Business websites now do much more than display information. They collect enquiries, run analytics, fire tracking pixels, build remarketing audiences, capture emails, use booking tools, show reviews and make claims about services. That means compliance issues can hide inside normal marketing setup.
This checklist covers the areas most likely to create problems: privacy policies, data collection, tracking and cookies, remarketing, email and SMS marketing, accessibility basics, advertising claims and overall digital trust. Many of these issues also show up as trust and conversion leaks, which is why they connect to the broader SEO strategy in our SEO guide.
Before you start: what this checklist can and cannot do
This checklist can help you:
Identify obvious website compliance gaps
Prepare better questions for a lawyer
Brief your developer or agency clearly
Clean up unnecessary tracking
Improve trust and transparency
This checklist cannot:
Confirm legal compliance for your specific situation
Replace professional legal advice
Cover every industry specific regulation
Decide whether the small business Privacy Act exemption applies to you
Use this checklist to find the gaps. Use professional advice to decide exactly how to close them.
Website compliance scorecard: the eight areas
Score each area as Pass, Needs Review or Urgent after working through the checks.
Area | Checks | Status |
|---|---|---|
Privacy policy | 1 to 4 | Pass / Review / Urgent |
Forms and data collection | 5 to 8 | Pass / Review / Urgent |
Cookies and tracking | 9 to 13 | Pass / Review / Urgent |
Remarketing and ads | 14 to 16 | Pass / Review / Urgent |
Email/SMS marketing | 17 to 19 | Pass / Review / Urgent |
Accessibility basics | 20 to 22 | Pass / Review / Urgent |
Advertising claims | 23 to 26 | Pass / Review / Urgent |
Digital trust/UX | General | Pass / Review / Urgent |
Privacy policy checklist (checks 1 to 4)
The OAIC's Australian Privacy Principle 1 focuses on open and transparent management of personal information, including having a clearly expressed and up to date privacy policy.
Check 1: do you have a privacy policy?
If your business is covered by the Privacy Act, you need a privacy policy. Even if the small business exemption currently applies, having a clear privacy policy builds trust with customers and prepares you for future reform. Link it in the footer and near forms. For more detail on what the recent law changes mean for your website, see our article on Australia's privacy law changes. For a deeper look at what legal pages your site needs, see our guide to privacy policies and website terms.
Check 2: does it reflect what your website actually does?
Your privacy policy should describe the website you run today, not the one you had when the policy was first written. Check whether it mentions:
Contact forms and newsletter signups
Analytics (GA4) and ad pixels
Remarketing and CRM systems
Booking tools, payment tools and call tracking
Overseas data disclosures
Data access, correction rights and complaints process
Check 3: does it explain third party tools?
If your website sends data to Google Analytics, Google Ads, Meta, TikTok, LinkedIn, Hotjar, Mailchimp, HubSpot, Calendly, Stripe or similar platforms, your privacy policy should reflect that. Most generic template policies do not mention these tools.
Check 4: is it current?
Review your privacy policy every time:
The website is rebuilt
New forms are added
New tracking pixels are installed
Your CRM changes
Email or SMS flows are added
AI or chatbot tools are introduced
Privacy laws change
A privacy policy is only useful if it describes the website you actually run, not the website you had three years ago.
Data collection and form checklist (checks 5 to 8)
Every form on your website is a data collection point. For guidance on building forms that convert without over collecting, see our article on form design best practices.
Check 5: are your forms collecting only what you need?
Review every form on your website. For each field, ask: do we need this? Common over collection:
Asking for date of birth when it is not needed for the service
Asking for medical or legal details in a general enquiry form
Requiring full address when suburb is enough
Collecting budget information at the enquiry stage
Upload fields that could capture sensitive documents
Check 6: is there a collection notice near important forms?
Under APP 5, entities collecting personal information must take reasonable steps to notify individuals about collection matters at or before collection. For higher risk forms, include a short notice explaining what you collect, why, what happens after submission and where to find the privacy policy.
Check 7: are form submissions stored safely?
Check where form data ends up: website database, email inbox, CRM, spreadsheets, automation tools, agency or developer systems, old plugin storage and backups. If you do not know where the data goes after someone hits submit, that is a gap.
