Veracly
Cookies

Cookie consent in Australia: what the law actually requires

Australian businesses install consent banners because European advice tells them to. There is no Australian rule requiring one for ordinary analytics. But sensitive information is a real exception, and the Privacy Commissioner enforced it against tracking pixels in June 2026.

By Veracly Compliance Team6 min read

General information, current at the date above. This describes what the cited sources say; it is not legal advice and no lawyer has reviewed it. Australian privacy and discrimination law turns heavily on your specific circumstances — what you collect, from whom, and which carve-outs apply — so treat this as orientation and verify your own position before acting on it.

If you run an Australian website and you have been told you need a cookie consent banner, you were probably told by something written for Europe. Australia has no prior-consent rule for cookies. There is no Australian Article 5(3), no Australian “reject all” parity requirement, and no Australian regulator issuing penalties simply because an analytics cookie fired before a click. There is a significant exception for sensitive information, which we come to below.

This is the single biggest structural difference between Australian and European web compliance, and getting it wrong costs money in both directions: businesses buy consent platforms they do not need, and then fail the obligation they actually have.

Where the EU rule comes from, and why it has no Australian twin

Every cookie banner in Europe traces to Article 5(3) of the ePrivacy Directive (2002/58/EC). It says that storing information on, or gaining access to information already stored in, a user’s terminal equipment requires that user’s consent, unless it is strictly necessary to provide a service they requested.

The important thing about that provision is what it regulates: it regulates the act of writing to the device. It applies whether or not the cookie contains personal data. That is why a European banner has to appear before anything non-essential is written, and why analytics cookies need opt-in even when the operator argues they are anonymous, though some regulators exempt narrowly scoped first-party audience measurement.

Australia never enacted an equivalent. The Privacy Act regulates the handling of personal information, not access to terminal equipment. If a cookie does not collect personal information, the Privacy Act has nothing to say about it. If it does, the Act attaches transparency duties for ordinary non-sensitive data — not a general consent gate. Sensitive information is the exception, and it is a big one; see below.

What Australian law does require

Assume you are an APP entity — that is, your annual turnover exceeded AUD 3,000,000 last financial year or in any year since you started trading, or one of the section 6D carve-outs applies to you. Two Australian Privacy Principles are then relevant to tracking:

  • APP 5 — notification of collection. At or before the time you collect personal information — or, if that is not practicable, as soon as practicable afterwards — you must take reasonable steps to notify the individual of a list of matters, including who you are, why you are collecting, who you usually disclose to, and whether you disclose overseas.
  • APP 1 — open and transparent management. You must have a clearly expressed and up-to-date privacy policy, available free of charge, describing what you collect and hold, how, for what purposes, how someone can access and correct it, how they complain, and whether you disclose overseas.

For ordinary non-sensitive analytics, that is a documentation obligation rather than a consent obligation. The overseas disclosure point is the one Australian sites most often get wrong. Google Analytics, Meta Pixel and most advertising and session-replay tools involve disclosure to recipients outside Australia. APP 1 and APP 5 both expect that to be stated. A policy that says nothing about overseas recipients while the site runs a US-hosted analytics stack is inaccurate, and inaccuracy is the failure mode that actually attracts regulator attention.

Where Australian law does require consent

Australia has no general prior-consent rule for cookies, but it does have consent obligations that bite on tracking in specific circumstances, and they have been enforced recently enough that no honest post can leave them out.

APP 3.3 requires express consent before collecting sensitive information — health, sexuality, race, religion, political opinions, trade-union membership. APP 7 requires consent to use or disclose sensitive information for direct marketing. On 11 June 2026 the Privacy Commissioner applied both to tracking pixels: in Medmate Australia Pty Ltd [2026] AICmr 41 and Monash IVF Pty Ltd [2026] AICmr 40, pixels on health-related websites were held to collect sensitive information about visitors, in breach of APP 3.3, 5.1 and 7.1. The Commissioner rejected Medmate’s generic cookie pop-up as consent: consent had to be express, informed and specific to the pixel and the platforms involved.

The OAIC’s November 2024 tracking-pixel guidance goes further, warning that collecting personal information covertly is likely to be an unfair means of collection under APP 3.5, and adtech is on the Commissioner’s stated enforcement priorities.

So the accurate statement is narrower than “no consent required in Australia”. It is: writing to the device does not require consent, and for ordinary non-sensitive analytics the duties are transparency duties. But if your site is about health, or your tracking otherwise reveals sensitive information, or you are disclosing to advertising platforms for matching and retargeting, consent obligations do apply — and a generic banner will not discharge them.

