By Raymond Vale · 2026-09-29 · 18 min read

With the 2026 reforms to the Australia Privacy Act, the way businesses go about data trading, targeted advertising and the use of customer lists could be altered. The main thrust of the proposal is to do away with APP 7 in favour of a fairness test on certain data uses, firmer consent standards and a definition of direct marketing that is not tied to any one technology. Detailed APP guideline updates outline these significant changes, including new rules on automated decision-making under the Privacy Act amendments.

One should consider these reforms as they stand, proposed and not yet settled obligations. While it is prudent for a business to get its data operations in order, any alteration to customer communications would be best made after checking the final legislative text and the transitional rules and when they are due to commence. Raymond Vale has put together this guide to set out what will have an impact in practice; there is no point in acting as if a bill were already law. Regulatory reform seldom affords legal certainty on time.

The Way Things Are Heading in Australia

professionals reviewing privacy documents and laptops

In the course of discussing the 2026 Privacy Act changes, the emphasis is on bringing some clarity to the rules for modern advertising. These developments also connect with online ad privacy regulations. This is necessary given that a few clicks can see customer data pass from retail databases and email platforms to social media audiences, analytics and programmatic media buying.

There is a human element to the direction of the reform too. The expectation is that individuals will have more say over their personal information being put to use by businesses for profiling or marketing. In turn, those businesses must be able to demonstrate their approach is fair and transparent and has a legitimate purpose behind it.

What is being aimed at

The Australian privacy reform bill as put forward is likely to have an effect on automated decision-making of a sort, as well as data trading and direct and targeted advertising. It could also make short work of the broad wording in a privacy policy where a person might reasonably think his information would be put to another use.

And it is not just a matter of email or SMS. With a technology-neutral definition, marketing via mobile apps, websites, loyalty schemes, connected devices or even channels not yet in vogue could be encompassed.

As the public authority for enforcement and guidance under the 1988 Privacy Act, the Office of the Australian Information Commissioner is the one to watch. Keep an eye on OAIC material, such as its review and reform information, since the legislation may take a different shape before it is done.

Current Law and the Proposal

For organisations under the Act, APP 7 is the present framework for direct marketing. The replacement on the table will be more forthright on the need for express consent, the right to object and the conditions under which marketing is allowed.

But do not read into it that every marketing email is going to want a new form or that a standing relationship with a customer is now off limits. What will stand up to scrutiny is whether the business can account for the source of the information, the choice on offer and its relationship with the individual.

It would be unwise to proclaim the rules have been changed. One would be better to say the 2026 reforms will probably mean more evidence is called for in making responsible decisions on data sharing and marketing.

Making the APP 7 Replacement Work

This is of some import as it has the potential to align the rules of direct marketing with the realities of advertising. An advert placed by one business may have started with a purchase, gone via a loyalty platform and been turned into a statistical audience without the person ever knowing.

Consequently new obligations will look at the activity in its entirety, not merely the text or email at the end of it. Old ways of thinking will not hold up.

A Wider Definition of Direct Marketing

In the normal course of things, direct marketing is the communication or use of information to put goods or services before people who can be identified. Under a neutral definition this could be personalised content on a web page, recommendations based on what an individual has been doing or lookalike audiences.

The dividing line is between the general and the particular. You will not find much in the way of direct marketing or profiling questions with a billboard on the Stuart Highway. But an advert a platform has put in front of you because it has defined an audience from your purchase history is quite another matter.

Document why the person would expect the activity and what data was used to build the audience. Relying on “the platform did it” is no strategy for compliance and tends to lead to an uncomfortable meeting.

The Necessity of a Meaningful Choice

In matters of consent, what is at stake is greatest when the marketing use is one a person would not put down to reasonable expectation, or where there is disclosure of information for marketing to a third party, or sensitive data and in-depth profiling are in play. Any express consent given has to be voluntary, informed and specific, with the business having a record it can call on.

One will not find a firm basis for more risky activity in a pre-ticked box or some vague pronouncement that data might be put to “related purposes”, nor in an acceptance that is bundled in. The individual needs to know how he or she can withdraw consent, who is in receipt of the information and what is going to transpire.

Where it can be done, businesses ought to keep consent apart from other terms. To make a purchase contingent on putting up with targeted advertising of no necessity is open to question on fairness grounds if the person is left with little option.

Direct Marketing Rules: A Technology-Neutral View

By defining things in a technology-neutral manner one can stave off privacy obligations becoming obsolete with the advent of a new channel. This will encompass the likes of email and SMS but also newer systems that read location or purchasing signals to divine preferences.

