Opinion

Exposure draft proposes overhaul of Privacy Act to address tech sector dominance

The government’s latest draft introduces a “fair and reasonable” test and a right to erasure, aiming to modernise legislation drafted four decades ago.

Editorial persona
Jonah Pike
Investigations Editor
Published
Draft
Source: The Guardian Opinion · View original source
Tech giants are trying to obliterate privacy. Australia has a rare chance to take back part of their power | Lizzie O'Shea
POLICY

The Australian government has released an exposure draft proposing significant reforms to the Privacy Act, a move described as overdue given that the majority of the current legislation was drafted four decades ago. The proposals aim to align Australia’s regulatory framework more closely with jurisdictions such as Europe and California, addressing the growing influence of technology companies and the limitations of existing consent models.

Central to the draft is the introduction of a “fair and reasonable” test, which would replace the current tick-a-box consent model. This shift moves the onus away from individuals, who are often required to navigate complex terms and conditions, and instead requires companies to demonstrate that their collection and use of personal information are fair and reasonable. The government has also included provisions for a right to erasure, allowing individuals to request the deletion of their personal data, subject to specific carve-outs and limitations that remain under review.

The draft highlights the need for specific regulations regarding invasive technologies, particularly facial recognition, which is currently described as almost entirely unregulated in Australia. While some aspects of the proposed reforms may touch on this technology, the document suggests that more targeted rules are required to address its proliferation in everyday environments.

Enforcement mechanisms are a key focus of the proposal, which seeks to strengthen the Office of the Australian Information Commissioner (OAIC). The current regulator is considered under-resourced and outmatched in size compared to the large corporations it supervises. The draft also clarifies the role of courts in enforcing privacy rights and the digital duty of care, potentially allowing individuals to sue technology companies directly for harms experienced in Australia.

The need for stronger enforcement is underscored by recent international developments, including Meta’s US$17 billion settlement in the United States over child safety concerns. While the settlement has prompted improvements in the US, it remains unclear whether these changes will be applied to Meta’s Australian service. The draft suggests that allowing direct court action would help ensure that companies are held accountable for similar harms domestically.

Public support for these reforms appears strong, with 93% of Australians stating that protecting personal information is important and 87% reporting increased privacy concerns over the past five years. However, the exact timeline for the implementation of the proposed reforms has not yet been specified, leaving the final scope of the changes subject to further government review.

Continue reading

More from Opinion

Read next: Psychologists warn AI chatbots can deepen emotional dependency
Read next: AfD result prompts warning over normalisation of far-right politics
Read next: Guardian opinion urges federal human rights law to govern AI decisions