Almost every business website in Australia uses cookies, usually without the owner knowing exactly which ones. Google Analytics, a Facebook pixel, a live chat widget, a booking plugin and an embedded YouTube video all set them. The question we get asked most often is whether a small Australian business legally needs a cookie policy or one of those consent banners and the answer is more nuanced than the American and European guides suggest. This article explains what the law actually requires in Australia in 2026, why you should probably have a policy anyway, what to put in it and which tools make it painless on a WordPress site.
One caveat before we start: we build websites, we are not lawyers and privacy law is changing. Treat this as a practical guide and get legal advice for your specific situation, particularly if you handle health, financial or children’s data.
What cookies are and why they matter
Cookies are small text files a website stores on a visitor’s device. Some are essential: they keep a shopper logged in or remember what is in a cart. Others exist to measure and track: analytics cookies record how people use the site and advertising cookies from Google, Meta and others follow visitors across the web to target ads. It is that second category, along with the data they send overseas, that privacy law is concerned with.
A cookie policy is a plain statement of which cookies your site uses, what data they collect, why, who receives it (including overseas), how long they last and how visitors can control them. It can be a section of your privacy policy or a separate page.
What Australian law currently requires
The Privacy Act 1988 and its Australian Privacy Principles (APPs) apply to businesses with annual turnover above $3 million and to some smaller businesses regardless of turnover: health service providers, businesses that trade in personal information, contractors to the Commonwealth and a few other categories. If the Act applies to you, APP 1 requires a clear, up-to-date privacy policy explaining what personal information you collect (which can include data collected through cookies), how you use and store it and whether you send it overseas. APP 5 requires you to notify people about collection at or before the time it happens.
Two points that surprise people. First, Australian law is notice-based rather than consent-based: unlike the EU, there is currently no general legal requirement in Australia to show a cookie consent banner or to get opt-in consent before setting analytics or advertising cookies. Second, most genuinely small businesses are, for now, outside the Act altogether because of the $3 million threshold. Neither point means you should ignore the topic, for reasons below.
Where the law is heading
The first tranche of Privacy Act reform passed in late 2024. Its most significant pieces are a statutory tort for serious invasions of privacy, which commenced on 10 June 2025 and lets individuals sue directly; a requirement, with a transition period running to late 2026, for privacy policies to disclose the use of automated decision-making that significantly affects people; a Children’s Online Privacy Code being developed by the OAIC; and stronger OAIC enforcement powers, including a tiered civil penalty regime.
The second tranche is the one that matters most for small businesses. The Government has signalled support in principle for removing the $3 million small business exemption, which would bring roughly two million more businesses under the Act. As at the time of writing, no second-tranche Bill has passed and no commencement date is fixed; a transition period of a year or more would be likely once it does. The practical advice is to build your privacy and cookie practices now as if the exemption were already gone, because retrofitting under a deadline is more expensive than doing it once properly. The OAIC website is the authoritative source for current status.
Why you should have a cookie policy even if the Act doesn’t yet apply to you
Google requires it. Google Analytics and Google Ads terms of service require you to disclose your use of their cookies and, for advertising features, to obtain consent where law requires it. If you run Google Ads in Australia, Google Consent Mode is now expected for accurate conversion measurement and it works with a consent banner.
Overseas visitors. If your site is accessible to people in the European Union or the United Kingdom and you market to them, the GDPR and UK GDPR require a clear cookie policy and opt-in consent for non-essential cookies. An Australian tour operator, online store or software company selling to European customers is caught.
Trust. Australian customers have become noticeably more privacy-conscious since the Optus and Medibank breaches. A clear, honest policy is a small credibility signal that costs nothing.
Future-proofing. When the exemption goes, businesses with a policy and a consent tool already in place will have nothing to do.
What a cookie policy should cover
- What cookies are, in one or two plain sentences.
- The categories you use: strictly necessary, functional, analytics or performance and advertising or targeting.
- The specific cookies and their purpose, such as Google Analytics for site measurement or the Meta pixel for advertising. A table works well and most consent tools generate it automatically from a scan.
- How long each lasts, from session-only to two years.
- Third parties and overseas transfers: name the services (Google, Meta, your chat or booking provider) and note that data may be processed outside Australia.
- How visitors can manage or refuse cookies, through the banner if you have one and through browser settings.
- Contact details and the date the policy was last updated.
Link the policy from your footer and from the consent banner. Review it whenever you add a new plugin, pixel or embedded service; new cookies appear far more often than owners realise.
Setting it up on a WordPress site
You do not need to write any of this by hand. Consent management plugins scan your site, categorise the cookies they find, generate the policy table, display a banner and block non-essential scripts until the visitor chooses. CookieYes and Complianz are the two we install most often on client sites; Cookiebot and iubenda are solid alternatives and all have free tiers adequate for a small business. Complianz in particular has an Australian region setting that shows a notice rather than a full opt-in wall, which suits the current legal position here while still enabling Google Consent Mode.
Whichever you choose, set the banner to load fast and stay out of the way on mobile, connect it to Google Tag Manager or your GA4 and Ads tags so consent actually controls the tags and test that declining really does stop the pixels firing. A banner that looks compliant but changes nothing is worse than none. Our accessibility guide covers making the banner itself usable and our website security guide covers the data protection side of APP 11.
Frequently asked questions
Do I legally need a cookie banner in Australia?
Not under Australian law as it stands in 2026; the Privacy Act is notice-based and does not mandate opt-in consent for cookies. You may need one because of Google’s terms, because you have EU or UK visitors, or because you want to be ready for reform. Most business sites benefit from a light-touch notice banner connected to Consent Mode.
Does the Privacy Act apply to my small business?
If your turnover is under $3 million, generally not yet, unless you are a health service provider, trade in personal information, contract to the Commonwealth or fall into another exception. Removal of the exemption is proposed but not legislated; check the OAIC for current status.
Is a cookie policy the same as a privacy policy?
No. A privacy policy covers all the personal information you collect and how you handle it. A cookie policy covers the tracking technologies specifically. It can sit inside the privacy policy or on its own page; either way, have both.
What happens if I collect data through cookies without a policy?
If the Act applies to you, you are likely in breach of APP 1 and possibly APP 5 and the OAIC now has meaningful penalty powers. If it doesn’t, you may still be breaching Google’s terms and the GDPR for overseas visitors and you are eroding customer trust for no benefit.
Which cookies count as essential?
Ones the site cannot function without: session, login, cart and security cookies. Analytics, chat, embedded media and advertising cookies are not essential, however useful they are to you.
Can VisualWeb set this up?
Yes. Cookie policy, consent banner, Consent Mode and tag configuration are included in our website builds and can be added to an existing site as part of a maintenance plan. Get in touch if you would like it done properly.
This article is general information, not legal advice. For obligations specific to your business, consult a privacy lawyer and the Office of the Australian Information Commissioner.