In Brief
On 31 August the government published a draft law that would change what most Australian businesses may do with customer data. The same morning the advertising industry reported a record $19.8 billion year online, about $700 for every Australian. Much of that money depends on practices the draft would restrict. Boards should find out how much of their own revenue is exposed, put a number on it and decide what to do, before the start date is set.
The day the ad boom met the privacy bill
Two announcements landed a few hours apart on 31 August 2026. First, the Attorney-General’s Department published its draft privacy bill: about 40 changes to the rules for collecting and using personal information. Then IAB Australia reported that online advertising had reached $19.8 billion for the year, up 14 per cent, its fastest growth in four years. That is about $700 for every person in the country.
Put the two side by side and the tension is obvious. Search ads earned $8.6 billion and video ads $5.9 billion. Most of that money works because advertisers know things about people: what they searched for, which sites they visited, what they are likely to buy next. Small tracking codes on websites, called pixels, pass that knowledge from one company to another. The draft would make many of those hand-offs ask permission first.
spent on internet advertising in Australia in FY26, up 14 per cent, reported on the day the draft privacy bill was released
IAB Australia Internet Advertising Revenue Report FY26, compiled by PwC, 31 August 2026
The bill is a draft. Consultation ran to 18 September, no start date has been set, and the text may change. Its direction is clear, though. The question it puts to a board is commercial rather than legal: how much of our revenue depends on data we could not justify using if this became law?
That is the test this article asks the board to run.
What the draft changes, in plain words
Take an everyday example. A shopper opens a retailer’s app, looks at running shoes, and closes it. That evening an ad for the same shoes appears on a news site. Three companies handled the shopper’s data to make that happen, and the shopper agreed to all of it in a privacy policy nobody read. Today that can be lawful, if the existing rules are followed. Multiply it across every app, every site and every ad in that $19.8 billion, and you have what the draft is aimed at. Each of those companies would have to answer a simpler and tougher question: was it fair and reasonable to collect, use or share this information at all?
The draft answers with seven questions, and together they read like an investment appraisal. Would a reasonable person expect it? Does it relate to what the business actually does? Was the business open about it? Could less information have done the job? Did the person have a genuine choice? Is the harm to the person in proportion to the benefit? And for a child, does it serve the child’s best interests?
No single factor decides; the question is whether the use is fair and reasonable overall. Every data-driven revenue line in a business covered by the Act would have to pass. Ticked box or not.
Two other changes reach the profit and loss statement. First, selling personal information, or passing it to other companies for advertising, would need valid, specific consent, with a few carve-outs. The government’s own consultation paper says this may include the pixels and cookies used in automated ad buying. Second, once a company has reasonable grounds to believe a serious data breach has occurred, it would have 72 hours to tell the regulator. Three days.
The bill. Privacy Amendment (Personal Data Protection) Bill 2026, exposure draft released 31 August 2026. Consultation ran to 18 September; no start date yet. It would replace three of the Australian Privacy Principles (3, 4 and 6).
The test (new APP 3). Collection, use and disclosure must be lawful and fair and reasonable, judged on seven factors overall.
Consent (new APP 4, section 6FC). Needed to collect sensitive information and to trade personal information, where trade means passing it on for value or for direct marketing; four carve-outs. Consent must be voluntary, informed, current, specific and unambiguous (section 6AAB).
Breaches. A serious data breach must be reported to the Commissioner within 72 hours of the company having reasonable grounds to believe it occurred. Detail and sources in the FAQ.
The public is already where the draft is heading. In the OAIC’s 2026 survey of 1,504 Australians, 96 per cent said selling or trading personal information is unfair, and 93 per cent said the same about using their data to train AI. Only one in ten said organisations’ practices are usually fair. Those numbers decide no case. They do show how a regulator, a journalist or a customer will read yours.
The regulator has already run this kind of test, under today’s law. In 2025 the Privacy Commissioner found that Kmart’s facial-recognition cameras, running in 28 stores from 2020 to 2022, scanned every shopper’s face to catch a small number of refund fraudsters. The Commissioner called that out of proportion to the problem and noted that less intrusive options existed. Kmart has taken the finding to the Administrative Review Tribunal.
Bunnings, on similar facts, won on the cameras and lost on the process. In February 2026 it persuaded that tribunal that its cameras were justified against serious retail crime, but it had not adequately told customers about the cameras and had never done a documented risk assessment. Both companies spent years inside the process over a data use nobody had priced. The draft would extend that exposure from cameras to every revenue line built on personal information.
In June 2026 the Commissioner also found that two health providers broke the law when advertising pixels on their websites collected visitors’ sensitive health information. Pixels, again.
Find the revenue that would need permission
A board can answer this question in a quarter, with no new spending.
Start with the revenue lines, not the systems. Ask management to list every revenue line, and every approved investment, that would not exist without collecting, inferring or sharing personal information. For a retailer that is the media network. For a publisher it is programmatic advertising, the automated auctions that sell ad space. For a lender it is a bought-in data feed that prices risk.
Test each line against the seven factors and the sharing rule. For each line, management should explain how the factors weigh in the overall fair-and-reasonable assessment, and whether any hand-off of data would count as a trade under the draft. Most companies will find the exposure in their marketing before they find it in a data sale.
