Australia's Attorney-General's Department opened consultation on 31 August 2026 on an exposure draft that would make consent a precondition for disclosing personal information for direct marketing purposes. The accompanying consultation paper names cookie and pixel disclosures in programmatic advertising as an example of the conduct caught.

The Privacy Amendment (Personal Data Protection) Bill 2026 runs to six schedules and 54 pages of drafting. It would repeal three Australian Privacy Principles outright, rewrite the definition of personal information, add a category of sensitive information keyed to a 500-metre radius, and give individuals a right to demand deletion from platforms above a revenue or user threshold. Consultation closes on Friday 18 September 2026, which leaves stakeholders 18 days. The department has asked for submissions of around 1,000 words.

According to the Attorney-General's Department, the package contains roughly 40 proposals. Twenty-five come from the Privacy Act Review and are described as uplifting protections. Five more Review proposals clarify and simplify existing obligations. Four additional measures simplify further, and seven target the efficiency of the Office of the Australian Information Commissioner. The department states that about 900 written submissions were received across the process that produced the draft, including the Privacy Act Review and the 2024 amendments.

The bill remains subject to further consideration by government. Its commencement table is blank.

The provision with the sharpest edge for advertising sits in Schedule 2. A new section 6FC would define trade in personal information. A disclosure is a trade if an organisation discloses the information "for money or other consideration" or "for the purposes of direct marketing". A new Australian Privacy Principle 4.2 would then prohibit an organisation from trading personal information without the individual's consent, unless an exception applies.

The consultation paper spells out the reach. Disclosure for the purposes of direct marketing is intended to be read broadly and to capture disclosures that support or inform direct marketing even where marketing is not the sole purpose. The example given is "disclosures of cookies or pixels in programmatic advertising processes".

That single sentence converts a routine mechanic of real-time bidding into a consent-gated act. Bid stream transmission, cookie syncing, pixel firing that passes an identifier to a third party for audience construction: each becomes a disclosure, and each disclosure made for a purpose that supports direct marketing becomes a trade requiring consent, absent a carve-out.

Four carve-outs are drafted. A disclosure is not a trade where it is necessary for the recipient to provide a product or service the individual requested from that recipient, including where the disclosing organisation earns a commission. Nor is it a trade where the disclosure is incidental to a merger, acquisition or business transfer, provided disclosure for consideration is not a substantial purpose of the transaction. The third carve-out covers disclosures from a controller to a processor acting on documented instructions. The fourth covers disclosures necessary to prevent, detect, investigate or remedy unlawful activity or serious fraud-related wrongdoing.

The controller-to-processor carve-out is the one that will attract the most drafting scrutiny from supply chain participants, because it is the only route by which data can move between commercial entities without a consent event. Its availability depends on Schedule 6, which is discussed below.

The consent standard itself tightens. A new section 6AAB would require consent to be voluntary, informed, current, specific and unambiguous. The consultation paper states that bundled consent, where an individual must accept multiple handling practices through one mechanism, would most likely not be voluntary. Interfaces that make it unreasonably difficult to avoid giving consent are named in the same category. Preselected settings and pre-ticked boxes would likely not be unambiguous.

Direct marketing is redefined around cohorts

APP 7 would be repealed and replaced. The new definition of direct marketing covers communication of advertising or marketing material to an individual where the individual is selected, identified or otherwise targeted for receipt of the material, whether individually or as a member of a class, and where that targeting is done using personal information relating to the individual.

The consultation paper lists what this captures: emails, text messages, telemarketing calls, targeted social media advertising, and online behavioural advertising based on personal information including browsing history. The department states that the definition reflects the increasing use of profiling and audience segmentation and makes clear that direct marketing includes group-level targeting.

Cohort-level targeting has been the industry's principal answer to identifier deprecation. Under this drafting, a cohort built from personal information is direct marketing, and the entity making the communication carries the opt-out obligation.

