Most business websites collect more data than their owners realise. Even a simple lead generation site might use Google Analytics, Meta Pixel, Google Ads conversion tags, CRM integrations, newsletter signups, call tracking, booking tools, chat widgets and remarketing audiences. That is not just marketing data. Depending on the business and what the user enters, it can include personal information and sometimes sensitive information.
Australian privacy law is shifting toward stronger transparency, stronger enforcement and more accountability. The Privacy and Other Legislation Amendment Act 2024 is the first major tranche of reform and more changes are coming. Businesses that rely on tracking, forms and retargeting need to understand what this means for their websites. Our SEO guide covers how tracking and analytics fit into the broader SEO picture. This article focuses on the privacy side of that setup.
What changed in Australia's privacy law
Here is what has already happened and what is coming next.
Change | Status | Website action |
|---|---|---|
Privacy and Other Legislation Amendment Act 2024 | In effect from 10 December 2024 | Review privacy policy, data practices and governance |
Statutory tort for serious invasions of privacy | In effect from 10 June 2025 | Avoid misuse of private information. Review sensitive data collection |
Expanded OAIC enforcement powers | In effect | Improve documentation and compliance readiness |
OAIC tracking pixel guidance | Current guidance | Audit pixels, provide opt outs, review third party sharing |
Automated decision making transparency | Starts 10 December 2026 | Review automation tools, update privacy policy before deadline |
Children's Online Privacy Code | To be developed by 10 December 2026 | Review if website collects data from children or young people |
Small business exemption changes | Proposed, not yet enacted | Prepare early regardless of current turnover |
The Privacy and Other Legislation Amendment Act 2024
This is the first tranche of major privacy reform. It received Royal Assent on 10 December 2024 and progresses 23 proposals from the Government Response to the Privacy Act Review. The Attorney General's Department has published details on what the Act covers and what further reforms are expected.
Statutory tort for serious invasions of privacy
This commenced on 10 June 2025. It gives individuals an additional route to seek redress in court for serious privacy invasions, covering both intrusion upon seclusion and misuse of private information. Importantly, this applies more broadly than just APP entities in some situations.
Stronger OAIC powers
The reforms expanded the OAIC's enforcement and investigation powers, including new civil penalty tiers and infringement notices. The regulator has more tools to act on non compliance.
Automated decision making transparency
From 10 December 2026, APP entities that use personal information in automated decisions that may significantly affect an individual's rights or interests will need their privacy policies to explain the kinds of personal information used and the kinds of decisions made. If your website or CRM uses automation to qualify, score, route or prioritise leads, this is relevant.
Small business exemption
The current small business exemption (for businesses with under $3 million annual turnover) has not been removed yet. But the Privacy Act Review raised recalibrating this exemption and the Government response indicated further consultation. If your website collects meaningful customer data, preparing now is the sensible move regardless of your turnover.
The direction is clear: more transparency, stronger enforcement and less tolerance for vague data practices.
Why this matters for SEO, analytics and websites
SEO and website work routinely involves tools that collect or disclose personal information. Most businesses do not think of their marketing stack as a privacy issue, but it is.
Common tools that handle personal information:
GA4 and Google Analytics (page views, device data, event tracking)
Google Tag Manager (fires tags that send data to third parties)
Google Ads conversion tracking (links website actions to ad campaigns). See our guide on setting up conversion tracking properly.
Meta Pixel (sends behavioural data to Meta for ad targeting)
TikTok Pixel, LinkedIn Insight Tag, Microsoft Ads tags
Hotjar, Microsoft Clarity or similar heatmap and session replay tools
Call tracking services (dynamic number insertion, call recording)
CRM integrations (form data sent to HubSpot, Salesforce, etc.)
Email capture and newsletter platforms (Mailchimp, ActiveCampaign)
Remarketing audiences built from website visitor data
Booking and payment tools (Calendly, Square, Stripe)
Understanding what your site tracks is also relevant to how you measure SEO performance. Our article on zero click search strategy covers the shift from 'track everything' to 'track what matters'. Privacy reform is pushing in the same direction.
The website privacy audit: what to check first
Before you change anything, you need to know what your website is actually doing with data. Our website compliance checklist covers the full audit framework. Here are the five starting checks.
