Australia

Privacy & Compliance / Regional guide

Website Tracking Compliance in Australia

What applies in this market

Australia: The Privacy Act and the Australian Privacy Principles.

Summary

Website tracking is legal in Australia, with rules lighter than the EU’s, though tightening. The Privacy Act and its Australian Privacy Principles (APPs) require transparency about what you collect and consent for sensitive information, with no EU-style cookie banner rule. A major reform is underway, and a new statutory tort lets people sue for serious invasions of privacy.

For a marketing or analytics team, Australia today is closer to “tell people clearly and handle sensitive data carefully” than to “block everything until consent.” That gap is narrowing, which is the thing to watch.

The sections below cover what the Privacy Act and the APPs require today, what is changing, and what compliance means in practice for your tags. The last section shows how to verify your Australian setup.

What the Privacy Act and the APPs require

The APPs set obligations that apply to tracking even without a cookie-consent mandate.

Collection has to be reasonably necessary and done by lawful, fair means (APP 3). You have to tell people what you collect and why, usually through a clear privacy policy and collection notice (APP 5). You can only use or disclose personal information for the purpose you collected it, or a reasonably expected related purpose (APP 6). And sensitive information, such as health data, generally needs consent before you collect it (APP 3), which is where a pixel picking up health data becomes a real problem.

So a tag that quietly collects sensitive data, or shares personal information in a way people would not expect, is an APP issue even though Australia has no cookie banner requirement.

What is changing

Australia is in the middle of its biggest privacy overhaul in a generation, and it matters for tracking.

The first tranche of reforms, approved in 2024, strengthened the regulator’s powers and introduced a statutory tort for serious invasions of privacy, which commenced on 10 June 2025. That tort gives individuals a direct way to sue, a litigation risk that did not exist before. A second wave followed as an exposure draft, the Privacy Amendment (Personal Data Protection) Bill 2026, released for consultation that closed on 18 September 2026. It proposes that collection, use and disclosure be fair and reasonable, and a right to have information destroyed by large digital platforms. It is a draft and has not become law.

What Australian tracking compliance requires in practice

Be transparent about what your tags collect and why, get consent before collecting sensitive information, and do not let tags share personal data in ways a visitor would not expect. Given the reform direction and the new statutory tort, treating consent-before-tracking as a sensible default, even where it is not yet strictly required, is the low-risk position.

For specific OAIC enforcement actions, see our Enforcement Watch tracker.

How to verify your Australian setup

Even without a cookie-consent mandate, the APP risks are testable: is a tag collecting sensitive data, and is personal data going somewhere unexpected. DataTrue loads your site in a real browser and records what every tag sends, so you can see whether any tag is picking up sensitive information such as health data, and where each tag sends what it collects. Sensitive Data Detection inspects the payloads with fictitious personas, so you can check for sensitive-data collection without using a real visitor. As the reforms tighten toward consent, the same test confirms consent-gating too.

Choosing where a DataTrue test runs from: Ireland, the USA, Canada, the UK, Australia or France.

See how consent verification works

Questions

Is website tracking legal in Australia?

Yes. Australia is principles-based under the Privacy Act and the Australian Privacy Principles. There is no EU-style requirement for a cookie-consent banner, but you must be transparent about what you collect and get consent before collecting sensitive information. Reform is tightening these rules.

Does Australia require cookie consent?

Not in the EU sense. Australia has no law requiring consent before ordinary cookies or tags fire. Consent is required for collecting sensitive information such as health data, and the APPs require clear notice of what you collect. A major reform underway may move Australia closer to consent-based rules.

What is the statutory tort for serious invasions of privacy?

A cause of action introduced in the 2024 reforms and commenced on 10 June 2025 that lets individuals sue directly for serious invasions of privacy. It is a new litigation risk for organizations handling personal data, separate from regulator enforcement.

How should I handle tracking in Australia now?

Be transparent about what your tags collect, get consent before collecting sensitive data, and avoid unexpected sharing of personal information. Given the reform direction and the new statutory tort, treating consent-before-tracking as a default is the low-risk approach.

30-day free trial

See what your tags do in every consent state

DataTrue loads your real pages as a visitor who accepts, rejects, or sends an opt-out signal, and reads what each tag sends. A tag that ignores the visitor’s choice shows up in a test.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

A DataTrue opt-out consent test listing the tags that should be blocked, with pass or fail for each
A consent-state test in DataTrue