Allocation of that obligation is stated explicitly. Where multiple entities are involved, such as an advertiser and a social media platform, the consultation paper says the platform will generally carry the opt-out requirement unless it acts solely as a processor. Requests must be actioned by taking reasonable steps, a qualification the department attributes to the reality that marketing reaches individuals across multiple accounts, devices and identifiers that an organisation may not be able to link.

Each direct marketing communication would have to carry information on how to opt out, in clear and plain language, up to date and concise. That obligation sits alongside browser-level signals such as GPC, which carry legal force in several United States jurisdictions but have no Australian statutory hook.

Clause 7.5 of the new APP 7 addresses ad-supported services. Where an individual asks not to receive direct marketing, an organisation providing an ad-supported service may offer that service, or an element of it, on different terms, provided those terms give the individual a genuine choice to continue using the service without receiving direct marketing.

The consultation paper is direct about the lineage. It states the provision is intended to draw on similar principles to consent or pay guidance in data protection regimes in the United Kingdom and the European Union.

That reference imports a contested body of practice. The European Data Protection Board determined in Opinion 08/2024 that most consent or pay models fail the GDPR standard for valid consent, and recommended platforms offer a genuinely free alternative without behavioural advertising. Nine digital advertising trade associations submitted a joint defence of the models in January 2025, arguing that between 10% and 50% of users leave services rather than select either option, which they read as evidence of genuine choice. OpenAI's European advertising rollout added a third door, an ads-free configuration of the free plan with reduced message limits, distinguishing it from the binary structures the Board examined.

The Australian drafting sets no price ceiling and no equivalence test. The consultation paper says whether choice is genuine depends on circumstances including how easy it was to select a preferred option, the information provided, and the comparative value of the options, and that choice would not be genuine if illusory or influenced through dark patterns.

An ad-supported service is defined at clause 7.6 as one where making direct marketing communications is itself a source of revenue, disregarding revenue from sales of the goods marketed. No minimum revenue threshold applies, and the test operates at service level rather than organisation level.

A single fairness test replaces three principles

APPs 3, 4 and 6 would be repealed. In their place, a new APP 3 would prohibit collection, use or disclosure of personal information unless it is both fair and reasonable in the circumstances and lawful.

Seven factors are legislated. Whether a reasonable person would expect the handling. Whether it relates to the entity's functions or activities. Whether the entity is transparent about means and purposes. Whether the purpose could be met with less information, or with information that is not personal information. Whether the individual has genuine choice. The privacy impact and risk of harm, including whether that impact is proportionate to benefits accruing to the individual or the entity. And, where the information relates to a child, the best interests of the child as a primary consideration.

No single factor is decisive. The consultation paper states that entities are not required to satisfy every factor, and that assessment is holistic.

Several passages narrow the escape routes. Being described in a collection notice or privacy policy does not make a practice reasonably expected. An entity is not automatically transparent because information appears in a privacy policy, particularly a lengthy or unclear one. Choice is not genuine where individuals face take it or leave it terms, would suffer detriment for refusing, or are influenced through dark patterns. Where the entity is the primary beneficiary and there is significant risk to individuals, handling is unlikely to be proportionate.

The express requirement to obtain consent for unexpected or unrelated secondary uses disappears. Consent survives as one mechanism for demonstrating genuine choice rather than as a standalone gate, except for sensitive information and trading. The consultation paper puts it plainly: the framework does not require consent for direct marketing, but entities must obtain consent to trade personal information.

Definitions move to cover inference and cohorts

Schedule 1 rewrites the core vocabulary. Personal information would mean information or an opinion that relates to an identified individual or an individual who is reasonably identifiable, replacing the current requirement that information be about an individual.

A note to the new section 6FD states that an individual can be identified even where name or legal identity is unknown, where information allows the person to be "recognised, singled out, or otherwise dealt with as a distinct individual in practice". The note lists pseudonyms and identifiers, location and geolocation data, and characteristics, behaviours, traits, preferences or patterns of activity.