Put a number on it. Illustrative only: a retail media line contributing $10 million might earn $3 million from data hand-offs that would need consent. If four in ten customers said no, $1.2 million of contribution would be at risk before any cost of redesign. Ask for the range and the assumptions. Refuse any paper that presents a refusal rate as a fact, because no Australian data on refusal rates exists yet.
Decide what to do with each line. There are three choices: redesign the data flow so it passes the test without needing consent, keep it behind a consent screen and accept the refusal rate, or exit. Consent does not fix an unfair practice. The test applies either way.
Record the decisions. Minute them, and name an executive who owns remediation. Add one approval condition: before capital is released, management must show on paper that a new data-dependent investment is fair and reasonable overall against the seven factors. That record is the first thing a regulator asks for. It is also ordinary governance.
Before the next capital plan
| Action | Owner | Timeline | Priority |
|---|---|---|---|
| List every revenue line and approved investment that depends on personal information, and test each against the seven proposed factors and the trading rule | CFO with CMO and privacy officer | Within 30 days | critical |
| Estimate contribution margin at risk per line as a range of consent refusal rates and redesign costs; present assumptions to the audit and risk committee | CFO | Within 90 days | high |
| Put in writing, with every advertising platform and data partner, who decides what the data is used for and who only acts on instructions | General counsel with CMO | Within 60 days | high |
| Adopt an approval condition for new data-dependent investment, name a remediation owner, and minute the decision | Board, advised by the risk committee | Next scheduled meeting | high |
The draft may change before any bill becomes law, and its start date is unknown. The list and the number will be needed whatever the final text says. The board should ask for both before it approves the next capital plan. The first question to management is simple: which of our revenue lines could we not justify if this became law?
Before the next capital plan: which of our revenue lines could we not justify if this became law, and what is the margin at risk?
Questions for Leadership
Which of our revenue lines would not exist without collecting, inferring or sharing personal information?
The board cannot size the exposure until management has listed the lines that carry it.
For each of those lines, could management explain today why the data use is fair and reasonable, without relying on a tick-box consent?
Consent would no longer be enough on its own, as the Kmart and Bunnings cases show.
Which of our data hand-offs to advertising platforms would count as a trade under the draft, and need valid consent?
The refusal rate on that permission is a revenue variable nobody has measured.
What is the contribution margin at risk, as a range with stated assumptions?
A single figure invites false confidence; a range with assumptions can be challenged and owned.
What approval condition will we attach to new data-dependent investment while the start date is unknown?
Capital committed to a data flow that fails the test is capital committed to a remediation project.
The Bottom Line
Treat the draft as a stress test of the data business model. List the revenue lines that depend on personal information, put a range on the margin at risk, and make new data-dependent investment pass the test on paper before capital is released.
Frequently Asked Questions
What does the draft leave out?
Several things boards might expect. The exposure draft keeps the small business exemption, so businesses with annual turnover of $3 million or less stay outside the Act unless an exception applies, such as providing a health service or trading in personal information, and the draft changes how that trading exception works. It keeps the employee records exemption. It creates no general right for individuals to sue for a breach of the Australian Privacy Principles; the separate statutory tort for serious invasions of privacy already exists from the 2024 amendments. It does not mandate privacy impact assessments. And its commencement table is blank, so the start date and any transition period are unknown until the government settles them.
Is any of this law yet?
No. The Bill is an exposure draft and its commencement table is blank; the consultation paper says application and transitional provisions will be added once settled. The draft may change. What is already law comes from the 2024 amendments: a statutory tort for serious invasions of privacy, tiered civil penalties, and automated-decision transparency in privacy policies from 10 December 2026. Boards should plan on the draft changing in detail while assuming its direction survives: a substantive fairness test and a consent gate on trading personal information.
What counts as trading personal information?
Under proposed section 6FC, a disclosure is a trade if it is made for money or other consideration, or for the purposes of direct marketing. The consultation paper says direct marketing disclosures are read broadly and may include cookies or pixels in programmatic advertising. Four carve-outs apply: a disclosure needed to provide a product or service the person requested from the recipient; a disclosure incidental to a business takeover whose main purpose is not selling information; a disclosure to a processor acting on documented instructions; and fraud-related disclosures that meet the section's recipient and necessity conditions.
Does an ad-supported service escape the consent rule if users accept advertising?
No. The ad-supported-service provision concerns opting out of direct marketing. A service that earns revenue from marketing to its users could offer different terms to users who decline, provided the terms give genuine choice and avoid dark patterns. It does not touch the separate requirement to obtain consent before trading personal information. The consultation paper is explicit: marketing needs no consent, trading does. A user who accepts advertising on a platform has not consented to that platform passing their information to a third party for value.
How should management estimate the margin at risk?
Start with the revenue line, then trace the personal information it depends on and the hand-offs it makes. For each hand-off, decide whether it would be a trade under the proposed definition or fall within a carve-out. For lines that would need consent, model a range of refusal rates rather than one figure, because no Australian data on refusal under the proposed standard exists yet. Subtract the cost of redesign and of consent infrastructure. Present the result as a range with stated assumptions, label any worked example as illustrative, and expect the board to challenge the assumptions rather than accept a point estimate.