Guides

Plain-English guides to the rules that apply to your website.

The Privacy Act, Australian Consumer Law, the Spam Act, email security: the obligations that quietly apply to every small-business website, explained for a business owner rather than an engineer. No jargon, no fear, just what to do.

Start here

What Australian law actually requires of your website

Consumer Law, the Privacy Act, the Spam Act, the 2027 unfair trading ban, cookies and your ABN: in plain English, with sources. Including the laws that probably don't apply to you at all, the part that's easy to miss.

Transparency

Everything AegorIQ checks, and why it matters

The complete, itemised list of every check we run on a website (security, privacy, consumer law and performance) plus, just as importantly, exactly what we don't check. If you're going to trust a report, you should see precisely what produced it.

Read the full list →
Privacy Act

A new privacy rule starts 10 December. Does it apply to your website or CRM?

From 10 December 2026, a privacy policy has to disclose decisions made or materially assisted by software, and APP 1.7 is a three-limb test, not the one limb most summaries quote. Who is actually caught, who is not, and three things worth doing before the deadline. Read the guide →

Security alert

A critical alert went out for online stores. The real target is your checkout page.

On 9 September 2026 the ACSC issued a Critical alert about a flaw in Adobe Commerce and Magento already being used against shops, and said a substantial number of vulnerable instances sit inside the Australian economy. Why it matters even if you run WooCommerce or have never heard of Magento, and seven checks worth doing this week. Read the guide →

Privacy Act

The privacy regulator just ruled a cookie banner isn’t consent for a tracking pixel.

In June 2026 the OAIC found two Australian health businesses breached the Privacy Act over undisclosed Facebook and TikTok tracking pixels, and that their existing cookie banners were not valid consent. What the determinations require, who they bind today, and the checks worth doing on your own site. Read the guide →

Security alert

Your website can be perfect and still be broken into: through your web host.

The ACSC has confirmed active exploitation in Australia of a critical cPanel/WHM flaw (CVE-2026-41940), and that several managed hosting providers were compromised, taking their customers with them. The one layer you cannot patch yourself, and the five questions to email your host this week. Read the guide →

Scams & email security

Four in five small businesses had a scam attempt last year

Scams Awareness Week closed on 28 August. The scam small businesses report most is false billing, a real invoice from a real supplier with the account number changed. Three checks that make your business harder to impersonate, and the one rule that beats all of them.

Read the guide →
Privacy

A supplier got breached. It's still your business's data breach.

Quest Apartment Hotels disclosed a breach on 19 August 2026 that happened at a third-party provider, not on its own systems. Australia's Privacy Commissioner is clear that you stay responsible for personal information you hand to a supplier, and the 30-minute list that tells you who's holding your customers' details right now.

Read the guide →
Security & privacy

900,000 records, one login nobody switched off

Reports point to the Origin Energy breach starting with a former employee's login that was never deactivated. The Notifiable Data Breaches duty that applies at your scale, and the 15-minute offboarding check that closes the same gap on your own website.

Read the guide →
Security alert

A serious WordPress flaw was patched on Friday. Check your site in two minutes.

On 17 July 2026 WordPress shipped emergency updates for "wp2shell", a flaw in WordPress itself, exploited within hours, no plugins needed. Which versions are affected, why "auto-update was on" isn't proof, and the two-minute check to do today.

Read the guide →
Privacy Act

The Privacy Act just started applying to businesses that were always exempt

From 1 July 2026, new anti-money-laundering rules cover real estate agents, conveyancers, lawyers and accountants: and bring Privacy Act obligations with them, regardless of turnover. Who's covered, the 29 July AUSTRAC deadline, and the privacy steps to take now.

Read the guide →
Privacy & trust

Data breaches just hit a record high: what your website should show customers

Australia logged a record 1,205 data breach notifications in 2025, and 82% of Australians now rank breaches their top privacy worry. The six visible signals on your own site that show customers you take their data seriously, and how to check each one this week.

Read the guide →
Security alert

The government just issued a critical alert about websites like yours

On 9 July 2026 the ACSC warned that attackers are mass-scanning websites (many Australian small businesses included): for out-of-date WordPress plugins. What's happening, whether it applies to your site, and the checks to do this week.

Read the guide →
Consumer law

Australia just banned unfair trading. Your website has until 1 July 2027.

Parliament has passed a ban on subscription traps, hidden checkout fees and manipulative online design, taking effect 1 July 2027. What it covers, what's already law today, and what to check on your own site.

Read the guide →
Spam Act

ACMA just fined a company $2.7 million for spam. Here's what the law actually requires.

TAB was fined more than $2.7 million on 22 July 2026 for spam and telemarketing breaches, its second such penalty in about two years. What the Spam Act and Do Not Call Register require (no small-business exemption), plus the SMS Sender ID rule in force since 1 July.

Read the guide →
Consumer law

"No refunds on sale items." The ACCC says that's illegal, and it's still checking.

The ACCC swept 2,000+ retail websites for illegal return-policy wording, then kept enforcing: a $10 million Federal Court penalty landed against JustAnswer on 8 July 2026. The exact phrases that break the law, what you're still allowed to say, and how to check your own site.

Read the guide →
Privacy Act

Privacy Act 2026: what your website must have

The Privacy Act reforms are widening the net of who has to comply, and what your privacy policy has to say. A plain-English rundown of what's changing, what's proposed, and the elements your policy needs today.

Read the guide →
Common mistakes

The compliance mistakes we see most often

Blanket "no refunds" wording, a privacy policy missing half its required parts, email that anyone can spoof, pre-ticked consent boxes. The everyday website mistakes that carry real regulatory and trust risk, and how to fix each one.

Read the guide →

More guides are published regularly. Each is grounded in current Australian regulation and cites its sources.

Prefer a checklist you can work through?

The 14 things every Australian small-business website needs: privacy, consumer law, spam, security. Plain English, yours free.

Get the free checklist