What the fair and reasonable test means for the way you collect, use and hold customer data
By Simon Wickson, 11th September 2026
Everyone is reading the new privacy reforms as a media and advertising story. Cookies, tracking pixels, ad platforms, data brokers, the pixels that tell Meta or Google what a customer did on your site. Loyalty programs get little mention in that conversation.
Yet a loyalty program is, at its core, a business built on customer data in exchange for personalised value. Every point earned, every offer sent, every "welcome back" message only happens because a customer trusted you with their information. These reforms ask one question of every business that runs a loyalty program: can you prove you still deserve that trust?
A decade in the making
The Privacy Act has governed how Australian organisations handle personal information since 1988, long before loyalty apps, geofenced offers or predictive segmentation existed. The first tranche of reform became law in late 2024, dealing with the more straightforward items: a statutory tort for serious invasions of privacy, transparency requirements around automated decision-making, and tighter rules for children's data. The bigger, more contested questions, including how personal information should be collected and used in the first place, were deferred.
That deferral ended in late August 2026, when the Attorney-General's Department released the Privacy Amendment (Personal Data Protection) Bill as an exposure draft.¹ Legal and industry commentators have called it the most significant overhaul of the Act in more than a decade, and some have debated whether it constitutes the full second tranche of reform long promised, or a more contained "tranche 1.5."² Either way, the direction is clear.
At the centre of the draft bill is a new "fair and reasonable" test, replacing the current Australian Privacy Principles that govern collection, use and disclosure with a single, principles-based standard.³ Rather than relying on consent alone, organisations will need to show that handling a customer's personal information is objectively fair and reasonable, weighing the benefit to the customer against how intrusive the data use actually is.⁴ Consent itself is being redefined too: to count, it must be voluntary, informed, current, specific and unambiguous, and even valid consent will not end the inquiry.⁵ The definition of personal information is also widening, to capture behavioural patterns and device identifiers, not just names and addresses.⁶ And under the draft, sharing data with a third party for advertising purposes, including the pixels, list matches and lookalike audiences that sit behind most retail media, is treated as trading in that data, which will require the customer's permission.⁷
Most of the commentary since has focused on direct marketing, media and advertising, data governance, and internal privacy impact assessments. Those are real and important. But they are also, in large part, the operating mechanics of any well-functioning loyalty program.
Five things worth understanding
Your basket data can become sensitive information
The draft bill treats ordinary personal information as sensitive information whenever it is used as a stand-in for something sensitive. Loyalty programs do this constantly, without ever calling it that. Nappies and prenatal vitamins in a basket become a "likely expecting" segment. Pharmacy purchases become a health segment. Regular kosher or halal buying becomes something close to a religious inference. This is simply what segmentation looks like at scale.
Grocery, pharmacy and health-adjacent loyalty programs are among the most exposed businesses in the country on this point, and few think of themselves as handling sensitive data at all. If the draft becomes law as written, some long-standing audience categories may need to be rebuilt from the ground up or retired.
A fair and reasonable test could favour loyalty over media and advertising
There is a case that loyalty is the best-positioned data practice in Australia for a fairness test built on weighing benefit against intrusiveness. A well-run program has an explicit, quantified, customer-visible value exchange: points, discounts, tier benefits, a stated deal the customer opted into. That is a different proposition to a tracking pixel a customer never saw or a data trade buried in a privacy policy nobody read.
Programs that can point to a genuine, understood exchange of value may find the fair and reasonable test easier to satisfy than the media and advertising practices it is aimed squarely at. Programs relying on data they cannot really justify, regardless of what the consent screen once said, are the ones who should be worried.
Data hygiene is critical
Every loyalty database has a long tail of members who joined once and never came back. Somebody needs to be able to say why the business is still holding their details, and to remove what can no longer be justified.
This lesson found me early in my career, on my third day in a new marketing role. The phone on my desk rang. It was an irate customer, a recent widow, who had told us months earlier that her husband had passed away, and was now upset to receive a renewal letter and a plastic membership card addressed to him in the mail. All I could do was apologise and promise to call her back the next day. I called her back four days running, until I had a proper answer for her.
Those four days sent me on an internal discovery I have never forgotten: a post room stacked with boxes of returned membership mail, a database team who could tell me the details of customers who had last transacted decades earlier, and a mail house sending annual renewal cycles to the entire customer file accumulated since the program's earliest days. That kind customer never knew she was the catalyst for a genuine rethink of how the business handled data from sign-up through to dormancy and deletion, or that her call helped stop years of wasted mail, and $000s in cost savings to members who had not engaged in a decade or more. Good data hygiene is what a customer-first, commercially-minded business does anyway, and the fair and reasonable test simply makes it non-negotiable.
A points expiry notice sits in an unresolved grey zone
"You have 1,500 points expiring in two months." Is that a marketing communication requiring an opt-out, or servicing information about something the customer already owns? The same question applies to tier upgrade notices, statements and reward availability alerts. Get it wrong and the exposure is more likely to sit under the Spam Act than the Privacy Act, though the historical overlap between the two has confused plenty of loyalty teams already. It is a question the regulator will need to clarify, and one worth resolving in your own program before someone else forces the answer.
Long tenure consent might be loyalty's most valuable and most exposed asset
Consent must now be current, but the draft does not specify how long "current" lasts. Loyalty is the channel where the customer relationship, and lifetime value, is deliberately measured in years or decades, and where almost nobody ever re-asks for consent. A tick captured at sign-up in 2014 is still doing a great deal of work in most programs today. Loyalty teams who have never had to think about consent as a decaying asset will need to start.
In practice
None of this needs to wait for the bill to pass. The organisations best placed when the fair and reasonable test lands will be the ones who can already answer basic questions about their loyalty data:
What personal information is held and why,
Is the value exchange genuinely visible and understood,
Does consent captured years ago still reflects what the program does with that data today.
That points to a handful of practical starting points. Loyalty and privacy teams should jointly audit which segments are built from ordinary data standing in for sensitive inferences, since these are the first candidates for review under the new test. Data hygiene needs an owner within the loyalty function, or somewhere in the organisation at least, given how directly the long tail of dormant records sits inside program economics as well as compliance risk. And programs with long-tenured members should treat consent currency as a strategic question: a refreshed, well-designed re-permissioning moment can enhance customer-trust.
Treat customer data as a gift
Early in my career I was taught to treat customer data as a gift: something to treasure and care for. In the language of these reforms, that idea now has a name: the responsible use of data, particularly customer data. Loyalty programs that have taken that seriously all along will find the fair and reasonable test reads like a description of what they were already trying to do.
The businesses that treated data collection as something to be justified are about to find that discipline pays off. Everyone else has some catching up to do.
We are Ellipsis, the Loyalty Experts®. We help you measure, manage and grow customer loyalty. We're here to help, please get in touch…
References
Attorney-General's Department, Privacy Amendment (Personal Data Protection) Bill 2026, exposure draft, released 31 August 2026.
Mi3, "Most significant overhaul of Australian privacy law in more than a decade," 1 September 2026.
Maddocks, "Privacy Reform 2026: Australia's biggest privacy overhaul," September 2026.
IAPP, "Australia publishes initial proposals for second wave of Privacy Act reforms," 31 August 2026.
TechTimes, "Australia Privacy Law 2026: World-First Test Forces Companies to Justify Every Data Use," September 2026.
IAPP, ibid.
Mi3, ibid.