Business websites now do much more than display information. They collect enquiries, run analytics, fire tracking pixels, build remarketing audiences, capture emails, use booking tools, show reviews and make claims about services. That means compliance issues can hide inside normal marketing setup.

This checklist covers the areas most likely to create problems: privacy policies, data collection, tracking and cookies, remarketing, email and SMS marketing, accessibility basics, advertising claims and overall digital trust. Many of these issues also show up as trust and conversion leaks, which is why they connect to the broader SEO strategy in our SEO guide.

Before you start: what this checklist can and cannot do

This checklist can help you:

  • Identify obvious website compliance gaps

  • Prepare better questions for a lawyer

  • Brief your developer or agency clearly

  • Clean up unnecessary tracking

  • Improve trust and transparency

This checklist cannot:

  • Confirm legal compliance for your specific situation

  • Replace professional legal advice

  • Cover every industry specific regulation

  • Decide whether the small business Privacy Act exemption applies to you

Use this checklist to find the gaps. Use professional advice to decide exactly how to close them.

Website compliance scorecard: the eight areas

Score each area as Pass, Needs Review or Urgent after working through the checks.

Area

Checks

Status

Privacy policy

1 to 4

Pass / Review / Urgent

Forms and data collection

5 to 8

Pass / Review / Urgent

Cookies and tracking

9 to 13

Pass / Review / Urgent

Remarketing and ads

14 to 16

Pass / Review / Urgent

Email/SMS marketing

17 to 19

Pass / Review / Urgent

Accessibility basics

20 to 22

Pass / Review / Urgent

Advertising claims

23 to 26

Pass / Review / Urgent

Digital trust/UX

General

Pass / Review / Urgent

Privacy policy checklist (checks 1 to 4)

The OAIC's Australian Privacy Principle 1 focuses on open and transparent management of personal information, including having a clearly expressed and up to date privacy policy.

Check 1: do you have a privacy policy?

If your business is covered by the Privacy Act, you need a privacy policy. Even if the small business exemption currently applies, having a clear privacy policy builds trust with customers and prepares you for future reform. Link it in the footer and near forms. For more detail on what the recent law changes mean for your website, see our article on Australia's privacy law changes. For a deeper look at what legal pages your site needs, see our guide to privacy policies and website terms.

Check 2: does it reflect what your website actually does?

Your privacy policy should describe the website you run today, not the one you had when the policy was first written. Check whether it mentions:

  • Contact forms and newsletter signups

  • Analytics (GA4) and ad pixels

  • Remarketing and CRM systems

  • Booking tools, payment tools and call tracking

  • Overseas data disclosures

  • Data access, correction rights and complaints process

Check 3: does it explain third party tools?

If your website sends data to Google Analytics, Google Ads, Meta, TikTok, LinkedIn, Hotjar, Mailchimp, HubSpot, Calendly, Stripe or similar platforms, your privacy policy should reflect that. Most generic template policies do not mention these tools.

Check 4: is it current?

Review your privacy policy every time:

  • The website is rebuilt

  • New forms are added

  • New tracking pixels are installed

  • Your CRM changes

  • Email or SMS flows are added

  • AI or chatbot tools are introduced

  • Privacy laws change

A privacy policy is only useful if it describes the website you actually run, not the website you had three years ago.

Data collection and form checklist (checks 5 to 8)

Every form on your website is a data collection point. For guidance on building forms that convert without over collecting, see our article on form design best practices.

Check 5: are your forms collecting only what you need?

Review every form on your website. For each field, ask: do we need this? Common over collection:

  • Asking for date of birth when it is not needed for the service

  • Asking for medical or legal details in a general enquiry form

  • Requiring full address when suburb is enough

  • Collecting budget information at the enquiry stage

  • Upload fields that could capture sensitive documents

Check 6: is there a collection notice near important forms?

Under APP 5, entities collecting personal information must take reasonable steps to notify individuals about collection matters at or before collection. For higher risk forms, include a short notice explaining what you collect, why, what happens after submission and where to find the privacy policy.

Check 7: are form submissions stored safely?

Check where form data ends up: website database, email inbox, CRM, spreadsheets, automation tools, agency or developer systems, old plugin storage and backups. If you do not know where the data goes after someone hits submit, that is a gap.

