Happy Goat Web Design Logo

Australian Privacy and Cookie Compliance for Business Websites

Most small business websites collect more personal information than their owners realise. This guide explains what Australian privacy law expects, how cookies and forms fit in, and the practical build decisions that keep a Perth business on the right side of it all.
Request a Quote
web design gallery - Happy Goat Web Design
August 17, 2026

Australian Privacy and Cookie Compliance for Business Websites

A plain-English look at Australian privacy law, cookie consent and contact-form data - and the practical build decisions that keep a Perth business site compliant.

Most Perth business owners never think about privacy law until an enquiry form starts collecting names and phone numbers, or an analytics tool asks a question they can’t answer. That’s usually the moment it dawns on them that a website isn’t just a brochure – it’s a system that quietly gathers data. Compliance is baked into how a site is built, which is exactly why working with web design specialists from the outset beats bolting fixes on after launch.

The good news is that privacy compliance for a typical service business is far less scary than it sounds. You don’t need a legal team. You need to understand what your site actually does, and make honest, sensible choices about it.

What Australian Privacy Law Requires of a Small Business Website

The main framework is the Privacy Act and the Australian Privacy Principles (APPs) it contains. The APPs set out how organisations should collect, use, store and disclose personal information – anything that can identify a person, like a name, email, phone number or address.

Here’s the part many people miss: businesses with an annual turnover under a set threshold are often exempt from the Privacy Act. But there are important exceptions – health service providers, businesses that trade in personal information, and certain contractors are covered regardless of size. Even when you’re technically exempt, following the APPs is good practice, builds trust, and future-proofs you as the law tightens.

Reforms to Australian privacy law are steadily raising the bar. Treating compliance as the baseline rather than the ceiling is the sensible position for any Perth service business planning to be around for years.

Cookies, Analytics and the Data Your Site Quietly Collects

Every website leaves a trail. The moment a visitor lands on your page, scripts may be recording their behaviour, storing cookies, or sending data to third-party tools. Common culprits include:

  • Analytics platforms that track page views, time on site and visitor location
  • Advertising and remarketing pixels that follow users across the web
  • Embedded maps, videos and social feeds that load third-party trackers
  • Chat widgets and booking tools that capture contact details

Some of this data is anonymous. Some of it isn’t. When tracking can be tied back to an identifiable person, it starts to look like personal information – and that changes your obligations around notice and, in some cases, consent.

Writing a Privacy Policy That Matches What Your Site Actually Does

A privacy policy is not a copy-paste job. The single most common mistake is publishing a generic template that promises things the site doesn’t do, or stays silent on things it does.

Your policy should honestly describe what you collect (contact-form fields, enquiry details, analytics data), why you collect it, where it’s stored, who you share it with, and how someone can request access or deletion. If your enquiry form feeds into an email inbox and a customer database, say so. If a third-party analytics tool processes visitor data offshore, mention that too.

Accuracy matters more than legal polish. A short, plain-English policy that reflects reality serves you far better than an impressive one that describes a business that isn’t yours.

Consent, Notices and Avoiding Dark-Pattern Traps

Cookie banners, form disclosures and consent notices are the visible face of compliance. Done well, they’re brief and clear. Done badly, they annoy visitors and undermine trust.

A few practical principles keep you on solid ground:

  • Give notice before non-essential tracking loads, not after
  • Make declining as easy as accepting – buried “reject” options are a dark pattern regulators frown on
  • Add a short line near contact forms explaining what happens to the details submitted
  • Keep consent controls readable and operable for everyone, which overlaps with broader accessibility standards every Australian website should meet

Honesty and clarity aren’t just ethical – they reduce the risk of complaints and reflect well on your brand.

Data Handling for Lead-Generation Sites

For service businesses, the website’s main job is generating enquiries – which means it collects personal information by design. That raises questions about where those enquiries go and how they’re protected.

Think through the full path a submission takes. It might land in an email inbox, a form-tool dashboard, and a customer relationship system all at once. Each of those places stores personal data, and each is a point where a leak or misuse could occur. Choose reputable tools, use secure connections, limit who can access the data, and delete enquiries you no longer need. Only collect fields you genuinely require – every extra field is extra data you’re now responsible for.

A Practical Compliance Checklist for Perth Service Businesses

If you’re reviewing an existing site, work through this list:

  1. Confirm whether the Privacy Act applies to your business
  2. List every form, tool and script that collects or transmits data
  3. Publish a privacy policy that matches what the site actually does
  4. Add clear notice before non-essential cookies and tracking load
  5. Include a short disclosure near enquiry and booking forms
  6. Review where enquiry data is stored and who can access it
  7. Remove tools and data you no longer use
  8. Set a reminder to revisit this as your site and the law evolve

None of these steps is difficult in isolation. Together, they turn a vague worry into a manageable routine.

Privacy compliance is one of those quiet fundamentals that separates a professionally built website from a rushed one. And it rarely goes wrong on its own – a site that overlooks privacy usually overlooks a handful of other basics too, which is why these oversights tend to cluster into a wider pattern of avoidable slip-ups Perth businesses make when building or updating a site. Understanding that pattern is the best way to catch problems before they cost you.

Privacy and Cookie Compliance FAQs

Ready to Book?

Request a Quote and we’ll confirm your timeline and scope—then keep you updated right through to handover.

Get In Touch

Fill out the form below and our team will reach out to you soon: