Let us be straight about something first, because most tools in this category are not. Australia does not have a law requiring a cookie banner. The GDPR-style "accept or reject before anything loads" rule is European, and plenty of Australian businesses have been sold a banner they did not need by a tool that implied otherwise. We are not going to do that.
What Australian law does require, under the Privacy Act and the Australian Privacy Principles, is a clear and current privacy policy, honest notice about what you collect, and accountability for what happens to personal information you hand to somebody else, including when that somebody is overseas. And separately from the law, if you run Google or Meta advertising and have any UK or European visitors, those companies' own policies require consent signals you may not have. This tool checks all of it, and keeps the legal obligations and the platform requirements clearly apart.
Check my site- Tracking cookies set before a visitor agrees to anything
- Every third-party analytics and advertising script on the page
- Whether a consent platform is installed, and which one
- Google Consent Mode v2, required if you advertise into the UK or EU
- Where your form data goes, and whether it leaves Australia
- Whether your privacy policy exists, covers the APPs and is current
Do I need a cookie banner in Australia?
Probably not, on the law alone. The Privacy Act does not contain a prior-consent requirement for cookies the way the EU ePrivacy Directive and GDPR do. What it requires is that you tell people what personal information you collect and what you do with it, which is a privacy policy and a collection notice, not a pop-up. You do need consent handling if you have UK or European visitors, if you advertise into those markets, or if you collect sensitive information. If you sell only to Australians, a clear privacy policy is worth far more than a banner nobody reads.
Then why does this tool check for one?
Because plenty of Australian businesses do have overseas visitors, and because Google requires it independently of any law. Since March 2024, Google's EU User Consent Policy has required advertisers to pass Consent Mode v2 signals for users in the UK and EEA. Without them, remarketing audiences stop filling and conversion measurement degrades for those visitors, whether or not anyone ever complains. That is a commercial consequence with no legal proceeding attached, and it catches people out constantly.
What does the Privacy Act actually require of a website?
The obligations that touch a website sit mostly in three Australian Privacy Principles. APP 1 requires a clearly expressed and up-to-date privacy policy that is free and easy to find. APP 5 requires you to tell people, at or before the time you collect it, what you are collecting and why. APP 8 makes you accountable when you disclose personal information to an overseas recipient, which includes most analytics, email and form tools. Note the small business exemption: businesses turning over under $3 million are largely outside the Act, with significant exceptions including health service providers and anyone trading in personal information.
What changed in the 2024 Privacy Act reforms?
The Privacy and Other Legislation Amendment Act 2024 was the first substantial change in years. The headline items for a business with a website are a new statutory tort for serious invasions of privacy, stronger enforcement powers for the OAIC including lower-tier penalties that do not require a court, and a transparency requirement around automated decisions that significantly affect people. Further tranches of reform, including a possible narrowing of the small business exemption, have been flagged but not legislated. If your business handles anything sensitive, this is the point to get advice rather than read a blog.
How do I read this result?
Split it in two. The privacy policy checks are the ones with a legal obligation behind them for most businesses, and a missing or ten-year-old policy is worth fixing this week. The consent and tracking checks are about accuracy, overseas exposure and your advertising platforms working properly. And one honest limit: we fetch your page once and read what it sends. We do not run your JavaScript, so a cookie dropped later by a script is invisible to us, and we cannot click your banner to see whether it really blocks anything. This is a technical check. It is not legal advice and it is not a compliance certificate.
Who requires what
The obligations get conflated constantly. They are not the same rules and they do not have the same consequences.
| Requirement | Who imposes it | Applies to you if |
|---|---|---|
| A current privacy policy | Privacy Act, APP 1 | You are covered by the Act (broadly, turnover over $3m) |
| Notice of what you collect | Privacy Act, APP 5 | You collect personal information, including via a form |
| Accountability for overseas transfer | Privacy Act, APP 8 | You use offshore analytics, email or form tools |
| Consent before tracking | GDPR / UK GDPR | You have UK or European visitors |
| Consent Mode v2 signals | Google advertiser policy | You run Google Ads or GA4 with UK or EEA traffic |
| Secure and SameSite cookies | Browser vendors | Always. Browsers increasingly reject cookies without them |
How to get a website's privacy in order
-
1
Find out what is actually running
Run the check above. Most people are surprised by at least one tracker they never installed, usually left behind by a previous developer or agency.
-
2
Write or refresh the privacy policy
It must say what you collect, why, who you disclose it to, whether it goes overseas, and how somebody accesses, corrects or complains about it.
-
3
Remove the trackers you do not use
An abandoned pixel from an agency you parted ways with three years ago is still sending your visitors to them. Delete it.
-
4
Add a collection notice where you collect
A line under the form saying what happens to the details, linked to the policy. This is APP 5 and it takes five minutes.
-
5
Wire up consent only if you need it
Overseas visitors or Google advertising: install a consent platform and actually connect it to your tags. Australia-only and no ads: spend the effort on the policy instead.
-
6
Review it once a year
Or whenever you add a tool that touches customer data, which in practice is what triggers the need.
Fair questions.
Is this legal advice?
No, and nothing on this page is. It is a technical check of what your website sends to a visitor, plus a plain-English summary of publicly available regulator guidance. Whether the Privacy Act applies to your business, and what it requires of you specifically, is a question for a lawyer who knows your circumstances. We would rather say that plainly than sell you a fix for a problem you may not have.
Why did it say I have no consent banner when I definitely do?
We detect the consent platforms in common use by their code signature. A custom-built banner, or one loaded entirely through Tag Manager after the page renders, will not be visible to us. The check errs toward telling you what we could not see rather than assuming.
It found Google Analytics but says no Consent Mode. Is that wrong?
It may be. Consent Mode can be configured inside Google Tag Manager rather than in your page source, and in that case we cannot see it. That is why this check is a warning rather than a failure. Confirm it in your own Tag Manager container before acting.
What is the small business exemption?
Businesses with an annual turnover of $3 million or less are largely exempt from the Privacy Act. The exceptions matter though: health service providers, businesses that buy or sell personal information, contractors to the Commonwealth, credit reporting bodies and a few others are covered regardless of size. Being under the threshold today does not make a privacy policy a bad idea, and customers increasingly expect one.
Do I need to name every tracker in my privacy policy?
You need to describe the kinds of information you collect and who you disclose it to, and be specific enough that someone reading it understands what happens to their data. Listing your analytics and advertising providers by name is the clearest way to do it, and it is what the OAIC's own guidance points toward. It also has the useful side effect of making you notice a pixel you forgot about.
My site is on Shopify or Wix. Does this still apply?
Yes. The platform handles the technical plumbing but the obligations are yours, and both platforms make it easy to add tracking that fires immediately. The privacy policy is entirely your responsibility on any platform.
Will you store the results of my scan?
No. We fetch your page, run the checks in memory and return the result. Nothing is written down, and there is no report withheld behind an email form.
What happens if I ignore all this?
Realistically, for a small Australian business with only local customers, probably nothing for a long time. The risks that actually bite are a data breach that draws attention to a policy that was never written, a Google advertising account quietly measuring less than you think, and a customer who asks what you do with their information and gets an unconvincing answer. None of those are catastrophes. All three are cheap to prevent.
Finally see what visitors actually do on your site: where they click, where they rage-quit, and where the money leaks.