Australia’s evolving privacy landscape: What's changed & what’s coming

Published on 23 April 2026

LW-2026-March-April

Article by Jaaden Morrall, Senior Workforce Advisor/Consultant and Angela Farmer, Workforce Advisor – Legal and Workforce

Australia is entering a transformative period in privacy regulation, with sweeping reforms already underway and additional obligations rolling out this year. These changes affect organisations at both the federal and state levels, and are reshaping how personal information must be handled, secured, and reported. For Queensland local governments, regulatory expectations are increasing substantially as the state finalises its staged rollout of mandatory privacy reforms.

Major privacy reforms already in effect

Australia’s privacy landscape shifted significantly following the passage of the Privacy and Other Legislation Amendment Bill 2024, which passed both Houses on 29 November 2024 and received Royal Assent on 10 December 2024, becoming the Privacy and Other Legislation Amendment Act 2024 (Cth). This Act introduced the first tranche of long‑awaited privacy reforms aimed at modernising the national framework.

Several high‑impact changes took effect immediately. One of the most notable is the creation of a criminal offence for doxxing1, with penalties of up to seven years’ imprisonment. The Office of the Australian Information Commissioner (OAIC) highlighted the significance of these reforms, noting that the enhanced enforcement powers and new civil penalty tiers come at a time of increasing privacy harms and growing public expectations for stronger protections.

The reforms also clarify the longstanding obligation for organisations to take ‘reasonable steps’ to protect personal information, explicitly requiring both technical and organisational security measures. In practice, this signals a move away from generic or informal security measures towards demonstrable, risk-based controls. In addition, a new ministerial ‘whitelist’ mechanism has been introduced to support secure overseas data transfers.

At the state level, Queensland has progressed parallel reforms through the Information Privacy and Other Legislation Amendment Act 2023 (IPOLA Act) delivering a substantial overhaul of the public‑sector privacy regime. As of 1 July 2025, all Queensland public sector agencies must comply with a Mandatory Notification of Data Breach (MNDB) scheme, requiring notification to the Queensland Information Commissioner and affected individuals when an eligible breach occurs. Agencies are required to act immediately to contain suspected breaches and conduct an assessment within 30 days. Failure to meet these obligations may expose agencies to regulatory scrutiny, complaints, and enforcement action. This represents a shift from discretionary disclosure to a legally mandated, time-bound reporting regime for privacy incidents.

New Queensland Privacy Principles (QPPs) also took effect, strengthening requirements around how personal information is managed across the state’s public sector.

What’s coming in 2026

Further reforms are scheduled to commence in 2026 at both the federal and state levels.

Nationally, organisations must prepare for new automated decision‑making (ADM) transparency obligations, which take effect on 10 December 2026. These rules require organisations to clearly disclose when meaningful decisions about individuals are made using automated processes or artificial intelligence. While these obligations will not capture all digital systems, they may apply where automated tools materially influence decisions that affect individuals.

Another major reform slated for 2026 is the introduction of the Children’s Online Privacy Code, which must be finalised and registered by 10 December 2026. This Code will create strict new obligations for any online service likely to be accessed by children, reflecting rising expectations for stronger protections around children’s data.

What these changes mean for Queensland local governments

For Queensland councils, 2026 is a pivotal year in the state’s privacy reform journey. Although the broader IPOLA reforms took effect for state agencies in 2025, local governments were granted a 12‑month transition period to prepare for the new obligations. This means that from 1 July 2026, all Queensland councils must fully comply with the Mandatory Data Breach Notification scheme.

This shift has major operational implications. Councils must ensure that they have the capability to identify, contain, assess, and report eligible data breaches within strict timeframes. The requirement to notify both the Queensland Information Commissioner and affected individuals means councils’ decisions about data breaches are no longer internal matters, but subject to external scrutiny and review.

Compliance also demands documented procedures, staff training, and a clear incident‑response framework capable of supporting a breach assessment within the 30 day limit. Alongside these obligations, councils will operate under the strengthened Queensland Privacy Principles, which place greater emphasis on responsible information handling, data minimisation, and secure storage practices.

These principles align Queensland’s public‑sector privacy framework with modern data‑governance standards and prepare Councils for integration into the broader statewide compliance environment.

The road ahead for local government

For Queensland councils, the combination of state‑based privacy reforms and national privacy changes creates a more complex compliance environment than ever before. Together, these reforms place greater emphasis on governance, documentation, and decision-making discipline, rather than reliance on informal practices. Councils will need to uplift their internal privacy practices, ensure staff are trained in recognising and responding to data breaches, and review their information management strategies to meet both state and federal requirements.

With automated decision‑making transparency obligations and children’s privacy protections taking effect nationally by late 2026, councils that deliver online services, manage citizen portals, or use digital systems for public engagement will also need to assess whether these new federal obligations apply to their operations.

Overall, 2026 is a critical year for Queensland local governments, with rising expectations for accountability, transparency, and responsible handling of personal information. Preparing early and embedding strong privacy governance processes will be essential as these changes continue to unfold.

What councils should be doing now

To prepare for full compliance by 1 July 2026, Queensland councils should:

  • Review and update privacy policies and procedures to align with the Queensland Privacy Principles.
  • Establish or refresh a data breach response plan, including internal reporting pathways and escalation processes.
  • Train staff to recognise and promptly report suspected data breaches.
  • Confirm roles and responsibilities for assessing breaches and determining notification obligations.
  • Review contracts with service providers to ensure privacy and breach response obligations are clearly addressed.
  • Assess whether council systems or online services use automated decision‑making and may be impacted by upcoming federal transparency requirements.

If you have any questions about how these changes apply to your council, please contact us on 07 3000 2148 or at Legal@peakservices.com.au

1doxxing is the act of publicly revealing someone’s private or identifying information online without their consent, often to intimidate, harass, or harm them