The draft proposals released on 31 August include a “fair and reasonable” test for how personal information is handled, consent requirements for sensitive information and data trading, a right to erasure for large platforms, and a requirement to notify the Information Commissioner of a breach within 72 hours of having reasonable grounds to believe it has occurred. Consultation runs to 18 September, and a bill is reportedly expected later in 2026.

The 72-hour clock is the part most small businesses will feel first. Under today’s Notifiable Data Breaches scheme, organisations have up to 30 days to assess a suspected breach. Seventy-two hours means knowing what personal information you hold, where it lives and who makes the call — before anything happens. The summaries published so far don’t address the $3 million small-business exemption, so watch that one.

None of this is law yet, and drafts change. But the direction hasn’t changed in three years: faster notification, higher standards, fewer exemptions. The work that prepares you — a data inventory, an incident response plan with the notification steps written down, and clearing out data you no longer need — pays off whatever the final wording.

What it means for your businessStart working to a 72-hour breach timeline now. Know what personal information you hold, where it lives, and who decides whether to notify.
Source & referenceMcCullough Robertson — Privacy Act reforms: tranche 2 proposals ↑