Check 1: what data does the website collect?
Name, phone number, email address
Physical address or suburb
IP address, device type, browser data (captured automatically by analytics)
Form message content (enquiry details, sometimes including sensitive information)
Health, legal or financial details (common in medical, legal and finance intake forms)
Booking details, payment details and advertising identifiers
Check 2: where does the data go?
Email inbox, shared inbox or CRM
Google Analytics, Google Ads, Meta (via Pixel)
Call tracking provider, booking system, newsletter platform
Payment processor, web hosting provider
Spreadsheets, shared drives, automation tools (Zapier, Make)
Check 3: is the privacy policy accurate?
Under APP 5, an entity collecting personal information must take reasonable steps to notify the individual at or before collection. Check whether your policy explains what is collected, why, who it is shared with, whether information goes overseas, how tracking and remarketing are used and how individuals can access, correct or complain.
Check 4: are forms asking for too much?
Collecting more data than you need is a risk, not a benefit. For guidance on building forms that work without over collecting, see our article on form design best practices. Common examples of over collection:
Asking for date of birth when it is not needed for the service
Asking for medical or legal details in a general enquiry form
Requiring full address when suburb is enough
Collecting sensitive information without a clear and specific reason
Check 5: are tracking pixels still needed?
Audit every pixel and tracking tag on your website. It is common to find old pixels, unused tags and tools that were added for a campaign years ago and never removed. The OAIC says organisations should conduct regular, ongoing reviews of tracking technologies deployed on their websites. If a tag is not actively used for something you can explain, remove it.
Analytics and conversion tracking: what needs to change
Good tracking does not mean tracking everything. Good tracking means tracking the actions that matter without collecting more personal information than you need. For the full picture of how GA4 works for small businesses, see our separate guide.
GA4 and analytics
Use sensible data retention settings (not the maximum by default)
Avoid sending personal information in URLs or event parameters
Review form tracking events to ensure you are not capturing sensitive enquiry text
Document what is tracked and why
Use clear privacy policy language that explains analytics use
Google Tag Manager
Audit all active tags and remove anything unused
Name tags clearly so anyone can understand what each one does
Document triggers and where data is sent
Restrict who can publish changes to the container
Review tags on sensitive pages (medical, legal, financial intake)
Call tracking
Disclose call recording to callers if you record calls
Disclose the use of call tracking where appropriate
Avoid recording sensitive calls unless necessary and compliant
Review how long call recordings and metadata are retained
Heatmaps and session replay
Mask form fields so text inputs are not recorded
Suppress recording on sensitive pages
Explain heatmap and session replay use in your privacy policy
Remarketing, pixels and ad platforms
Tracking pixels are one of the highest risk areas for business websites because they can disclose personal information to third party advertising platforms, often without the website visitor fully understanding what is happening.
What businesses should do:
List every pixel and ad tag on your website
Remove unused pixels
Check what events are firing and what data is included
Avoid firing pixels on sensitive pages where possible
Use Google Consent Mode or a consent management platform where appropriate
Update your privacy and cookie notices to explain pixel use
Provide a clear opt out pathway for remarketing
Document which platforms receive data and what that data includes
Higher risk industries for remarketing
Industry | Why remarketing carries extra risk |
|---|---|
Medical and allied health | Visiting a condition page can reveal health information to ad platforms |
Legal services | Family law, criminal defence or dispute pages reveal sensitive circumstances |
Finance and insurance | Debt, insurance claims or loan pages involve sensitive financial data |
Counselling and psychology | Mental health enquiries are highly sensitive |
Children's services | Specific obligations under the upcoming Children's Online Privacy Code |
Cross border data transfers: where your website data actually goes
Almost every Australian business website sends personal information overseas. Google Analytics processes data in the United States. Meta Pixel sends data to Meta's US servers. Mailchimp, HubSpot, Stripe, Calendly and most SaaS platforms operate from overseas data centres.
Under APP 8 (cross border disclosure), an APP entity that discloses personal information to an overseas recipient must take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, unless an exception applies.
