AI Agents and the Australian Privacy Act Review: What Outbound Teams Should Prepare For - Zian AI

AI Agents and the Australian Privacy Act Review: What Outbound Teams Should Prepare For

Australia’s privacy overhaul is not one event — it is a staged program, and teams treating it as a single future deadline are already behind on the parts that are law today. The Privacy Act Review produced 116 reform proposals; the first tranche was legislated in December 2024 and commences in pieces, while the second tranche — the one aimed squarely at direct marketing — is still being drafted. If your team runs AI agents that call, text or email prospects, each stage lands somewhere in your workflow.

At a glance: The Privacy and Other Legislation Amendment Act 2024 (Cth) commences in stages. A statutory tort for serious invasions of privacy has been live since 10 June 2025 — actionable without proof of damage. Automated decision-making (ADM) transparency in privacy policies is due by 10 December 2026. The “tranche 2” reforms — an unqualified direct-marketing opt-out, a fair-and-reasonable test, removal of the small business exemption — are agreed in principle but, as at August 2026, not yet before Parliament. Fix data provenance and ADM disclosure now; build opt-out plumbing before it becomes mandatory.

This is general information for sales and RevOps teams, current as at 20 August 2026 — not legal advice. Commencement dates are verified against the legislation and regulator pages linked below, but your obligations depend on your circumstances; talk to a qualified Australian privacy lawyer.

Where the reform actually stands in August 2026

The sequence matters, so here it is without the vendor-blog fog. The Attorney-General’s Department released the Privacy Act Review Report in February 2023 with 116 proposals, and the Government responded on 28 September 2023. The Privacy and Other Legislation Amendment Act 2024 (No. 128, 2024) — the first tranche — received Royal Assent on 10 December 2024 and, per the department, progresses 23 of those proposals. Everything else is tranche 2: the department says it “will continue to engage with stakeholders through targeted consultation on draft provisions on remaining proposals the government agreed or agreed in principle to progress”. At the time of writing, no tranche-2 bill has been introduced to Parliament.

Reform item Status (August 2026) Commencement What it means for outbound
Statutory tort for serious invasions of privacy In force (Schedule 2, Privacy Act) 10 June 2025 Reckless data handling in prospecting is now directly suable — no proof of damage needed
Stronger OAIC enforcement (mid-tier civil penalties, infringement notices) In force 11 December 2024 Sub-catastrophic breaches are now cheaply enforceable — the “too small to pursue” era is over
ADM transparency in privacy policies (APP 1) Legislated, commencing 10 December 2026 Automated decisions that significantly affect people must be disclosed in your privacy policy
Children’s Online Privacy Code Legislated; OAIC must register the code By 10 December 2026 Mostly out of scope for B2B outbound, but relevant if your funnel touches under-18s
Unqualified opt-out of direct marketing (proposal 20.2) Agreed in principle — not yet law No bill, no date Opt-out will stop being channel-by-channel and become universal
Fair-and-reasonable test (proposal 12.1) Agreed in principle — not yet law No bill, no date Consent will no longer launder unfair data use, including for AI targeting
Small business exemption removal (proposal 6.1) Agreed in principle, conditional on impact analysis No bill, no date Sub-$3m-turnover teams should stop assuming the Privacy Act is someone else’s problem

Already in force: the statutory tort is the sleeper risk for outbound

Most commentary on the tort focuses on paparazzi-style intrusion. Outbound teams should read the second limb. Under Schedule 2 of the Privacy Act, an individual has a cause of action where someone invades their privacy by intruding on their seclusion or by misusing information that relates to them, they had a reasonable expectation of privacy, the invasion was intentional or reckless, it was serious, and the public interest in their privacy outweighs any countervailing public interest. Two design choices in the Act deserve a highlight:

  • No proof of damage. The Act states the invasion “is actionable without proof of damage” — a plaintiff does not need to show financial loss.
  • Real money. Damages for non-economic loss plus any exemplary or punitive damages (available in exceptional circumstances) are capped at the greater of $478,550 and the maximum damages for non-economic loss available in defamation proceedings.

The OAIC’s summary adds three points worth knowing: the tort applies to entities that are not APP entities at all (the small business exemption does not shield you here); consent and lawful authority are defences; and claims must generally be brought within the earlier of one year from the plaintiff becoming aware of the invasion and three years from its occurrence.