Check 8: are sensitive industries handling forms carefully?
If your business handles health, legal, financial, insurance, counselling, NDIS, recruitment or children's data, standard contact forms carry higher risk. Consider whether the form should warn users about sensitive information, whether data is stored with appropriate access controls and whether your privacy policy addresses the specific types of information collected.
Cookie, analytics and tracking checklist (checks 9 to 12)
The OAIC's tracking pixel guidance says organisations should conduct regular, ongoing reviews of website tracking technologies and comply with APP 7 when using tracking pixels for targeted online ads.
Check 9: do you know which tags are installed?
Open Google Tag Manager (or view page source) and list every tag, pixel and script running on your website:
GA4 (Google Analytics)
Google Ads conversion tag
Meta Pixel
TikTok Pixel and LinkedIn Insight Tag
Microsoft Ads UET tag
Hotjar or Microsoft Clarity
Call tracking scripts
Chat widget scripts
Affiliate tracking and booking widget scripts
If you are running Google Ads, make sure your conversion tracking is set up properly so you are not firing tags unnecessarily or missing legitimate conversions.
Check 10: are old tags removed?
It is common to find tags left behind by previous agencies, old campaign setups or abandoned tools. Look for:
Old agency tags still firing
Duplicate GA4 properties
Unused remarketing pixels
Abandoned heatmap tools
Duplicate conversion events
Tags firing on every page when they only need to fire on specific ones
Check 11: are you using tracking pixels responsibly?
The OAIC says organisations using third party tracking pixels for targeted online advertising must comply with APP 7 (direct marketing) and provide individuals with a simple opt out. Check:
Which pages do pixels fire on (especially sensitive pages)?
What events are sent to ad platforms?
Are thank you pages sending sensitive event labels?
Is there a clear opt out option?
Does the privacy policy explain targeted advertising use?
Check 12: are analytics events privacy safe?
Avoid sending personal information in page URLs, event names, form field values, thank you page labels, search terms, CRM identifiers or uploaded file names. If your GA4 setup captures enquiry form text in an event parameter, that is a problem.
Good tracking tells you what marketing works. Bad tracking quietly sends data you never meant to share.
Check 13: do you understand your server-side tracking setup?
Many businesses have moved to server-side Google Tag Manager or Google Consent Mode v2 without fully understanding what changed. Server-side tracking sends data from your server to ad platforms rather than from the user's browser. This can improve data accuracy and page speed, but it also changes how consent and privacy apply.
Check:
Is your GTM container running server-side, client-side or both?
If server-side, which platforms receive data through the server container?
Is Google Consent Mode v2 implemented and does it actually block tags when consent is withheld?
Are enhanced conversions or server-side event tracking sending hashed personal data to ad platforms?
Does your privacy policy disclose server-side data processing?
Server-side tracking is not automatically more or less compliant than client-side. It just moves where the data processing happens. Your privacy obligations apply either way.
Remarketing and advertising audience checklist (checks 14 to 16)
Check 14: are remarketing audiences appropriate?
Review what audiences you are building from website visits. Remarketing from a general service page is different from remarketing from a page about mental health counselling, family law or financial hardship.
Higher risk audience sources:
Medical or health condition pages
Legal issue pages (family law, criminal, employment disputes)
Financial hardship or debt pages
Counselling or psychology services
Children's services and job application pages
Check 15: do users have a clear opt out path?
The OAIC's guidance on direct marketing says APP 7 applies when organisations use or disclose personal information for direct marketing. Sensitive information can only be used for direct marketing with consent. Make sure your website provides a meaningful way for users to opt out of remarketing.
Check 16: are ad platforms receiving only necessary data?
Review enhanced conversions, custom audiences, hashed email uploads, CRM list imports, offline conversion imports and server-side tracking configurations. Each sends personal information to an advertising platform. Check whether each is necessary, disclosed and documented.
Remarketing is useful until it feels creepy. The line is usually crossed when businesses track sensitive intent without thinking through the customer's perspective.
Email and SMS marketing checklist (checks 17 to 19)
The ACMA says businesses must have consent before sending commercial electronic messages. Messages must identify the sender, include contact details and make unsubscribing easy.
Check 17: do you have consent?
Review consent for:
Newsletter signup forms
Quote and enquiry forms (is marketing consent separate?)
Checkout opt ins
Lead magnet downloads
Webinar and event registrations
CRM imports from old customer lists
Check 18: is marketing consent separate from enquiry consent?
Avoid automatically subscribing every form enquiry to your marketing list. Avoid pre ticked marketing checkboxes. Avoid unclear 'by submitting this form you agree to receive marketing' language buried in fine print. Make the marketing opt in a clear, separate choice.
Check 19: is unsubscribe easy?
Every marketing email should have a visible unsubscribe link. SMS messages should include opt out wording. Unsubscribed contacts should go to a suppression list and not be reimported later.
A person asking for a quote is not automatically asking for your newsletter forever.
AI chatbots and website privacy
If your website uses an AI chatbot, live chat widget or automated assistant, it creates privacy considerations that most compliance checklists miss entirely.
Check:
Is the chatbot collecting personal information (names, emails, phone numbers, service details)?
Where is conversation data stored and who can access it?
Is conversation data sent to a third party AI provider for processing?
Does your privacy policy disclose the use of AI or automated chat tools?
Are chat transcripts retained and for how long?
Can a user opt out of the chat tool or use a non AI alternative?
If the chatbot offers advice (legal, health, financial), is it clear that responses are automated and not professional advice?
An AI chatbot is a data collection point. If it asks questions and stores answers, it needs the same privacy treatment as a contact form.
Third party widgets and embedded content
Tracking pixels get the most attention, but many websites also load third party scripts through widgets and embeds that collect data without the business realising.
Common third party embeds to audit:
Booking widgets (Calendly, Acuity, SimplyBook)
Review widgets (Google, Trustpilot, third party aggregators)
Chat tools (Intercom, Drift, Zendesk, Tidio)
Payment forms (Stripe, Square, PayPal)
Video embeds (YouTube, Vimeo) which may set cookies on load
Social media feeds and share buttons
Google Maps embeds
Each of these loads external scripts that may set cookies, collect IP addresses or track behaviour. Your privacy policy should account for them. If you do not know what scripts your site loads, run a browser developer tools audit or ask your developer to document every third party connection.
Accessibility basics checklist (checks 20 to 22)
This is not a full WCAG audit. It is a basic check of whether real people can actually use your website. Check your starting point with our free Accessibility Quick Check tool.
Check 20: can people read and navigate the site?
Colour contrast is sufficient (text is easy to read against the background)
Font sizes are readable without zooming
The site can be navigated with a keyboard (tab through links and forms)
Focus states are visible (you can see where the cursor is)
Links have descriptive text (not just 'click here')
Headings are in a logical order
Form fields have visible labels
Error messages are clear and visible
Key videos or audio have captions or transcripts
Meaningful images have alt text
The Australian Human Rights Commission's digital accessibility guidelines explain how digital accessibility helps organisations meet Disability Discrimination Act obligations.
Check 21: does the website work on mobile and assistive technology?
Check:
Site works at 200% zoom or more
No horizontal scrolling on mobile
Buttons are easy to tap
Forms work on mobile devices
Page structure makes sense to screen readers
PDFs have HTML alternatives where possible
Mobile usability also affects search rankings. See our guide on mobile SEO for Australian businesses for the SEO side. If your site is slow, our article on how to speed up your website covers the technical fixes.
Check 22: are downloadable PDFs accessible?
Brochures, menus, price lists, forms, checklists, guides and compliance documents offered as PDFs should be accessible. This means real text (not just images of text), proper heading structure and alt text for images. If PDFs are not accessible, consider offering an HTML alternative.
ACCC advertising claims checklist (checks 23 to 26)
Check 23: can you prove every claim?
The ACCC says businesses must be able to prove advertising claims and claims should be true, accurate and based on reasonable grounds. Review claims like:
'Best', '#1', 'leading'
'Guaranteed results'
'Fastest' or 'cheapest'
'Trusted by thousands'
'Award winning' (is the award real and verifiable?)
'Risk free'
'Australian made' (does it meet the criteria?)
If a claim helps sell the service, the business needs to be able to stand behind it with evidence.
