Data Trading: Every Loyalty Program?

What the new rules on “trading” customer data mean for marketing services, retail media, partner deals and points exchanges 

By Simon Wickson, 1 October 2026

I recently wrote about how Australia’s privacy reforms will impact on loyalty programs, and why the fair and reasonable test deserves much more attention from loyalty teams. 

This piece focusses on a particular topic in the draft bill: trade. Say “data trading” to many marketers, and it can be an unfamiliar term - they might picture a customer list being sold to a data broker or how we gain revenue from retail media. The draft bill uses the word far more widely. Handing customer information to another business would now count as a trade in two situations: when you get money or some other benefit for it, and when you do it for advertising purposes. That second one is where loyalty programs live. 

It matters more now because data trading is going to need the customer’s permission. Not permission to join. Not permission to receive offers. A separate, specific yes to that information going to that party for that purpose. Everything below is based on the current draft bill’s wording the time of writing, and we all await the Government's absolute final wording as it will appear in law, in (probably, but not definitely) the coming months. 

Some real examples 

A clothing retailer uploads its member's email list to a social platform so it can advertise to people who resemble its best customers. Information has gone to another business for advertising. That would now be considered trading. 

A pet supplies program shares a group of members with an insurance partner, so the partner can offer them cover at a member price. Also now considered trading. 

A supermarket lets a cereal brand reach shoppers who regularly buy breakfast food and charge the brand for it. This one depends; if the supermarket does the targeting itself and the brand only ever sees aggregate results, there may be no disclosure. If the brand gets access to the underlying customer data, even inside a secure environment where no human ever sees a customer name, the draft bill counts that as a disclosure. The test is whether information is made accessible to someone else, not whether it is handed over. 

Permission on its own is not enough 

Consent doesn't replace the fair and reasonable test; it's added to it. “Fair” and “reasonableness” applies to everything you do with customer data, and customer consent is an extra requirement for two specific things: sensitive information, and trading.  

It's worth being clear about what kind of consent this is. It isn't the permission a member gives to join your program, or to receive marketing from you, it's a separate permission for the trade itself. 

The draft bill says consent must be voluntary, informed, current, specific, and unambiguous. It doesn't explicitly say each third party must be named, but the "specific" requirement is noteworthy, and early legal commentary suggests broad or bundled permissions won't meet the bar. In practice, that probably means naming the partner or at least describing a narrow and clearly identifiable type of recipient and saying what the information will be used for. In the pet insurance example above, that would mean members agreeing to their details going to that insurer, for that purpose. 

A few things that will probably no longer cut it: 

  • One tick at sign-up covering "our partners" or "selected third parties". 

  • Permission is buried in long terms and conditions. 

  • A single consent that bundles joining the program, receiving marketing and sharing data with others. 

Consent can still be implied in some cases, but the more valuable or unexpected the trade, the harder it will be to argue the customer genuinely understood what they were agreeing to. 

The draft also says consent must be current but doesn't say how long "current" lasts. Hopefully the Government will provide more clarity on that soon. 

A trade is still a disclosure, and every disclosure must be fair and reasonable in its own right. So, an arrangement can have textbook consent and still fail. If your loyalty program is extracting most of the value and the customer is carrying most of the exposure, that's a sign of unfairness regardless of what they agreed to. Two simple but practical examples: 

  • A supermarket uses your purchase history to send you a discount on the brand of coffee you buy every week. You’d likely expect it, and you get something out of it. Presumably, fair and reasonable. 

  • The same supermarket uses your purchase history to work out if you’re potentially pregnant, then sells that segment to a baby milk formula brand. You never expected targeted communication about baby milk formula, and frankly it may be an inaccurate prediction in the first place. 

Four situations that do not require additional customer consent  

1. Your supplier is only doing what you told them. If a company handles data purely on your behalf and follows your instructions, that's not trading. But several criteria must be met. You give the formal instructions, and the work is only for your purposes. 

The watch-out: many advertising platforms and identity companies keep the data and use it to build their own products. You cannot tolerate a business that isn't following your direct instructions or using your customer data for other than your purposes. 

2. Your customer asked the other business for something. If one of your loyalty members asks an airline to take their points, they've asked the airline directly. Your program sending these members details so the airline can do it, is fine. 

