Home Resources Don’t wait for Tranche 2: The privacy reckoning has already started Don’t wait for Tranche 2: The privacy reckoning has already started Too many marketers think data privacy stops at their own front door. Peter Leonard, Chair of ADMA’s Regulatory and Advocacy Working Group, explains how responsibility now spans your entire data ecosystem and why action can't wait for Tranche 2. With the federal government’s Tranche 2 privacy reforms on the horizon, many marketers seem to be holding their breath in anticipation of tighter rules, increased scrutiny and an overhaul of how to use personal data.And yet, despite growing consensus on the need for reform, the precise timing and final details of Tranche 2 remain uncertain.In this state of anticipation, marketers could be forgiven for feeling as if they are in limbo: unsure whether to take action now, or wait for new legislation to dictate the next move.But a wait-and-see approach creates real legal risk.While Tranche 2 is still in development, the Office of the Australian Information Commissioner (OAIC) has made it abundantly clear it expects organisations to be lifting their compliance with existing privacy obligations.The OAIC has signalled that it is now adopting a more active enforcement stance. The regulator has issued multiple privacy determinations and updated guidance materials that specifically address current digital marketing practices - including digital tracking, third-party pixels and sharing profiling data. An additional area of concern is the lack of transparency in data-sharing practices that have come to characterise parts of the martech and adtech ecosystem.Use of tracking pixels and similar tools embedded across websites and campaigns is a particular focus. These technologies form the backbone of modern marketing, enabling measurement, personalisation and retargeting at scale. But they also expose organisations to significant compliance risk, particularly when personal or sensitive information is being collected without transparent notice or appropriate consent.The Privacy Commissioner’s recent investigation into a major social video platform concluded that the existing provisions of the Privacy Act were inadequate in addressing some opaque aspects of sharing profiling data associated with third-party pixels. However, the Commissioner emphasised that media publishers and other operators of websites that permit the deployment of third-party pixels and tracking codes to collect personal information about users of their sites, for the purpose of sharing with others, are now on notice: they may already be breaching existing law requiring clear disclosure as to those practices.In fact, in many instances, marketers themselves may not know exactly what data is being captured, where that data is going, or who that data is being shared with. This is not just a technical or ethical issue – it’s a legal liability. Under Australian privacy law, not monitoring or ‘turning a blind eye’ to what other parties in a marketing data ecosystem are doing is not a defence.The good news for marketers is that despite the absence of a refreshed legal framework, the Privacy Commissioner has made expectations clear regarding the collection and sharing of profiling data. When using pixels and other tracking codes and device identifiers to collect and share data that could reasonably identify individuals, businesses must ensure those practices are transparent and compliant.The OAIC’s guidance confirmed that even in the absence of new legislation, organisations must conduct due diligence to ensure their use of third-party pixels complies with the Privacy Act. The OAIC also made clear that covert or poorly disclosed data collection - particularly where sensitive information may be involved – will constitute a privacy breach.Legal liability does not end once marketing operations are outsourced. Businesses can still be held responsible if a subcontractor or service provider breaches privacy obligations that are outsourced.Even where the subcontractor or service provider did not comply with provisions in the outsourcing contract requiring them to ensure data privacy compliance. That’s because, in many cases, third-party service providers act as agents, making their conduct legally attributable to the business that engaged them.This is a critical point for marketers, who often work in complex digital ecosystems involving agencies, publishers, platforms, vendors and intermediaries. Even if data handling is delegated, the legal duty remains.Compounding this issue is the time it takes to fix it. Changing digital data flows, reconfiguring tracking technologies, updating privacy policies, renegotiating vendor contracts and rolling out governance frameworks is not an overnight exercise. These kinds of changes can take 12-18 months to fully implement.That means the time to act isn’t when Tranche 2 arrives - it’s now. If your organisation is already skating close to the line, your organisation may be in the firing line for enforcement of the current law, and ‘tranche 2’ reforms are likely to up the data governance required to ensure compliance. What marketers can do nowThere is still time to act. The OAIC’s existing guidance provides a clear roadmap of what marketers can do today to prepare:● Map your tracking ecosystem. Understand where pixels and similar technologies are deployed, what data they collect and where that data is sent.● Minimise data collection. Configure tracking tools to capture only what is necessary for a defined purpose, avoiding over-collection.● Ensure transparency. Update privacy notices and consent mechanisms to clearly explain who is collecting data, what it’s being used for and who it’s being shared with.● Address sensitive data risks. Take particular care where tracking could relate to health, politics, or other sensitive categories - these require explicit consent.