facebook-pixel

Australia Privacy Act 2026: Your Rights Explained

L
Lunyb Security Team
··10 min read

The Australian privacy landscape has undergone its most significant transformation in decades. The Australia Privacy Act 2026 introduces sweeping reforms that reshape how organisations collect, store, and use personal information — and it hands Australians a robust new set of rights over their own data. Whether you're a consumer wanting to understand what you can now demand from businesses, or a business owner trying to stay compliant, this guide explains everything you need to know.

What Is the Australia Privacy Act 2026?

The Australia Privacy Act 2026 is a comprehensive update to the original Privacy Act 1988, reflecting years of consultation and the recommendations of the Attorney-General's Privacy Act Review Report. It modernises Australian privacy law to align more closely with international standards such as the EU's GDPR, while introducing distinctly Australian protections tailored to local concerns like data breaches, targeted advertising, and children's online safety.

The reforms address a simple reality: the 1988 Act was written before smartphones, social media, cloud computing, and artificial intelligence existed. The 2026 Act closes those gaps with expanded definitions, stronger enforcement powers for the Office of the Australian Information Commissioner (OAIC), and a raft of new individual rights.

Who Does the Act Apply To?

The Act applies to a broader range of entities than ever before. The previous small business exemption — which excluded organisations with an annual turnover under $3 million — has been significantly narrowed and is being phased out entirely. This means the vast majority of Australian businesses, community organisations, and government agencies must now comply.

The Act also applies extraterritorially: overseas companies that collect personal information from Australians (think global e-commerce sites or social platforms) are captured, even without a physical presence in Australia.

Your New Rights Under the Privacy Act 2026

The most consumer-friendly aspect of the reforms is the introduction of clear, enforceable individual rights. Here's what you can now do.

1. The Right to Erasure

You now have a legal right to request that an organisation delete personal information it holds about you. Similar to the GDPR's "right to be forgotten," this applies when the data is no longer necessary, when you withdraw consent, or when the information was collected unlawfully. Organisations must respond within a reasonable timeframe (generally 30 days) and cannot charge you for the request.

2. The Right to Object to Direct Marketing

While opt-outs have long existed under the Spam Act, the 2026 Act formalises a broader right to object to any use of your personal information for direct marketing, including targeted advertising and profiling. Once you object, the organisation must stop — no exceptions.

3. The Right to De-Index Search Results

Australians can now request that search engines remove specific URLs from search results that appear when their name is searched, particularly where the information is inaccurate, outdated, irrelevant, or excessive. This is a landmark right, bringing Australia closer to European standards.

4. The Right to Explanation for Automated Decisions

If a significant decision about you — such as a loan approval, insurance premium, or job application screening — is made using automated systems or AI, you have the right to a meaningful explanation of how that decision was reached. You can also request human review.

5. Enhanced Access and Correction Rights

You've always had the right to access your personal information, but the 2026 Act strengthens this. Responses must now be provided in a commonly used, machine-readable format, and organisations must actively assist you in understanding the information provided.

6. A Direct Right of Action

Perhaps the most significant change: individuals can now sue organisations directly in the Federal Court for serious interferences with privacy. Previously, complaints had to go through the OAIC. This new direct pathway includes the ability to claim compensation for non-economic loss such as emotional distress.

7. A Statutory Tort for Serious Invasions of Privacy

Australia now has a statutory tort of serious invasion of privacy, covering both intrusion upon seclusion (e.g., unauthorised surveillance) and misuse of private information. Damages can include aggravated and, in limited circumstances, exemplary damages.

New Obligations for Businesses

The other side of expanded rights is expanded responsibility. Businesses handling personal information now face stricter obligations across the data lifecycle.

The "Fair and Reasonable" Test

Every collection, use, and disclosure of personal information must now be "fair and reasonable in the circumstances" — regardless of whether the individual consented. This is a fundamental shift: consent alone is no longer a get-out-of-jail-free card. Organisations must genuinely assess whether their data practices would be considered fair by a reasonable person.

Privacy by Design and by Default

Organisations must build privacy considerations into products and services from the ground up. Default settings must be the most privacy-protective option available, requiring users to actively opt in to less private configurations.

Mandatory Privacy Impact Assessments

For high-risk activities — including any large-scale processing, use of biometric data, or deployment of AI systems that affect individuals — organisations must complete and document a Privacy Impact Assessment (PIA) before commencing the activity.

Enhanced Data Breach Notification

The Notifiable Data Breaches scheme has been tightened. Organisations must now notify the OAIC within 72 hours of becoming aware of an eligible breach (previously "as soon as practicable"), and notify affected individuals without undue delay. Failure to comply attracts significant penalties.

Penalties for Non-Compliance

Penalties under the 2026 Act have teeth. For serious or repeated interferences with privacy, corporations face fines of up to the greater of:

  • AU$50 million;
  • Three times the value of any benefit obtained from the misuse of information; or
  • 30% of the company's adjusted turnover during the relevant period.

Mid-tier and low-tier penalties for less serious contraventions have also been introduced, giving the OAIC a graduated enforcement toolkit rather than an all-or-nothing approach.

