Compliance

The Australian Privacy Act, APPs, and a reforming regime.

Australia has no general cookie-specific prior-consent rule. It has notice, necessity and direct-marketing obligations under the Australian Privacy Principles, alongside a continuing reform programme whose second tranche was released as draft legislation for consultation in August 2026.

Law
Privacy Act 1988 and the Australian Privacy Principles
Detected as
AU
Regulator
OAIC
Default model
Opt-in (stricter than the statutory baseline)

The principles that bite online

The Australian Privacy Principles are schedule 1 of the Privacy Act. Four of them do most of the work for a website. APP 1 requires an open and transparent privacy policy. APP 3 limits collection to what is reasonably necessary for your functions, and requires consent for sensitive information. APP 5 requires notification at or before collection, or as soon as practicable afterwards. APP 7 restricts direct marketing and requires a simple means of opting out.

None of those is a prior-consent rule for cookies. What they add up to is a duty to say what you are collecting and why, to avoid collecting more than you need, and to let people stop direct marketing. The OAIC has been clear that tracking identifiers can be personal information where the individual is reasonably identifiable, which pulls ordinary advertising technology inside the Act.

A regime in motion

The Privacy and Other Legislation Amendment Act 2024 was the first tranche of a larger reform programme. Its measures include a statutory tort for serious invasions of privacy, a Children’s Online Privacy Code to be developed by the Information Commissioner, expanded enforcement powers and future privacy-policy transparency duties for certain substantially automated decisions. The OAIC says those APP 1 automated-decision provisions commence on 10 December 2026, so they are enacted but not yet in force on this page’s 19 September 2026 review date.

The second tranche is still a consultation draft

On 31 August 2026 the Australian Government released a consultation paper and draft second-tranche legislation, including proposed changes such as a fair-and-reasonable test. Consultation closed on 18 September 2026. A consultation draft is not enacted law or necessarily a bill before Parliament, so check the current legislative position before relying on a proposal.

What each region profile resolves to

Region profileResolved modelWhat the visitor sees
Regional defaultsopt-inNothing optional loads until a choice is made
Global strictopt-inNothing optional loads until a choice is made, everywhere
Global balancedopt-inNothing optional loads until a choice is made
EU and UK opt-innoneNo banner

AU is in the engine’s opt-in set. As with Canada and Switzerland, that is stricter than the statute requires and is a product default rather than a legal assertion. An AU region rule with the opt-out model gives Australian visitors a notice-and-refuse experience if you would rather align tightly with the Act as it stands.

This is a product reference, not legal advice

It describes how StrongPrivacy behaves and summarises published law so you can configure the product deliberately. Whether a particular configuration satisfies your obligations is a question for your own counsel, who knows your data flows and your risk position.

Common questions

Do Australian websites need a cookie banner?

The Privacy Act does not impose a general cookie-banner rule. For an APP entity, APP 5 can require collection notice and APP 1 requires a clear privacy policy; a contextual notice or banner may help deliver information, while consent is specifically required in narrower situations such as collection of sensitive information unless an exception applies. Other jurisdictions or technologies may add separate requirements.

Are cookie identifiers personal information in Australia?

They can be, where the individual is reasonably identifiable from the information or from it combined with other information you hold. That is a fact-specific test rather than a blanket rule, and the OAIC has applied it to online identifiers.

What does StrongPrivacy record for an Australian visitor?

The same fields as anywhere else: the resolved location (`AU`, or `AU-VIC` where a region was determined), the categories granted and refused, the surface that collected the decision, the timestamp, and the configuration version that was live, all against a pseudonymous visitor key.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.