Home » CHANNEL NEWS » Australia’s Privacy Overhaul Puts Enterprises on 72-Hour Data Breach Reporting Clock

Australia’s Privacy Overhaul Puts Enterprises on 72-Hour Data Breach Reporting Clock

Draft privacy reforms seek to strengthen breach response, consent requirements and personal data protections as cyber and AI-related risks rise. The Australian Government has proposed a fixed 72-hour deadline for organisations to report eligible data breaches to the Office of the Australian Information Commissioner (OAIC) as part of the next phase of reforms to the country’s Privacy Act.

The proposal forms part of the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, released by the Attorney-General’s Department for public consultation. Under the proposed framework, the 72-hour period would begin once an organisation has reasonable grounds to believe that an eligible data breach has occurred. This would replace the existing requirement to notify the regulator “as soon as practicable”.

Organisations would still have up to 30 days to investigate a suspected breach and determine whether it meets the threshold for notification. However, once an eligible breach is confirmed, the new deadline would significantly reduce the time available for regulatory reporting. Where all details are not available within 72 hours, organisations may be able to submit an initial incomplete notification and provide additional information later.

The reforms come as Australia experiences increasing levels of data compromise. OAIC received 1,205 data breach notifications during 2025, an 8% increase over 2024 and the highest annual figure since mandatory breach reporting began in 2018. Malicious or criminal activity accounted for the majority of reported incidents, with healthcare and financial services among the most affected sectors.

Beyond breach reporting, the draft legislation proposes wider changes to Australia’s privacy regime, including stronger consent requirements, a new “fair and reasonable” standard for handling personal information, expanded definitions of personal information and new obligations around data security and breach-response processes. The proposed reforms would also introduce a limited right to erasure for large digital platforms meeting specified revenue or Australian-user thresholds, enabling individuals in certain circumstances to request deletion of their personal information.

The government said the reforms are intended to strengthen privacy protections as technologies such as artificial intelligence, connected devices and smart glasses create new ways of collecting and processing personal information.

The draft legislation is currently open for consultation, with submissions due by 18 September 2026. The proposals are not yet law and may change following industry and stakeholder feedback.

 

Check Also

JFrog Introduces the Software Supply Chain Traffic Controller: One Trusted Path for Every Software Package

JFrog Introduces the Software Supply Chain Traffic Controller: One Trusted Path for Every Software Package

Together with industry-leading SASE providers Zscaler, Cloudflare, and Netskope, JFrog enables organizations to control open …

Leave a Reply

Do NOT follow this link or you will be banned from the site!