Evinact Director Jane Brimacombe and Senior Manager Mainaaz Oakley explore what Australia’s proposed Tranche 2 privacy reforms could mean for organisations using data, analytics and AI.
The Australian Government has released a new suite of proposed Tranche 2 privacy reforms designed to modernise Australia’s privacy framework for the digital age. For organisations increasingly using data, analytics and AI in their operations and decision-making, the implications extend well beyond compliance.
The reforms are set out in the Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026 and accompanying Consultation Paper, which are now open for feedback. (The Bill remains subject to further consideration by the Australian Government, and may change before legislation is introduced.)
They arrive as personal information plays a growing role in how organisations operate and make decisions. It’s no longer just collected and stored; it’s now used to shape who gets access to a service, how support is prioritised, or how a customer experience is personalised.
For organisations using data, analytics and AI this way, the reforms carry implications that extend beyond compliance. Privacy obligations have traditionally focused on how organisations collect, use, disclose, store and protect personal information. The proposed reforms build on this, with a stronger focus on whether that handling is fair and reasonable, and on addressing risks associated with newer technologies like AI and wearable devices.
For organisations, this raises a broader question than simply:
“Can we collect and use this personal information?”
Increasingly, organisations need to be able to answer:
“Can we explain why we’re using this personal information, whether that use is reasonable, and what safeguards are in place?”
This points to a broader view of organisational accountability. Organisations need to understand how personal information is used and protected, and be able to demonstrate that those uses are appropriate.
Privacy is becoming a broader governance issue
For many organisations, privacy has traditionally been treated primarily as a legal or compliance function. But as personal information becomes more deeply embedded in operations and decision-making, privacy increasingly intersects with governance, digital strategy, customer trust, service delivery and AI governance.
The implications will vary between organisations. For government, personal information may inform decisions about access to services, benefits or regulatory outcomes. For not-for-profits, it may influence how services are prioritised. For businesses, it may shape customer experiences, marketing, recruitment, pricing and risk management.
The common factor is that personal information is increasingly being used to support actions and decisions that affect people. That makes it increasingly important for organisations to know what personal information they hold, why it’s being used, where it flows and what controls apply.
It’s also a trust issue. People are more likely to trust organisations with their personal information when they can see that it’s being handled responsibly and appropriately. Trust is built not only through strong security and privacy controls, but through confidence that organisations understand how information is being used and can account for those uses.
What should organisations do now?
The reforms may change before legislation is introduced, so organisations don’t need to redesign their privacy frameworks around the current Exposure Draft. But they do provide a useful prompt to assess how well organisations understand and manage their personal information.
Organisations can start by asking some foundational questions:
- What personal information do we hold and where is it held?
- Why do we collect, use and retain it?
- Are we collecting or retaining more personal information than we need?
- Who has access to it, and is that access appropriate?
- How does personal information flow between systems, teams and third parties?
- Can we identify and respond quickly if personal information is compromised?
- Where is personal information being used in analytics or AI, and what safeguards are in place?
- Can we demonstrate that our use of personal information is appropriate, proportionate and consistent with people’s reasonable expectations?
If these questions are difficult to answer, that is often a sign personal information is not being governed as effectively as it could be. Addressing that gap requires more than policies. It requires a clear understanding of information assets, ownership, data flows, risks and controls across the organisation.
Speak to Evinact about strengthening privacy, data and AI governance in your organisation.




