Privacy Act Overhaul to Strengthen 72-Hour Breach Notification Deadline


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Rapid Overview

  • Under new legislation, Australian organisations might soon be required to inform the Information Commissioner of data breaches within a 72-hour timeframe.
  • The limited erasure right will apply solely to major digital platforms that satisfy certain revenue or user criteria.
  • Smart glasses pose privacy risks but are not included in the proposed legislative alterations regarding personal use.

Proposed 72-Hour Breach Notification Obligation

Under draft legislation introduced by the Attorney-General’s department, Australian organisations are mandated to notify the Information Commissioner of an eligible data breach within 72 hours. The Privacy Amendment (Personal Data Protection) Bill 2026 intends to replace the existing “as soon as practicable” criterion with a definitive deadline. This corresponds with current cyber regulation timelines outlined in the Security of Critical Infrastructure Act 2018 and the Cyber Security Act 2024.

Retention of the Two-Stage Breach Evaluation

The proposed bill keeps the current 30-day period for evaluating suspected breaches. Once there are reasonable grounds for suspecting a breach, the 72-hour notification countdown starts. Organisations may file an incomplete report with a rationale if a complete statement cannot be presented within the specified timeframe. Not reporting may result in infringement or compliance notices.

Introduction of a Restricted Erasure Right

The proposed legislation brings forth a restricted erasure right that applies exclusively to large digital platforms as outlined by the Online Safety Act 2021. To qualify, platforms must achieve a gross revenue of $500m or have 2.5 million Australian users monthly. They are required to remove personal information upon request unless certain exceptions are applicable.

Smart Glasses and Privacy Issues

Although the proposed legislation recognizes the privacy risks linked with smart glasses, it does not intend to prohibit them for personal use. The Privacy Act does not apply to individuals using these devices for personal purposes. When regulated entities gather data via wearables, compliance with privacy laws is necessary, which includes acquiring consent for sensitive data collection.

Conclusion

The suggested amendments to the Privacy Act seek to bolster data breach reporting obligations, introduce a restricted erasure right for major digital platforms, and address privacy concerns associated with smart glasses without enforcing additional restrictions on personal use. These modifications reflect continual efforts to modernize Australia’s privacy framework in light of technological developments.

Reader questions

Frequently asked questions

Fast answers to the questions readers ask most about Privacy Act Overhaul to Strengthen 72-Hour Breach Notification Deadline.

What is the updated reporting time for data breaches?

The proposed legislation mandates organisations to report eligible data breaches to the Information Commissioner within 72 hours.

Is the new erasure right applicable to all companies?

No, the erasure right is limited to large digital platforms that meet specific revenue or user criteria.

Are smart glasses prohibited under the new rules?

No, the legislation does not recommend banning smart glasses for personal use, although it acknowledges related privacy issues.

What is the process for the two-stage breach notification?

Organisations have a 30-day window to evaluate a suspected breach, followed by 72 hours to notify the Information Commissioner if a breach is verified.

What consequences arise for failing to report a breach within 72 hours?

Not reporting within the 72-hour timeframe may lead to an infringement or compliance notice.

What exceptions are in place for the erasure right?

Exceptions include law enforcement, legal retention obligations, technical impossibility, trivial requests, and ongoing service requirements.

Posted by Matthew Miller

Matthew Miller is a Brisbane-based Consumer Technology Editor at Techbest covering breaking Australia tech news.

Leave a Reply

Your email address will not be published. Required fields are marked *