Check 8: are sensitive industries handling forms carefully?

If your business handles health, legal, financial, insurance, counselling, NDIS, recruitment or children's data, standard contact forms carry higher risk. Consider whether the form should warn users about sensitive information, whether data is stored with appropriate access controls and whether your privacy policy addresses the specific types of information collected.

Cookie, analytics and tracking checklist (checks 9 to 12)

The OAIC's tracking pixel guidance says organisations should conduct regular, ongoing reviews of website tracking technologies and comply with APP 7 when using tracking pixels for targeted online ads.

Check 9: do you know which tags are installed?

Open Google Tag Manager (or view page source) and list every tag, pixel and script running on your website:

  • GA4 (Google Analytics)

  • Google Ads conversion tag

  • Meta Pixel

  • TikTok Pixel and LinkedIn Insight Tag

  • Microsoft Ads UET tag

  • Hotjar or Microsoft Clarity

  • Call tracking scripts

  • Chat widget scripts

  • Affiliate tracking and booking widget scripts

If you are running Google Ads, make sure your conversion tracking is set up properly so you are not firing tags unnecessarily or missing legitimate conversions.

Check 10: are old tags removed?

It is common to find tags left behind by previous agencies, old campaign setups or abandoned tools. Look for:

  • Old agency tags still firing

  • Duplicate GA4 properties

  • Unused remarketing pixels

  • Abandoned heatmap tools

  • Duplicate conversion events

  • Tags firing on every page when they only need to fire on specific ones

Check 11: are you using tracking pixels responsibly?

The OAIC says organisations using third party tracking pixels for targeted online advertising must comply with APP 7 (direct marketing) and provide individuals with a simple opt out. Check:

  • Which pages do pixels fire on (especially sensitive pages)?

  • What events are sent to ad platforms?

  • Are thank you pages sending sensitive event labels?

  • Is there a clear opt out option?

  • Does the privacy policy explain targeted advertising use?

Check 12: are analytics events privacy safe?

Avoid sending personal information in page URLs, event names, form field values, thank you page labels, search terms, CRM identifiers or uploaded file names. If your GA4 setup captures enquiry form text in an event parameter, that is a problem.

Good tracking tells you what marketing works. Bad tracking quietly sends data you never meant to share.

Check 13: do you understand your server-side tracking setup?

Many businesses have moved to server-side Google Tag Manager or Google Consent Mode v2 without fully understanding what changed. Server-side tracking sends data from your server to ad platforms rather than from the user's browser. This can improve data accuracy and page speed, but it also changes how consent and privacy apply.

Check:

  • Is your GTM container running server-side, client-side or both?

  • If server-side, which platforms receive data through the server container?

  • Is Google Consent Mode v2 implemented and does it actually block tags when consent is withheld?

  • Are enhanced conversions or server-side event tracking sending hashed personal data to ad platforms?

  • Does your privacy policy disclose server-side data processing?

Server-side tracking is not automatically more or less compliant than client-side. It just moves where the data processing happens. Your privacy obligations apply either way.

Remarketing and advertising audience checklist (checks 14 to 16)

Check 14: are remarketing audiences appropriate?

Review what audiences you are building from website visits. Remarketing from a general service page is different from remarketing from a page about mental health counselling, family law or financial hardship.

Higher risk audience sources:

  • Medical or health condition pages

  • Legal issue pages (family law, criminal, employment disputes)

  • Financial hardship or debt pages

  • Counselling or psychology services

  • Children's services and job application pages

Check 15: do users have a clear opt out path?

The OAIC's guidance on direct marketing says APP 7 applies when organisations use or disclose personal information for direct marketing. Sensitive information can only be used for direct marketing with consent. Make sure your website provides a meaningful way for users to opt out of remarketing.

Check 16: are ad platforms receiving only necessary data?

Review enhanced conversions, custom audiences, hashed email uploads, CRM list imports, offline conversion imports and server-side tracking configurations. Each sends personal information to an advertising platform. Check whether each is necessary, disclosed and documented.

Remarketing is useful until it feels creepy. The line is usually crossed when businesses track sensitive intent without thinking through the customer's perspective.

