28/05/2026
The "Notice and Consent" illusion is officially dead. The OAIC’s 2026 Privacy Survey proves consumer trust requires deep operational change.
The Office of the Australian Information Commissioner (OAIC) just released its 2026 Australian Community Attitudes to Privacy Survey (ACAPS), and it is a massive wake-up call for anyone running a business.
The numbers are staggering, yet entirely predictable:
📊 The Concern Gap: 93% of people say protecting personal info is deeply important to them, and 87% are more concerned about privacy today than 5 years ago.
❌ The Illusion of Control: 78% feel they have little to no real control over how their data is handled. 68% say clicking "Consent" rarely or never feels like a genuine choice.
🛑 The AI Red Line: 93% state that using their personal data to train AI models is flat-out unfair and unreasonable. 71% reject letting an organization train an AI system on their data after a service relationship has ended.
⚖️ The Fairness Verdict: Only 10% of consumers believe that organisations' real-world data practices are actually fair.
THE GLOBAL CONTEXT:
This data directly mirrors what we are seeing across Europe and North America. Regulatory bodies globally (such as those enforcing the EU AI Act or U.S. state privacy mandates) are pivoting away from checkboxes. They are moving toward active "Privacy by Default" enforcement, testing whether your data infrastructure is fundamentally "fair and reasonable".
WHAT SMALL AND MID-SIZED BUSINESSES NEED TO DO TODAY:
Privacy isn't just an enterprise legal task anymore, it is your ultimate competitive advantage. 68% of consumers state they would actively choose digital services if they trusted their data was being handled responsibly.
Here is the common-sense roadmap to secure your client data by design:
🛡️ Enforce Privacy by Default: Ensure your software platforms default to the highest privacy settings automatically. Don't make clients dig through settings to opt out.
📉 Radical Data Minimisation: Stop collecting "just-in-case" data. If a piece of information isn’t strictly necessary to deliver your immediate service, do not ask for it.
🛑 Fence Your Data from AI Engines: If you plug customer data pipelines into generative AI extensions, ensure you opt out of data-sharing and model-training clauses. Your customers explicitly draw a red line here.
🗑️ Automated Lifecycle Deletion: Build structural lifecycle controls that securely purge client data once the service retention requirement has ended.
(I have attached the full infographic summary below so you can see the data breakdown at a glance! I have also provided links to the full report as well as a infographic PDF provided by them)
Do you think we need to increase privacy for client data? share your comments👇