations that wait for royal assent before acting will find themselves starting from a more difficult position.

*Before taking any steps, it’s very important that you liaise with your internal privacy and legal teams to align and ensure you are compliant.The guidance below is a practical starting point, not legal advice.*

## What is the "fair and reasonable" test, and why does it matter?

The most important change in the Privacy Amendment (Personal Data Protection) Bill 2026 is the introduction of a new standard: collection, use and disclosure of personal data must be fair, reasonable and proportionate.

Under Australia's current Privacy Act 1988, consent provides a primary line of defence. The proposed framework changes that. An organisation can have a consent banner in place and still fall short of the new standard if the data use is excessive, unexpected, or primarily self-serving. Consent becomes one control in a broader governance framework, not a standalone answer.  
  
For organisations that have built their data practices around consent as the primary mechanism, this is a structural shift, not a cosmetic update.

## What does the Privacy Amendment (Personal Data Protection) Bill 2026 change?

Several provisions matter directly to customer-data teams:  
  
**Broader definition of personal information.** Data that can identify someone when combined with other reasonably available information would fall within scope, not just data that identifies them directly. Device identifiers, behavioural patterns, browsing data and AI-generated inferences may all require the same governance discipline as directly identifying data.

**Stricter consent requirements.** Consent would need to be voluntary, informed, current, specific and unambiguous. Pre-ticked boxes and bundled permissions would not meet this standard.

**Targeted advertising clearly in scope.** The draft brings advertising directed to an individual, audience, segment or cohort within the direct-marketing framework, including online behavioural targeting. This reaches directly into how most digital campaigns are built and activated.

**Breach notification tightened.** Eligible data breaches would require notification to the Privacy Commissioner within a proposed 72-hour window.

**Deletion and de-identification obligations.** Organisations would need to consider destroying or de-identifying personal information they no longer need. Data without a clear current purpose becomes a liability.

**Right to erasure for large digital platforms.** A specific erasure regime would apply to large platforms, with clear obligations around how and when data must be removed.

One point worth emphasising: the proposed requirements would apply to existing customer lists, historical data relationships and partner feeds, not only to newly collected data. There is no assumption that current arrangements are grandfathered.

## Actions you can take now

The practical work falls into three areas. These are questions worth working through with your data, marketing, legal and technology teams before the legislation is finalised.

### 1. Audit your data collection and tag environment

- Do you have an up-to-date inventory of every tag, pixel and connector active across all your digital properties?
- Which companies are receiving data from those tags, and is any of that data being transmitted overseas?
- What data is being collected directly, and what is being inferred from behavioural or event signals?
- Can you minimise the data collected to what is genuinely required for each use case?

### 2. Review your consent management framework

- Are you capturing consent across every channel where personal data is collected?
- Does consent meet the proposed standard: voluntary, informed, current, specific and unambiguous?
- Can customers easily opt out, and can they change their preferences at any time?
- Are your tags and connectors automatically enabled or suppressed based on consent status?
- When a preference changes, does that signal propagate consistently across every downstream platform and activation path?

### 3. Map your vendor and partner data flows

- Do you have a clear record of which vendors and platforms receive customer data, for what purpose, and under what terms?
- Which relationships are processor-only, and which involve vendors who may retain, enrich or reuse data beyond your written instructions?
- Can you retrieve, delete or de-identify the relevant data across every system in your environment if a customer requests it?
- Are your existing partner permissions and customer lists defensible under the proposed fair-and-reasonable standard?

## Tealium can help you prepare for the privacy reforms in several way

Tealium helps organisations build the governed data foundation these questions require, alongside the consent-management, warehouse and activation tools already in place.

**Data collection with governance built in.** Tealium captures first-party event data across web, mobile, server-side and API sources through a single governed layer. Every collection point can be configured to respect consent status from the point of capture, so the data flowing downstream reflects the customer's actual preferences.

**Consent propagation across activation.** When a customer changes their preferences, that signal needs to reach every downstream platform, not just the consent banner that captured it. Tealium connects consent status to activation decisions, so suppression is consistent rather than manual and ad hoc.

**Full visibility of data flows.** Tealium maps data from source through to every downstream destination, with the consent signal and purpose attached. That gives marketing, data and security teams a shared view of what data exists, where it has gone, and what permissions apply.

**Vendor relationship classification.** With over 1,300 connectors, Tealium helps organisations classify outbound connections by data-use type, supporting the review of which vendor relationships are processor-only and which may require closer scrutiny under the proposed framework.

Across all of this, the aim is the same: give marketing, data and security teams a single, governed view of what data exists, what permissions apply, and where it has gone, so that compliance can be controlled rather than just assumed.

## Don’t Wait - Take Control Today

To get practical, independent guidance on where to start, join **Chris Brinkworth, Director at Civic Data, and Tim Till, RVP Field Engineering & Ecosystem Development APJ** at Tealium, for an upcoming live fireside chat covering **what the proposed reforms mean in practice and the specific steps your team can take to prepare.**

**8 October, 11:00am AEST | Register [here](https://tealium.com/event/australias-2026-privacy-reform-what-customer-data-teams-need-to-do-now/)**

*This article is based on publicly available information about the proposed Privacy Amendment (Personal Data Protection) Bill 2026 exposure draft and should not be treated as legal advice. The proposals remain subject to consultation and may change before legislation is introduced or enacted.*

## Related Content [Powered by Tealium](https://tealium.com/blog/teal-on-teal/how-we-used-our-own-stack-to-personalize-tealium-com/?db_surface=web&db_slot=0)

### Loading

Learn more

### Loading

Learn more

### Loading

Learn more

### Submitted! Thank you!