Email and SMS marketing checklist (checks 17 to 19)

The ACMA says businesses must have consent before sending commercial electronic messages. Messages must identify the sender, include contact details and make unsubscribing easy.

Check 17: do you have consent?

Review consent for:

  • Newsletter signup forms

  • Quote and enquiry forms (is marketing consent separate?)

  • Checkout opt ins

  • Lead magnet downloads

  • Webinar and event registrations

  • CRM imports from old customer lists

Check 18: is marketing consent separate from enquiry consent?

Avoid automatically subscribing every form enquiry to your marketing list. Avoid pre ticked marketing checkboxes. Avoid unclear 'by submitting this form you agree to receive marketing' language buried in fine print. Make the marketing opt in a clear, separate choice.

Check 19: is unsubscribe easy?

Every marketing email should have a visible unsubscribe link. SMS messages should include opt out wording. Unsubscribed contacts should go to a suppression list and not be reimported later.

A person asking for a quote is not automatically asking for your newsletter forever.

AI chatbots and website privacy

If your website uses an AI chatbot, live chat widget or automated assistant, it creates privacy considerations that most compliance checklists miss entirely.

Check:

  • Is the chatbot collecting personal information (names, emails, phone numbers, service details)?

  • Where is conversation data stored and who can access it?

  • Is conversation data sent to a third party AI provider for processing?

  • Does your privacy policy disclose the use of AI or automated chat tools?

  • Are chat transcripts retained and for how long?

  • Can a user opt out of the chat tool or use a non AI alternative?

  • If the chatbot offers advice (legal, health, financial), is it clear that responses are automated and not professional advice?

An AI chatbot is a data collection point. If it asks questions and stores answers, it needs the same privacy treatment as a contact form.

Third party widgets and embedded content

Tracking pixels get the most attention, but many websites also load third party scripts through widgets and embeds that collect data without the business realising.

Common third party embeds to audit:

  • Booking widgets (Calendly, Acuity, SimplyBook)

  • Review widgets (Google, Trustpilot, third party aggregators)

  • Chat tools (Intercom, Drift, Zendesk, Tidio)

  • Payment forms (Stripe, Square, PayPal)

  • Video embeds (YouTube, Vimeo) which may set cookies on load

  • Social media feeds and share buttons

  • Google Maps embeds

Each of these loads external scripts that may set cookies, collect IP addresses or track behaviour. Your privacy policy should account for them. If you do not know what scripts your site loads, run a browser developer tools audit or ask your developer to document every third party connection.

Accessibility basics checklist (checks 20 to 22)

This is not a full WCAG audit. It is a basic check of whether real people can actually use your website. Check your starting point with our free Accessibility Quick Check tool.

Check 20: can people read and navigate the site?

  • Colour contrast is sufficient (text is easy to read against the background)

  • Font sizes are readable without zooming

  • The site can be navigated with a keyboard (tab through links and forms)

  • Focus states are visible (you can see where the cursor is)

  • Links have descriptive text (not just 'click here')

  • Headings are in a logical order

  • Form fields have visible labels

  • Error messages are clear and visible

  • Key videos or audio have captions or transcripts

  • Meaningful images have alt text

The Australian Human Rights Commission's digital accessibility guidelines explain how digital accessibility helps organisations meet Disability Discrimination Act obligations.

Check 21: does the website work on mobile and assistive technology?

Check:

  • Site works at 200% zoom or more

  • No horizontal scrolling on mobile

  • Buttons are easy to tap

  • Forms work on mobile devices

  • Page structure makes sense to screen readers

  • PDFs have HTML alternatives where possible

Mobile usability also affects search rankings. See our guide on mobile SEO for Australian businesses for the SEO side. If your site is slow, our article on how to speed up your website covers the technical fixes.

Check 22: are downloadable PDFs accessible?

Brochures, menus, price lists, forms, checklists, guides and compliance documents offered as PDFs should be accessible. This means real text (not just images of text), proper heading structure and alt text for images. If PDFs are not accessible, consider offering an HTML alternative.

ACCC advertising claims checklist (checks 23 to 26)

Check 23: can you prove every claim?

The ACCC says businesses must be able to prove advertising claims and claims should be true, accurate and based on reasonable grounds. Review claims like:

  • 'Best', '#1', 'leading'

  • 'Guaranteed results'

  • 'Fastest' or 'cheapest'

  • 'Trusted by thousands'

  • 'Award winning' (is the award real and verifiable?)

