Website compliance in Australia: the DDA, the Privacy Act and WCAG
Australian web compliance is not a translated version of the GDPR. There is no statute naming WCAG, no prior-consent rule for cookies, and a small-business exemption that excuses most SMBs from the privacy-policy duty entirely. Here is what actually applies.
General information, current at the date above. This describes what the cited sources say; it is not legal advice and no lawyer has reviewed it. Australian privacy and discrimination law turns heavily on your specific circumstances — what you collect, from whom, and which carve-outs apply — so treat this as orientation and verify your own position before acting on it.
Most compliance advice an Australian business finds online is European advice with the place names changed. That is a problem, because Australian web law differs from the EU model in three structural ways: there is no statute that names WCAG for private websites, there is no prior-consent rule for cookies, and a turnover-based exemption removes most small businesses from the privacy regime altogether.
None of that means an Australian website has no obligations. It means the obligations have a different shape, and copying a GDPR checklist will leave you doing work you do not need to do while missing the thing that actually creates liability.
The two Commonwealth frameworks that apply
- Accessibility — Disability Discrimination Act 1992 (Cth). Section 24 makes it unlawful to discriminate against a person on the ground of disability in the provision of goods, services and facilities. A website is a service. The duty is not absolute: section 21B excuses discrimination where avoiding it would impose an unjustifiable hardship, assessed under section 11. SOCOG ran that defence in Maguire and lost. Enforcement is complaint-driven through the Australian Human Rights Commission.
- Privacy — Privacy Act 1988 (Cth). The Australian Privacy Principles govern how APP entities handle personal information. Regulated by the Office of the Australian Information Commissioner, which has real investigation and enforcement powers — but only over entities the Act actually binds.
Note what is missing from that list: there is no Australian ePrivacy Directive, and no Australian equivalent of the European Accessibility Act with a compliance deadline attached to it.
State and territory law sits alongside both. Every state and territory has its own anti-discrimination statute with a goods-and-services limb, and New South Wales, Victoria and the ACT have health-records legislation that binds small health providers regardless of the Commonwealth turnover exemption. The AHRC Guidelines say as much at page 14: they should be read together with the whole of the DDA and state and territory anti-discrimination laws.
Accessibility: the duty is the DDA, not WCAG
This distinction matters more than it sounds. The obligation you can be taken to court over is section 24 of the DDA — unlawful discrimination. WCAG is not the law; it is the yardstick the regulator points at when explaining what the law expects.
That yardstick was updated recently, and a lot of Australian guidance is still citing the old one. In April 2025 the Australian Human Rights Commission published Guidelines on equal access to digital goods and services, which expressly updates the World Wide Web Access: Disability Discrimination Act Advisory Note ver 4.1 from 2014. The new Guidelines name WCAG 2.2 Level AA as the minimum. If a checklist you are following still says WCAG 2.0 or cites the 2014 Advisory Note, it predates the current guidance.
The Guidelines are issued under section 67(1)(k) of the DDA and section 11(1)(n) of the Australian Human Rights Commission Act 1986, and they are candid about their own status. Page 14 states that an organisation “may not be protected from a finding of unlawful discrimination” by having relied on them. Conformance is evidence of good faith, not a safe harbour.
The decision that anchors all of this is Maguire v Sydney Organising Committee for the Olympic Games (No 2) [2000] HREOCA 31, in which the Sydney Olympics website was found to have unlawfully discriminated against a blind user. It is a determination of the Commission (then HREOC) rather than a court judgment, so it is not binding precedent in the way it is often described — but it is the case everyone cites, and the AHRC relies on it in the 2025 Guidelines.
Cookies: Australia is not the EU
There is no Australian rule requiring consent before a cookie is set. Article 5(3) of the EU ePrivacy Directive — the provision that produces every cookie banner you have ever clicked — has no Australian counterpart. Neither does the “reject must be as easy as accept” parity requirement that EU regulators have built on top of it.
What does apply is the Privacy Act, and only when a cookie collects personal information. Then Australian Privacy Principle 5 requires notification at or before collection — or, if that is not practicable, as soon as practicable afterwards — and APP 1 requires a privacy policy describing what you collect and why. For ordinary, non-sensitive analytics those are transparency duties rather than consent duties.
