VERICODE vericode.com.au

Privacy Act Tranche 2 changes how fraud works today

Vericode · 18 February 2026


Most fraud isn’t a clever caller. It’s a list. Names, numbers, account hints, addresses, roles, recovery details and old facts that somebody leaked, sold, scraped, lost or kept too long. The caller is the part you see. The list is where the work actually starts.

That’s why Tranche 2 of the Privacy Act reforms matters to fraud.

The Attorney-General has confirmed the government is progressing the second tranche of privacy reforms this year. Most of the coverage will treat that as a privacy story, which is fair enough. Privacy law is about individual rights, organisational obligations and the boundaries around collection, use and disclosure.

But in the scam economy, privacy reform is also fraud reform. That’s our framing, not the government’s slogan. It holds because most social engineering runs on a supply of true facts. The more unnecessary data an organisation keeps, the more raw material sits there waiting for the next pretext when something goes wrong.

The fraud chain isn’t complicated. Leak. List. Pretext. Call. Transfer. Most of the visible controls sit in the back half. Banks watch payments. Platforms pull ads. Telcos block traffic. Customers get warned. Staff get trained. All of that is necessary, and all of it starts after the facts have already escaped.

Data minimisation bites earlier.

If a business doesn’t collect a detail, it can’t leak it. If it deletes information it no longer needs, that information can’t turn up in a script two years later. If it stops treating every customer interaction as a reason to keep another copy of identity material, the future fraud market has less to assemble.

That’s not a neat or an immediate fix. Privacy reform doesn’t make tomorrow’s scam call vanish. It changes the slope over time. It asks whether the fact needed to impersonate a person should have been sitting in so many places to begin with.

The recent fraud signals make the point. Identity-support services are seeing thousands of myGov-linked account misuse cases. Fraud-intelligence sharing is surfacing large volumes of attempted fraud before it lands. Voice-cloning losses and romance-scam campaigns keep showing how much damage gets done once enough personal context is available.

The lists are working.

That phrase should make you uncomfortable. It means fraudsters don’t need perfect information. They need enough. A phone number, a name and a recent interaction can be enough to keep someone on the line. A partial account detail can be enough to make a fake bank call feel credible. A branch name, a manager’s name, an invoice number, a travel detail or a family clue can turn a cold approach into a warm one.

The privacy conversation usually starts with fairness to the individual. It should. But for fraud teams the starting point is attack surface. Every retained field is a future credential in somebody else’s mouth.

That’s the part of Tranche 2 worth watching. Not as a silver bullet, and not as a reason to stop building controls at the payment, platform, telco or contact-centre layer. Those controls still matter. The point is that the cheapest place to remove a fraud input is before the input exists.

Less data doesn’t mean no service. It means fewer stale facts sitting around waiting to be repurposed. Fewer old forms, fewer duplicated identity checks, fewer retention habits feeding the next caller’s script.

Privacy reforms are fraud reforms when they shorten the chain at its source.

The cheapest fraud control is the one that stops the list from existing.