15 September 2026

Privacy Act Tranche 2: What it means for marketing data, consent and audiences

broken smashed ice

This article is not written, or presented as legal advice nor opinion. Readers should neither act, nor rely on opinion(s) in this article and linked materials without seeking legal counsel.

In summary:

  • What: The Australian Government has released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, setting out the second tranche of proposed Privacy Act reforms.
  • Why it matters: The proposals could materially affect how marketers collect, use and share customer data, particularly across digital advertising and audience activation.
  • The big shift: Consent would still matter, but organisations would also need to show that their handling of personal information is fair and reasonable.
  • What else: Behavioural and derived information is more clearly brought into scope, precise geolocation tracking data would become sensitive information, and responsibilities between data controllers and processors would become clearer.
  • What marketers should do: Review consent, customer data flows, third-party sharing, audience practices and how information is classified across the marketing ecosystem.

The direction was already clear. The consequences are becoming clearer.

The Australian Government has released the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, giving us the first detailed look at the second tranche of proposed reforms to Australia’s privacy laws.

There is a lot in the draft, but several proposals are particularly relevant to marketing, data and measurement teams. They cover consent, what constitutes personal information, how information is shared for direct marketing and the accountability organisations have for the way customer data is handled.

These aren’t entirely new issues. Throughout this year, the OAIC’s guidance and enforcement activity has already pointed towards greater accountability for how personal information is collected and used. What Tranche 2 does is potentially give those principles much firmer legislative footing.

The Bill is still an exposure draft and may change, but the implications for existing digital marketing practices are significant enough to warrant attention now.

One of the most significant proposals is the introduction of a requirement that collecting, using or disclosing personal information must be “fair and reasonable” in the circumstances, as well as lawful.

This moves the privacy conversation beyond relying primarily on notice and consent.

Organisations would need to consider whether the way they handle information is necessary and proportionate to the purpose, whether an individual would reasonably expect it and whether they have genuine choice.

Consent still matters, but it would not necessarily make every subsequent use of personal information fair and reasonable.

We have previously written about the shift away from treating “obtained consent” as the end of the conversation, however, the exposure draft provides a clearer picture of what that could mean in practice.

For marketers, the question becomes not only whether permission exists, but whether the organisation can justify why the information is needed and how it is being used.

The exposure draft proposes that consent must be voluntary, informed, current, specific and unambiguous.

This is relevant well beyond the consent banner. Customer permissions can sit across websites, apps, CRM systems, marketing preferences and advertising platforms, while the purposes for which information is used can change over time.

If the proposals go ahead, organisations will need to understand what consent they hold, what it actually covers and whether it still reflects how the information is being used today.

Sharing customer data for marketing is an area to watch

The draft also introduces the concept of “trading” personal information. A disclosure would be considered a trade where personal information is disclosed for money or other consideration, or for the purposes of direct marketing. Subject to exceptions, consent would be required.

For marketers, this puts customer-list activation, audience sharing and some third-party advertising data flows into focus.

It doesn’t mean every pixel, audience upload or advertising integration should automatically be treated the same way. The important question is what information is actually being disclosed, who receives it and what it is being used for.

This is consistent with what we wrote following the OAIC’s recent pixel determinations: the technology itself isn’t necessarily the problem. The issue is understanding what data is being collected and shared, and being accountable for it.

Audience segmentation needs closer attention

The implications for audience segmentation are particularly important, but not entirely settled.

The draft more clearly brings behaviours, preferences and patterns of activity into the definition of personal information where that information relates to an identifiable or reasonably identifiable individual.

That has obvious implications for digital marketing, where audiences are often built around what people do rather than who they are.

However, questions remain around effectively anonymised audience segments, inferences made at scale and when particular forms of segment-based advertising would constitute direct marketing.

For marketers, the takeaway isn’t that audience segmentation suddenly becomes off limits, but more so the way audiences are created, curated, shared and activated needs to be better understood, particularly where personal or sensitive information is involved.

Behavioural and derived information is more clearly in scope

The proposed definition of personal information makes clear that an individual’s name or legal identity does not necessarily need to be known. Information can still be personal where it allows someone to be recognised or singled out, including through identifiers, location data, behaviours, preferences and patterns of activity.

The draft also recognises information generated or derived through an organisation’s own processes, systems, observations or measurements.

That is particularly relevant to analytics and AI. Organisations increasingly derive audience classifications, propensity scores, likely interests and other attributes from customer behaviour rather than collecting that information directly. As we’ve previously explored, privacy, AI and data governance are increasingly becoming part of the same conversation.

As AI becomes more embedded in marketing and measurement, organisations therefore need to understand not only what customers provide, but what their systems create from that information and how those outputs are subsequently used.

Precise geolocation would become sensitive information

The exposure draft also proposes adding precise geolocation tracking data to the definition of sensitive information.

The proposed definition covers information generated or derived from a device or other technology that identifies an individual’s location within 500 metres and is collected and held by reference to their location over time.

For organisations using location data, apps, connected devices or location-based customer insights, this is an important distinction because sensitive information attracts additional privacy requirements.

Who is responsible would become clearer

Another important proposal is the introduction of a distinction between data controllers and processors.

Under the draft, a processor acting on documented instructions from a controller would have different responsibilities under the Australian Privacy Principles, with the controller generally accountable for the instructed handling of personal information.

For digital marketing, this matters because customer information often passes through multiple parties, including advertisers, agencies, technology providers and advertising platforms.

It also builds on a point we’ve made previously: outsourcing technology or implementation does not mean organisations can simply outsource responsibility for customer data.

Clearer controller and processor roles should make it even more important to understand who is doing what with information across multi-party adtech and martech environments.

Louder’s recommendations

The Bill is still in draft, so organisations should be careful about making significant changes based on provisions that may evolve, however, there is plenty marketers can do now to understand where they stand.

We recommend:

  • Review consent: Understand what customers have consented to, when that consent was obtained and whether it still reflects how their information is being used.
  • Map customer data flows: Know what information is collected across websites, apps, CRM, analytics and advertising platforms, where it goes and which parties have access to it.
  • Review third-party sharing: Understand what pixels, cookies, APIs, customer-list uploads and advertising integrations collect, disclose and share, and for what purpose.
  • Review audience practices: Understand how audiences are created, what information is used to build them and how those audiences are subsequently shared and activated.
  • Improve data classification: Know what information you hold and how it should be treated, particularly where behavioural, derived or sensitive information is involved.
  • Understand derived information: Identify the attributes, scores and inferences being generated from customer behaviour, particularly through analytics and AI.
  • Check location data: Understand whether precise geolocation tracking data is being collected and how it is being used.
  • Clarify responsibilities: Understand the roles of agencies, platforms and technology partners handling personal information and ensure responsibilities are clearly defined.
  • Apply the fair and reasonable test: Consider not only whether consent exists, but whether the information is necessary, the use is proportionate and the customer would reasonably expect it.

Get in touch

Get in touch with Louder to discuss how evolving privacy requirements may affect your consent, customer data, measurement and marketing technology.



About Andrew Hughes

Andrew is a Consultant and Partner at Louder, focussing on how clients can maximise their return from digital media investments.