Why does this matter to AI outreach? Because “reckless” is a fault standard a messy prospecting stack can meet. Scraped personal data from sources you never audited, purchased lists with no provenance, call recordings retained indefinitely and shared with unvetted vendors — if that pipeline seriously misuses information about an identifiable person, the tort gives them a direct route to court that did not exist before June 2025. The fix is unglamorous: know where every field in your CRM came from, and be able to show it.

The hard deadline: ADM transparency by 10 December 2026

The timely item is Schedule 1, Part 15 of the Amendment Act, which commences on 10 December 2026 — the Act’s commencement table sets it at 24 months from Royal Assent. From that date, APP entities that have arranged for a computer program to make — or do something substantially and directly related to making — a decision that could reasonably be expected to significantly affect an individual’s rights or interests, using their personal information, must disclose in their privacy policy the kinds of personal information used and the kinds of decisions made. That test is the Act’s own wording; the OAIC confirms the commencement date and the two disclosure requirements.

The honest scoping question is which of your automated calls actually “significantly affect rights or interests”. An AI agent drafting a follow-up email almost certainly does not; automated eligibility screening, credit-relevant scoring, or an agent that decides who is refused a service plausibly does. The OAIC consulted on guidance in May–June 2026 (submissions closed 15 June 2026) and final guidance had not been published when this article went live — so build your decision inventory now and keep the disclosure draft cheap to amend. We have published a full walkthrough in our practical guide to writing an ADM transparency statement, so this post won’t repeat the how-to. One trap: the obligation applies to arrangements that already exist on commencement day, not just new deployments — a scoring model that has quietly decided who gets called since 2024 belongs in the inventory.

Apply For Partnership

Tranche 2: the direct-marketing reforms outbound teams should watch

The second tranche is where the reform stops being adjacent to outbound and lands on it directly. In its response to the Review Report, the Government agreed in principle to:

  • Defining direct marketing, targeting and trading in the Act (proposal 20.1) — currently the Privacy Act does not define them;
  • An unqualified right to opt out of personal information being used or disclosed for direct marketing (proposal 20.2), with the response flagging harmonisation “across the Privacy Act, Spam Act 2003 (Cth) and Do Not Call Register Act 2006 (Cth)”;
  • Requirements that targeting individuals be fair and reasonable (proposal 20.8) and that entities explain their use of algorithms and profiling to recommend content (20.9). The related proposal for an unqualified opt-out of receiving targeted advertising (20.3) got the softest response — noted, with further consideration of layered opt-outs and industry codes flagged;
  • A fair-and-reasonable test for all collection, use and disclosure (proposal 12.1) — applying, in the Government’s words, “irrespective of whether consent has been obtained”;
  • Removing the small business exemption (proposal 6.1) — conditional on an impact analysis and support for small business — with short-term carve-outs flagged for facial-recognition biometrics and businesses trading in personal information (6.2), plus further consultation on employee records (7.1).

None of this is law yet, and drafting details will move. But the direction is stable: consent theatre is ending. Today an outbound program can satisfy the Spam Act on email and SMS, follow the Do Not Call Register rules on voice, and still use personal information in ways a reasonable person would find unfair. Tranche 2 closes that gap twice over — a universal opt-out that follows the person rather than the channel, and a fairness test that applies even where someone clicked “agree”. Teams already running suppression as one cross-channel source of truth will barely notice; teams managing opt-outs per channel will be rebuilding under deadline pressure. Our guide to outreach compliance across the Spam Act, TCPA and GDPR covers the rules as they stand today.

A preparation plan that survives the uncertainty

Because tranche 2 has no date, the rational strategy is to do now what is valuable under every scenario:

  • Build the ADM decision inventory (needed by 10 December 2026 regardless): every point where software makes or substantially shapes a decision about a person — lead scoring, eligibility rules, routing, refusals.
  • Unify opt-out handling across phone, SMS, email and WhatsApp into one suppression record per person. Mandatory later; fewer complaints immediately.
  • Audit data provenance. For every list and enrichment source, record where it came from and what the person was told — your tort defence and your future fair-and-reasonable evidence in one artefact.
  • Fix retention. Recordings and transcripts kept forever are pure downside under both the tort and the strengthened OAIC penalties in force since December 2024.
  • Sort your hosting and model architecture — where transcripts flow and whether inference happens onshore. That is a data-sovereignty question, covered separately in AI agent data sovereignty in Australia; this post is the regulatory timeline, that one is the infrastructure answer.
  • Under the $3m small business threshold? Plan as if covered. Removal is agreed in principle, and the tort already applies to you — it reaches entities that are not APP entities at all.