There is an important exception, and it has teeth. APP 3.3 requires express consent before collecting sensitive information — health, sexuality, race, religion, political or trade-union affiliation. In June 2026 the Privacy Commissioner applied that to tracking pixels in Medmate Australia Pty Ltd [2026] AICmr 41 and Monash IVF Pty Ltd [2026] AICmr 40, finding that pixels on health-related websites collected sensitive information about visitors, and rejecting a generic cookie pop-up as consent: consent had to be express, informed and specific to the pixel. The OAIC’s November 2024 tracking-pixel guidance also warns that collecting personal information covertly is likely to be an unfair means of collection under APP 3.5.
Whether an online identifier is “personal information” is also more contested in Australia than in the EU. In Privacy Commissioner v Telstra Corporation Limited [2017] FCAFC 4 the Full Federal Court considered whether certain network metadata was information about an individual. Australian courts have not simply adopted the EU position that an IP address is personal data in most circumstances — though note the Full Court was construing the pre-2014 definition, and the OAIC’s 2026 tracking-pixel determinations treated IP addresses, device data and full URLs as personal information where a visitor could be singled out. The practical answer is unchanged: if your stack can single out an individual, treat the data as personal information and describe it in your policy.
The practical consequence for an Australian SMB: for ordinary analytics you probably do not need an EU-style consent banner for Australian visitors — unless your tracking touches sensitive information, in which case APP 3.3 requires express consent and a generic banner will not supply it. You very likely do need an accurate privacy policy, and you need it to actually describe the tracking you run. And if you serve EU or UK customers, EU and UK rules apply to those visitors no matter where your business sits.
Privacy: the small business exemption
Section 6D of the Privacy Act excludes a small business operator from the definition of an APP entity. The headline test is annual turnover for the previous financial year: section 6D(1) says AUD 3,000,000 or less, so the boundary is inclusive and a business at exactly three million is still exempt.
The test only runs one way, though, and this is the part most summaries drop. Under section 6D(4)(a) a business is not a small business operator if it has had an annual turnover above AUD 3,000,000 in any financial year since it started trading. You cannot fall back under the threshold in a lean year and become exempt again.
An exempt business owes no APP obligations — including no obligation to publish a privacy policy at all. This is genuinely different from the EU, where the GDPR has no turnover threshold and Articles 13 and 14 bind a sole trader the same as a multinational.
The carve-outs matter, though. You are an APP entity regardless of turnover if you are a health service provider holding health records, if you disclose personal information about someone for a benefit or service, if you provide a service under a Commonwealth contract, or if you are a credit reporting body. A business can also opt in to APP coverage.
One correction worth making, because it circulates widely: the Privacy and Other Legislation Amendment Act 2024 did not repeal the small business exemption. Repeal was deferred to a further tranche of reform. We have written a separate post on that date, because the confusion has a specific and traceable source.
What we check, and what we do not
Veracly grades an Australian site against the DDA accessibility duty and the APP 1 privacy-policy duty. Being precise about the limits is part of the point:
- Accessibility. We run axe-core against the rendered page, plus our own checks for criteria axe does not cover. The AHRC Guidelines name WCAG 2.2 AA, and no automated tool reaches all of it. Of the six A and AA success criteria WCAG 2.2 adds, we automate one — 2.5.8 Target Size (Minimum). The other five we do not test: 2.4.11 Focus Not Obscured (Minimum, AA), 2.5.7 Dragging Movements (AA), 3.3.8 Accessible Authentication (Minimum, AA), 3.2.6 Consistent Help (A) and 3.3.7 Redundant Entry (A). Some turn on interaction states or sit behind authentication; others are simply hard to detect reliably. Every Australian report we issue names them on its face.
- Privacy policy. We check that one exists and is reachable. Under the AU rule set we suppress that finding for businesses at or below the section 6D threshold, because asserting a statutory breach against a business that owes no duty would be wrong. If you have not told us your turnover we still score it, but we attach a note saying the duty may not apply — claiming a breach we cannot establish is the failure we are avoiding in both directions.
- Cookies. We do not report pre-consent cookies or trackers as Australian violations, because under Australian law a pre-consent cookie is not, by itself, a violation. If your site is also scored against EU or UK rules, they appear there.