What this means for your website:
Your privacy policy should disclose which countries receive personal information from your website
Where practical, identify the countries (commonly the United States, European Union and wherever your SaaS providers operate)
Review the privacy and data handling practices of your key third party tools
Be aware that some tools allow you to choose data processing regions (GA4 allows regional data storage settings)
Understand that using a US based platform does not automatically breach APP 8, but you need to take reasonable steps
Most generic privacy policy templates say 'we may disclose information overseas' without naming countries or explaining which tools send data where. That is the gap to fix.
Consent management platforms: what they are and when you need one
A consent management platform (CMP) is a tool that sits between your website and its tracking tags. It presents a consent notice to visitors, records their choices and controls which tags fire based on those choices.
How a CMP works
The visitor sees a notice explaining what tracking is used (analytics, advertising, functional)
The visitor can accept, decline or choose categories
The CMP stores the consent choice and passes it to Google Tag Manager
Tags only fire if the visitor has consented to that category
Google Consent Mode v2 adjusts how Google tags behave based on consent signals
Common CMPs used in Australia
CookieYes, Cookiebot, OneTrust, Osano, Termly
Most integrate with Google Tag Manager and support Google Consent Mode
Pricing ranges from free (limited) to enterprise plans for larger sites
Do you need one?
Australia does not mandate a GDPR style consent banner. But if your website fires remarketing pixels, builds advertising audiences or shares behavioural data with ad platforms, a CMP provides the clearest way to offer meaningful choice and document consent. The OAIC's guidance increasingly expects transparency and opt out mechanisms for tracking pixels.
Cookie banners: do Australian websites need them?
Australia does not have the exact same cookie consent model as the EU under GDPR. There is no specific Australian law that says 'you must show a cookie banner before any tracking occurs'. However, transparency and consent obligations still matter depending on what you collect and how you use it.
When a basic notice is not enough:
If you use third party pixels that share data with advertising platforms
If you run behavioural remarketing based on website visits
If you build audience profiles for targeted advertising
If you use session replay or heatmap tools on sensitive pages
The better question is not 'Do I need a cookie banner?' It is 'Can I explain my tracking clearly and can people make a meaningful choice?'
Forms, lead magnets and email marketing
Contact forms
Every contact form on your website is a data collection point. Under APP 5, you need to take reasonable steps to notify individuals about what you collect and why, at or before the time of collection. Check:
Are required fields limited to what you actually need?
Is there a collection notice near the form?
Does the form warn users before they enter sensitive information?
Is marketing consent separated from the enquiry itself?
Where does the submitted data go and how long is it retained?
Lead magnets
If your website offers a downloadable guide or template in exchange for an email address:
Is consent for marketing emails clearly explained before submission?
Is marketing consent bundled with the download or is it a separate opt in?
Can people easily unsubscribe after downloading?
Email and SMS marketing
The Australian Communications and Media Authority (ACMA) requires businesses to have consent before sending commercial electronic messages. Messages must identify the sender, include contact details and make unsubscribing easy.
A form submission is not automatically permission to market forever.
Automated decision making: what websites should prepare for
From 10 December 2026, APP entities that use personal information in automated decisions that may significantly affect an individual's rights or interests will need their privacy policies to include information about the kinds of personal information used and the kinds of decisions made.
Automated decision making on websites may include:
Loan or finance pre qualification tools
Insurance quote flows
Recruitment screening or eligibility checks
Dynamic pricing or personalised offers
Customer segmentation or lead scoring in CRM
Booking triage that prioritises certain enquiries
AI chatbots that route, qualify or classify users
If your website or CRM uses automation to decide who gets approved, prioritised, rejected, quoted or contacted, start documenting it now.
Notifiable Data Breaches: what happens if your website is compromised
The Notifiable Data Breaches (NDB) scheme has been in effect since February 2018. It requires APP entities to notify the OAIC and affected individuals when a data breach is likely to result in serious harm.
How this connects to your website:
If your website database is compromised (SQL injection, plugin vulnerability, stolen credentials) and personal information is accessed, the NDB scheme may apply
If a third party tool connected to your website (CRM, email platform, booking system) is breached, you may still have notification obligations if you disclosed personal information to that provider
If form submissions stored in plain text in an email inbox are accessed by an unauthorised person, that may be a notifiable breach
What to do now:
Keep your website platform, plugins and hosting up to date. Our article on WordPress security for small businesses covers the technical side.
