The Australian website compliance check

What Australian law actually requires of your website

Including — and this is the part that's easy to miss — the laws that probably don't apply to you at all.

This guide is written to be useful rather than alarming: here is what the law says, here is who it actually binds, and here is where you can stop reading and get back to work.

Last reviewed 14 July 2026 · Written for Australian small business · Advisory only — not legal advice

The short version

The lawDoes it apply to you?What it means for your website
Australian Consumer LawYes. Always. No small-business exemption exists.Your refund and returns wording must not deny consumer guarantees. "No refunds" is likely unlawful.
Spam Act 2003Yes. Always.Consent, identify yourself, and a working unsubscribe on every marketing email.
Unfair trading banYes — from 1 July 2027.No subscription traps, hidden fees, or manipulative checkout design.
Privacy Act 1988Probably not — unless you turn over $3m+, or you're in a covered industry.If covered: a privacy policy that is complete and reachable, plus real security over the data.
Cookie consentNot in Australia. Only if you have EU/UK visitors.If you use a banner, it must actually block non-essential cookies until accepted.
Displaying your ABNNot clearly required on a website.Not a law, but customers use it to check you're real. Publish it anyway.

1. Australian Consumer Law — this one is not optional

Applies to every business

Start here, because this is the law most likely to cost you money and the one least likely to be on your radar. Everyone talks about privacy. Almost nobody mentions that the Australian Consumer Law has no small-business exemption and never has. You may well be outside the Privacy Act. You are never outside the ACL.

Your refund page is a legal document

Consumer guarantees apply automatically to almost everything you sell. They exist independently of your store policy, and you cannot sign them away in your terms. Which means the following, all extremely common on Australian websites, are likely to be misleading:

Most of these were not written by anyone malicious. They were pasted in from a template years ago, by someone who has since left, and nobody has read that page since.

The regulator reads return policies. The ACCC runs sweeps of online shopping return policies and terms and conditions — it is looking at the words on your website. In November 2024, furniture retailer Koala Living paid $56,340 in penalties after infringement notices over misleading statements about customers' rights to a remedy, including representing that the right to seek a remedy was limited to 72 hours. In June 2025, electronics marketplace Reebelo Australia paid $59,400 for much the same thing.

Reports to the ACCC about consumer guarantees rose 20% to more than 38,000 in 2025.

What to do

Open your own returns page and read it as if you were an unhappy customer. If it contains any sentence whose job is to stop someone getting a remedy, that sentence is a liability. The safe framing is that your policy sits on top of consumer guarantees, never instead of them — and saying so plainly is also good for trust.

2. The Privacy Act — it may well not apply to you

Depends on turnover and industry

Here is the sentence you will not read on a compliance consultant's website, quoted from the OAIC itself: “Most small businesses are not covered by the Privacy Act, but some are.”

The general rule is that the Act applies once your annual turnover exceeds $3 million. Below that, you are usually outside it. But there are two traps.

Trap one: the turnover test is sticky

It doesn't ask what you turned over last year. It asks whether you have exceeded $3 million in any financial year since 2002. One strong year a decade ago, and you have been covered ever since — probably without knowing it.

Trap two: some industries are covered no matter how small

Turnover is irrelevant if you are a health service provider — and the OAIC defines that broadly enough to catch childcare centres, private schools, allied health practices, pharmacies and complementary therapists. Also covered regardless of size: credit reporting bodies, residential tenancy databases, businesses that trade in personal information, and Commonwealth contractors.

And since 1 July 2026, real estate professionals, lawyers, conveyancers, accountants and dealers in precious metals and stones have been brought in by the AML/CTF reforms — but only for the personal information they handle for their anti-money-laundering obligations, not for their whole business. This was widely and wrongly reported as "the small business exemption has been removed". It has not been. Its removal has been recommended, not legislated.

If the Act does cover you, the two things that most often go wrong on a website are: your privacy policy is missing elements the APPs expect (how someone makes a complaint, whether data goes overseas, how information is stored and secured), and — more often than you'd think — the policy exists but nothing on the site links to it. Under APP 1.5 you must take reasonable steps to make your policy readily available. A page nobody can find does not meet that. It is a very common failure on Shopify, which publishes your policy at a standard address but does not add it to your menu.

If it doesn't cover you, do you still need a privacy policy?

Legally, no. Practically, yes — if your site collects personal information, publish one. Not because a regulator will come, but because customers look for it before they hand over their details, and its absence reads as carelessness. It costs you an afternoon.

3. The Spam Act — also applies to everyone

Applies to every business

If you send marketing email or SMS, three things are required, and there is no small-business exemption here either:

The practical website consequence: your sign-up form needs a real consent step, and an email field quietly bolted to the bottom of a contact form is not one.

