Almost every Australian business website should have a privacy policy, even if the law does not strictly force yours to. A cookie banner is a different question. Australia has no blanket rule that every site must ask permission before dropping cookies, so plenty of small local businesses do not need one. If you sell to people in Europe or the UK, or you run tracking and advertising pixels, a proper consent banner becomes much more important. Here is how to work out where your site sits.
Who the Privacy Act actually covers
The Privacy Act 1988 and the Australian Privacy Principles apply to government agencies and to most organisations with an annual turnover above three million dollars. Businesses under that threshold are generally exempt, which is why so many small Australian sites have quietly gone without a policy for years.
The exemption has holes in it though. You are covered regardless of turnover if you handle health information, trade in personal information, are a credit reporting body, or provide services under a Commonwealth contract. You can also choose to opt in. The exemption has been under review for some years and there is steady pressure to remove it, so building good habits now is cheaper than scrambling later.
One thing worth knowing: from December 2026, organisations covered by the Act that use personal information in automated decision making need to explain that in their privacy policy. If a computer program decides something that meaningfully affects someone, you have to say so.
Why publish a policy anyway
Even when you are exempt, a privacy policy earns its keep. Google requires one if you run Analytics or Ads. Facebook and Instagram ask for one before you run lead ads. Payment providers and app stores expect one. Larger clients doing supplier checks will look for it. And customers handing over a phone number reasonably want to know what happens next.
It is also the cheapest trust signal on your website. A page that says plainly what you collect and why makes an enquiry feel safer, which is the same reason we bang on about clear contact pages in our WordPress web design work.
What to put in it
Skip the copied template full of clauses that do not match your business. Write something short and true instead. Cover:
- What you collect, in plain terms. Names, emails, phone numbers, order details, analytics data.
- How you collect it. Contact forms, newsletter sign-ups, checkout, cookies.
- Why you collect it, and what you do with it.
- Who else sees it. Your email platform, payment gateway, accountant, booking system.
- Whether any of it leaves Australia, which it usually does the moment you use an overseas service.
- How long you keep it and how someone asks for a copy or a deletion.
- A real contact point. A monitored email address, not a dead form.
Then keep it current. A policy that still names a plugin you removed in 2023 is worse than no policy at all.
So do you need a cookie banner?
Australia does not have the equivalent of the European rule that made those pop-ups universal. Our law focuses on personal information and reasonable notice rather than consent for every cookie. For a plumber in Penrith with a contact form and basic analytics, a banner is usually unnecessary clutter.
You should seriously consider one if any of these apply:
- You sell or market to people in the EU or UK, where GDPR travels with the visitor.
- You run advertising pixels for Google Ads or Meta and want reliable measurement, since both now expect consent signals from European traffic.
- You collect sensitive information, or your industry has its own rules.
If you do add one, make it honest. A banner where declining is as easy as accepting, and where the tracking scripts genuinely do not load until someone agrees. A banner that sets cookies before you click anything is theatre, and it looks worse than having nothing.
Getting it sorted on a WordPress site
WordPress ships with a draft privacy policy page you can adapt. Write your version, link it in the footer, and link it near your contact and checkout forms. If you use a consent plugin, pick one that actually blocks scripts rather than one that only draws a bar. Keep the plugin count sensible while you are at it.
If your site does something less ordinary with data, like a member portal, a booking system or a custom integration, it is worth a proper look at what is stored and where. That is the sort of build our sister studio Defyn handles, and it is also where we spend most of our WordPress development time.
One caveat: this is general information, not legal advice. If you handle health records, financial data or anything sensitive, get a lawyer to read your policy.
Not sure what your site is collecting behind the scenes? We are happy to take a look and tell you straight. Give us a call on 02 9834 4119 or get in touch.
Need a WordPress website, theme or plugin built properly? We would love to help.
Start a project