Reasonably identifiable gets its own definition at section 6FF: an individual is reasonably identifiable where they could be identified by combining the information with other information reasonably available. The consultation paper directs an objective assessment considering the availability of other information, technical feasibility, the time, cost and effort required, and any controls on access, use or re-identification.

The definition of collects changes in a way that reaches artificial intelligence systems. Section 6AAA would provide that an entity collects personal information when it collects the information for inclusion in a record or generally available publication, regardless of source or means. The accompanying note gives generating information through an entity's own processes, systems, observations or measurements, or deriving it from other information, as examples of means. The consultation paper states this ensures inferences drawn by AI-enabled technology about an individual count as collection.

Timing rules follow for derived sensitive information. An entity is not taken to collect sensitive information merely because it collects personal information from which sensitive information can be derived. But where the personal information is collected for a purpose involving use or disclosure of the sensitive information, collection occurs at the same moment. Otherwise, collection occurs at the earlier of first use or disclosure as sensitive information, or first separate recording.

The paper's worked example concerns a halal meal order. Processing the order is not collection of religious belief. Deriving religious belief from the order to send marketing about a religious festival is.

Disclosure receives a statutory definition for the first time: an entity discloses personal information if it makes that information accessible to another person or body. Mere transmission or storage, including overseas, does not constitute disclosure unless the information is made accessible. Intention is not required.

Location within 500 metres becomes sensitive information

The definition of sensitive information at section 6FE would add precise geolocation tracking data, genomic information, and biometric templates as named categories.

Precise geolocation tracking data means personal information generated by or derived from a device or other technology that identifies an individual's location within a radius of 500 metres and is collected and held by reference to location over time, whether at points in time, by aggregation, or otherwise. The consultation paper states the definition targets tracking, monitoring or analysis over time and is not intended to extend to one-off disclosures or to less precise data such as city-level location.

Sensitive information cannot be collected without consent unless an exception applies, and clause 4.5 closes one door explicitly: collection of sensitive information for the purposes of direct marketing is never strictly necessary within the meaning of the requested goods or services exception, regardless of whether the individual requested the marketing.

The 500-metre radius is looser than comparable thresholds elsewhere. The House privacy bill backed by the ANA defines precise geolocation at 1,750 feet, roughly 533 metres. Vermont's Act 138 sets 1,850 feet, about 564 metres. The Australian number is stated in metres and paired with a temporal element the American definitions do not carry, so a single coordinate would not qualify while a sequence would.

An exception permits collection of sensitive information from a publicly available document without consent. That definition is broad and covers documents behind a paywall, registration or account creation, provided any ordinary member of the public can clear the barrier. Social media posts are named as a possible example. Such collections would still need to be fair and reasonable.

De-identification stops being permanent

Section 6FG would define information as de-identified where, at a particular time or in particular circumstances, it has ceased to relate to an identified or reasonably identifiable individual. The consultation paper states that de-identification is not a static condition, having regard to technological developments, data availability, and the effectiveness of technical and organisational measures.

APP 11 is rewritten in parallel. Entities holding personal information no longer needed for any permitted purpose would have to consider whether to destroy it, then take reasonable steps either to destroy it or ensure it is de-identified. Entities must take any steps needed to be able to identify the personal information those obligations apply to. And clause 11.5 requires regular evaluation of the effectiveness of compliance.

That evaluation duty reaches measurement infrastructure built on the premise that de-identification is a completed state, including clean room deployments and retained match tables. The consultation paper directs entities to assess whether de-identified information remains de-identified, whether re-identification risks are being managed, and whether retention in de-identified form remains justified against destruction.

The Office of the Australian Information Commissioner already applies a demanding standard here. Sarah Kruger, Director of Policy and Regulatory Affairs at IAB Australia, told a March 2026 webinar that the regulator applies a very low risk threshold for reidentification and will look at all available information when assessing whether a dataset has been deidentified.

Erasure rights arrive at a revenue threshold

Schedule 4 Part 2 creates APP 14, a right to demand destruction of personal information held by a large digital platform.