  • 'Risk free'

  • 'Australian made' (does it meet the criteria?)

If a claim helps sell the service, the business needs to be able to stand behind it with evidence.

Check 24: are pricing claims clear?

Check whether pricing includes GST, whether 'from' pricing is genuine, whether setup fees, ongoing costs, contract terms and exclusions are disclosed. If there are cancellation fees, installation costs or shipping and return conditions, these should be visible before the customer commits.

Check 25: are testimonials and reviews handled properly?

The ACCC says it is against the law for businesses to create fake or misleading reviews or to arrange for others to do so. Check that your website does not display fake reviews, cherry pick in a way that misleads, edit testimonials to change meaning or suppress negative feedback in a deceptive way. For more on handling reviews the right way, see our guide on getting Google reviews legally.

Check 26: are before/after and results claims realistic?

This is relevant for SEO, Google Ads, fitness, cosmetic services, finance, coaching, health, renovations and professional services. Before and after claims, results claims and performance promises should be realistic, not misleading and ideally accompanied by context about what affects outcomes.

Digital trust and user experience checklist

Trust is not one badge or one policy page. It is the whole experience feeling clear, safe and honest. Building visible trust on your website is also a core part of E-E-A-T for small businesses. If your site needs a security review, our article on WordPress security covers the technical foundations.

Check:

  • HTTPS is active across the entire site

  • No mixed content warnings

  • All forms work properly and do not produce errors

  • Clear contact details visible on every page

  • Real business name displayed

  • ABN or ACN shown where useful

  • Privacy policy linked in the footer

  • Terms, returns or refund policies where relevant

  • Accurate opening hours

  • No broken links on key pages

  • Mobile friendly layout

  • Fast enough loading speed

  • Secure checkout (if applicable)

  • Accessible contact options (phone, email, form)

30 minute website compliance self audit

You do not need a full day to find the obvious gaps. Here is how to run through the key checks in about 30 minutes.

Time

Focus

What to do

0 to 5 min

Open essentials

Open homepage, contact page, privacy policy, top service page, checkout or booking page if relevant, Google Tag Manager and your email/SMS platform.

5 to 12 min

Forms and privacy

Check privacy policy exists and is linked. Review form fields and collection notices. Check where submissions go.

12 to 18 min

Tracking

Check GA4, ad pixels, remarketing tags, heatmaps, call tracking and old or unused tags in GTM.

18 to 23 min

Claims

Review homepage and service page claims. Check testimonials and reviews. Review pricing for clarity.

23 to 28 min

Accessibility basics

Check mobile layout, text size, contrast, headings, form labels, alt text on key images and keyboard navigation.

28 to 30 min

Score and prioritise

Mark each area as Pass, Needs Review or Urgent. Note which items need legal review, developer work or marketing cleanup.

This pairs well with our SEO audit checklist, which covers the technical, content, local and off page SEO checks alongside these compliance foundations.

Common website compliance mistakes

The biggest compliance problem is usually ownership. Everyone assumes someone else checked it.

Mistake

Why it matters

Copying a privacy policy from another site

Does not describe your actual data practices

Installing a cookie banner without auditing tags

Theatre, not transparency

Assuming the developer handled privacy

Developers build sites, they are not privacy lawyers

Collecting too much form data

Every unnecessary field is a risk with no upside

Using Meta Pixel on every page by default

Firing remarketing on sensitive pages is high risk

Adding people to email lists after a quote request

A quote request is not marketing consent

Making claims you cannot prove

Needs evidence or should be removed

Using fake or edited reviews

Against the law per ACCC guidance

What to do after the checklist

If privacy gaps show up

  • Speak with a privacy lawyer or legal adviser

  • Update your privacy policy

  • Add or improve form collection notices

  • Map your data flows so you know where information goes

If tracking gaps show up

  • Audit Google Tag Manager

  • Remove old and unused tags

  • Document every active tool

  • Review pixel events and where data is sent. This is part of ongoing website maintenance that most businesses overlook.

