Most business websites collect more data than their owners realise. Even a simple lead generation site might use Google Analytics, Meta Pixel, Google Ads conversion tags, CRM integrations, newsletter signups, call tracking, booking tools, chat widgets and remarketing audiences. That is not just marketing data. Depending on the business and what the user enters, it can include personal information and sometimes sensitive information.

Australian privacy law is shifting toward stronger transparency, stronger enforcement and more accountability. The Privacy and Other Legislation Amendment Act 2024 is the first major tranche of reform and more changes are coming. Businesses that rely on tracking, forms and retargeting need to understand what this means for their websites. Our SEO guide covers how tracking and analytics fit into the broader SEO picture. This article focuses on the privacy side of that setup.

What changed in Australia's privacy law

Here is what has already happened and what is coming next.

Change

Status

Website action

Privacy and Other Legislation Amendment Act 2024

In effect from 10 December 2024

Review privacy policy, data practices and governance

Statutory tort for serious invasions of privacy

In effect from 10 June 2025

Avoid misuse of private information. Review sensitive data collection

Expanded OAIC enforcement powers

In effect

Improve documentation and compliance readiness

OAIC tracking pixel guidance

Current guidance

Audit pixels, provide opt outs, review third party sharing

Automated decision making transparency

Starts 10 December 2026

Review automation tools, update privacy policy before deadline

Children's Online Privacy Code

To be developed by 10 December 2026

Review if website collects data from children or young people

Small business exemption changes

Proposed, not yet enacted

Prepare early regardless of current turnover

The Privacy and Other Legislation Amendment Act 2024

This is the first tranche of major privacy reform. It received Royal Assent on 10 December 2024 and progresses 23 proposals from the Government Response to the Privacy Act Review. The Attorney General's Department has published details on what the Act covers and what further reforms are expected.

Statutory tort for serious invasions of privacy

This commenced on 10 June 2025. It gives individuals an additional route to seek redress in court for serious privacy invasions, covering both intrusion upon seclusion and misuse of private information. Importantly, this applies more broadly than just APP entities in some situations.

Stronger OAIC powers

The reforms expanded the OAIC's enforcement and investigation powers, including new civil penalty tiers and infringement notices. The regulator has more tools to act on non compliance.

Automated decision making transparency

From 10 December 2026, APP entities that use personal information in automated decisions that may significantly affect an individual's rights or interests will need their privacy policies to explain the kinds of personal information used and the kinds of decisions made. If your website or CRM uses automation to qualify, score, route or prioritise leads, this is relevant.

Small business exemption

The current small business exemption (for businesses with under $3 million annual turnover) has not been removed yet. But the Privacy Act Review raised recalibrating this exemption and the Government response indicated further consultation. If your website collects meaningful customer data, preparing now is the sensible move regardless of your turnover.

The direction is clear: more transparency, stronger enforcement and less tolerance for vague data practices.

Why this matters for SEO, analytics and websites

SEO and website work routinely involves tools that collect or disclose personal information. Most businesses do not think of their marketing stack as a privacy issue, but it is.

Common tools that handle personal information:

  • GA4 and Google Analytics (page views, device data, event tracking)

  • Google Tag Manager (fires tags that send data to third parties)

  • Google Ads conversion tracking (links website actions to ad campaigns). See our guide on setting up conversion tracking properly.

  • Meta Pixel (sends behavioural data to Meta for ad targeting)

  • TikTok Pixel, LinkedIn Insight Tag, Microsoft Ads tags

  • Hotjar, Microsoft Clarity or similar heatmap and session replay tools

  • Call tracking services (dynamic number insertion, call recording)

  • CRM integrations (form data sent to HubSpot, Salesforce, etc.)

  • Email capture and newsletter platforms (Mailchimp, ActiveCampaign)

  • Remarketing audiences built from website visitor data

  • Booking and payment tools (Calendly, Square, Stripe)

Understanding what your site tracks is also relevant to how you measure SEO performance. Our article on zero click search strategy covers the shift from 'track everything' to 'track what matters'. Privacy reform is pushing in the same direction.

The website privacy audit: what to check first

Before you change anything, you need to know what your website is actually doing with data. Our website compliance checklist covers the full audit framework. Here are the five starting checks.

Check 1: what data does the website collect?