Comparison: Privacy Act 1988 vs Privacy Act 2026

FeaturePrivacy Act 1988Privacy Act 2026
Small business exemptionApplied to businesses under $3M turnoverLargely removed / phased out
Right to erasureLimitedFull statutory right
Direct right of actionNoYes, in Federal Court
Statutory tort of privacyNoYes
Maximum corporate penalty$50M / 30% turnover (2022 amendment)$50M / 30% turnover + tiered penalties
Breach notification window"As soon as practicable"72 hours to OAIC
AI/automated decision rightsNoneRight to explanation and human review
"Fair and reasonable" testNoYes, applied to all handling

Special Protections for Children

The Act introduces a Children's Online Privacy Code, developed by the OAIC, which sets specific standards for services likely to be accessed by anyone under 18. Key protections include:

  1. A prohibition on targeted advertising to children based on their personal information.
  2. A requirement that default settings for children's accounts be the highest privacy setting available.
  3. Restrictions on the use of "dark patterns" designed to encourage children to share more information.
  4. Enhanced parental consent requirements for children under 15.

How to Exercise Your Rights: A Step-by-Step Guide

Knowing your rights is one thing; using them is another. Here's a practical process for exercising any of your privacy rights under the new Act.

  1. Identify the organisation. Determine which entity holds the personal information you want to access, correct, or delete.
  2. Find their privacy contact. Under the Act, every APP entity must publish a clear, accessible privacy policy with a designated contact.
  3. Submit a written request. Be specific about what right you're exercising (e.g., "I am requesting erasure of my personal information under the Privacy Act 2026"). Include enough information to verify your identity.
  4. Await the response. Organisations generally have 30 days to respond. They must respond in writing and cannot charge a fee for most requests.
  5. Escalate if needed. If you're unsatisfied with the response, you can lodge a complaint with the OAIC at oaic.gov.au, or now pursue direct action in the Federal Court.

Practical Steps to Protect Your Privacy Today

The Act gives you powerful rights, but proactive privacy hygiene remains the best defence. Here are practical steps every Australian should consider.

Audit Your Digital Footprint

Search your own name across major search engines. Note which sites hold information about you, and use your new de-indexing and erasure rights to clean up outdated or unwanted results.

Review App Permissions Regularly

Australians install dozens of apps that quietly collect location data, contacts, and usage patterns. Set a quarterly reminder to review permissions on your phone and revoke anything unnecessary.

Use Encrypted DNS and Privacy-Focused Browsers

Consider switching to a browser that blocks trackers by default (such as Brave or Firefox with strict tracking protection) and enabling encrypted DNS (DNS over HTTPS) in your browser or router settings. These network-level protections stop many trackers before they ever reach a website.

Be Careful What You Share in Links

Long URLs often contain tracking parameters, personal identifiers, and referral information. When sharing links on social media, in emails, or in messaging apps, use a trusted link shortener that strips tracking parameters and doesn't sell click data. Services like Lunyb provide privacy-respecting link shortening — you can read our honest Lunyb review or compare options in our 2026 buyer's guide to URL shorteners to see which suits your needs.

Enable Multi-Factor Authentication

Data breaches remain the number one privacy threat. MFA on your email, banking, and social accounts drastically reduces the impact of leaked passwords.

What the Act Means for Australian Businesses

If you run a business, compliance is no longer optional or affordable to ignore. Here's a compliance checklist to get started.

  1. Map your data. Understand what personal information you collect, where it's stored, who has access, and how long you keep it.
  2. Update your privacy policy. Ensure it reflects the new rights, contact channels, and the "fair and reasonable" test.
  3. Train your team. Every employee who handles personal information should understand the new obligations, especially the 72-hour breach notification window.
  4. Appoint a Privacy Officer. While not universally mandatory, larger organisations should have a designated privacy lead responsible for compliance.
  5. Conduct PIAs. For any new product, feature, or data practice that could pose privacy risks.
  6. Review third-party contracts. Ensure vendors, processors, and marketing partners meet the new standards.
  7. Prepare for direct action lawsuits. Review insurance, incident response plans, and legal resources.

Frequently Asked Questions

When does the Australia Privacy Act 2026 take effect?

The Act is being rolled out in phases throughout 2026, with the core individual rights and enforcement provisions commencing early in the year. Some obligations, such as the full removal of the small business exemption, are subject to transitional periods extending into 2027. Businesses should treat 2026 as the effective compliance deadline.

Does the Privacy Act 2026 apply to overseas companies?

Yes. The Act has extraterritorial reach. Any organisation that collects or handles the personal information of Australians — regardless of where it is based — must comply. This includes global tech platforms, e-commerce sites, and cloud service providers serving Australian users.

Can I sue a company directly for a privacy breach?

Yes. One of the biggest changes is the new direct right of action, which allows individuals to bring privacy claims in the Federal Court without first going through the OAIC. You can also claim damages for emotional distress, not just financial loss. Additionally, the new statutory tort provides another pathway for serious invasions of privacy.

What counts as "personal information" under the new Act?

The definition has been expanded and clarified. It now explicitly includes technical identifiers such as IP addresses, device IDs, location data, and online identifiers where they can reasonably identify an individual. Inferred information — such as profiles built from your browsing habits — is also captured.

How do I lodge a complaint if a company ignores my request?

You have two main options. First, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) via oaic.gov.au — this remains free and doesn't require legal representation. Second, for serious interferences, you can now pursue direct legal action in the Federal Court. Many privacy lawyers offer no-win-no-fee arrangements for stronger cases.

Final Thoughts

The Australia Privacy Act 2026 represents a decisive step toward giving Australians meaningful control over their personal information. For consumers, it means real, enforceable rights backed by significant penalties. For businesses, it means privacy can no longer be an afterthought — it must be built into every product, process, and decision.

The best time to understand your rights (or bring your business into compliance) was yesterday. The second-best time is today. Bookmark the OAIC website, review your digital footprint, and start exercising the rights that Australian law now guarantees you.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles