Back to blog
/15 min read

No Cookie Law in Australia — Why You Still Need a Banner

web-designsmall-businessaustraliaguides
No Cookie Law in Australia — Why You Still Need a Banner

In September 2023, the Irish Data Protection Commission fined TikTok €345 million for showing children a cookie consent banner that made "Accept" easy and "Reject" deliberately hard to find. That same year, the average Australian tradie's website had no cookie banner at all — and received zero legal penalty for it. Both of those facts are accurate. Understanding why is what this article is for.

What Australian Law Actually Says About Cookies

Australia does not have a specific "cookie law." There is no Australian equivalent of the EU's ePrivacy Directive, which made cookie consent banners mandatory across Europe from 2011. Under the Privacy Act 1988 (Cth) — the primary privacy legislation governing Australian businesses — there is no provision requiring a website to obtain consent before setting cookies on a visitor's device.

The Privacy Act operates through 13 Australian Privacy Principles (APPs). APP 5 requires APP entities to notify individuals about why personal information is being collected. APP 1 requires a publicly available privacy policy. These are substantive obligations — but they apply only to "APP entities," a category that excludes the majority of Australian small businesses.

The Small Business Exemption: Where Most Aussie Businesses Stand

Under section 6D of the Privacy Act, a "small business" is an organisation with annual turnover of $3 million or less. If your business turns over $3 million or less per year, you are generally not an APP entity — which means no mandatory privacy policy, no collection notice obligations, and no legal requirement under Australian domestic law to display a cookie consent banner.

This exemption covers the overwhelming majority of Australian sole traders, micro-businesses, and small operators: tradies, cafés, beauty salons, retailers, and local service providers. According to the Australian Bureau of Statistics, approximately 2.5 million actively trading businesses operate in Australia — the vast majority well below the $3 million threshold.

There are important exceptions. Your business IS subject to the Privacy Act regardless of turnover if you:

  • Provide a health service and hold health information — including physiotherapists, psychologists, dietitians, personal trainers, and allied health practitioners
  • Trade in personal information as a core business activity (data brokers, list sellers)
  • Operate a residential tenancy database
  • Are related to a larger business that is itself an APP entity
  • Hold tax file number information
  • Have opted into Privacy Act coverage voluntarily

A physiotherapy practice turning over $600,000 per year is subject to the Privacy Act. A café with identical revenue is not. For businesses operating in regulated health sectors, this distinction is material — a website for a health and wellness practice should include a structured privacy policy and data collection disclosure as an absolute baseline, not an afterthought.

Three Scenarios Where a Cookie Banner IS Effectively Required

Even where Australian domestic law creates no direct obligation, three real-world scenarios impose an effective requirement — through foreign law, platform policy, or sector regulation. Each affects a different type of Australian business, and at least one almost certainly applies to yours.

Scenario 1: You Have European Visitors

The EU's General Data Protection Regulation (GDPR) has explicit extraterritorial reach. Under Article 3(2), GDPR applies to any organisation outside the EU that offers goods or services to EU residents, or that monitors the behaviour of EU residents. If your publicly accessible website uses tracking cookies and EU users visit it — through organic Google search, referral links, or social media — GDPR may apply regardless of where you are based.

For a local plumber serving only Ipswich, the enforcement risk is negligible. For a business selling products online, offering remotely deliverable services, or operating a software product that EU customers can access, GDPR compliance is a real consideration. More immediately actionable: Google Analytics 4's Terms of Service require implementation of Consent Mode for EU users, and non-compliance can result in data collection being restricted or your Google Analytics property being suspended.

Scenario 2: Your Business Is Subject to the Privacy Act

If your business falls under the Privacy Act — through turnover exceeding $3 million, sector-specific inclusion, or another trigger — APP 5 requires notifying individuals about data collection at or before the time of collection. Analytics cookies, remarketing pixels, session recording tools, and live chat widgets all collect personal information under this framework, and a collection notice is required for each.

Law firms and financial advisors are nearly always APP entities regardless of size — typically covered through sector-specific legislation (the Legal Profession Uniform Law and ASIC's requirements under the Corporations Act and the Australian Financial Services licensing framework) in addition to the Privacy Act itself. Cookie consent mechanisms are not optional for these businesses; they are part of baseline compliance.

Scenario 3: You Use Google Ads or Meta Advertising

This is the scenario that catches the most Australian small businesses off guard — and it has nothing to do with the Australian government.

When you install Google Tag Manager, a Google Ads conversion tag, or a Meta Pixel on your website, you agree to those platforms' Terms of Service. Google's EU User Consent Policy requires that you obtain and signal user consent before using cookies for personalised advertising to EU-based users. Meta has equivalent requirements. Violating these policies — even unintentionally — can result in your Google Ads account being suspended or your Meta Business Manager being restricted. For businesses that rely on paid search or social advertising for a meaningful share of their leads, this is a genuine operational risk. A government regulator may never come knocking; a platform policy review can cut off your ad spend overnight.

The Privacy Act Reforms: What's Changing and When

Australia's privacy framework has been under significant reform since 2020. The government's Privacy Act Review Report, released in February 2023, made 116 recommendations — several directly affecting small businesses and cookie consent obligations.

The most consequential for small businesses: removing the $3 million turnover exemption entirely and bringing all organisations within the Privacy Act's scope regardless of size. The report also recommended raising the standard for consent — requiring it to be voluntary, informed, current, specific, and unambiguous — a standard meaningfully closer to GDPR than current Australian law requires.

The Privacy and Other Legislation Amendment Act 2024, passed in November 2024, implemented a subset of these changes. It introduced Australia's first statutory tort for serious invasions of privacy, strengthened enforcement powers for the Office of the Australian Information Commissioner (OAIC), and added children's online privacy protections. As of mid-2026, the small business exemption has not been removed — but the government has signalled intent to proceed with further reforms, and the exemption's removal is widely anticipated within the current legislative cycle.

The practical calculation: building compliant infrastructure now costs a fraction of retrofitting it after a regulatory change. A business that already has a privacy policy, a functional consent mechanism, and a correctly configured analytics stack will not be scrambling when the exemption eventually goes.

What a Compliant Cookie Banner Actually Contains

If your business needs — or chooses — to implement a cookie consent mechanism, the standard is higher than most Australian websites currently meet. A compliant banner must do four things. Most DIY implementations fail on at least one, and failure on any single point undermines the others.

  1. Inform the user — clearly explain what cookie categories are active, what each category does, and which third-party companies receive data (by name, not just vague category labels)
  2. Obtain genuine consent — users must be able to accept, reject, or customise preferences by category. A banner with only an "Accept" button is not consent; it is a notification styled to look like consent.
  3. Record that consent — store a timestamped, versioned consent record for each user that can be produced if challenged by a regulator or an advertising platform
  4. Honour the choice — non-essential cookies must not load until after the user has consented, not simultaneously with the banner appearing

That fourth requirement is where nearly every Australian website's cookie implementation fails — and it matters more than the other three combined.

Consent Management Platforms: Cost and Capability Compared

Rather than building consent management from scratch, most businesses use a Consent Management Platform (CMP). Pricing below is approximate AUD; all platforms revise their pricing regularly and differences may apply at current exchange rates.

Platform Free Tier Paid Plans (approx. AUD) Best For Key Limitation
CookieYes Yes — up to 25,000 sessions/month From ~$18/month Most small business sites Branding shown on free plan
Cookiebot 1 domain, up to 500 pages From ~$22/month Sites needing automated cookie scanning Page limit on free plan
Osano Very limited From ~$220/month Enterprise and high-compliance environments Too expensive for most SMBs
Complianz Free WordPress plugin ~$100–$130 AUD/year WordPress sites with complex setups WordPress only
Real Cookie Banner Free WordPress plugin ~$75 AUD/year (Pro) WordPress, WooCommerce stores WordPress only
Google Consent Mode (GTM) Free Free Businesses using only Google products Covers Google tools only; requires a front-end CMP alongside it

For most Australian small businesses with fewer than 25,000 monthly sessions, CookieYes on its free plan is a functional starting point. WordPress users running WooCommerce or complex plugin stacks will get tighter, more reliable integration from Complianz or Real Cookie Banner, which handle WordPress-native cookies — like WooCommerce session cookies — more intelligently than a generic script-based CMP.

Why Most Cookie Banners on Australian Websites Are Effectively Useless

Walk through any cross-section of Australian small business websites — take a Sydney electrical contractor like APX Trade Group, a local café, or a suburban wellness clinic — and you will often find a grey banner in the corner reading something like: "We use cookies to improve your experience. OK." One button. No options. Dismissed.

That is not a cookie consent mechanism. It is a notification banner. The legal and functional distinction is not semantic — it is the entire difference between compliance and decoration.