  • Name, phone number, email address

  • Physical address or suburb

  • IP address, device type, browser data (captured automatically by analytics)

  • Form message content (enquiry details, sometimes including sensitive information)

  • Health, legal or financial details (common in medical, legal and finance intake forms)

  • Booking details, payment details and advertising identifiers

Check 2: where does the data go?

  • Email inbox, shared inbox or CRM

  • Google Analytics, Google Ads, Meta (via Pixel)

  • Call tracking provider, booking system, newsletter platform

  • Payment processor, web hosting provider

  • Spreadsheets, shared drives, automation tools (Zapier, Make)

Check 3: is the privacy policy accurate?

Under APP 5, an entity collecting personal information must take reasonable steps to notify the individual at or before collection. Check whether your policy explains what is collected, why, who it is shared with, whether information goes overseas, how tracking and remarketing are used and how individuals can access, correct or complain.

Check 4: are forms asking for too much?

Collecting more data than you need is a risk, not a benefit. For guidance on building forms that work without over collecting, see our article on form design best practices. Common examples of over collection:

  • Asking for date of birth when it is not needed for the service

  • Asking for medical or legal details in a general enquiry form

  • Requiring full address when suburb is enough

  • Collecting sensitive information without a clear and specific reason

Check 5: are tracking pixels still needed?

Audit every pixel and tracking tag on your website. It is common to find old pixels, unused tags and tools that were added for a campaign years ago and never removed. The OAIC says organisations should conduct regular, ongoing reviews of tracking technologies deployed on their websites. If a tag is not actively used for something you can explain, remove it.

Analytics and conversion tracking: what needs to change

Good tracking does not mean tracking everything. Good tracking means tracking the actions that matter without collecting more personal information than you need. For the full picture of how GA4 works for small businesses, see our separate guide.

GA4 and analytics

  • Use sensible data retention settings (not the maximum by default)

  • Avoid sending personal information in URLs or event parameters

  • Review form tracking events to ensure you are not capturing sensitive enquiry text

  • Document what is tracked and why

  • Use clear privacy policy language that explains analytics use

Google Tag Manager

  • Audit all active tags and remove anything unused

  • Name tags clearly so anyone can understand what each one does

  • Document triggers and where data is sent

  • Restrict who can publish changes to the container

  • Review tags on sensitive pages (medical, legal, financial intake)

Call tracking

  • Disclose call recording to callers if you record calls

  • Disclose the use of call tracking where appropriate

  • Avoid recording sensitive calls unless necessary and compliant

  • Review how long call recordings and metadata are retained

Heatmaps and session replay

  • Mask form fields so text inputs are not recorded

  • Suppress recording on sensitive pages

  • Explain heatmap and session replay use in your privacy policy

Remarketing, pixels and ad platforms

Tracking pixels are one of the highest risk areas for business websites because they can disclose personal information to third party advertising platforms, often without the website visitor fully understanding what is happening.

What businesses should do:

  • List every pixel and ad tag on your website

  • Remove unused pixels

  • Check what events are firing and what data is included

  • Avoid firing pixels on sensitive pages where possible

  • Use Google Consent Mode or a consent management platform where appropriate

  • Update your privacy and cookie notices to explain pixel use

  • Provide a clear opt out pathway for remarketing

  • Document which platforms receive data and what that data includes

Higher risk industries for remarketing

Industry

Why remarketing carries extra risk

Medical and allied health

Visiting a condition page can reveal health information to ad platforms

Legal services

Family law, criminal defence or dispute pages reveal sensitive circumstances

Finance and insurance

Debt, insurance claims or loan pages involve sensitive financial data

Counselling and psychology

Mental health enquiries are highly sensitive

Children's services

Specific obligations under the upcoming Children's Online Privacy Code

Cross border data transfers: where your website data actually goes

Almost every Australian business website sends personal information overseas. Google Analytics processes data in the United States. Meta Pixel sends data to Meta's US servers. Mailchimp, HubSpot, Stripe, Calendly and most SaaS platforms operate from overseas data centres.

Under APP 8 (cross border disclosure), an APP entity that discloses personal information to an overseas recipient must take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, unless an exception applies.