Use strong passwords, multi factor authentication and limited admin access
Know where personal information is stored so you can assess the scope of any incident quickly
Have a basic data breach response plan: who to contact, how to assess severity, when to notify the OAIC
Review your third party tools for their own breach notification processes
The NDB scheme does not require you to prevent every possible breach. It requires you to respond properly when one occurs. Knowing where your data lives is the first step.
Industry specific privacy risks
Privacy risk is not only for banks and hospitals. A small business can still collect surprisingly personal information through a normal website form.
Medical and allied health
Medical websites are higher risk because appointment forms, patient enquiry fields and service pages can capture or imply sensitive health information. Remarketing from a page about a specific condition can effectively disclose that information to advertising platforms. For the broader SEO picture, see our guide on SEO for medical practices.
Legal services
Legal intake forms often capture confidential details. Service pages for family law, criminal defence or employment disputes can reveal sensitive personal circumstances. See our guide on SEO for lawyers for more context.
Ecommerce
Abandoned cart tracking, behavioural profiling, loyalty programs, product recommendations, customer segmentation and payment and shipping data all create privacy touchpoints. For the broader strategy, see our guide on ecommerce SEO in Australia.
Professional services
Quote forms that ask for financial or business details, lead scoring in CRM, email nurture sequences and automated follow ups can all involve personal information that needs proper handling.
Tradies and local services
Quote forms, call recording, SMS and email marketing, remarketing from service pages and job photos that include identifiable people or properties are all areas to review.
What to update on your website
You cannot explain your data practices if you do not know your own data stack. Here is the practical change list. If your website was built by a web design team, involve them in this process. They will know where the tags, forms and integrations live.
Update 1: privacy policy
Review and update your privacy policy to accurately reflect what happens on your website. Add or review sections covering analytics, pixels, remarketing, CRM and form destinations, call tracking, overseas disclosures, automated decision making (where relevant), access and correction rights, complaint process, data retention and third party processors. For a deeper look at what legal pages your site needs, see our guide to privacy policies and website terms.
Update 2: collection notices near forms
Add a short notice near each form explaining what is collected, why and where to find the full privacy policy. If the form might capture sensitive information, add a specific warning. Separate marketing consent from the enquiry itself.
Update 3: cookie and tracking notice
If you do not have one, add a clear notice explaining what cookies and tracking technologies your site uses, broken down by category (essential, analytics, advertising). Include opt out choices and consent settings where appropriate.
Update 4: tracking setup
Audit Google Tag Manager, all pixels, event tracking, heatmaps, session replay and any thank you page tags. Remove old or unused tools. Check whether tags are firing on sensitive pages.
Update 5: forms and CRM
Review required fields, sensitive data handling, storage locations, access permissions, data retention and any integrations that send data to third parties.
Update 6: email and SMS consent
Review opt in checkbox wording, consent logs, unsubscribe processes and the distinction between transactional and marketing emails.
Update 7: vendor and tool register
Document every third party tool that touches personal information from your website. This register is useful for your legal team, your web team and for compliance reviews. It is also part of good ongoing website maintenance.
30 day website privacy action plan
The first privacy win is visibility: know what the site collects before you try to fix everything.
Week | Focus | Actions |
|---|---|---|
Week 1 | Map the data | List all forms, pixels, analytics tools, CRM integrations, email and SMS tools, call tracking and booking or payment tools. Document what each collects and where the data goes. |
Week 2 | Remove obvious risk | Delete old or unused pixels. Remove unnecessary form fields. Rename sensitive event labels in analytics. Disable session replay on sensitive pages. |
Week 3 | Update notices | Review and update your privacy policy. Add form collection notices. Add or improve your cookie and tracking notice. Separate marketing consent from enquiry forms. |
Week 4 | Document and monitor | Create a vendor register. Start a GTM change log. Set up consent records. Define data retention periods. Schedule a quarterly tracking audit. |
This audit pairs well with a broader technical check of your website. Our SEO audit checklist covers indexing, speed, mobile, content and local SEO alongside the tracking and technical foundations.
What not to do
The riskiest privacy setup is the one nobody owns.