If accessibility gaps show up

  • Fix obvious UX barriers first (broken forms, unreadable text, missing alt text)

  • Then consider a more thorough accessibility audit

  • Prioritise forms, navigation, CTAs and downloadable PDFs

If advertising claims are risky

  • Collect evidence to support your claims

  • Rewrite anything you cannot substantiate

  • Remove exaggerated language

  • Check that testimonials are genuine and unedited

If everything looks messy

Run a full website audit that brings legal, developer and marketing together. Consider a website rebuild with compliance built in rather than patching an old site. Our website redesign checklist covers what to plan for.

What we recommend at Elev8d

We can help you see what your website is doing. Your legal team should decide what your business must say, disclose or change.

When we build or audit websites, we review the tracking stack, form setup, tag configuration and user experience as part of the project. We can show you which tags are firing, which forms are collecting more than they need, which pixels are active and where the obvious trust and UX gaps are.

For most Australian businesses, the practical first step is visibility: know what your website collects, where it sends data and what it claims. From there, your legal adviser can review the policy side, your developer can fix the technical side and your marketing team can clean up the tracking side.

If you want help mapping your tracking stack and form setup, our SEO services include website audits that cover these compliance foundations alongside the search performance work.

Frequently asked questions

Answers to common questions about website compliance for Australian businesses.

What legal pages does an Australian business website need?

At minimum, a privacy policy if you collect personal information (which most business websites do through forms, analytics or tracking). Depending on your business, you may also need terms and conditions, refund and returns policies, shipping policies and specific industry disclaimers.

Does my website need a privacy policy in Australia?

If you are an APP entity under the Privacy Act (generally businesses with over $3 million annual turnover, plus health providers and some others), yes. Even if the small business exemption currently applies, a privacy policy builds trust and prepares you for future reform.

Do Australian websites need cookie consent?

Australia does not have the same cookie consent model as the EU. However, if your website uses tracking pixels, remarketing or behavioural profiling, you should provide clear notice and meaningful opt out options. The exact requirements depend on your situation.

Can I use Meta Pixel on my website?

Yes, but you must comply with your Privacy Act obligations. Disclose pixel use, comply with direct marketing rules under APP 7, provide a simple opt out and avoid firing pixels on sensitive pages without careful consideration.

Are website testimonials regulated in Australia?

Yes. The ACCC says businesses must not create fake or misleading reviews or arrange for others to do so. Testimonials should be genuine, unedited in meaning and any incentives should be disclosed.

Does my business website need to meet WCAG?

There is no single law that requires all private Australian business websites to meet a specific WCAG level. However, the Disability Discrimination Act covers goods and services and WCAG is widely accepted as the practical benchmark. Basic accessibility improvements also help usability, conversion and SEO.

How often should I review website compliance?

At minimum, review whenever you rebuild the site, add new forms or tracking, change CRM or email tools, launch new advertising campaigns or when privacy laws change. A quarterly tracking audit is good practice.

Should my web designer or lawyer handle compliance?

Both, in their areas. Your web designer or agency can audit tracking, forms, tags and UX. Your lawyer can review privacy policy wording, consent mechanisms and industry specific obligations. Neither should be expected to do the other's job.

Next steps: pick your path

Path 1: run the checklist yourself

Work through the checks in this article. Mark each as Pass, Needs Review or Urgent. Use the 30 minute audit workflow to keep it focused. Then decide what needs legal review, developer work or marketing cleanup.

Path 2: get your tracking and forms reviewed

If you are not sure what tags, pixels and integrations are running on your site, get in touch. We can map the tracking stack, review form setup and show you where the gaps are so your legal adviser has a clear picture to work with.

Path 3: get proper legal advice

If your business handles sensitive data, operates in a regulated industry or needs specific compliance guidance, involve a qualified privacy lawyer alongside the website review.

A compliant website is not just one with legal pages. It is one where the business knows what it collects, explains it clearly, avoids misleading claims and gives people a fair, usable experience.

Sources and further reading

Sources used in this article:

General information only. This article is not legal advice. Website compliance depends on your business, industry, data collection, customers and legal obligations. If you need compliance guidance, consult a qualified Australian lawyer or privacy professional.

AK
Written by

Ajay K.

Ajay is the co-founder of Elev8d. Psychology grad turned marketer. He writes plain English guides on SEO, Google Ads and web design for Australian businesses.