When EU and UK rules reach an Australian site anyway

The GDPR applies extraterritorially where you offer goods or services to individuals in the EU, or monitor their behaviour there. The ePrivacy consent rule travels with it in practice. So an Australian business that sells to European customers, or runs European ad campaigns, is doing EU-facing processing and the banner requirement is real — for those visitors.

What that does not mean is that every Australian site should adopt EU defaults just in case. Ask a concrete question instead: do you have EU or UK visitors you are actually trying to reach? If the honest answer is no, an EU-style consent flow is imposing friction on your Australian customers for no legal benefit.

How we grade this, and why

Veracly’s Australian rule set deliberately does not treat pre-consent cookies or trackers as Australian violations. The finding types exist in our engine — they are exactly what we grade an EU site on — but they are not mapped into the Australian pack, because flagging them under Australian law would be an overclaim.

If your site is scored against multiple markets, a tracker firing before consent appears under the EU or UK scorecard and not under the Australian one. The same scan, the same evidence, graded against the law that actually applies in each place.

We would rather tell you that a finding does not apply to you than inflate a score report. A compliance tool that reports EU violations against Australian law is selling anxiety, and it is trivially falsifiable by anyone who reads the statute.

How to work out your own position

None of the below is a recommendation about your site. It is the order in which the questions are usually worth asking.

  1. Work out whether the Privacy Act binds you at all. At or under the AUD 3,000,000 turnover threshold, never above it since you started trading, and outside the carve-outs — it does not.
  2. Ask whether any of your tracking touches sensitive information. If your site is about health or any other sensitive category, APP 3.3 requires express, specific consent and a generic banner will not do it.
  3. Inventory what your site actually loads. Open DevTools, go to the Network tab, reload, and look at the third-party hosts. Most operators are surprised.
  4. Make the privacy policy match that inventory, including overseas disclosure.
  5. If you have EU or UK visitors, implement consent properly for them — genuine prior consent with an equally prominent reject path, not a cosmetic notice bar.
  6. Weigh accessibility alongside it. Australian website liability has an actual litigation history there, and the duty has no turnover threshold.

That last point is worth dwelling on. Australia has a leading case in which an inaccessible website was held to be unlawful discrimination — Maguire v Sydney Organising Committee for the Olympic Games (No 2) [2000] HREOCA 31, a determination of the Commission rather than a court judgment. If you are allocating a fixed compliance budget, the Disability Discrimination Act is where the accessibility risk sits — and, since June 2026, sensitive-data tracking is where the privacy risk sits.

Common questions

Is a cookie banner legally required in Australia?+

Not as a general rule. Australia has no equivalent of Article 5(3) of the EU ePrivacy Directive, which is the provision that requires consent before storing or reading information on a user's device. Without it there is no general Australian requirement to obtain consent before setting a cookie, and no requirement that rejecting be as easy as accepting. There is an important exception: APP 3.3 requires express consent to collect sensitive information, and in June 2026 the Privacy Commissioner applied that to tracking pixels on health-related websites in Medmate Australia Pty Ltd [2026] AICmr 41 and Monash IVF Pty Ltd [2026] AICmr 40, holding that a generic cookie pop-up was not valid consent.

So why do so many Australian sites have one?+

Three reasons, only one of which is a legal requirement. First, many Australian sites genuinely serve EU or UK visitors, and those visitors bring their own law with them. Second, consent management platforms are sold globally with EU defaults, so the banner arrives with the tool. Third, a great deal of Australian compliance content is European content with the place names changed. If you have no EU or UK visitors, the banner is very likely doing nothing for you legally.

What does the Privacy Act actually require for tracking?+

If a cookie or pixel collects personal information and you are an APP entity, Australian Privacy Principle 5 requires you to notify the individual at or before the time of collection — or as soon as practicable afterwards if that is not practicable — and APP 1 requires a clearly expressed, up-to-date privacy policy describing what you collect, why, and to whom you disclose it, including overseas recipients, which covers most analytics and advertising vendors. For ordinary non-sensitive data those are documentation obligations. If the tracking collects sensitive information, APP 3.3 adds an express consent requirement on top.

Is an IP address personal information in Australia?+

Less settled than in the EU. In Privacy Commissioner v Telstra Corporation Limited [2017] FCAFC 4 the Full Federal Court considered whether certain network metadata was information "about an individual" — though it was construing the pre-2014 definition. Australian courts have not simply adopted the European position that an IP address is personal data in most circumstances, but the OAIC's 2026 tracking-pixel determinations treated IP addresses, device data and full URLs as personal information where a visitor could be singled out. The practical answer is unchanged: if your stack can single out an individual, treat the data as personal information and describe it in your privacy policy.

See where your site stands.

Run a free Veracly scan and get a multi-jurisdiction report, EAA, GDPR, ADA, UK Equality Act, AODA, with copy-paste developer fixes.

Run a free scan

Keep reading