For the individual this is to be welcomed; protections should be in place whether the marketing comes via an app, a letterbox or a smart TV. For the business it is less easy as the compliance analysis has to be of the activity’s purpose and effect, not merely its technical description.

How It Plays Out

Promotional emails to a list, a personalised offer in an account portal, retargeting off website activity, social ads made possible by uploaded contacts and messages from a loyalty profile are all likely examples. Then there are service-related or transactional activities needed to deliver a product which are not direct marketing per se. But a business would do well not to have a service message stand in as a flimsy cover for a sales drive.

Care is called for in audience segmentation. A “recent customers” segment is unremarkable. Build one on inferred health or financial stress, relationship status or the like and the risk is considerably higher, even if such terminology does not appear in the campaign plan.

A Matter of Fairness

Under the proposed test, or fair and reasonable test, the question will be whether the practice is fair under the circumstances. One may look at the strength of the relationship, the consequences of the marketing, the kind of information and the person’s expectations, and if he or she could have stayed out of it.

It is not as simple as ticking a box for “consent obtained”. There is the case of someone who has put his name to broad terms without realising his purchase history is being collated with other data to forecast behaviour. Consent is of assistance but it does not render any use proportionate.

From my experience in customer-facing roles I have seen that people will not object to communication put before them in plain terms. They do when a business appears to have too much knowledge and puts forward no obvious exit.

On Data Trading and Ads

In Australia the rules around data trading will probably come under the microscope since the act of trading can put distance between the original collection and the subsequent marketing. A customer hands over details to put shoes in the bag and later finds some other organisation making an advertising audience of them. Expectations have a way of deflating in that space.

The prudent course is to map every disclosure and determine if the person was aware of it when the data was taken. Do not be under the impression that a lengthy privacy policy is a substitute for informed consent.

An express request is best served when it lays out the data and the type of marketing, the recipients and the process for withdrawal. Put the date, the channel, the person’s identity and the wording in the records, as well as any withdrawal.

Consent management has to deal with reality. An unsubscribe from a promotional email means the business has to see that connected systems do not put the same marketing in front of the person by another means. A suppression list is of no value unless it gets to the agency, vendor and platform.

And if data is to be sold or licensed for another’s marketing, ask if the individual would have foreseen it. If not, amending the privacy policy after the fact is no remedy.

Let Statistics Inform You

Rather than go on assumptions, measure your own marketing signals. Things like opt-out and complaint rates, requests for deletion, the number of unmatched records and how often you employ third-party audience data are all worth keeping track of.

The numbers are not evidence of compliance, they show where the friction is. Take a spike in complaints once you have put a new audience segment in front of them and one can surmise the campaign has been too intrusive. And a paucity of opt-outs is no guarantee that the practice was understood; one should not mistake silence for acquiescence.

Marketing Activity Key Question Practical Evidence
Existing customer email Is this promotion something the individual would anticipate? Look at the opt-out log, relationship record and what the purchase history tells you.
Third-party customer list Was there proper disclosure and permission? Consent wording, source contract and data-flow record will tell.
Targeted online advertising What made up the audience? Campaign approval, platform settings and the audience definition.
Data trading Did the person expect the commercial use down the line? Evidence of consent, recipient details and the disclosure register.
Automated recommendation Any chance of an unfair outcome for the person? Human review process, testing record and a summary of the logic.

Risks in Online Behavioural Advertising

In Australia the rules on online behavioural advertising can be more of a headache to manage if a business is putting first-party data together with what it gets from analytics tools, data brokers or advertising platforms. The question goes beyond a personalised advert to how the profile came to be and whether the individual was aware of it.

While “online ad privacy regulations” is a convenient way of putting it, a more thorough internal analysis is called for. A business has to be in a position to say if a platform is in possession of identifiable information, if it is building a persistent profile, if another organisation is making use of the data and if the business has any control over its deletion.

Programmatic Buying and Segmentation

With programmatic media buying there are advertisers, agencies, publishers, demand-side and measurement providers all in play, each with their own contracts, retention and settings. You cannot be sure of your privacy obligations if you cannot account for the whole chain.

Make note of the approved purpose, exclusions, matching method and the origin of the audience prior to a campaign going live. Put it to vendors if they are using the data to put together larger audiences or to better their own products; it may be telling as to how the data is flowing.

Then there is Tealium and others in the data stack. Having a platform does not absolve a business of accountability. An understanding of the contractual controls, permissions and configuration is still required.

Oversight of Automated Decisions

When a system is the arbiter of an offer, a service pathway, an exclusion or price, there is added risk. A marketing score is of little concern until it has an impact on treatment or reputation.

It is prudent to put audience rules through their paces for anything unreasonable and to have a human review option when the situation warrants. There should be a clear rationale for the key logic. Privacy impact assessments must extend to the campaign result as well as the database.