Check 24: are pricing claims clear?
Check whether pricing includes GST, whether 'from' pricing is genuine, whether setup fees, ongoing costs, contract terms and exclusions are disclosed. If there are cancellation fees, installation costs or shipping and return conditions, these should be visible before the customer commits.
Check 25: are testimonials and reviews handled properly?
The ACCC says it is against the law for businesses to create fake or misleading reviews or to arrange for others to do so. Check that your website does not display fake reviews, cherry pick in a way that misleads, edit testimonials to change meaning or suppress negative feedback in a deceptive way. For more on handling reviews the right way, see our guide on getting Google reviews legally.
Check 26: are before/after and results claims realistic?
This is relevant for SEO, Google Ads, fitness, cosmetic services, finance, coaching, health, renovations and professional services. Before and after claims, results claims and performance promises should be realistic, not misleading and ideally accompanied by context about what affects outcomes.
Digital trust and user experience checklist
Trust is not one badge or one policy page. It is the whole experience feeling clear, safe and honest. Building visible trust on your website is also a core part of E-E-A-T for small businesses. If your site needs a security review, our article on WordPress security covers the technical foundations.
Check:
HTTPS is active across the entire site
No mixed content warnings
All forms work properly and do not produce errors
Clear contact details visible on every page
Real business name displayed
ABN or ACN shown where useful
Privacy policy linked in the footer
Terms, returns or refund policies where relevant
Accurate opening hours
No broken links on key pages
Mobile friendly layout
Fast enough loading speed
Secure checkout (if applicable)
Accessible contact options (phone, email, form)
30 minute website compliance self audit
You do not need a full day to find the obvious gaps. Here is how to run through the key checks in about 30 minutes.
Time | Focus | What to do |
|---|---|---|
0 to 5 min | Open essentials | Open homepage, contact page, privacy policy, top service page, checkout or booking page if relevant, Google Tag Manager and your email/SMS platform. |
5 to 12 min | Forms and privacy | Check privacy policy exists and is linked. Review form fields and collection notices. Check where submissions go. |
12 to 18 min | Tracking | Check GA4, ad pixels, remarketing tags, heatmaps, call tracking and old or unused tags in GTM. |
18 to 23 min | Claims | Review homepage and service page claims. Check testimonials and reviews. Review pricing for clarity. |
23 to 28 min | Accessibility basics | Check mobile layout, text size, contrast, headings, form labels, alt text on key images and keyboard navigation. |
28 to 30 min | Score and prioritise | Mark each area as Pass, Needs Review or Urgent. Note which items need legal review, developer work or marketing cleanup. |
This pairs well with our SEO audit checklist, which covers the technical, content, local and off page SEO checks alongside these compliance foundations.
Common website compliance mistakes
The biggest compliance problem is usually ownership. Everyone assumes someone else checked it.
Mistake | Why it matters |
|---|---|
Copying a privacy policy from another site | Does not describe your actual data practices |
Installing a cookie banner without auditing tags | Theatre, not transparency |
Assuming the developer handled privacy | Developers build sites, they are not privacy lawyers |
Collecting too much form data | Every unnecessary field is a risk with no upside |
Using Meta Pixel on every page by default | Firing remarketing on sensitive pages is high risk |
Adding people to email lists after a quote request | A quote request is not marketing consent |
Making claims you cannot prove | Needs evidence or should be removed |
Using fake or edited reviews | Against the law per ACCC guidance |
What to do after the checklist
If privacy gaps show up
Speak with a privacy lawyer or legal adviser
Update your privacy policy
Add or improve form collection notices
Map your data flows so you know where information goes
If tracking gaps show up
Audit Google Tag Manager
Remove old and unused tags
Document every active tool
Review pixel events and where data is sent. This is part of ongoing website maintenance that most businesses overlook.
If accessibility gaps show up
Fix obvious UX barriers first (broken forms, unreadable text, missing alt text)
Then consider a more thorough accessibility audit
Prioritise forms, navigation, CTAs and downloadable PDFs
If advertising claims are risky
Collect evidence to support your claims
Rewrite anything you cannot substantiate
Remove exaggerated language
Check that testimonials are genuine and unedited
If everything looks messy
Run a full website audit that brings legal, developer and marketing together. Consider a website rebuild with compliance built in rather than patching an old site. Our website redesign checklist covers what to plan for.
What we recommend at Elev8d
We can help you see what your website is doing. Your legal team should decide what your business must say, disclose or change.
When we build or audit websites, we review the tracking stack, form setup, tag configuration and user experience as part of the project. We can show you which tags are firing, which forms are collecting more than they need, which pixels are active and where the obvious trust and UX gaps are.
For most Australian businesses, the practical first step is visibility: know what your website collects, where it sends data and what it claims. From there, your legal adviser can review the policy side, your developer can fix the technical side and your marketing team can clean up the tracking side.
If you want help mapping your tracking stack and form setup, our SEO services include website audits that cover these compliance foundations alongside the search performance work.
Frequently asked questions
Answers to common questions about website compliance for Australian businesses.
What legal pages does an Australian business website need?
At minimum, a privacy policy if you collect personal information (which most business websites do through forms, analytics or tracking). Depending on your business, you may also need terms and conditions, refund and returns policies, shipping policies and specific industry disclaimers.
Does my website need a privacy policy in Australia?
If you are an APP entity under the Privacy Act (generally businesses with over $3 million annual turnover, plus health providers and some others), yes. Even if the small business exemption currently applies, a privacy policy builds trust and prepares you for future reform.
Do Australian websites need cookie consent?
Australia does not have the same cookie consent model as the EU. However, if your website uses tracking pixels, remarketing or behavioural profiling, you should provide clear notice and meaningful opt out options. The exact requirements depend on your situation.
Can I use Meta Pixel on my website?
Yes, but you must comply with your Privacy Act obligations. Disclose pixel use, comply with direct marketing rules under APP 7, provide a simple opt out and avoid firing pixels on sensitive pages without careful consideration.
Are website testimonials regulated in Australia?
Yes. The ACCC says businesses must not create fake or misleading reviews or arrange for others to do so. Testimonials should be genuine, unedited in meaning and any incentives should be disclosed.
Does my business website need to meet WCAG?
There is no single law that requires all private Australian business websites to meet a specific WCAG level. However, the Disability Discrimination Act covers goods and services and WCAG is widely accepted as the practical benchmark. Basic accessibility improvements also help usability, conversion and SEO.
How often should I review website compliance?
At minimum, review whenever you rebuild the site, add new forms or tracking, change CRM or email tools, launch new advertising campaigns or when privacy laws change. A quarterly tracking audit is good practice.
Should my web designer or lawyer handle compliance?
Both, in their areas. Your web designer or agency can audit tracking, forms, tags and UX. Your lawyer can review privacy policy wording, consent mechanisms and industry specific obligations. Neither should be expected to do the other's job.
Next steps: pick your path
Path 1: run the checklist yourself
Work through the checks in this article. Mark each as Pass, Needs Review or Urgent. Use the 30 minute audit workflow to keep it focused. Then decide what needs legal review, developer work or marketing cleanup.
Path 2: get your tracking and forms reviewed
If you are not sure what tags, pixels and integrations are running on your site, get in touch. We can map the tracking stack, review form setup and show you where the gaps are so your legal adviser has a clear picture to work with.
Path 3: get proper legal advice
If your business handles sensitive data, operates in a regulated industry or needs specific compliance guidance, involve a qualified privacy lawyer alongside the website review.
A compliant website is not just one with legal pages. It is one where the business knows what it collects, explains it clearly, avoids misleading claims and gives people a fair, usable experience.
Sources and further reading
Sources used in this article:
OAIC: Australian Privacy Principles: The 13 principles governing personal information handling.
OAIC: Tracking Pixels Guidance: Specific guidance on tracking pixel obligations.
ACCC: Advertising and Promotions: Guidance on truthful claims, reviews and pricing.
ACMA: Avoiding Spam: Rules on electronic marketing messages and consent.
Australian Human Rights Commission: Disability Rights: Digital accessibility and Disability Discrimination Act obligations.
General information only. This article is not legal advice. Website compliance depends on your business, industry, data collection, customers and legal obligations. If you need compliance guidance, consult a qualified Australian lawyer or privacy professional.