An organisation is a large digital platform if it provides a social media service, relevant electronic service or designated internet service within the meaning of the Online Safety Act 2021, and passes either of two tests. The gross revenue test is met where the organisation's business group recorded at least $500 million in gross revenue in the previous financial year, calculated across the entire group including overseas members, and regardless of whether the revenue has an Australian source. The end users test is met where the service averaged at least 2.5 million monthly Australian end users across the previous financial year. An end user includes anyone accessing the platform whether or not they hold an account.

Regulations may prescribe additional platforms, subject to a public interest test and consultation with the Commissioner.

Exceptions cover permitted general and health situations, retention required by law or court order, technical impossibility or infeasibility after reasonable steps, and information strictly necessary to continue providing a requested good or service. Frivolous or vexatious requests can be refused outright. Platforms must assess each request, destroy what is not covered by an exception, and give written notice identifying what was destroyed, the reasons for any refusal, and available complaint mechanisms. Failure to give that notice is a civil penalty provision.

Australia currently has no general deletion right. IAB Australia published a data deletion framework explainer in November 2025 covering the IAB Tech Lab specification, noting at the time that the Privacy Act did not mandate general deletion and that reforms might create one.

Controller and processor enter the statute

Schedule 6 would insert section 16D. A processor is an APP entity that acts on another APP entity's documented written instructions and for purposes specified in those instructions. Contracted service providers for Commonwealth contracts are excluded.

Where a processor acts within instructions, its acts do not breach the APPs or a registered APP code, except APP 1 and APP 11, for which processors remain directly liable. The controller is taken to have done the act and to have committed any breach. Where a processor acts outside instructions, the exception falls away and the processor is directly responsible.

The vocabulary follows the direction other jurisdictions have taken. The SECURE Data Act, filed in the United States House on 21 April 2026, borrowed controller directly from European data protection language. In the Australian draft the classification carries a second consequence, because the controller-to-processor carve-out from the definition of trade depends on it. An intermediary that cannot show documented instructions confined to specified purposes is not a processor, and its onward disclosures for direct marketing purposes are trades.

Breach timelines compress to 72 hours

Schedule 3 separates a data breach from an eligible data breach. A new section 26WBA defines a data breach as unauthorised access to, unauthorised disclosure of, or loss of personal information in circumstances where unauthorised access or disclosure is likely.

Two new obligations attach to any data breach, not only eligible ones. Section 26WDA requires entities to take reasonable steps to implement practices, procedures and systems ensuring compliance with the notifiable data breach Part. Section 26WDB requires entities, as soon as practicable after becoming aware of reasonable grounds to believe or suspect a breach, to take reasonable steps to prevent or reduce harm. Failure on either counts as an interference with the privacy of an individual.

Where an eligible data breach is believed to have occurred, the entity would have 72 hours to give the Commissioner a statement. The consultation paper aligns the period with the Security of Critical Infrastructure Act 2018 and the Cyber Security Act 2024. The existing 30-day assessment window for suspected breaches remains. Statements must now include information about steps taken or proposed to reduce harm. Incomplete statements are permitted where a complete one is impossible or impracticable, on written notice identifying the gaps and the reason. Failure to provide any statement within 72 hours attracts a civil penalty.

Regulator powers and the emerging technology questions

The paper describes measures under development rather than drafted. Individuals would generally have to raise concerns with an entity before complaining to the Commissioner. Entities would have to provide accessible complaint mechanisms, respond within 60 days, and issue written decisions setting out outcomes and review options. Breaching those obligations would become an interference with privacy, bringing civil penalties, infringement notices and compliance notices into scope.

The Commissioner would gain an express power to group and determine multiple complaints, modelled on section 46PF of the Australian Human Rights Commission Act 1986. A broad power to require any person able to assist an investigation to provide reasonable assistance would be added, backed by a civil penalty regime and preserving defences for self-incrimination, legal professional privilege and journalists' sources. Subsection 43(8A) would be repealed, removing the restriction on briefing Ministers about investigations into private sector entities. The undefined reasonable excuse defence to information-gathering notices at section 66 would be replaced with a closed list.

