Cookie Policy Generator Australia
The Privacy Act 1988, thirteen Australian Privacy Principles, and consumer guarantees that no refund policy can override.
Australia has no dedicated cookie consent statute, so the obligation runs through the Australian Privacy Principles instead: cookies that collect personal information need notification under APP 5, and the OAIC expects that notification to be meaningful rather than buried.
Australian privacy law is built on the thirteen Australian Privacy Principles in the Privacy Act 1988, supervised by the OAIC. APP 1 is unusual and important: it requires a clearly expressed and up-to-date privacy policy as an obligation in its own right, with prescribed content - not merely as a by-product of transparency duties.
The 2024 reforms began a multi-year expansion. A statutory tort for serious invasions of privacy is now available, transparency obligations for automated decisions that significantly affect individuals are phased in, a Children’s Online Privacy Code is being developed, and the OAIC has gained more direct enforcement powers.
Alongside privacy, Australian Consumer Law imposes consumer guarantees that cannot be contracted out of. A "no refunds" sign is not merely unenforceable - it is itself a breach that the ACCC has repeatedly penalised.
What a cookie policy in Australia has to cover
Which cookies collect personal information as the Privacy Act defines it, including device identifiers
APP 5 notification at or before collection, and where that notice actually appears
Overseas disclosure through advertising and analytics providers, with the countries involved
Opt-out routes for advertising cookies, and what stops working if they are used
The interaction with GDPR where you also serve UK or EU visitors from the same site
Australia is one of the few markets where a consent banner is not strictly required but a clear disclosure is. Businesses serving both Australia and the EU usually run one banner to the stricter standard rather than two experiences.
How Australia actually moves personal data
Overseas disclosure under APP 8
Sending personal information overseas makes you accountable for the recipient’s handling of it unless an exception applies, and APP 1 requires you to list the countries involved where practicable.
Government-related identifiers
Tax file numbers, Medicare numbers and driver licence numbers are restricted under APP 9, and the identity-verification breaches of recent years made this a live enforcement area.
Direct marketing under APP 7
Marketing to individuals requires either their expectation or consent, and every message must offer a simple opt-out - separate from and in addition to Spam Act duties.
Health and sensitive information
Sensitive information requires consent for collection under APP 3, and health service providers are covered by the Privacy Act regardless of turnover.
Automated decision-making
The reforms require privacy policies to disclose the use of automated decisions that significantly affect individuals, with the transparency obligation phasing in ahead of enforcement.
Third parties the draft will ask you about
Stripe · Afterpay · Zip · Australia Post · Xero · AWS ap-southeast-2 · Campaign Monitor · Atlassian · Telstra
The rules that apply
Privacy Act 1988 and the 13 APPs
Applies to businesses with turnover above AUD 3 million and to smaller businesses in specified categories including health service providers and those trading in personal information.
APP 1 - open and transparent management
Requires a clearly expressed, up-to-date and free privacy policy with prescribed content, including overseas disclosure countries.
Notifiable Data Breaches scheme
Eligible data breaches must be assessed within thirty days and notified to the OAIC and affected individuals where serious harm is likely.
Australian Consumer Law
Consumer guarantees on acceptable quality, fitness for purpose and description, which cannot be excluded, restricted or modified.
Spam Act 2003
Consent, sender identification and a functional unsubscribe for commercial electronic messages, enforced by ACMA with substantial penalties.
What the generated cookie policy contains
What the technologies actually are
Cookies, local storage, session storage, pixels, SDKs and server-side tags - the law covers storage and access on a device, not the word "cookie".
A per-cookie table
Name, provider, purpose, category and duration for each cookie, which is the format UK and EU regulators expect to see.
Category definitions
Strictly necessary, functional, analytics and advertising, with an honest explanation of why only the first runs without consent.
How consent was obtained and how to change it
The banner, the granular choices, and a permanent link to reopen preferences - the withdrawal route has to be as easy as the acceptance route.
Third-party cookies and onward use
Which providers set cookies through your site and what they do with the data once it is theirs.
Browser and device controls
Practical instructions, plus a note that blocking strictly necessary cookies will break parts of the service.
Meeting APP 1 in practice
Check whether the Privacy Act catches you
Turnover above AUD 3 million, or one of the categories where turnover is irrelevant.
Write the policy to APP 1.4 content list
Kinds of information, how collected and held, purposes, access and correction, complaints, overseas disclosure and countries.
Build the breach assessment runbook
Thirty days to assess, then notification to the OAIC and individuals where serious harm is likely.
Separate marketing consent from privacy consent
APP 7 and the Spam Act need their own records.
Align refund terms with consumer guarantees
State the guarantees first, then any additional voluntary policy.
Where this usually goes wrong
Advertising "no refunds"
Consumer guarantees survive any policy. The ACCC has penalised businesses for signage and terms that misrepresent a consumer’s rights, independently of whether a refund was refused.
Not listing overseas disclosure countries
APP 1.4(f) asks for the countries where recipients are likely to be located. "We may transfer data internationally" does not satisfy it.
Assuming the small-business exemption applies
It does not apply to health service providers, businesses trading in personal information, contracted service providers to the Commonwealth, or those that have opted in.
Treating the Spam Act and APP 7 as one rule
They are separate: the Spam Act governs the message, APP 7 governs the use of personal information for marketing. Compliance with one does not discharge the other.
No breach assessment process
The NDB scheme requires an assessment within thirty days of becoming aware of a suspected eligible breach. Without a procedure, the clock runs unnoticed.
Frequently asked questions
Does the Privacy Act apply to small businesses?
Generally only above AUD 3 million turnover, but there are important exceptions: health service providers, businesses that buy or sell personal information, credit reporting bodies and Commonwealth contractors are covered whatever their size.
Is a privacy policy legally required in Australia?
Yes for APP entities. APP 1.3 requires a clearly expressed and up-to-date policy about the management of personal information, available free of charge and in an appropriate form.
Can I refuse a refund if the customer changed their mind?
Yes - consumer guarantees do not cover change of mind. What you cannot do is state or imply that no refunds are ever available, because that misrepresents the guarantees that do apply to faulty or misdescribed goods.
What is the new privacy tort?
A statutory cause of action for serious invasions of privacy, which lets individuals sue directly rather than relying on an OAIC complaint. It changes the risk profile of intrusive tracking and surveillance practices.
Do I need a cookie policy as well as a privacy policy?
In the UK and EU, yes in practice. PECR and the ePrivacy Directive regulate storing and reading information on a device separately from GDPR’s rules on processing, and the per-cookie disclosure is too detailed to bury in a privacy policy.
Do analytics cookies need consent?
In the UK and EU, yes - the ICO has said repeatedly that analytics is not "strictly necessary". Some EU regulators allow a narrow exemption for first-party, non-shared audience measurement, but the default answer is consent first.
Does a cookie policy need updating when I add a tool?
Yes, and this is the clause that goes stale fastest. Every new tag, pixel or embedded widget adds cookies your table does not list. Scanning your own site on a schedule is the only reliable way to keep it honest.
What about cookies set by embedded video and maps?
They count. An embedded YouTube player or Google Map sets third-party cookies as soon as it loads, so either it loads only after consent, or you use a privacy-preserving embed mode and say so.
Cookie Policy Generator Australia
Answer a short questionnaire and get a draft written for Australia. Free to start, no card required.
Generate your cookie policyOther documents for Australia
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.