What this means for your website:

  • Your privacy policy should disclose which countries receive personal information from your website

  • Where practical, identify the countries (commonly the United States, European Union and wherever your SaaS providers operate)

  • Review the privacy and data handling practices of your key third party tools

  • Be aware that some tools allow you to choose data processing regions (GA4 allows regional data storage settings)

  • Understand that using a US based platform does not automatically breach APP 8, but you need to take reasonable steps

Most generic privacy policy templates say 'we may disclose information overseas' without naming countries or explaining which tools send data where. That is the gap to fix.

Consent management platforms: what they are and when you need one

A consent management platform (CMP) is a tool that sits between your website and its tracking tags. It presents a consent notice to visitors, records their choices and controls which tags fire based on those choices.

How a CMP works

  • The visitor sees a notice explaining what tracking is used (analytics, advertising, functional)

  • The visitor can accept, decline or choose categories

  • The CMP stores the consent choice and passes it to Google Tag Manager

  • Tags only fire if the visitor has consented to that category

  • Google Consent Mode v2 adjusts how Google tags behave based on consent signals

Common CMPs used in Australia

  • CookieYes, Cookiebot, OneTrust, Osano, Termly

  • Most integrate with Google Tag Manager and support Google Consent Mode

  • Pricing ranges from free (limited) to enterprise plans for larger sites

Do you need one?

Australia does not mandate a GDPR style consent banner. But if your website fires remarketing pixels, builds advertising audiences or shares behavioural data with ad platforms, a CMP provides the clearest way to offer meaningful choice and document consent. The OAIC's guidance increasingly expects transparency and opt out mechanisms for tracking pixels.

Cookie banners: do Australian websites need them?

Australia does not have the exact same cookie consent model as the EU under GDPR. There is no specific Australian law that says 'you must show a cookie banner before any tracking occurs'. However, transparency and consent obligations still matter depending on what you collect and how you use it.

When a basic notice is not enough:

  • If you use third party pixels that share data with advertising platforms

  • If you run behavioural remarketing based on website visits

  • If you build audience profiles for targeted advertising

  • If you use session replay or heatmap tools on sensitive pages

The better question is not 'Do I need a cookie banner?' It is 'Can I explain my tracking clearly and can people make a meaningful choice?'

Forms, lead magnets and email marketing

Contact forms

Every contact form on your website is a data collection point. Under APP 5, you need to take reasonable steps to notify individuals about what you collect and why, at or before the time of collection. Check:

  • Are required fields limited to what you actually need?

  • Is there a collection notice near the form?

  • Does the form warn users before they enter sensitive information?

  • Is marketing consent separated from the enquiry itself?

  • Where does the submitted data go and how long is it retained?

Lead magnets

If your website offers a downloadable guide or template in exchange for an email address:

  • Is consent for marketing emails clearly explained before submission?

  • Is marketing consent bundled with the download or is it a separate opt in?

  • Can people easily unsubscribe after downloading?

Email and SMS marketing

The Australian Communications and Media Authority (ACMA) requires businesses to have consent before sending commercial electronic messages. Messages must identify the sender, include contact details and make unsubscribing easy.

A form submission is not automatically permission to market forever.

Automated decision making: what websites should prepare for

From 10 December 2026, APP entities that use personal information in automated decisions that may significantly affect an individual's rights or interests will need their privacy policies to include information about the kinds of personal information used and the kinds of decisions made.

Automated decision making on websites may include:

  • Loan or finance pre qualification tools

  • Insurance quote flows

  • Recruitment screening or eligibility checks

  • Dynamic pricing or personalised offers

  • Customer segmentation or lead scoring in CRM

  • Booking triage that prioritises certain enquiries

  • AI chatbots that route, qualify or classify users

If your website or CRM uses automation to decide who gets approved, prioritised, rejected, quoted or contacted, start documenting it now.

Notifiable Data Breaches: what happens if your website is compromised

The Notifiable Data Breaches (NDB) scheme has been in effect since February 2018. It requires APP entities to notify the OAIC and affected individuals when a data breach is likely to result in serious harm.

How this connects to your website:

  • If your website database is compromised (SQL injection, plugin vulnerability, stolen credentials) and personal information is accessed, the NDB scheme may apply

  • If a third party tool connected to your website (CRM, email platform, booking system) is breached, you may still have notification obligations if you disclosed personal information to that provider

  • If form submissions stored in plain text in an email inbox are accessed by an unauthorised person, that may be a notifiable breach

What to do now:

  • Keep your website platform, plugins and hosting up to date. Our article on WordPress security for small businesses covers the technical side.