Automated scanning also cannot tell you whether your privacy policy is accurate. It can tell you the policy exists and that a tracker is present; whether the policy honestly describes that tracker is a human judgement.
A practical order of work
- Establish whether you are an APP entity. Turnover over AUD 3,000,000 last financial year, or any carve-out applies? Then the Privacy Act binds you.
- If it does, publish an APP 1 compliant privacy policy: clearly expressed, current, free, and describing what you collect, why, who you disclose it to including overseas recipients, and how someone accesses, corrects or complains.
- Fix accessibility against WCAG 2.2 AA. Start with the machine-detectable failures — missing alternative text, unlabelled form fields, insufficient contrast, heading order — because they are the cheapest and the most commonly cited.
- Have a human review the five criteria automation cannot reach, and check that your privacy policy matches the tracking you actually run.
- If you serve EU or UK visitors, treat those obligations separately. That is where consent banners and their parity rules become real.
The Australian position is, on the whole, less onerous than the European one. It is also less well documented, which is why so much local advice is imported and wrong. The DDA duty is the one with a litigation history behind it, and it is the one worth spending your budget on.
Common questions
Is WCAG legally required in Australia?
Not by statute, for the private sector. No Australian law names WCAG as a requirement for private websites. The legal duty is section 24 of the Disability Discrimination Act 1992 (Cth), which makes it unlawful to discriminate in the provision of goods, services and facilities. WCAG enters through guidance: the Australian Human Rights Commission publishes Guidelines on equal access to digital goods and services (April 2025) under section 67(1)(k) of the DDA, and those Guidelines name WCAG 2.2 Level AA as the minimum at page 43. The Guidelines are explicitly not legally binding — page 14 says an organisation "may not be protected from a finding of unlawful discrimination" by having relied on them. In practice WCAG 2.2 AA is the benchmark a complaint will be measured against, without being a statutory standard.
Does Australian law require a cookie banner?
No — not in the way EU law does. Australia has no equivalent of Article 5(3) of the ePrivacy Directive, so there is no general rule that you must obtain consent before storing or reading a cookie. What does apply is the Privacy Act 1988 if the cookie collects personal information: for ordinary non-sensitive analytics those are transparency duties under Australian Privacy Principles 1 and 5, not a consent gate. The exception matters, though: APP 3.3 requires express consent to collect sensitive information, and in June 2026 the Privacy Commissioner applied that to tracking pixels on health-related sites in Medmate Australia Pty Ltd [2026] AICmr 41 and Monash IVF Pty Ltd [2026] AICmr 40, rejecting a generic cookie pop-up as consent. If your site also serves EU or UK visitors, their rules apply to those visitors regardless of where you are based.
Does the Privacy Act apply to my small business?
Often not. Section 6D of the Privacy Act 1988 excludes a "small business operator" from the definition of an APP entity. Section 6D(1) sets the threshold at annual turnover of AUD 3,000,000 or less for the previous financial year. Two qualifications matter. First, the test runs one way only: under s 6D(4)(a), a business that has exceeded the threshold in any financial year since it started trading is not a small business operator, and cannot become exempt again in a lean year. Second, the carve-outs are broad and not exhaustive — health service providers holding health records, businesses trading in personal information, Commonwealth contracted service providers, credit reporting bodies, and reporting entities under the AML/CTF Act 2006, which since the reforms commencing 1 July 2026 catches many real-estate agents, accountants, conveyancers and lawyers. A business can also opt in under s 6EA. As at 20 August 2026 the exemption has not been repealed.
Who enforces these rules in Australia?
Two different bodies, through two different routes. Accessibility runs through the Australian Human Rights Commission: an individual lodges a complaint, the Commission attempts conciliation, and an unresolved complaint can proceed to the Federal Court or the Federal Circuit and Family Court. There is no regulator that audits websites and issues accessibility fines. Privacy runs through the Office of the Australian Information Commissioner, which does have investigation and enforcement powers over APP entities.
See where your site stands.
Run a free Veracly scan and get a multi-jurisdiction report, EAA, GDPR, ADA, UK Equality Act, AODA, with copy-paste developer fixes.
Run a free scan