facebook-pixel

Australia Privacy Act 2026: Your Rights Explained

L
Lunyb Security Team
··9 min read

The Australia Privacy Act 2026 represents the most significant overhaul of Australian privacy law in nearly four decades. Building on the Privacy Act 1988 and the sweeping reforms introduced through the Privacy and Other Legislation Amendment Act 2024, the 2026 updates give Australians stronger rights over their personal information and place much heavier obligations on organisations that collect, store, or share data.

If you live in Australia, run a business, or handle customer data, understanding these changes is no longer optional. This guide breaks down what the Australia Privacy Act 2026 means for you, what new rights you have, and what businesses must do to stay compliant.

What Is the Australia Privacy Act 2026?

The Australia Privacy Act 2026 is the updated framework governing how personal information is handled by Australian government agencies and private-sector organisations with an annual turnover above the small business threshold. It modernises the original 1988 Act to reflect the realities of AI, biometric data, cross-border data flows, and large-scale data breaches like the Optus and Medibank incidents.

Administered by the Office of the Australian Information Commissioner (OAIC), the reformed Act introduces enforceable individual rights that align Australia more closely with the EU's GDPR, while retaining locally specific concepts like the 13 Australian Privacy Principles (APPs).

Why the Act Was Reformed

Three main forces drove the 2026 reforms:

  1. Major data breaches exposed the personal details of millions of Australians and revealed how weak enforcement had become.
  2. Emerging technologies like generative AI, facial recognition, and behavioural advertising outpaced the 1988 framework.
  3. International alignment was needed so Australian businesses could compete globally and receive data from GDPR-regulated regions.

Your Key Rights Under the Australia Privacy Act 2026

The 2026 amendments introduce several new individual rights that give Australians genuine control over their personal information for the first time. Below is a summary of the most important ones.

RightWhat It MeansWho Can Use It
Right to ErasureRequest deletion of your personal information in certain circumstances.All individuals
Right to ObjectObject to direct marketing and certain automated processing.All individuals
Right to De-indexRequest search engines de-index results containing your personal data.All individuals
Right to ExplanationUnderstand how automated decisions that affect you were made.All individuals
Statutory Tort for Serious Invasions of PrivacySue for damages when your privacy is seriously and intentionally invaded.All individuals
Children's Online Privacy CodeEnhanced protections for users under 18.Minors and guardians

1. The Right to Erasure (Right to Be Forgotten)

You can now formally request that an organisation delete your personal information if it is no longer necessary for the purpose it was collected, if you withdraw consent, or if the data was collected unlawfully. Organisations must respond within a reasonable timeframe and confirm the deletion in writing.

2. The Right to De-index Search Results

Similar to the European approach, Australians can request that search engines remove links to information that is inaccurate, out of date, irrelevant, or excessive. This is particularly powerful for people trying to move on from old news stories, court records, or outdated social media content.

3. The Right to an Explanation of Automated Decisions

If a business uses AI or algorithms to make decisions that significantly affect you — loan approvals, insurance quotes, hiring, or targeted pricing — you have the right to understand what personal information was used and how the decision was reached. Privacy policies must now explicitly disclose the use of such systems.

4. The Statutory Tort for Serious Invasions of Privacy

Perhaps the most consequential change: Australians can now sue directly in the Federal Court for serious invasions of privacy, including intrusion upon seclusion (unauthorised surveillance, doxxing) and misuse of private information. Damages can reach up to $478,550 plus aggravated damages.

New Obligations for Australian Businesses

The Australia Privacy Act 2026 dramatically increases what organisations must do to remain compliant. Even businesses that previously qualified for the small business exemption face tighter scrutiny, and that exemption is being progressively phased out.

Fair and Reasonable Test

Every collection, use, and disclosure of personal information must now be "fair and reasonable in the circumstances" — an objective standard that applies even if the individual has consented. Consent alone is no longer a shield.

Mandatory Privacy Impact Assessments

High-risk activities, including large-scale profiling, biometric processing, and AI-based decision-making, require documented Privacy Impact Assessments (PIAs) before deployment.

Data Breach Notification Within 72 Hours

The notifiable data breach scheme has been tightened. Organisations must now notify the OAIC and affected individuals within 72 hours of becoming aware of an eligible breach — down from the previous "as soon as practicable" standard.

Privacy by Design and Default

Products and services must have privacy protections built in from the start. Default settings should be the most privacy-protective option available, particularly for services likely to be used by children.

Penalties: What Happens If a Business Gets It Wrong

The financial consequences for non-compliance are now substantial and align Australia with global peers.

Type of BreachMaximum Penalty (Company)Maximum Penalty (Individual)
Serious or repeated interference with privacyGreater of $50 million, 3x benefit obtained, or 30% of adjusted turnover$2.5 million
Mid-tier civil penalty$3.3 million$660,000
Low-tier civil penalty$330,000$66,000
Administrative infringement notices$66,000 per breach$13,200 per breach

The OAIC also gains stronger investigative powers, including the ability to conduct on-site assessments, issue compliance notices, and refer serious matters directly to the Federal Court.