Vendor Controls and Customer Lists

Customer lists are where good intentions can run up against a messy reality. Between agency exports, old spreadsheets and former staff accounts a business may find it hard to substantiate the provenance of a contact or that an objection was put to rest.

Compliance with 2026 privacy reform demands some unglamorous housekeeping of the data. It is better than having to tell a regulator why a bloke’s personal spreadsheet and three systems were still sending offers to a customer who has been deleted.

An Audit of What Businesses Should Do

Do not accept vendor contracts that simply state the supplier will abide by the law. They need to cover the nitty-gritty: who is to answer an access request or delete a record, who will be looking into a breach, the timeliness of communication between parties and if the vendor has licence to use the data itself.

Updating Policies

Use plain language for a privacy policy in setting out matters of consent, data matching, overseas handling and targeted advertising. But do not make promises of absolute control the systems cannot support.

There also needs to be version control. Retain earlier versions and have a record of when customers were presented with them. Such evidence is important in establishing what was put before people at time of collection.

The need to be ready for privacy reform well in advance of any final start date is something Norton Rose Fulbright and their legal colleagues have made a point of. Firms would do well to seek counsel on practices that carry more risk, such as data trading or the making of automated decisions and sensitive profiling.

Practical Compliance By Scenario

There are different pressure points for different businesses. A retailer putting millions of records before an advertising platform has to have controls in place that a small salon with its newsletter never would, yet both must give an honest answer as to why a particular individual is being sent a message.

To make sense of the wide ranging direct marketing changes under the Privacy Act and arrive at workable decisions, consider these scenarios.

If You Only Have One Day

Take the three biggest customer lists and the campaign due to be put out and begin there. Put a hold on anything where the third-party source is not clear, see that your suppression lists are doing their job and get from every vendor an account in plain English of the data it is getting.

Make an entry in the internal approval record with the legal basis, the audience, the purpose and how a customer might withdraw; you will want to note the experience they can expect too. It is not going to amount to a full reform programme but it staves off the kind of mistake one makes by sending first and inquiring after a complaint is in hand.

Who Needs Extra Care

Automated systems for determining treatment or offers, targeting of children or the vulnerable, sensitive inferences, matching online identities to offline purchases and the purchase of customer lists are all high-risk.

None of this is off limits per se but a documented fairness assessment is called for, and a privacy impact assessment in some cases. Those new to compliance should not put their faith in a template; the way the data flows is what counts.

Expectation Versus Reality

It is expected that a privacy policy is cover for any marketing use. In reality a regulator or other will want to know if the use was fairly put across and reasonable to expect.

An unsubscribe link is thought to be the cure-all, but while it may close off one channel another system can be left to profile or advertise to the person.

And while a vendor is supposed to be on top of platform settings, the organisation behind the campaign is the one accountable for its data operations.

Frequently Asked Questions On Reform

What is in store for Australia in 2026?

One can anticipate firmer protections for direct marketing, broader expectations of fairness and a proposed successor to APP 7 along with more transparent rules on data trading and targeted advertising. But until the legislation is put to bed the fine print of the legal requirements and any carve-outs remain to be confirmed.

How should privacy policies be updated for 2026?

In language anyone can understand, set out matters of retention and withdrawal, data sharing, the use of automation and so forth. The policy has to be in line with the way things are done with vendors and systems; a change of words when the operations are the same is no solution.

Is Australia in favour of Digital ID?

That is a matter of digital regulation in its own right. While a digital ID could be used to gain access to services or prove who one is, it does not in itself give leave for behavioural advertising or data trading. Each use case should be measured against one’s privacy obligations.

What has changed with the Privacy Act in Australia of late?

The thrust of the reforms is towards stronger privacy and there are proposals touching on consent, fairness and the like. Do not go by a summary for a live campaign without checking the OAIC for guidance and separating what is enacted from what is only proposed.

Not of itself. For a start it has to be voluntary and specific and informed. The practice in its entirety still has to be fair. And one should be sure the consent extends to the method of profiling, the purpose and the actual recipients.

Prepare Before The Rules Land

online marketing and digital privacy

The 2026 reforms to the Australian Privacy Act have a simple enough message: be in a position to explain the customer experience, know your audience and your data. Go over your consent and vendor contracts, your breach response and the wording of the privacy policy before launching a campaign.

Raymond Vale has an unglamorous piece of advice for the end: ensure opting out is possible all round, keep a register and put down your decisions. When the next phase of the law comes around the organisations in the best shape will not be the ones with the most prolix policy but those who can put it to you in a calm way that their marketing is under control and fair.