Copying a generic privacy policy that does not describe your actual data practices
Assuming the web developer handled privacy obligations
Assuming GA4 and Meta Pixel are 'just anonymous'
Tracking everything because you can
Putting pixels on sensitive pages without review
Bundling marketing consent into every form submission
Using AI chatbots to collect sensitive information without a policy update
Treating the small business exemption as a reason to ignore privacy
What we recommend at Elev8d
When we build or audit a website, we look at the tracking stack as part of the project. That means reviewing Google Tag Manager, analytics configuration, pixel setup, form integrations and CRM connections, not just to make tracking work, but to make sure the business can explain what is happening. That approach connects to how we think about trust and E-E-A-T for small businesses. Transparent data practices are part of building a trustworthy online presence.
Privacy compliance is legal advice. But your website tracking stack is something we can help you see clearly. We can show you which tags, forms, events and tools are running, then help your team decide what to keep, change or remove.
For most small businesses, the practical first step is a tracking audit: map what is on the site, remove what is not needed and document the rest so your legal adviser can review the policy with accurate information. Our SEO company work includes these audits as part of the technical SEO foundations.
Frequently asked questions
Answers to common questions about Australian privacy law and business websites.
Do Australian websites need a privacy policy?
If your business is covered by the Privacy Act (most businesses over $3 million turnover, plus health providers and some others), yes. Even if the small business exemption currently applies, having a clear privacy policy is good practice.
Do Australian websites need cookie consent banners?
Australia does not have a GDPR style cookie consent requirement. However, if your website uses tracking pixels, remarketing or behavioural profiling, you should provide clear notice and offer meaningful opt out choices.
Do the new privacy laws apply to small businesses?
The small business exemption has not been removed yet, but removal has been proposed. Some small businesses are already covered regardless of turnover, including health service providers. Preparing now reduces future risk.
What changed in the Privacy Act in 2024 and 2025?
Key changes include the Privacy and Other Legislation Amendment Act 2024 (commenced December 2024), a statutory tort for serious privacy invasions (from June 2025), expanded OAIC enforcement powers and upcoming obligations around automated decision making (from December 2026).
Can I use Meta Pixel on my website in Australia?
Yes, but you need to comply with your Privacy Act obligations. Disclose pixel use clearly, comply with APP 7 direct marketing obligations, provide a simple opt out and conduct regular reviews.
Can I run remarketing ads under Australian privacy law?
You can, but you need to be transparent about it. Disclose remarketing in your privacy policy, provide an opt out, avoid remarketing from sensitive pages and make sure the data you share with ad platforms is disclosed.
What should my contact form say about privacy?
At minimum, include a short notice near the form explaining what is collected and why, with a link to your full privacy policy. If you want to use the submission for marketing, add a separate opt in checkbox.
Do I need consent for email marketing?
Yes. Under ACMA rules, you need consent before sending commercial electronic messages. Every marketing email must identify the sender, include contact details and make unsubscribing easy.
Should I remove tracking from my website?
No. The goal is to track what you need, explain it clearly, remove what you do not use and provide meaningful choices. Good analytics and conversion tracking are essential. The issue is undisclosed, unnecessary or excessive tracking.
Next steps: pick your path
Path 1: run the 30 day audit yourself
Follow the four week plan in this article. Map your data, remove obvious risk, update your notices and document your vendor stack.
Path 2: get your tracking stack reviewed
If you are not sure what tags, pixels and integrations are running on your site, get in touch. We can map the tracking stack and show you what needs attention.
Path 3: get proper legal advice
If your business handles sensitive data or operates in a regulated industry, involve a qualified privacy lawyer alongside the technical review.
Your website does not need to become a legal document. But it does need to be more honest about what data it collects, why it collects it, who it shares it with and how people can control it.
Sources and further reading
Sources used in this article:
OAIC: Australian Privacy Principles: The 13 principles governing personal information handling.
OAIC: Tracking Pixels Guidance: Specific guidance on tracking pixel obligations.
Attorney General's Department: Privacy: Overview of Australian privacy law and reform.
ACMA: Avoiding Spam: Rules on electronic marketing messages and consent.
ACSC: Cyber Basics: Practical security guidance for protecting data.
General information only. This article is not legal advice. Privacy law is complex and rules vary by business size, industry, data type and circumstances. If you need compliance guidance, consult a qualified privacy or legal professional.