The Commissioner would also gain express power to assess how social media platforms collect, use, retain and destroy personal information for age assurance purposes under the Social Media Minimum Age scheme. Australia's under-16 restrictions took effect on 10 December 2025 across nine named platforms with penalties up to approximately $49.5 million. Meta has since reported blocking 756,000 under-16 accounts across seven months.

A final section poses five questions on wearable surveillance technology and connected vehicles, asking whether the updated definitions are sufficient for emerging technology risks, whether collection is flexible enough to capture wearables, and whether consent can be meaningful when a device compromises the transparency of capture.

Why this matters to the marketing community

Australia's internet advertising market reached $18.4 billion in calendar 2025, growing 11.5%, and the first quarter of 2026 set a record at $4.9 billion, up 15.3%. Video alone reached $5.4 billion in calendar 2025. Retail media in the local market sits just above $2 billion and is projected to double by 2030. The consent to trade provision would apply across all of it.

Preparedness is uneven. An IAB Australia survey found 44% of respondents rated their understanding of the Tranche 1 reforms at 6 or higher on a ten-point scale, with 67% feeling at least somewhat prepared and 38% having deployed clean rooms. Those figures measured a smaller package than this one.

Tracking pixels were already an enforcement focus before this draft. Privacy law expert Peter Leonard told the IAB Australia Data and Privacy Summit in August 2025 that OAIC enforcement priorities included ad tech such as pixel tracking, citing regulator guidance that covert collection is likely an unfair means of collection. The exposure draft would move that position from guidance into a consent requirement with a defined exception set.

The pattern is not confined to Australia. France's CNIL adopted a recommendation on 12 March 2026 classifying email tracking pixels as trackers requiring consent under Article 82 of its data protection law. California's updated regulations took effect on 1 January 2026 with precise geolocation among the sensitive categories. Chrome on Android added an approximate location option in May 2026, capping precision before coordinates reach a site.

What separates the Australian draft is scope. It applies one fairness test to collection, use and disclosure alike, defines direct marketing to include cohort targeting, treats a routine programmatic disclosure as a trade, and makes the platform rather than the advertiser the default holder of the opt-out duty. Where the EEA built its regime around a lawful basis architecture and layered ePrivacy consent on top, this draft runs a principles-based fairness test with consent reserved for two acts: collecting sensitive information, and trading.

Submissions go to PrivacyReform@ag.gov.au and close on 18 September 2026.

Timeline

Summary

Who: The Australian Government, through the Attorney-General's Department, which drafted the bill and runs the consultation. The measures would bind APP entities including advertisers, publishers, platforms, demand-side and supply-side platforms, measurement vendors and data intermediaries operating in Australia. The Office of the Australian Information Commissioner, headed by Privacy Commissioner Carly Kind, would administer and enforce them.

What: An exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, running to six schedules, alongside a 42-page consultation paper describing roughly 40 proposals. Central changes include a consent requirement before trading personal information, with cookie and pixel disclosures in programmatic advertising named as an example of a trade; a single fair and reasonable test replacing APPs 3, 4 and 6; a rewritten direct marketing principle covering cohort targeting; precise geolocation tracking data within 500 metres classified as sensitive information; a 72-hour breach notification deadline; a right to erasure at platforms with $500 million in group gross revenue or 2.5 million monthly Australian users; and a statutory controller and processor split.

When: Consultation opened on Monday 31 August 2026 and closes on Friday 18 September 2026. Commencement dates are not filled in.

Where: Australia, amending the Privacy Act 1988 (Cth). The large digital platform revenue test reaches global group revenue regardless of source, so overseas parent entities count toward the threshold.

Why: The department describes the package as the next stage of uplifting Australian privacy law following the 2024 amendments, developed from about 900 written submissions. Stated aims are stronger safeguards for individuals, greater certainty for regulated entities, and more effective administration by the regulator, with emerging technologies including smart glasses, connected vehicles and AI inference named as drivers.