Key implications and next steps 21 min read
On 31 August, the Attorney-General's Department released a draft of the Privacy Amendment (Personal Data Protection) Bill 2026 (Draft Bill), along with a consultation paper (Consultation Paper).
If passed in its current form, the Draft Bill would be the most significant overhaul of Australia's privacy framework since the Australian Privacy Principles (APPs) were introduced in 2014.
Entities would need to fundamentally rethink how they collect, use, hold and disclose information. The operational and compliance impacts will be significant.
Entities have until Friday 18 September 2026 to make submissions on the Draft Bill. The Government has indicated it intends to introduce legislation to Parliament before the end of this year.
On This Page
- Key takeaways
- Considerations for consultation and next steps
- How did we get here?
- Core concepts and definitions – some amended, some new
- The collection, use and disclosure of personal information
- Updated direct marketing obligations
- Data breaches and security
- Data access and erasure
- Human research exception
- Introduction of GDPR concepts – controllers and processors
- The reforms left on the table (again)
- OAIC Powers and Efficiency
- Contact the team
Key takeaways
- The Draft Bill proposes to fundamentally reshape existing privacy law. The most critical changes are:
- updating definitions that impact the scope of the Privacy Act 1988 (Cth) (Privacy Act) including to broaden the definition of personal information to information that 'relates to' an individual, as well as capturing individuation (where an individual will be treated as being reasonably identifiable, even if the individual's name or legal identity is not known). This will vastly expand the scope of data held by businesses which will need to be treated as personal information, and will significantly impact programmatic advertising activities and data analytics;
- imposing a broad 'fair and reasonable' test in respect of the collection, use and disclosure of personal information, which will impose significant initial and ongoing operationalisation challenges, as well as introduce ambiguity for personal information use cases;
- materially amending direct marketing-related obligations which will have required a fundamental rethink of ad supported services;
- introducing strict new rules on 'trading', which may have unintended consequences; and
- updating data breach obligations, including a 72-hour notification timeframe and broad mitigation requirements.
While some of these are long expected, others are novel.
- Operational change and compliance costs will be significant. Businesses will need to undertake privacy uplift programs that involve:
- reviewing the impact of expanded personal-information definitions (including identifying existing datasets that may now be categorised as personal information and fall under the regulatory net), mapping those data assets, conducting privacy impact assessments and reconsidering existing information-handling practices;
- reviewing and updating existing consent, notice and disclosure workflows, documentation and processes;
- operational changes to direct marketing activities (particularly online targeted advertising);
- identifying and uplifting any existing arrangements that fall within the new definition of 'trading' of personal information;
- updating incident response plans and playbooks for new 72-hour data breach notification timeframes and additional mitigation requirements;
- reviewing and updating record retention and destruction processes;
- processes for erasure request, verification and assessment for entities subject to the new 'large digital platforms' erasure right; and
- reviewing and uplifting existing contractual arrangements with suppliers and third parties that involve the use and disclosure of personal information, to account for the new requirements as well as the new processor/controller liability position.
- Although the reforms are in draft, the long road to get here and the short consultation period suggest the Government intends to proceed in this direction. Escalation of fundamental concerns – particularly regarding unintended consequences, cost, operational impacts and implementation timeframes – will be critical.
Considerations for consultation and next steps
- Effective date and implementation timeframe: Neither the Draft Bill nor the Consultation Paper specifies a timeframe for implementation. Given the significant changes required, an implementation period of at least two years should be provided, similar to when the APPs and GDPR were first introduced.
- OAIC guidance: Guidance from the Office of the Australian Information Commissioner (OAIC) will be critical in helping entities enact the changes, particularly given the ambiguous nature of some obligations. Key areas where further clarity will be needed include novel areas such as:
- the ‘fair and reasonable’ test (new APP 3)
- the scope and meaning of ‘individuation’ and expanded personal information definitions
- the boundaries between persuasive marketing and ‘dark patterns’ in the context of ‘genuine choice’
- the expectations for new 'controller/processor' contractual arrangements'
- Guidance should allow significant lead time: Given the OAIC's stretched resources and existing workload (eg, guidance has still not been released for the incoming ADM requirements under APPs 1.7-1.9), any delay in guidance could complicate implementation.
- Cost of implementation and regulatory simplicity: We have not yet seen a regulatory impact assessment for the Draft Bill. Its changes will require broad, economy-wide implementation costs to review and update existing practices, policies and documentation. It is unclear to what degree productivity considerations were taken into account.
