Privacy

Australia’s Draft Bill Would Treat Ad Pixel Disclosures as a ‘Trade’: Objections Close September 18

Low-poly padlock in wine tones representing consent-gated personal data

Australia’s Attorney-General’s Department opened public consultation on August 31 for an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026, the “second tranche” of Privacy Act reform. Its consultation paper points at the ordinary ad pixel: firing one that feeds a programmatic buy may count as a “trade” in personal data that needs consent first. The mechanics are fully drafted; every commencement date in the bill is blank, and the window to object closes September 18, eighteen days after the consultation opened.

What the Consultation Documents Say

The department published two documents on consultations.ag.gov.au: the exposure draft Bill itself, a 544KB PDF, and a Consultation Paper running to 792KB. Submissions close Friday, September 18, an 18-day window from opening. The department asks for “concise submissions of around 1,000 words” through its online portal and says it will not be able to consider submissions received after the closing date.

Consent Would Become the Price of a Trade

The draft would bar disclosing personal information “for money or other consideration,” or for direct marketing purposes, without the individual’s consent, subject to limited exceptions. The consultation paper gives “disclosures of cookies or pixels” in programmatic advertising processes as an example of what the trade definition may capture, subject to four carve-outs it lists; PPC Land’s report walked through the same passage. Direct marketing itself is defined expansively: it covers disclosures that support or inform direct marketing, not only the marketing message itself, and the paper counts targeting an individual “as part of a broader audience, segment, or cohort” as direct marketing too.

See also  Meta Off-Site Activity Data Reaches Feed and AI: One Privacy Control Removed

The draft also raises the bar for what counts as consent, full stop. It must be “voluntary, informed, current, specific, and unambiguous.” Pre-ticked boxes and bundled consent, one mechanism covering several practices, are named as examples that would likely fail that standard, and the same list names deceptive interfaces that make it unreasonably difficult for someone to avoid giving consent in the first place.

The guarantee sits before the disclosure here, not after it. That is a different order of operations from anonymization promised through the recipient’s own controls, the arrangement covering Google’s licensed European search dataset, where the safeguard is applied downstream, by the buyer. Australia’s draft asks for consent upstream, before personal information changes hands for value at all.

What Is Australia’s Consent-to-Trade Rule?

Australia’s exposure draft would require prior, specific consent before an organization discloses personal information “for money or other consideration” or for direct marketing purposes, which the consultation paper says may include disclosures of cookies or pixels in programmatic advertising, subject to four carve-outs. It sits alongside a separate “fair and reasonable” test governing collection, use and disclosure more broadly, which the consultation paper says does not itself require consent for direct marketing. Neither mechanism is in force yet; the bill is an exposure draft, and every commencement date in it is blank.

The Fair-and-Reasonable Centerpiece

The bill’s centerpiece replaces Australian Privacy Principles 3, 4 and 6 with a single fair-and-reasonable test, weighed against seven legislated factors: reasonable expectations, the entity’s own functions, transparency, data minimization, genuine choice, proportionality of impact, and the best interests of children. The consultation paper draws the line between the two mechanisms directly, stating the fairness framework “does not require consent for direct marketing, but entities must obtain consent to trade personal information.”

See also  Google Abandons Privacy Sandbox: Third-Party Cookies Survive in Chrome as Six-Year Initiative Ends

The Regulator Already Moved

Australia’s privacy regulator got there first. On June 11, the Office of the Australian Information Commissioner, under Privacy Commissioner Carly Kind, published determinations against Medmate Australia and Monash IVF, finding both had interfered with individuals’ privacy through website tracking pixels. Both were ordered to stop using the pixels until proper consent mechanisms were in place, months before this draft named the same conduct in draft legislation. It is the same terrain covered here in August, when an AliExpress page ran tracking that runs without asking. Regulators and drafters are converging on the same target: pixels as the place where consent has to be asked, not assumed.

Dates Left Blank

None of this is law. The bill remains an exposure draft subject to further government consideration, and the new core definitions would apply to personal information an entity already holds, regardless of when it was acquired. Whether a grace period exists is unclear, because the draft leaves every commencement date blank. The definitions arrive first; the clock, if there is one, arrives later, after a submission window that runs eighteen days and closes September 18.