Cross-Border Data Transfers

APP 8 has been tightened. Organisations transferring personal information overseas must now:

  1. Verify the recipient country has substantially similar privacy protections, or
  2. Use a prescribed set of standard contractual clauses issued by the OAIC, or
  3. Obtain explicit, informed consent from the individual after a clear explanation of the risks.

The Attorney-General can now formally designate "adequate" jurisdictions, similar to the EU adequacy decision system.

The Children's Online Privacy Code

A dedicated code for online services likely to be accessed by children under 18 came into force alongside the 2026 amendments. Key requirements include:

  • Default high-privacy settings for minor accounts.
  • Prohibitions on targeted advertising and behavioural profiling of children.
  • Age-appropriate privacy notices written in plain English.
  • Restrictions on the use of dark patterns that nudge minors into sharing more data.

Practical Steps to Protect Your Privacy in 2026

Knowing your rights is only half the battle — you also need practical habits to reduce your exposure. Here are steps every Australian can take today.

1. Audit Your Digital Footprint

Search your name, email address, and phone number in major search engines. Note which sites hold your information and whether you can request deletion or de-indexing.

2. Use Privacy-Respecting Tools

Choose services that minimise data collection. When sharing links, for example, use a privacy-focused shortener like Lunyb that doesn't build advertising profiles from your click data. You can read our transparency breakdown in this honest Lunyb review or compare options in our 2026 URL shortener buyer's guide.

3. Enable Encrypted DNS and Private Browsing

Turn on DNS-over-HTTPS in your browser settings and consider a privacy-oriented browser. This helps prevent internet service providers and network operators from logging your browsing activity.

4. Exercise Your New Rights

Don't wait — send erasure requests to businesses that hold data you no longer want them to have. Under the 2026 Act, they must respond and cannot ignore reasonable requests.

5. Review Privacy Policies Before Signing Up

Look for clear statements on data retention, third-party sharing, and automated decision-making. Organisations that use vague language are often the ones with the most to hide.

How the Australia Privacy Act 2026 Compares Globally

FeatureAustralia 2026EU GDPRCalifornia CPRA
Right to erasureYesYesYes
Right to sue individuallyYes (statutory tort)YesLimited
Max fine (% of turnover)Up to 30%Up to 4%Fixed dollar amounts
Breach notification window72 hours72 hoursWithout unreasonable delay
Children's codeYesYes (national codes)Yes (CAADCA)
Small business exemptionBeing phased outNoRevenue threshold

Pros and Cons of the 2026 Reforms

Pros

  • Australians finally have enforceable individual rights, including a direct right to sue.
  • Penalties are large enough to change corporate behaviour.
  • Children receive strong, dedicated protections.
  • Alignment with GDPR simplifies international business.
  • Transparency around AI and automated decisions is now mandatory.

Cons

  • Compliance costs are significant, especially for mid-sized businesses.
  • Some rights come with broad exceptions that may limit their practical use.
  • The statutory tort could generate strategic litigation risks.
  • Guidance from the OAIC is still evolving in several areas.

What to Do If Your Privacy Rights Are Breached

  1. Complain directly to the organisation first — they have 30 days to respond substantively.
  2. Escalate to the OAIC if you're not satisfied. The Commissioner can investigate, mediate, and issue determinations.
  3. Consider legal action under the new statutory tort for serious invasions of privacy, particularly for doxxing, stalking, or unauthorised surveillance.
  4. Report criminal conduct such as identity theft or blackmail to your state or territory police.

Frequently Asked Questions

When does the Australia Privacy Act 2026 fully take effect?

Different provisions commence at different times. The first tranche of reforms began under the 2024 amendments, with the majority of the new individual rights, the statutory tort, and the Children's Online Privacy Code operating from 2026. Some elements, like the full phase-out of the small business exemption, will roll out progressively through 2027.

Does the Privacy Act 2026 apply to small businesses?

Historically, businesses with turnover under $3 million were exempt. Under the 2026 reforms, this exemption is being phased out. Small businesses handling sensitive information, biometric data, or children's data are already covered, and the general exemption will end within a few years.

Can I sue a company directly for a privacy breach?

Yes. The new statutory tort for serious invasions of privacy lets you bring an action in the Federal Court without first going through the OAIC. You must show the invasion was serious, intentional or reckless, and that the public interest in your privacy outweighs any countervailing interests like freedom of expression.

What counts as "personal information" under the reformed Act?

The definition has been broadened. It now clearly covers technical identifiers like IP addresses, device IDs, and location data when they can be reasonably linked to an individual. Inferred information generated by AI systems is also included.

How do I make a right-to-erasure request?

Contact the organisation in writing (email is fine), identify yourself, specify the data you want deleted, and state the ground for your request. They must respond within a reasonable time — generally 30 days — and either comply, explain any lawful reason to refuse, or offer a partial resolution.

Final Thoughts

The Australia Privacy Act 2026 is a genuine turning point. For the first time, Australians have rights that resemble those enjoyed by Europeans under GDPR, backed by penalties that can genuinely deter misconduct. For businesses, the message is equally clear: privacy is no longer a compliance box to tick but a core operational responsibility.

Whether you're an individual reclaiming control of your data or a business updating your privacy program, the time to act is now. Understand your rights, audit your data, choose privacy-respecting tools, and don't hesitate to hold organisations accountable when they fall short.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles