By country

Cookie Policy Generator Australia

The Privacy Act 1988, thirteen Australian Privacy Principles, and consumer guarantees that no refund policy can override.

Generate your cookie policy Read the cookie policy guide

Australia has no dedicated cookie consent statute, so the obligation runs through the Australian Privacy Principles instead: cookies that collect personal information need notification under APP 5, and the OAIC expects that notification to be meaningful rather than buried.

Australian privacy law is built on the thirteen Australian Privacy Principles in the Privacy Act 1988, supervised by the OAIC. APP 1 is unusual and important: it requires a clearly expressed and up-to-date privacy policy as an obligation in its own right, with prescribed content - not merely as a by-product of transparency duties.

The 2024 reforms began a multi-year expansion. A statutory tort for serious invasions of privacy is now available, transparency obligations for automated decisions that significantly affect individuals are phased in, a Children’s Online Privacy Code is being developed, and the OAIC has gained more direct enforcement powers.

Alongside privacy, Australian Consumer Law imposes consumer guarantees that cannot be contracted out of. A "no refunds" sign is not merely unenforceable - it is itself a breach that the ACCC has repeatedly penalised.

What a cookie policy in Australia has to cover

Australia is one of the few markets where a consent banner is not strictly required but a clear disclosure is. Businesses serving both Australia and the EU usually run one banner to the stricter standard rather than two experiences.

How Australia actually moves personal data

Overseas disclosure under APP 8

Sending personal information overseas makes you accountable for the recipient’s handling of it unless an exception applies, and APP 1 requires you to list the countries involved where practicable.

Government-related identifiers

Tax file numbers, Medicare numbers and driver licence numbers are restricted under APP 9, and the identity-verification breaches of recent years made this a live enforcement area.

Direct marketing under APP 7

Marketing to individuals requires either their expectation or consent, and every message must offer a simple opt-out - separate from and in addition to Spam Act duties.

Health and sensitive information

Sensitive information requires consent for collection under APP 3, and health service providers are covered by the Privacy Act regardless of turnover.

Automated decision-making

The reforms require privacy policies to disclose the use of automated decisions that significantly affect individuals, with the transparency obligation phasing in ahead of enforcement.

Third parties the draft will ask you about

Stripe · Afterpay · Zip · Australia Post · Xero · AWS ap-southeast-2 · Campaign Monitor · Atlassian · Telstra

The rules that apply

Privacy Act 1988 and the 13 APPs

Applies to businesses with turnover above AUD 3 million and to smaller businesses in specified categories including health service providers and those trading in personal information.

APP 1 - open and transparent management

Requires a clearly expressed, up-to-date and free privacy policy with prescribed content, including overseas disclosure countries.

Notifiable Data Breaches scheme

Eligible data breaches must be assessed within thirty days and notified to the OAIC and affected individuals where serious harm is likely.

Australian Consumer Law

Consumer guarantees on acceptable quality, fitness for purpose and description, which cannot be excluded, restricted or modified.

Spam Act 2003

Consent, sender identification and a functional unsubscribe for commercial electronic messages, enforced by ACMA with substantial penalties.

What the generated cookie policy contains

Meeting APP 1 in practice

  1. Check whether the Privacy Act catches you

    Turnover above AUD 3 million, or one of the categories where turnover is irrelevant.

  2. Write the policy to APP 1.4 content list

    Kinds of information, how collected and held, purposes, access and correction, complaints, overseas disclosure and countries.

  3. Build the breach assessment runbook

    Thirty days to assess, then notification to the OAIC and individuals where serious harm is likely.

  4. Separate marketing consent from privacy consent

    APP 7 and the Spam Act need their own records.

  5. Align refund terms with consumer guarantees

    State the guarantees first, then any additional voluntary policy.

Where this usually goes wrong

Advertising "no refunds"

Consumer guarantees survive any policy. The ACCC has penalised businesses for signage and terms that misrepresent a consumer’s rights, independently of whether a refund was refused.

Not listing overseas disclosure countries

APP 1.4(f) asks for the countries where recipients are likely to be located. "We may transfer data internationally" does not satisfy it.

Assuming the small-business exemption applies

It does not apply to health service providers, businesses trading in personal information, contracted service providers to the Commonwealth, or those that have opted in.

Treating the Spam Act and APP 7 as one rule

They are separate: the Spam Act governs the message, APP 7 governs the use of personal information for marketing. Compliance with one does not discharge the other.

No breach assessment process

The NDB scheme requires an assessment within thirty days of becoming aware of a suspected eligible breach. Without a procedure, the clock runs unnoticed.

Frequently asked questions

Does the Privacy Act apply to small businesses?

Generally only above AUD 3 million turnover, but there are important exceptions: health service providers, businesses that buy or sell personal information, credit reporting bodies and Commonwealth contractors are covered whatever their size.

Is a privacy policy legally required in Australia?

Yes for APP entities. APP 1.3 requires a clearly expressed and up-to-date policy about the management of personal information, available free of charge and in an appropriate form.

Can I refuse a refund if the customer changed their mind?

Yes - consumer guarantees do not cover change of mind. What you cannot do is state or imply that no refunds are ever available, because that misrepresents the guarantees that do apply to faulty or misdescribed goods.

What is the new privacy tort?

A statutory cause of action for serious invasions of privacy, which lets individuals sue directly rather than relying on an OAIC complaint. It changes the risk profile of intrusive tracking and surveillance practices.

Do I need a cookie policy as well as a privacy policy?

In the UK and EU, yes in practice. PECR and the ePrivacy Directive regulate storing and reading information on a device separately from GDPR’s rules on processing, and the per-cookie disclosure is too detailed to bury in a privacy policy.

Do analytics cookies need consent?

In the UK and EU, yes - the ICO has said repeatedly that analytics is not "strictly necessary". Some EU regulators allow a narrow exemption for first-party, non-shared audience measurement, but the default answer is consent first.

Does a cookie policy need updating when I add a tool?

Yes, and this is the clause that goes stale fastest. Every new tag, pixel or embedded widget adds cookies your table does not list. Scanning your own site on a schedule is the only reliable way to keep it honest.

What about cookies set by embedded video and maps?

They count. An embedded YouTube player or Google Map sets third-party cookies as soon as it loads, so either it loads only after consent, or you use a privacy-preserving embed mode and say so.

Cookie Policy Generator Australia

Answer a short questionnaire and get a draft written for Australia. Free to start, no card required.

Generate your cookie policy

Other documents for Australia

Each one is written for the same context, not a generic template.

The same document, by country

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.