  • Use strong passwords, multi factor authentication and limited admin access

  • Know where personal information is stored so you can assess the scope of any incident quickly

  • Have a basic data breach response plan: who to contact, how to assess severity, when to notify the OAIC

  • Review your third party tools for their own breach notification processes

The NDB scheme does not require you to prevent every possible breach. It requires you to respond properly when one occurs. Knowing where your data lives is the first step.

Industry specific privacy risks

Privacy risk is not only for banks and hospitals. A small business can still collect surprisingly personal information through a normal website form.

Medical and allied health

Medical websites are higher risk because appointment forms, patient enquiry fields and service pages can capture or imply sensitive health information. Remarketing from a page about a specific condition can effectively disclose that information to advertising platforms. For the broader SEO picture, see our guide on SEO for medical practices.

Legal services

Legal intake forms often capture confidential details. Service pages for family law, criminal defence or employment disputes can reveal sensitive personal circumstances. See our guide on SEO for lawyers for more context.

Ecommerce

Abandoned cart tracking, behavioural profiling, loyalty programs, product recommendations, customer segmentation and payment and shipping data all create privacy touchpoints. For the broader strategy, see our guide on ecommerce SEO in Australia.

Professional services

Quote forms that ask for financial or business details, lead scoring in CRM, email nurture sequences and automated follow ups can all involve personal information that needs proper handling.

Tradies and local services

Quote forms, call recording, SMS and email marketing, remarketing from service pages and job photos that include identifiable people or properties are all areas to review.

What to update on your website

You cannot explain your data practices if you do not know your own data stack. Here is the practical change list. If your website was built by a web design team, involve them in this process. They will know where the tags, forms and integrations live.

Update 1: privacy policy

Review and update your privacy policy to accurately reflect what happens on your website. Add or review sections covering analytics, pixels, remarketing, CRM and form destinations, call tracking, overseas disclosures, automated decision making (where relevant), access and correction rights, complaint process, data retention and third party processors. For a deeper look at what legal pages your site needs, see our guide to privacy policies and website terms.

Update 2: collection notices near forms

Add a short notice near each form explaining what is collected, why and where to find the full privacy policy. If the form might capture sensitive information, add a specific warning. Separate marketing consent from the enquiry itself.

Update 3: cookie and tracking notice

If you do not have one, add a clear notice explaining what cookies and tracking technologies your site uses, broken down by category (essential, analytics, advertising). Include opt out choices and consent settings where appropriate.

Update 4: tracking setup

Audit Google Tag Manager, all pixels, event tracking, heatmaps, session replay and any thank you page tags. Remove old or unused tools. Check whether tags are firing on sensitive pages.

Update 5: forms and CRM

Review required fields, sensitive data handling, storage locations, access permissions, data retention and any integrations that send data to third parties.

Update 6: email and SMS consent

Review opt in checkbox wording, consent logs, unsubscribe processes and the distinction between transactional and marketing emails.

Update 7: vendor and tool register

Document every third party tool that touches personal information from your website. This register is useful for your legal team, your web team and for compliance reviews. It is also part of good ongoing website maintenance.

30 day website privacy action plan

The first privacy win is visibility: know what the site collects before you try to fix everything.

Week

Focus

Actions

Week 1

Map the data

List all forms, pixels, analytics tools, CRM integrations, email and SMS tools, call tracking and booking or payment tools. Document what each collects and where the data goes.

Week 2

Remove obvious risk

Delete old or unused pixels. Remove unnecessary form fields. Rename sensitive event labels in analytics. Disable session replay on sensitive pages.

Week 3

Update notices

Review and update your privacy policy. Add form collection notices. Add or improve your cookie and tracking notice. Separate marketing consent from enquiry forms.

Week 4

Document and monitor

Create a vendor register. Start a GTM change log. Set up consent records. Define data retention periods. Schedule a quarterly tracking audit.

This audit pairs well with a broader technical check of your website. Our SEO audit checklist covers indexing, speed, mobile, content and local SEO alongside the tracking and technical foundations.