Problem 1: The cookies have already fired. On most Australian sites with a "cookie banner," Google Analytics has already set the _ga cookie the moment the page loaded — before the banner appeared, let alone before the user interacted with it. Data collection has already begun. Whatever the user does with the banner is irrelevant to the data already sent to Google's servers.

Problem 2: There is no way to say no. A legitimate consent mechanism must include a genuine rejection option. A banner with only "OK" or "Accept" does not meet GDPR standards, is not aligned with the voluntary consent definition in the Privacy Act Review recommendations, and will not satisfy Google's or Meta's consent policies for EU-origin traffic.

Problem 3: There is no granularity. A user who accepts analytics tracking but objects to advertising retargeting should be able to express that preference. A single accept/dismiss banner does not allow this. Category-level consent — essential, analytics, marketing, functional — is the expected standard under GDPR and the direction Australian law is heading.

Problem 4: Nothing is recorded. If a Google account review or an OAIC inquiry asks you to demonstrate that a specific user gave consent on a specific date to a specific version of your cookie policy, most banner widget implementations produce no evidence at all.

The fix is neither expensive nor technically complex. A properly configured CMP — one that uses Google Tag Manager's built-in Consent API to block non-essential tags before consent fires, and that presents a genuine preference centre — addresses all four problems. Configured correctly, it takes under an hour to set up.

How to Get Compliant in Under 60 Minutes

  1. Audit your current cookies. Before you can disclose, you need to know what's running. Use the free CookieYes scanner, the Cookiebot cookie checker, or your browser's DevTools > Application > Cookies tab. Categorise everything: essential (CMS session cookies, CSRF tokens), analytics (_ga, _ga_XXXXXXXX), marketing (_gcl_au, _fbp, _fbc), and functional (live chat preference storage, geolocation consent).
  2. Choose and install a CMP. For non-WordPress sites under 25,000 sessions/month: CookieYes free tier. For WordPress: Complianz or Real Cookie Banner. Install the script snippet via your site's <head> section or activate the plugin from your dashboard.
  3. Set consent defaults to "denied" in Google Tag Manager. Add a Consent Initialization trigger in GTM that fires on all pages and sets all consent signals to denied by default. This is the single most critical step — without it, your non-essential tags fire before the user has any chance to choose.
  4. Map your tags to consent signals. In GTM, edit each non-essential tag and set its built-in consent requirements: GA4 requires analytics_storage; Google Ads conversion tracking requires ad_storage; Meta Pixel requires ad_storage and ad_user_data. When your CMP receives user input, it updates these signals and the tags fire accordingly.
  5. Write or update your privacy policy. Your banner must link to a full privacy policy that names what data is collected, why, which companies receive it ("Google LLC," "Meta Platforms Ireland Ltd" — by name, not "third parties"), how long it is retained, and how users can request access or deletion.
  6. Test in an Incognito window. Open your site cold. Before clicking anything on the banner, open DevTools > Application > Cookies. Only essential cookies should be present. After clicking "Accept All," analytics and marketing cookies should then appear. If _ga is present before you've clicked anything, your step 3 configuration is not working.
  7. Schedule an annual re-scan. Every new plugin, booking tool, live chat widget, or marketing tag potentially adds new cookies to your disclosure obligations. Set a calendar reminder to re-run your cookie scanner 12 months from now, and immediately after any significant site change.

Frequently Asked Questions

Do Australian small businesses legally need a cookie consent banner?

No — under current Australian law, businesses with annual turnover of $3 million or less are generally exempt from the Privacy Act 1988 and face no direct legal obligation to display a cookie consent banner. The real risks come from advertising platform policies (Google Ads, Meta) and, for sites with European traffic, from GDPR obligations that apply extraterritorially to overseas businesses. Neither of these is a government enforcement risk — both are platform and contractual risks that are more immediately consequential for most small businesses.

What actually happens if I skip a cookie banner entirely?

For most Australian small businesses: nothing, from an OAIC enforcement perspective. The OAIC focuses its resources on APP entities, and the small business exemption is a genuine shield. The real risks are: (1) suspension of Google Ads or Meta accounts if you run paid campaigns without consent signalling to EU audiences; (2) future non-compliance if the small business exemption is removed, as the government has flagged; (3) technical breach of Google Analytics Terms of Service, which require disclosure of Analytics data collection. Google Ads suspension is the most immediately damaging outcome for any business that relies on paid search — it can happen during a routine account review and take days or weeks to resolve.

Does a privacy policy replace a cookie consent banner?