Platform choice does some of this work for you. Zian’s agents operate across phone, SMS, email and WhatsApp with CRM integrations — one system of record rather than four channel silos — and private model deployment on customer infrastructure is supported where a sovereignty analysis demands it. If you want outbound AI designed for where Australian privacy law is going rather than where it was, Apply For Partnership.

FAQ

Has the small business exemption been removed from the Privacy Act?

No. As at August 2026, the exemption for most businesses with $3 million or less annual turnover still stands. The Government agreed in principle to remove it (proposal 6.1), conditional on an impact analysis, and no implementing bill has been introduced. The statutory tort, however, is not limited to APP entities — small businesses are already exposed there.

When exactly do we need to update our privacy policy for automated decisions?

By 10 December 2026. The OAIC confirms that from 10 December 2026, APP entities using personal information in automated decision-making with the potential to affect rights or interests must describe in their privacy policies the kinds of personal information used and the kinds of decisions made — the Act sets the threshold at decisions that could reasonably be expected to significantly affect an individual’s rights or interests. The obligation sits in APP 1 and applies to existing arrangements, not just new ones.

Can someone sue us under the new privacy tort without proving they lost money?

Yes. Schedule 2 of the Privacy Act states the invasion of privacy “is actionable without proof of damage”. The plaintiff must still establish the elements — a reasonable expectation of privacy, an intentional or reckless invasion, seriousness, and that their privacy interest outweighs countervailing public interests — and consent is a defence.

Is there already an unqualified right to opt out of direct marketing in Australia?

Not yet. The Government agreed in principle to proposal 20.2 (an unqualified opt-out from personal information being used or disclosed for direct marketing) in September 2023, but it has not been legislated. Today, opt-out obligations come channel by channel — the Spam Act 2003 for email and SMS, the Do Not Call Register Act 2006 for voice, and APP 7 where the Privacy Act applies.

Will tranche 2 definitely happen, and when?

No date exists. The Attorney-General’s Department says it is developing draft provisions for the remaining agreed and agreed-in-principle proposals through targeted consultation, but as at August 2026 no tranche-2 bill is before Parliament. Treat the direction (universal opt-out, fairness test, broader coverage) as settled and the details and timing as open.

Sources and verification

Every external claim in this article was verified at the owner’s page listed below.

Claim / figure Owner Verified at
Act No. 128 of 2024; assent 10 Dec 2024; commencement table (Sch 1 Pt 15 → 10 Dec 2026; Sch 2 by proclamation/6 months); “intentional or reckless”; “actionable without proof of damage”; $478,550 cap; Children’s Code within 24 months Federal Register of Legislation https://www.legislation.gov.au/C2024A00128
Tort commenced 10 June 2025; two limbs; defences, exemptions, limitation periods, remedies; applies beyond APP entities OAIC https://www.oaic.gov.au/privacy/your-privacy-rights/more-privacy-rights/statutory-tort-for-serious-invasions-of-privacy
ADM transparency from 10 December 2026; what must be disclosed; consultation published 18 May 2026, submissions closed 15 June 2026, final guidance pending OAIC https://www.oaic.gov.au/engage-with-us/consultations/consultation-on-guidance-for-transparency-in-automated-decision-making
Review Report (Feb 2023) contained 116 proposals; response 28 September 2023; Amendment Act progresses 23 proposals; ongoing “targeted consultation on draft provisions on remaining proposals” Attorney-General’s Department https://www.ag.gov.au/rights-and-protections/publications/government-response-privacy-act-review-report
Proposals 20.1–20.2, 20.8–20.9, 12.1 (“irrespective of whether consent has been obtained”), 6.1–6.2, 7.1 agreed in principle; proposal 20.3 noted only; Spam Act/Do Not Call Register harmonisation; 116 = count of proposals listed in the Response’s Attachment A Attorney-General’s Department (Government Response, Sept 2023) https://www.ag.gov.au/sites/default/files/2023-09/government-response-privacy-act-review-report.PDF
Children’s Online Privacy Code must be finalised and registered by 10 December 2026 OAIC https://www.oaic.gov.au/privacy/privacy-registers/privacy-codes/childrens-online-privacy-code

Current as at 20 August 2026. Reform status changes; check the OAIC and the Attorney-General’s Department before relying on any date here.

Related Blogs

Related from Zian AI