4. The unfair trading ban — 1 July 2027

Applies to every business — from 1 July 2027

Parliament has passed a ban on unfair trading practices, in force from 1 July 2027. It targets three things, all of which live on websites:

You have time. But note that a good deal of this is already unlawful under the existing prohibition on misleading and deceptive conduct — the new law makes it explicit rather than inventing it. If your checkout does any of the above today, it is not safe today.

5. Cookie banners — not required in Australia

Not required, unless you have EU/UK visitors

Australia has no equivalent of the EU cookie rules. You do not need a banner to sell to Australians. You effectively do need one the moment you have EU or UK visitors, which for an online shop is easier to acquire than you might think.

If you do add one, it has to be real: non-essential cookies must actually be blocked until the visitor accepts. A banner that merely announces tracking that is already running is not consent — it is decoration, and it is the specific thing regulators look for. “Reject” must also be as easy as “Accept”.

6. Your ABN — and an honest admission

Not clearly required on a website

We check whether your website displays an ABN. It is worth being straight about why, because it is not the reason you might assume.

There is no general law requiring your ABN to appear on your website. The obligations bite on tax invoices and receipts, and companies must show their ACN or ABN on certain public documents. Whether a website counts as a "public document" for a company is a question we are not qualified to answer — ask a lawyer if you trade as a Pty Ltd.

So we flag it as best practice, not law: an ABN on your site is how a customer confirms you are a real, registered Australian business, and its absence is one of the standard signals people use to identify a scam site. That is a good enough reason on its own. It just isn't a legal one, and we would rather tell you that than let you believe a rule exists because it happens to suit us.

7. Security and compliance are the same job

Most of this market splits these in half, and the split is why so many small businesses end up with neither.

On one side, security scanners look for vulnerabilities and know nothing whatsoever about Australian law. On the other, compliance consultants write you a policy and never look at your TLS configuration. The firms that genuinely cover both do exist — and they will quote you five figures, because they are built for organisations with a risk committee. That is a fair price for that work. It is simply not a price a suburban physio practice can pay, which is how a business ends up with neither half.

And each half is close to worthless without the other. Here is why that isn't a slogan.

Compliance is what you promise. Security is whether you can keep it.

A privacy policy is a written undertaking about how you handle someone's data. If your website isn't secure, you have not merely failed to protect that data — you have published a promise you cannot keep. That is a worse position than saying nothing at all, because the obligation is now documented, in your own words, on your own website.

And the law already treats them as one thing

You don't have to take our word for that, because the Privacy Act says it outright:

The other direction is just as bad

Flip it around. You can run flawless security — every header set, every certificate current, every plugin patched — and still lose the business, because nobody outside your server ever sees any of it. What a customer sees is your refund page. What a regulator reads is your terms. Security is invisible; compliance is the part of your business that faces the world. Get it wrong and you don't get hacked. You just quietly stop being trusted, which takes longer to notice and longer to fix.

So: the most compliant website in Australia is worthless if the data behind it isn't protected, and the most secure website in Australia is worthless if nobody trusts the business running it. The two aren't alternatives to be traded off against each other. They are two halves of a single question — can this business be trusted with my details? — and the honest answer requires looking at both.

That is the entire reason AegorIQ exists as one report rather than two.

One last number, because it makes the point better than any argument. The average self-reported cost of cybercrime to an Australian small business is $56,571 per incident (ASD). The ACCC penalties above were $56,340 and $59,400. Two entirely different ways to lose the same $56,000 — and a business that only defends against one of them has not halved its risk. It has simply chosen which way it would prefer to find out.

What to actually do this week

Want this as a list you can tick off?

We keep a free one-page Australian website compliance & security checklist covering everything above — no scan, no payment, no sales call. Work through it yourself at your own pace. Get the free checklist →

Or have us check it for you.

We run every check on this page against your live website — and, unusually, we tell you when a law doesn't apply to you. The scorecard is free.

Get your free Scorecard

This is advisory, not legal advice. AegorIQ is not a law firm. Whether a particular obligation applies to your business, and whether your wording satisfies it, depends on facts we cannot see and judgement a scan cannot make. Before you rely on, change, or decide not to change a legal document, get advice from a qualified Australian legal practitioner. Treat this page as a well-informed list of things worth asking them about — that is exactly what it is good for.

Sources

Consumer guarantees, "no refunds" wording, the ACCC's sweep of online return policies, and the Koala Living ($56,340, November 2024) and Reebelo Australia ($59,400, June 2025) infringement notices: ACCC.

Privacy Act coverage, the $3 million turnover test and the covered-industry exceptions: OAIC — Small business. APP 1 (privacy policy) and APP 1.5 (making it readily available): OAIC APP Guidelines, Chapter 1.

Cost of cybercrime to small business ($56,571, up from $49,615): ASD Annual Cyber Threat Report 2024–25.

ABN and ACN disclosure obligations: business.gov.au and ASIC.

We publish a source for every figure on this page. Any number we can't attribute, we don't print — a rule that cost us several more alarming statistics.