What not to do

The riskiest privacy setup is the one nobody owns.

  • Copying a generic privacy policy that does not describe your actual data practices

  • Assuming the web developer handled privacy obligations

  • Assuming GA4 and Meta Pixel are 'just anonymous'

  • Tracking everything because you can

  • Putting pixels on sensitive pages without review

  • Bundling marketing consent into every form submission

  • Using AI chatbots to collect sensitive information without a policy update

  • Treating the small business exemption as a reason to ignore privacy

What we recommend at Elev8d

When we build or audit a website, we look at the tracking stack as part of the project. That means reviewing Google Tag Manager, analytics configuration, pixel setup, form integrations and CRM connections, not just to make tracking work, but to make sure the business can explain what is happening. That approach connects to how we think about trust and E-E-A-T for small businesses. Transparent data practices are part of building a trustworthy online presence.

Privacy compliance is legal advice. But your website tracking stack is something we can help you see clearly. We can show you which tags, forms, events and tools are running, then help your team decide what to keep, change or remove.

For most small businesses, the practical first step is a tracking audit: map what is on the site, remove what is not needed and document the rest so your legal adviser can review the policy with accurate information. Our SEO company work includes these audits as part of the technical SEO foundations.

Frequently asked questions

Answers to common questions about Australian privacy law and business websites.

Do Australian websites need a privacy policy?

If your business is covered by the Privacy Act (most businesses over $3 million turnover, plus health providers and some others), yes. Even if the small business exemption currently applies, having a clear privacy policy is good practice.

Do Australian websites need cookie consent banners?

Australia does not have a GDPR style cookie consent requirement. However, if your website uses tracking pixels, remarketing or behavioural profiling, you should provide clear notice and offer meaningful opt out choices.

Do the new privacy laws apply to small businesses?

The small business exemption has not been removed yet, but removal has been proposed. Some small businesses are already covered regardless of turnover, including health service providers. Preparing now reduces future risk.

What changed in the Privacy Act in 2024 and 2025?

Key changes include the Privacy and Other Legislation Amendment Act 2024 (commenced December 2024), a statutory tort for serious privacy invasions (from June 2025), expanded OAIC enforcement powers and upcoming obligations around automated decision making (from December 2026).

Can I use Meta Pixel on my website in Australia?

Yes, but you need to comply with your Privacy Act obligations. Disclose pixel use clearly, comply with APP 7 direct marketing obligations, provide a simple opt out and conduct regular reviews.

Can I run remarketing ads under Australian privacy law?

You can, but you need to be transparent about it. Disclose remarketing in your privacy policy, provide an opt out, avoid remarketing from sensitive pages and make sure the data you share with ad platforms is disclosed.

What should my contact form say about privacy?

At minimum, include a short notice near the form explaining what is collected and why, with a link to your full privacy policy. If you want to use the submission for marketing, add a separate opt in checkbox.

Do I need consent for email marketing?

Yes. Under ACMA rules, you need consent before sending commercial electronic messages. Every marketing email must identify the sender, include contact details and make unsubscribing easy.

Should I remove tracking from my website?

No. The goal is to track what you need, explain it clearly, remove what you do not use and provide meaningful choices. Good analytics and conversion tracking are essential. The issue is undisclosed, unnecessary or excessive tracking.

Next steps: pick your path

Path 1: run the 30 day audit yourself

Follow the four week plan in this article. Map your data, remove obvious risk, update your notices and document your vendor stack.

Path 2: get your tracking stack reviewed

If you are not sure what tags, pixels and integrations are running on your site, get in touch. We can map the tracking stack and show you what needs attention.

Path 3: get proper legal advice

If your business handles sensitive data or operates in a regulated industry, involve a qualified privacy lawyer alongside the technical review.

Your website does not need to become a legal document. But it does need to be more honest about what data it collects, why it collects it, who it shares it with and how people can control it.

Sources and further reading

Sources used in this article:

General information only. This article is not legal advice. Privacy law is complex and rules vary by business size, industry, data type and circumstances. If you need compliance guidance, consult a qualified privacy or legal professional.

AK
Written by

Ajay K.

Ajay is the co-founder of Elev8d. Psychology grad turned marketer. He writes plain English guides on SEO, Google Ads and web design for Australian businesses.