Australians will gain the right to have their personal information deleted from large online platforms such as search engines and social media apps, under draft privacy legislation released by the federal government on Monday.
The introduction of a so-called ‘right to erasure’ "will further bring our privacy laws into the digital age”, Attorney-General Michelle Rowland said as she announced the government’s much-anticipated ‘Tranche 2’ Privacy Act reforms.
The ‘right to erasure’ would apply to the likes of large social media, email, messaging, streaming, gaming, and artificial intelligence platforms with a gross annual revenue of more than $500 million, or more than 2.5 million average monthly users.
Individuals wishing to have their personal data deleted would need to directly ask individual platforms to do so, and would not be able to request their information be deleted from news articles published by media organisations.
The government would not be shy about implementing “high” financial penalties for breaches of the ‘right to erasure’ measure, Rowland suggested.
“We're bringing forward the toughest and most digital-compliant privacy reforms in this generation,” she said.
The proposed reforms also seek to introduce stronger standards for consenting to data collection, measures to stop businesses selling personal information “without clear permission”, and a “fair and reasonable test” to limit companies’ data collection.
While the Greens described the 'right to erasure' as "critically important" reform, the minor party said it worried that platform size thresholds meant the rule would only apply to "a tiny fraction" of companies which collect data about Australians.
The first tranche of the Labor government’s privacy reforms, which passed in late 2024, criminalised doxxing and empowered Australians to sue over privacy breaches, among other changes.
But privacy advocates were disappointed it did not include a right to data erasure – often called the ‘right to be forgotten’ – like that available in the European Union.
Rowland referenced the EU laws during her press conference on Monday, and suggested Australia would take a similar approach.
An eye on smart glasses, and AI
Amid rising public concern over the privacy implications of smart glasses, Rowland said that while the government is not proposing an import ban (as was pushed by the Greens), public anxiety about the technology is “indeed valid”.
The government wants to modernise the Privacy Act “to clarify that personal information is not limited to names and legal identifiers but can also include behavioural information and other data generated or collected by wearable devices, including smart glasses”, according to its draft legislation.
“We know that Australians are increasingly concerned about how their data is being collected, used, and shared, particularly as AI and other emerging technologies such as smart glasses become more accessible,” Rowland said.
Meta, which both sells smart glasses and operates several social media platforms, would be subject to individuals’ ‘right to erasure’ under the government’s proposed reforms, Rowland added.
Shadow Attorney-General Michaelia Cash said while the Coalition will consider the government’s proposed legislation, it is “particularly concerned that this legislation does nothing to address the use of smart glasses”.
“We believe the Albanese government needs to ensure there is a strong legal framework in relation to the use of these glasses, particularly in areas where privacy is expected,” she said in a statement.
Greens Senator David Shoebridge said, “We need to extend these laws to cover the use of so-called ‘smart glasses’ regardless of whether or not the wearer is doing it for personal curiosity or as part of a business."
The government has begun a three-week public consultation on its proposed changes, which Rowland expects will be subject to a parliamentary committee review.
She said she hopes the reforms will pass parliament in the coming 12 months.

Attorney-General Michelle Rowland says Australians deserve more control over how their data is collected and used. Image: Parliament House / YouTube
The attorney-general earlier this month asked Privacy Commissioner Carly Kind to investigate the potential need for greater regulation of smart glasses, amid growing concern about the increasingly affordable techology being used to record people without their consent.
Companies producing smart glasses should "automatically blur the faces of people who have not provided informed consent”, the office of Australia’s eSafety commissioner said in advice to industry on Monday.
It also recommended that recording be disabled when such glasses are not being worn, that they have “a clear and unmistakable recording indicator that cannot be disabled or easily obscured”, and that such devices should not be able to “obtain information about members of the public”.
Brisbane City Council last week banned people wearing smart glasses from secretly filming or photographing others without their permission at local swimming pools.
Govt fights data breaches and identity theft
The government’s proposed privacy reforms also seek to strengthen rules around data breaches, as affected entities would be required to report eligible data breaches to the information commissioner within 72 hours, and “take reasonable steps” to “prevent or reduce harm to affected individuals”.
The government also announced it will soon begin public testing of a new ID protection service called IDLock, to give Australians a new way to protect identity documents from misuse in identity theft and scams – including those exposed during data breaches.
Accessed through myGov, IDLock will allow Australians to more easily access the Credential Protection Register, which can block compromised documents like passports, driver licences, or Medicare cards from being fraudulently verified.
Users will be able to “block, unblock and monitor the use of eligible identity documents through the Document Verification Service at any time”, the government said.
The Credential Protection Register was established in late 2022 after a data breach of telecommunications giant Optus left almost 10 million Australians’ personal information exposed.
The register has since blocked over 830,000 fraudulent ID verification attempts, or an average of around 18,000 attempts each month, according to the government.
Rowland said Australia “must evolve”, because “data breaches, scams and cyber-enabled crime continue to evolve”.
Early access and testing of IDLock will begin for “a small cohort of users” later in 2026, the government said, before a broader national rollout in 2027.