On August 31, 2026, Australia's Attorney-General released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, the most substantial rewrite of the Privacy Act 1988 in almost forty years. The Bill replaces the current collection and disclosure rules with a single "fair and reasonable" test, formalizes a controller and processor distinction, introduces a 72-hour data breach notification deadline, and creates a limited right of erasure for large digital platforms. Public consultation closes on September 18, 2026. For French and European companies setting up an Australian subsidiary, this is the moment to build GDPR-adjacent data governance into the entity from day one rather than retrofitting it later.
Australia's Privacy Act has stayed largely the same since 1988, even as the country's digital economy grew far beyond what the original framework anticipated. A first tranche of reforms passed in late 2024 introduced a statutory tort for serious privacy invasions and stronger enforcement powers for the Office of the Australian Information Commissioner (OAIC), but it addressed only a fraction of the 116 recommendations from the government's 2023 Privacy Act Review Report.
The Bill released on August 31, 2026 is the second and considerably more ambitious tranche. It is designed to bring Australia's data protection standards closer to what European and UK companies already expect under the GDPR, which matters directly if your organization is used to operating under that regime and is now establishing a presence in Australia.
If you are weighing when to formalize your Australian entity's data practices, our team at Expandys can walk you through how this reform intersects with your broader market entry plan.
The reform touches nearly every part of how a business collects, uses, discloses, and eventually destroys personal information. The most consequential elements are:
Each of these has direct implications for a newly established subsidiary building its data handling processes from scratch.
Instead of assessing each collection or disclosure activity against narrow rules, businesses will need to weigh their data practices against seven legislated factors, including the individual's reasonable expectations, whether the data handling is proportionate to its purpose, whether genuine choice was offered, and whether less data could have achieved the same outcome. No single factor decides the outcome on its own. This is a meaningful shift away from relying on broad secondary purpose justifications or bundled consent, both of which are common shortcuts that will no longer hold up well under the new standard.
For a foreign subsidiary, this means data governance cannot be an afterthought bolted on once the business is running. It needs to be part of how the entity is structured from the outset, including how customer data is captured on your website, CRM, and any local marketing tools.
The Bill introduces a formal split between controllers, who determine why and how personal information is handled, and processors, who act strictly on a controller's documented instructions. This will feel familiar to any company already operating under the GDPR. Where a processor acts within its instructions, responsibility for compliance sits with the controller. Where a processor steps outside those instructions, it takes on full responsibility itself.
In practice, this means every data processing relationship, including arrangements with local payroll providers, marketing platforms, or IT vendors, will need clear written instructions and properly allocated risk in the underlying contracts.
The current standard of notifying the regulator "as soon as practicable" is being replaced with a hard 72-hour deadline from the point an organization has reasonable grounds to believe an eligible breach has occurred. This mirrors similar timeframes already familiar to European companies. Businesses will also be expected to maintain a functioning breach response system on an ongoing basis, not just activate one after an incident occurs.
For a newly formed Australian entity, this makes an incident response plan a day-one requirement rather than something to draft after the first scare.
Yes, but it is narrower than the equivalent right under the GDPR. It applies only to large digital platforms, defined as organizations providing certain online services that meet at least one of two thresholds: AUD 500 million in group revenue, or 2.5 million average monthly Australian users. Most foreign subsidiaries entering Australia through a standard trading or services entity will fall outside this threshold, though the broader "fair and reasonable" test and breach notification rules will still apply regardless of company size.
|
Area |
Current Australian Privacy Act |
Proposed Bill (2026) |
GDPR (EU) |
|---|---|---|---|
|
Core obligation |
Separate collection, use, and disclosure rules |
Single "fair and reasonable" test across all handling |
Lawful basis required for each processing activity |
|
Consent standard |
OAIC guidance only, not legislated |
Legislated: voluntary, informed, current, specific, unambiguous |
Legislated, similarly strict standard |
|
Controller/processor split |
Not formally defined |
Introduced, with documented instructions required |
Long-established distinction |
|
Breach notification |
"As soon as practicable" |
72 hours from awareness |
72 hours from awareness |
|
Right of erasure |
Not available |
Limited to large digital platforms only |
Available to individuals against all controllers |
|
Small business exemption |
Applies below AUD 3 million turnover |
Retained, not removed in this Bill |
No equivalent exemption |
The Bill's commencement date is not yet fixed, and further transitional provisions are still to come, but the direction of travel is clear enough to start preparing now. Priority actions include:
Public consultation on the Bill closes September 18, 2026, and submissions are limited to roughly 1,000 words, so companies with meaningful data exposure in Australia still have a short window to engage with the process directly.
Does this Bill apply to a newly established Australian subsidiary of a French company? Yes. The Privacy Act and its proposed amendments apply to any organization operating in Australia that meets the relevant turnover or activity thresholds, regardless of where its parent company is based. A new subsidiary should build compliance into its data processes from formation rather than treating it as a later add-on.
When will the Bill actually take effect? The exposure draft released on August 31, 2026 does not yet include a commencement date, and further transitional provisions are still being finalized. Consultation closes September 18, 2026, after which the government will refine the Bill before it is introduced to Parliament.
Is the right of erasure the same as under the GDPR? No. Under the proposed Bill, the right of erasure applies only to large digital platforms meeting specific revenue or user thresholds. Most standard trading or services subsidiaries will not be covered by this particular right, though other obligations, including the fair and reasonable test, apply more broadly.
Does the small business exemption still apply? Yes, for now. The Bill does not remove the existing exemption for organizations below AUD 3 million in annual turnover, even though the government's original review recommended removing it. This could still change before the Bill is finalized.
Reform of this scale changes the calculus for any company establishing an Australian presence over the next twelve months. Building the right data governance structure into your subsidiary from the start is considerably easier than retrofitting it once local operations, marketing systems, and vendor contracts are already in place. Expandys has supported over 600 clients across 1,200 projects entering Australia, India, and the UK, and our Sydney team can help you map this reform against your specific market entry plan before consultation closes.