- Children's Online Privacy Code: The OAIC must publish the Children's Online Privacy Code (Children's Code) by 10 December 2026. The draft published earlier this year was based on the existing APPs, and it will require redrafting to align with the new framework. It is unclear whether the parallel implications have been considered, and it seems unlikely that the deadline for issuing the Children's Code can be delayed.
How did we get here?
The Attorney-General's Privacy Act Review Report (2023 Report), published in February 2023 following years of consultation, put forward 116 proposals to reform Australia’s privacy framework.
The Government's first step was the introduction of the 'Tranche 1' reforms, contained in the Privacy and Other Legislation Amendment Act 2024. Tranche 1 dealt with 23 of the proposals, including a statutory tort for serious invasions of privacy, a tiered penalty regime, doxxing offences, and the groundwork for a Children's Online Privacy Code.
Tranche 2 was intended to address the remaining proposals the Government had agreed to implement. The Draft Bill encompasses many, but not all, of the proposed Tranche 2 reforms.
Wearables and AI reform, or wholesale economy reform?
The Consultation Paper and Draft Bill were accompanied by media reports and commentary that the proposals would ‘help tackle emerging risks from new technologies, including artificial intelligence and wearable devices such as smart glasses'.
However, the reforms mostly appear general in application rather than specifically directed at these risks. This is unsurprising given the preference for technology-neutral regulation. Nonetheless, the reforms will be relevant for the use of personal information in AI implementation and training contexts. The focus on wearable technology seems more tenuous, particularly given jurisdictional challenges under the Privacy Act, and will apply only to the extent the statutory tort applies. The Consultation Paper seeks feedback on the adequacy of these measures in addressing risks from wearable technology.
Core concepts and definitions – some amended, some new
The Draft Bill updates core privacy concepts and introduces definitions not previously included in the Privacy Act. Many of these will materially impact the scope of obligations under the Privacy Act.
| Definition | Key changes | Implications |
|---|---|---|
|
Personal information (s 6FD) |
Related to: Expanded scope would apply to information that 'relates to' an individual, not 'about' an individual. Individuation: A 'note' in the definition flags that an individual will be reasonably identifiable 'even if the individual’s name or legal identity is not known’, including where they can be 'recognised, singled out or otherwise dealt with as a distinct individual in practice'. It also includes a non-exhaustive list of examples (eg, location data, behavioural patterns or preferences, pseudonyms) which 'may' be personal information. |
Related to: This change was anticipated but is nonetheless significant. It effectively overturns a long maintained distinction, requiring a person to be the subject of the information to be covered by the Privacy Act. Individuation as personal information: This change codifies recent (and 'novel') determinations by the OAIC on Medmate and Monash IVF (see our Insight on these decisions), where 'individuation' through online tracking was determined to be 'personal information'. This will have broad consequences, including for data analytics, data sharing arrangements and online advertising. It will likely mean the majority of cookie, pixel or web tracking data is treated as personal information by default. The use of a 'note' to define the scope of what 'reasonably identifiable' means is an unusual approach, the rationale for which is unclear. |
|
Reasonably identifiable (s 6FF) |
Introduces a new standalone definition of 'reasonably identifiable' to include scenarios where an individual could be identified by combining the relevant information or opinion with other information or opinions that are 'reasonably available'. | This amendment codifies the 'mosaic effect' repeatedly referenced by the OAIC in its data breach reports and guidance, recognising that information that does not identify an individual in isolation may do so when combined with other reasonably available information. |
| Sensitive Information (s 6FE) |
New categories of sensitive information, including:
|
Entities that collect or analyse location data will now need to first obtain an individual's consent. In practice, entities will need to assess and update their data consent and notice architecture. This will particularly impact geolocation devices, including fleet monitoring, telematics and connected vehicle services. We would welcome further guidance or clarity in the context of location monitoring of employees (eg through fleet telematics), and whether the employee-records exemption applies in such a circumstance (particularly given uncertainty as to the application of this exemption to collection following historical Fair Work Commission decisions on this subject).1 |
| Collects (s 6AAA) |
The amendments clarify:
|
This change is also an implementation of the OAIC's determinations on Medmate and Monash IVF. All entities that handle information from which inferences may be drawn regarding a sensitive information attribute (such as health information, religion or criminal record) will need to assess whether this is a risk. Combined with the 'individuation' concept described above, this may have broader implications. The practical impact is that upfront consent will be required where sensitive information is inferred or may be intended to be inferred. The example provided in the Consultation Paper is that where a person has ordered a halal meal, the meal order is not sensitive information merely because the entity could use it to derive the person's religious beliefs. However, if the entity later uses the meal order to derive information about the person's religious beliefs to send marketing material about a religious festival, the entity is taken to collect the sensitive information when it first records the derived religious beliefs, or uses or discloses them (whichever occurs first). However, this distinction may be tricky to implement. Does a retailer selling maternity clothes to a consumer, and seeking to market to that consumer further maternity clothes, infer that the consumer is pregnant (and thus collect sensitive information)? |
| De-identified information (s 6FG) |
Clarifies that de-identification is determined 'at the particular time or in the circumstances'. |
This new definition codifies existing OAIC guidance that de-identification is not a 'set and forget' exercise. Re-identification risk will need to be actively monitored as external data sources and re-identification techniques evolve. |
| Consent (s 6AAB) | The amended definition incorporates the OAIC's existing guidance that consent must be voluntary, informed, current and specific, and introduces a fifth element that consent must be 'unambiguous'. |
Entities will need to carefully review their consent practices to ensure these elements are satisfied. The risk for entities that use bundled consent, pre-selected settings or pre-ticked boxes will significantly increase, given the commentary in the Consultation Paper. Consent and opt out pathways that make it challenging to opt out will also be at high risk. Helpfully, the Consultation Paper does acknowledge that consent may still be voluntary where it is required to access particular features of elements of a service. |
| Discloses (s 6(a)) | The amended definition makes clear that disclosure will occur where personal information is made accessible to another person or body, regardless of whether a level of control is retained by the entity. |
The Consultation Paper states that the mere transmission or storage of personal information, including overseas, will not constitute a disclosure unless the information is made 'accessible'. It is unclear whether this is intended to remove the prior distinction between a 'use' within effective control and a disclosure, which was an important feature of historical guidance and often relevant in the context of cloud storage. This is an important area to clarify in consultation, including the scope of 'made accessible' and whether 'storage' in a third-party service can occur without making information 'accessible'. |
The collection, use and disclosure of personal information
The Draft Bill represents a fundamental shift in how entities may collect, use and disclose personal information. APPs 3, 4 and 6 would be repealed and replaced.
Proposed amendment
All collection, use and disclosure of personal information will be subject to a new 'fair and reasonable in the circumstances' test. Whether an act is fair and reasonable will depend on a range of factors, including:
- what a 'reasonable person' would expect in the circumstances;
- the connection to the entity's functions or activities;
- whether the entity is transparent about the means and purposes of collection, use and disclosure;
- whether the purpose could be achieved by collecting, using and disclosing less information;
- whether the applicable individual is provided with a genuine choice;
- the impact on the individual's privacy, any risk of potential harm to the individual and whether it is proportionate to any benefits to the individual or the entity; and
- for children, best interests of the child as a primary consideration.
The Consultation Paper states that not all factors need to be satisfied for any particular act or practice; organisations must undertake a holistic assessment. No single factor is intended to be determinative.
Implications
- New test but ambiguous application: The new APP 3 test subsumes existing law and concepts (including primary purpose and ‘reasonable expectations') into a holistic assessment. While this may simplify matters by not layering a ‘fair and reasonable' factor over prior tests, the application will likely be ambiguous given the number of factors and the weight to be given to each in different circumstances. This will require significant regulatory guidance and may leave broad scope for interpretation.
- Data minimisation principles: This factor reflects reasoning in the Privacy Commissioner's determination in IRE/2Apply (currently under appeal to the Administrative Review Tribunal), which found that unnecessary collection was not reasonably necessary. This gives rise to a risk that a collection which is otherwise transparent, voluntary and related to an entity’s functions may still not be 'fair and reasonable' if the purpose could be achieved without the information.
- 'Genuine choice' and dark patterns: This is a new concept, distinct from consent. The guidance clarifies that the absence of a genuine choice will not automatically make a collection unfair or unreasonable. The Consultation Paper raises ‘dark patterns', which also featured in the IRE/2Apply In that decision, the Commissioner found online choice architecture was 'dark or deceptive' where it undermined individuals' choice and control through practices such as 'confirmshaming', biased framing and bundled consent (at [112] to [113]). The line between ordinary persuasive marketing and a 'dark pattern' remains unclear.
- Children's privacy: In addition to the Children's Online Privacy Code, the amendments propose a 'best interests' factor for all collection, use and disclosure of personal information involving children. While not determinative, this factor is intended to carry significant weight. Given the ongoing development of the Children's Online Privacy Code, it seems premature to include this factor at this stage.
- Wholesale review of privacy frameworks: All entities will need to reconsider their privacy frameworks, including collection notices and statements (see below), and should document assessments of their consideration of each factor. We anticipate the compliance burden will be high.
Proposed amendment
Collection of sensitive information is now addressed in new APP 4. Consent is still required (in accordance with the new definition), but applies in addition to the 'fair and reasonable' test in new APP 3, rather than as an alternative.
Current exceptions to the consent requirements are retained. There is also a new exception that applies where collection is 'strictly necessary' for an entity to deliver goods or services the individual has requested (with a higher threshold being required where the individual is a child). New APP 4.5 clarifies that collecting sensitive information for the purposes of direct marketing will never be strictly necessary.
Implications
All entities that collect sensitive information will need to assess their consent frameworks, and determine whether the collection is 'strictly necessary' to benefit from the exemption.
The characterisation of 'precise geolocation tracking data' as sensitive information will have particular impact under this new framework. While some services would likely fall within the 'strictly necessary' exception (eg, ridesharing and food delivery apps), others may encounter greater difficulty (eg, fleet management software).
Proposed amendment
New APP 4.2 prohibits entities from 'trading' personal information unless the individual has consented. 'Trade' is defined as disclosure of personal information for money or other consideration, or for purposes of direct marketing. Four categories of disclosure will not constitute a 'trade':
- where necessary to provide a product or service requested by the individual;
- where incidental to the sale, acquisition or transfer of a business or part of a business, provided the disclosure of personal information is not the substantial purpose of the transaction;
- to a 'processor' acting on behalf of a 'controller' and only in accordance with its documented instructions; and
- it is necessary to prevent, detect, investigate or remedy unlawful activity or wrongdoing of a serious nature 'involving fraud'.
Implications
This prohibition will directly impact various forms of online advertising. According to the Consultation Paper, disclosure for 'the purposes of direct marketing' must be interpreted broadly, including disclosures of cookies or pixels in programmatic advertising. Given the proposed 'individuation' changes, disclosure of website activity information in programmatic advertising will likely be considered 'trading'.
The carve-out from the 'trading' concept in the context of a sale of business is welcome, though substantial uncertainty will remain where customer-related information is core to an asset sale transaction.
The prohibition will also impact various data sharing practices between organisations (particularly in concert with the expanded definition of personal information).
The rationale for limiting serious misconduct exception to only serious misconduct 'involving fraud' is unclear, given the wide range of misconduct that may extend beyond fraud and that might reasonably be considered a basis to disclose information.
Proposed amendment
Several 'permitted general situations' (PGS) are added or amended under the Draft Bill (s 16A), including:
- broadening PGS 2 to cover 'wrongdoing' beyond just the internal activities; and
- amending PGS 4 and 5 to exclude disclosure to an overseas recipient in the context of a legal claim or confidential ADR process.
Implications
While the changes to PGS 2 are welcome, the Consultation Paper does not explain why the PGS 4 and 5 changes have been proposed. While there may be other bases for disclosure, this means that dealing with overseas court or ADR processes will not be a PGS, and may require domestic court processes when disclosure of personal information in civil cases is needed.
Proposed amendment
APP 5 has been simplified, removing prescriptive requirements and replacing them with an obligation to notify individuals of the collection of their personal information and the purposes for which it will be used or disclosed. Under new APP 5.3, this must be 'in clear and plain language', 'readily understandable', 'up-to-date' and 'concise’.
Implications
All collection notices will likely need to be reviewed and updated. This change is largely welcome, as it removes one of the most technical and least valuable compliance requirements under the existing APPs.
Updated direct marketing obligations
Proposed amendment
APP 7 would be overhauled, simplifying aspects of the prior framework and clarifying that:
- all direct marketing communications must also provide a simple means to opt out of such communications, and information on how to do so; and
- 'direct marketing' includes marketing conducted using personal information which identifies a person as either an individual or a member of a class.
