A client rang me last month after spotting a cookie pop-up on a partner organisation’s website. “Do we need one of those too?”
Good question, and one I get more often than you’d think. The honest answer is: probably not that exact pop-up. But almost certainly something.
Cookie consent banners are one of the most over-copied bits of website furniture around, mostly because people see them on big sites and assume it’s a universal legal requirement. In Australia, it isn’t, not in the blanket way people assume. But there’s a real obligation underneath the confusion, and it’s one that catches out more regional businesses and community organisations than the exemption headlines suggest.
What a Cookie Policy actually is
A Cookie Policy explains what tracking technologies your website uses, cookies, tracking pixels, local storage, and what they actually do. Some remember a visitor’s login or shopping cart. Some measure how people move through your site. Some, like Meta’s pixel or Google’s remarketing tags, quietly build a profile of a visitor so you can show them an ad later.
It’s usually a short, separate document, or a clearly labelled section inside your Privacy Policy. Either way, the job is the same: tell people what’s watching them, and why.
It isn’t the same thing as a consent banner, the pop-up asking someone to “accept all cookies” before they can read your page. A Cookie Policy is the disclosure. A consent banner is one possible mechanism for getting permission before tracking starts. You can have the first without the second, and for most of the small regional businesses and community organisations I work with, that’s exactly the right setup.
Does Australian law actually require a cookie banner?
No, not the way people assume. There’s no Australian law that says “you must show a pop-up before any tracking occurs,” the way GDPR effectively requires across the EU. If someone tells you otherwise, I’d want to see the legislation.
What Australian law does require, if the Privacy Act applies to your organisation, is the same thing it requires everywhere else: clear disclosure of what personal information you’re collecting and why, under Australian Privacy Principle 1. Cookies and tracking pixels that identify or profile a visitor fall within that. The OAIC’s guidance on the Australian Privacy Principles covers this, and I’ve written separately about whether the Privacy Act actually applies to your organisation, and where that’s heading, in “Will Australia’s Privacy Act Soon Apply to Small Businesses?”
So the legal picture is more “disclose clearly” than “pop-up or bust.” Where it gets more concrete is Google’s own rules.
Google requires it, regardless of what the Privacy Act says
If you run Google Analytics or Google Ads, and most business websites do, Google’s own terms of service require you to have an appropriate policy in place that discloses your use of cookies and tracking, and to comply with applicable law wherever your visitors are. That applies to every business using those tools, regardless of turnover or Privacy Act exemptions. Google isn’t asking whether the Privacy Act covers you. It’s asking whether you’ve told your visitors what’s happening.
If any of your traffic comes from the EU, UK or Switzerland, even a handful of visitors from an overseas tourism enquiry or an international volunteer program, Google’s EU User Consent Policy goes further again. It requires an actual consent mechanism, not just disclosure, before those specific visitors are tracked for remarketing or personalised ads. Most purely local regional businesses won’t trip this. Anyone running a tourism site, an online store that ships internationally, or a program that attracts overseas volunteers or donors, might.
Non-compliance isn’t a theoretical risk either. Google can, and does, restrict advertising features, remarketing, conversion tracking, personalised ads, for accounts it considers non-compliant. For a business relying on Google Ads for enquiries, that’s not a small thing to have switched off without warning.
What’s actually running on your site
Worth being specific, because most site owners underestimate this. Google Analytics tracks visitor behaviour. Google Maps embeds can set cookies. Meta and Google ad tracking build advertising profiles. Embedded YouTube videos can set cookies before anyone’s clicked play. Live chat widgets, booking systems and membership platforms all typically add their own.
A brochure site that does none of this is rare. Most sites are doing more behind the scenes than the person who owns them realises, which is exactly why the disclosure matters more than the banner.
What it costs to get right
A free plugin will bolt a generic banner onto your site in twenty minutes, and for a lot of businesses that’s the first and last time anyone looks at it. The problem is the same one that affects free Privacy Policy templates: it’s written for someone else’s website, and nobody’s watching it when your site changes.
We manage this for clients through Termageddon, at $180 a year, which covers the Cookie Policy alongside your Privacy Policy and Website Terms as one document set that updates automatically when your website or the law changes. It’s the same idea as an electrical safety certificate. Nobody re-reads it day to day, but you’d notice fast if it went missing during an audit, or in this case, if Google quietly switched off your remarketing because your disclosure hadn’t kept up with what your site was actually doing.
So, do you need one?
If you run Google Analytics or Google Ads, which is most businesses, yes, at minimum a clear disclosure of what you’re tracking and why. If you’re specifically drawing EU, UK or Swiss traffic through advertising or an online store, you may need an actual consent mechanism on top of that. For most of the regional businesses and community organisations I work with, it’s the first case, not the second, and it’s a smaller job than people assume once someone’s actually looked at what the site is doing.
Not sure what your website is quietly tracking? Flick me an email and I’ll take a look →
This article provides general information about websites and privacy considerations. It isn’t legal advice. Privacy and advertising-platform obligations vary depending on your organisation, activities and audience. If you’re unsure of your legal obligations, speak to an appropriately qualified legal professional.
Sources and further reading:
OAIC — Australian Privacy Principles;
Google — Google Analytics Terms of Service;
Google — EU User Consent Policy.