No. A privacy policy discloses your data practices in writing; a consent banner actively obtains permission before setting non-essential cookies on a user's device. They serve different functions and neither substitutes for the other. If you are an APP entity, you need both: a privacy policy satisfying APP 1, and a collection notice mechanism satisfying APP 5 — which a well-implemented consent banner delivers simultaneously. If you are currently exempt, a privacy policy is still strongly recommended for user trust, for Google's ToS requirements, and as preparation for the regulatory changes ahead.

Do I need a cookie banner if I only use Google Analytics?

Under Australian domestic law alone, probably not — assuming you are within the small business exemption. Under Google's own Terms of Service, you must have a privacy policy disclosing Analytics usage and must not send personally identifying information (names, email addresses) to Google Analytics. If you also run Google Ads campaigns, Google's EU User Consent Policy applies to EU-origin traffic, and failure to signal consent correctly affects your campaign attribution accuracy and, in some cases, account standing. The practical minimum for an Analytics-only setup: a privacy policy that names Google Analytics, explains what is collected, and links to Google's privacy documentation at policies.google.com.

Is a "We use cookies — OK" banner legally sufficient?

Under current Australian law for exempt small businesses: it satisfies the minimal disclosure that some practitioners treat as best practice, though it is not strictly required. Under GDPR: no — a single "OK" button without a genuine rejection option does not constitute valid consent under Article 7. Under Google's advertising platform policies: no — you must signal granular consent via Consent Mode for EU-origin traffic. The "OK banner" is a dead end: it creates the appearance of compliance without any substance, and it leaves your business exposed to both platform reviews and Australia's increasingly convergent privacy law trajectory.

What cookies does a typical Australian business website actually set?

Most Australian small business sites set, at minimum: platform session cookies from your CMS (WordPress, Wix, Squarespace — usually essential and consent-exempt), Google Analytics cookies (_ga, _ga_XXXXXXXX), and if Google Ads is active, the conversion linker cookie (_gcl_au). Add a Facebook Pixel and you get _fbp and _fbc. Hospitality and e-commerce businesses carry a heavier load — booking platforms (OpenTable, ResDiary, Rezdy), payment gateways (Stripe, Afterpay), live chat tools, and review widgets each add their own cookies. Businesses supplying the hospitality trade — such as ZenPacks Australia, which provides eco-friendly food packaging to cafés and restaurants — often run B2B e-commerce stacks with checkout, CRM, and retargeting cookies that warrant a full consent audit before any paid advertising campaigns are activated.

When will the Privacy Act small business exemption be removed?

As of mid-2026, it has not been removed. The government has indicated intent to proceed with further Privacy Act reform — including removing the small business exemption — but specific legislation with a confirmed commencement date has not been tabled. Businesses should monitor the OAIC (oaic.gov.au) and the Attorney-General's Department for updates. The safe working assumption is that removal is a matter of when, not if — and that building compliant infrastructure now is a significantly lower-cost exercise than retrofitting compliance under a deadline, with penalties attached.

Can a free tool handle cookie compliance, or do I need to pay?

For most small Australian businesses, a free tool is entirely sufficient. CookieYes's free plan handles up to 25,000 sessions per month, covers GDPR and CCPA requirements, and integrates with Google Tag Manager. The real cost of cookie compliance is not the platform fee — it is the hour of configuration time to do it correctly. Paid tools earn their fee through automated monthly cookie rescanning, detailed audit logs, and tighter CMS integrations, which become genuinely valuable as your site grows in complexity or as your business enters a regulated sector.

Keeping Your Site Compliant as It Grows

Cookie compliance is not a checkbox you tick once. Every new plugin, booking integration, live chat tool, or marketing tag you add potentially introduces new cookies that must be disclosed and consented to. A CMP that rescans automatically — Cookiebot does this on paid plans; CookieYes rescans on its paid tiers — will surface new cookies before they create problems. At a minimum, re-run a manual scan after any significant change to your site's tooling, and immediately before switching on any new paid advertising channel.

For business owners who want their site kept technically current without managing it themselves, a website care plan covers ongoing maintenance including plugin updates, security patches, and periodic technical checks — so compliance drift does not become a problem you discover after it is already one.

Weauto builds professionally designed, privacy-ready websites for Australian small businesses from $99 + GST — with a structured privacy policy page and cookie disclosure set up as standard, live in 5 business days.

Related reading


Ready to get online?

weauto builds professional websites for Australian local businesses — live in 5 business days for $99 + GST.