New APP 7.5 outlines a regime enabling individuals to opt out of 'ad supported' services, meaning any service where advertising revenue from direct marketing is derived (with no monetary threshold). The opt out requirements for direct marketing communications for such services are modified, acknowledging that a different version or terms may apply, but an individual must be given a 'genuine choice' between service versions.
Implications
This change, alongside the proposed 'individuation' changes, will have a major impact on digital advertising for both suppliers and advertisers.
All entities will need to offer a means to opt out (including web and platform-based services). For web-based services without a user interface or platform setting, this will likely require ‘cookie banners' or similar mechanisms.
This new APP 7 removes the 'reasonably expect' exceptions in APPs 7.2 and 7.3, but any use or disclosure for direct marketing would still need to meet the 'fair and reasonable' test described above.
Entities will be required to reassess their approach to how they obtain direct marketing consent (and what options are offered to individuals). Collection notices and consent flows will also need to meet the new plain-language, concise, and up-to-date drafting requirements in New APP 7.4.
Data breaches and security
Proposed amendment
The notifiable data breach regime would be updated to introduce:
- mitigation and preparedness obligations in respect of all 'data breaches', whether or not they meet the threshold of an 'eligible data breach';
- a requirement to notify the OAIC of eligible data breaches within 72 hours of becoming aware that there are reasonable grounds to believe there has been an eligible data breach. Where it is 'impossible or impracticable' to report relevant information within that timeframe, an entity may provide an incomplete statement accompanied by a statement of reasons as to why that is the case, to be updated as soon as possible; and
- further clarification about different criteria for notifying affected or 'at risk' individuals in different scenarios.
Implications
- Entities will need to expedite internal triage, forensic investigations and legal sign-off, and update incident response plans and playbooks to reflect the new timing and mitigation expectations.
- While a 72-hour notification requirement aligns with other jurisdictions, the statement requirements do not reflect the realities of data breaches, where critical facts are often unknown in the first few days. The requirement imposes an unreasonably high bar, with additional mandatory reporting to justify omissions. This is out of step with other domestic and international reporting regimes. For example, under GDPR organisations do not need to set out the reasons in their notices for information being incomplete.
Proposed amendment
APP 11 would be expanded to require entities to:
- actively 'consider whether to destroy' personal information no longer needed and take reasonable steps to destroy or de-identify it (APP 11.2), and to ensure it is able to identify personal information it is required to protect and assess (APP 11.4);
- 'regularly evaluate the effectiveness' of their APP 11 compliance (APP 11.5).
Implications
These requirements would apply to all APP entities regardless of size, and reflect expectations in other regimes (for example, GDPR) about reviewing and evaluating the efficacy of controls. However, the ‘regularly evaluate' language is undefined, with no frequency specified, and expectations will likely be calibrated based on risk.
Data access and erasure
Proposed amendment
- New APP 12.3A would introduce an exception to access requests where providing access remains unreasonable or impracticable due to technical impossibility or infeasibility, despite the entity having taken reasonable steps.
- The Consultation Paper indicates the exception is aimed at technical limits in how information is stored, or where compliance would be unreasonable given the request. The exception applies only to the extent access is genuinely impracticable, with partial access to be given where possible.
Implications
- We expect that this exception will be of limited applicability. Administrative inconvenience and in many cases cost is unlikely to be enough.
Proposed amendment
- The Draft Bill introduces an erasure request right for individuals which is limited to 'large digital platforms'.
- 'Large digital platforms' are defined (under new s 6EB) as entities that provide a social media service, relevant electronic service or designated internet service (as those terms are defined in the Online Safety Act 2021), and that either have a 'business group' gross revenue of at least $500 million in the previous financial year, provide the relevant service to 2.5 million or more average monthly end users, or as otherwise prescribed by regulation.
- Several exceptions apply, including for frivolous or vexatious requests, permitted general or health situations, legal retention obligations, where destroying the information is unreasonable or impracticable due to technical impossibility or infeasibility, or where strictly necessary for a service that the individual has requested be provided.
Implications
- The proposed right to erasure is a narrower implementation than what was proposed in the original Privacy Act review, which is welcome given the compliance burden it would otherwise have imposed. The Productivity Commission highlighted last year that the broader reform should not proceed; it is unsurprising it has proceeded in a limited form.