● Review third-party relationships. Include privacy compliance obligations in contracts with vendors and establish audit rights or assurance mechanisms.● Clarify internal accountability. Don’t assume your agency, platform or publisher has it covered. Ensure your organisation knows who is responsible for what.● Treat clean rooms as compliance tools, not loopholes. If using data clean rooms, ensure they are designed and documented as part of a privacy-by-design strategy - not simply a way to argue information falls outside the Act.Ultimately, Australia’s privacy laws are evolving but the expectations of regulators, and indeed the public, are already changing.The organisations that invest in responsible data governance now will not only stay ahead of legal requirements, they will also be better positioned to build sustainable, trust-led relationships with their audiences.That’s not just good compliance. That’s good marketing. FIND OUT FIRST, STAY CONNECTEDSign up to receive ADMA newsletters, updates, trends, special offers, events, critical issues and more Job role*Agency Account Manager/ExecutiveAgency Account/Strategy DirectorCDOCEO / Managing DirectorClient Service / Sales ManagerClient Service/Sales DirectorCMO / CCO / Marketing DirectorCreative Director / HeadData Analyst / Scientist / EngineerDesigner/Copywriter/Creative ManagerEarly Career Data Analyst / Scientist / EngineerHead of Analytics / Analytics LeaderHead of Category/Customer Experience/InsightsHead of Marketing/BrandHead of ProductHR/Learning and Development ManagersIT Director/ManagerLegal/RegulatoryMarketing ConsultantMarketing Executive / CoordinatorMarketing Freelancer / ContractorProduct / Brand / Digital / Communication ManagerSenior Data Analyst / Scientist / EngineerSenior Marketing/Brand ManagerOther You may unsubscribe at any time using the link provided in the communication. View our Privacy Policy. Filter Resources Filter Courses Capability Capability Campaign Integration Compliance Customer Experience Marketing Technology Insights Learnings Brand Development Content Format Content Format Information sheet Member-only Press-release Article Blog Case Study Data Event Infographic Media Coverage Research Tool-kit Video Webinar Whitepaper Topics Topics ADMA Spotlight CMO Crib Sheet CMO Spotlight Global Forum Global Forum 2023 Privacy Awareness Week Privacy series Regulatory Spotlight Resource The Weakest Link Compliance Resources CEO Blog Compliance Regulatory Content Copywriting Creative Data Data-driven Marketing Digital Campaigns Leadership Social Media Thought Leadership Article 01st Jun 2021 4 mins Industry bodies publish new framework to enhance data privacy standards worldwide The Association for Data Driven Marketing and Advertising (ADMA)) and the Global Data and Marketing Alliance (GDMA) are pleased to announce the publication of the Global Privacy Principles. Article 01st Jun 2021 6 min Customer experience revolution underway thanks to AI and ML From columns and rows to collaboration and compliance, data-led insights and new technology is enabling a brave new world of data-led marketing opportunities. Infographic 26th May 2021 5 mins How to build the best eDM campaign in 10 steps eDM (Electronic Direct Mail) remains one of the best performing digital marketing channels. eDM marketing is a process of sending promotional emails to generate sales and leads. Article 25th May 2021 Everything you need to know about the media agency industry The 2021 release of ‘The MFA Guide – Everything you need to know about the media agency industry’ is a great reference point for the media industry. Article 11th May 2021 4 mins The freelance opportunity: upskilling for success With increasing demand to demonstrate genuine value to the bottom line, Australian marketers are being challenged to upskill or face the very real likelihood of being left behind. And for independent marketing professionals, the pressure may be even stronger. Article 03rd May 2021 4 mins Attention Freelance Marketers: How you can stay connected to the industry when out on your own The promises of flexibility, operational ease, and control over decision-making have enticed many to step away from the traditional ‘nine to five’ model and go out on their own. Load More
Article 01st Jun 2021 4 mins Industry bodies publish new framework to enhance data privacy standards worldwide The Association for Data Driven Marketing and Advertising (ADMA)) and the Global Data and Marketing Alliance (GDMA) are pleased to announce the publication of the Global Privacy Principles.
Article 01st Jun 2021 6 min Customer experience revolution underway thanks to AI and ML From columns and rows to collaboration and compliance, data-led insights and new technology is enabling a brave new world of data-led marketing opportunities.
Infographic 26th May 2021 5 mins How to build the best eDM campaign in 10 steps eDM (Electronic Direct Mail) remains one of the best performing digital marketing channels. eDM marketing is a process of sending promotional emails to generate sales and leads.
Article 25th May 2021 Everything you need to know about the media agency industry The 2021 release of ‘The MFA Guide – Everything you need to know about the media agency industry’ is a great reference point for the media industry.
Article 11th May 2021 4 mins The freelance opportunity: upskilling for success With increasing demand to demonstrate genuine value to the bottom line, Australian marketers are being challenged to upskill or face the very real likelihood of being left behind. And for independent marketing professionals, the pressure may be even stronger.
Article 03rd May 2021 4 mins Attention Freelance Marketers: How you can stay connected to the industry when out on your own The promises of flexibility, operational ease, and control over decision-making have enticed many to step away from the traditional ‘nine to five’ model and go out on their own.