But it's probably a narrower set of use cases than it looks. Two things both have to be true. The customer must have asked the other business. And the sharing must be to make that exact thing happen, not anything else. 

3. Someone buys a business. If another company takes over your business, or part of it, the customer data can move across as part of the deal. But the data moving must be a side effect of the sale, not one of the things being sold.  

4. Fraud. You can share information to help stop or investigate serious wrongdoing that involves fraud. It also matters who you send it to. Either the business fights fraud as part of its services, or it suspects fraud in its own operations.  

Does this apply to all your customer data? 

The proposed rules could cover every record already sitting in your member database. 

The trading rule is written around organisations that hold personal information, and the section setting out when the new rules start applies them to information already held, however long ago it was collected. 

It’s possible this isn’t what the government meant, and in practice it could apply only to data collected after the new law starts. Until the final draft wording is passed, this is one to watch closely! 

A final word 

Loyalty has always been a trade. Simply put, you share your details and let us see what you buy. We give you something worth having in return. What's changed is that trade now has legal framing, and a lot of what loyalty teams do with partners and platforms is going to need careful planning and probably some level of remediation work. 

The programs that come through this well will be the ones that already embrace a responsible use of data approach, can already articulate in customer friendly language why each data-sharing arrangement exists and what the customer gets from it.  

If you’re not sure where to start but need help, Ellipsis offers services to review or redraft your data-handling terms in loyalty partner and vendor contracts.  

We are Ellipsis, The Loyalty Experts®. We help you measure, manage and grow customer loyalty. We’re here to help, please get in touch… 

References 

  1. Attorney-General’s Department, Privacy Amendment (Personal Data Protection) Bill 2026, exposure draft, released 31 August 2026. consultations.ag.gov.au/rights-and-protections/privacy-reform

  2. Attorney-General’s Department, Privacy Reform – Consultation Paper, 31 August 2026. consultations.ag.gov.au/rights-and-protections/privacy-reform

  3. A&O Shearman, “New rules of engagement: Australia’s draft privacy bill and what it means for your business,” 4 September 2026. aoshearman.com/en/insights/new-rules-of-engagement-australias-draft-privacy-bill-and-what-it-means-for-your-business 

  4. Allens, “A new era for privacy: what the proposed Privacy Act reforms mean in practice,” September 2026. allens.com.au/insights-news/insights/2026/09/a-new-era-for-privacy-what-the-proposed-privacy-act-reforms-mean-in-practice

  5. Clayton Utz, “The next wave of Australian privacy reform: key proposals in the draft Personal Data Protection Bill 2026,” 2 September 2026. claytonutz.com/insights/2026/august/the-next-wave-of-australian-privacy-reform-key-proposals-in-the-draft-personal-data-protection-bill-2026

  6. Corrs Chambers Westgarth, “Australia’s Privacy Act reforms: fundamental changes proposed in new exposure draft,” September 2026. corrs.com.au/insights/australias-privacy-act-reforms-fundamental-changes-proposed-in-new-exposure-draft

  7. DLA Piper, Privacy Matters, “Australia: Privacy reform – consultation draft outlines proposed next steps,” September 2026. privacymatters.dlapiper.com/2026/09/australia-privacy-reform-consultation-draft-outlines-proposed-next-steps

  8. Herbert Smith Freehills Kramer, “The draft Tranche 2 Privacy Act reforms: what’s there, what’s new and what’s missing?,” 9 September 2026. hsfkramer.com/insights/2026-09/the-draft-tranche-2-privacy-act-reforms-whats-there-whats-new-and-whats-missing

  9. Johnson Winter Slattery, “Second tranche of Australian Privacy Act reform: exposure draft legislation, key proposals and practical implications,” September 2026. jws.com.au/what-we-think/second-tranche-of-australian-privacy-act-reform-exposure-draft-legislation-key-proposals-and-practical-implications

  10. White & Case, “Australia Privacy Update – proposed privacy law reform,” September 2026. whitecase.com/insight-alert/australia-privacy-update-proposed-privacy-law-reform

  11. Mi3, Nadia Cameron and Andrew Birmingham, “Most significant overhaul of Australian privacy law in more than a decade,” 1 September 2026. mi-3.com.au