- However, the potential scope of 'large digital platforms' is broad. ‘Designated internet service' captures services enabling end-users to access or deliver material via the internet. Despite the Consultation Paper using examples such as social media, messaging, email, gaming, streaming and 'other online platforms', this definition would capture a broader range of entities with a significant online presence such as financial services and retailers (provided the revenue or end-user thresholds are met).
- How the proposed erasure right interacts with personal information in AI training data and inferencing will be a key issue, particularly given the updated scope of definitions.
- Entities should also carefully consider if the exceptions are sufficient, including (for example) whether retention of information for compliance and risk management purposes would be permitted, particularly where those requirements are not strictly required or authorised by law or for mitigating or managing fraud and scams.
Human research exception
Proposed amendment
New s94B would exempt acts done in the course of 'human research' (ie, research conducted with or about individuals involving personal information) from breaching the APPs where the relevant act (i) is reviewed, approved and monitored under the applicable national ethics statement and (ii) satisfies any 'human research guidelines' published by the OAIC.
Implications
- The changes will apply to a broader range of studies and entities. In particular, entities in the clinical research supply chain will not need to evaluate whether their handling of personal information is relevant to public health or public safety to determine (as is currently required) whether they can deal with the personal information.
- The proposed legislation removes existing uncertainty for entities handling personal information in human studies. This will have a significant beneficial impact in health and life sciences, where privacy requirements currently cause substantial compliance friction.
Introduction of GDPR concepts – controllers and processors
Proposed amendment
New s16D introduces the concepts of 'controller' and 'processor' into Australian privacy law for the first time. As currently drafted, an entity is a processor on behalf of another entity (a 'controller') when acting in accordance with the controller's written instructions. Processors would be shielded from breaching most APPs (excluding APP 1 and APP 11) and registered APP codes under the new s6A(2A). Where this applies, the controller is deemed to have done the act and to have breached the relevant principle or code, placing legal accountability for compliant processing on the controller.
Implications
- While it may be attractive to align these concepts with the GDPR, in practice this may increase contracting complexity. Rather than building a framework designed around controller and processor roles, these concepts have been applied as a liability carve-out over the existing framework. In the context of the broader reforms, it is not clear what this achieves, and it does little to simplify the overall framework.
- Technology suppliers are the real winners, and we anticipate a material shift in documentation as suppliers seek to reframe themselves as processors. While this may assist with international alignment for such suppliers, customers may face increased contracting friction where a supplier exercises real control over personal information.
- Unlike the UK/EU GDPR, no minimum contractual content is prescribed. Instead, documented written instructions specifying purpose must be demonstrated. We expect OAIC guidance to clarify what form processor ‘instructions’ should take and what contractual terms should be agreed.
- As the protections will not extend to APP 1 or APP 11, processors must still manage their own privacy compliance and security, and they may be directly liable if they get that wrong. Further, new section 16D does not change entities' obligations (whether processors or controllers) under the notifiable data breach regime.
The reforms left on the table (again)
While the Draft Bill contains material changes, four significant structural proposals from the 2023 Report are absent:
- The small business exemption remains. Removing the $3 million turnover carve-out was recommended under the 2023 Report, but the only related adjustment is the operation of the 'trading' carve-in, not the monetary threshold itself. This will continue to hamper any attempt to achieve GDPR 'adequacy'.
- The employee records exemption survives. The section 7B(3) employee records exemption is not mentioned.
- No direct right of action. The 2023 Report recommended that individuals should have a right to sue for privacy interferences causing harm. This is absent from the Draft Bill.
- Political and journalism exemptions have not moved. The political exemption changes were among the 10 proposals from the 2023 Report that the Government formally rejected. While the journalism exemption reforms were agreed in-principle, these are absent from the Draft Bill.
OAIC Powers and Efficiency
The Consultation Paper contemplates measures to enhance the regulatory powers and efficiency of the OAIC, but these are not set out in the Draft Bill. These are proposed to cover:
- privacy complaint making and handling processes, including making privacy complaint handling compliance for entities mandatory and enforceable;
- representative complaint processes;
- assistance obligations and strengthened information gathering processes for the OAIC; and
- clarified Ministerial reporting powers.
We expect there will be limited opportunity to influence these processes, which are largely directed at improving the OAIC’s regulatory and enforcement functions.
Footnotes
-
Lee v Superior Wood [2019] FWCFB 2946.


