Security lock and digital protection concept representing data privacy
PC
Privacy & Compliance 7 min read

Australia's Privacy Act Reforms: What Small Business Websites Need to Fix

Australia's ongoing Privacy Act reforms are steadily narrowing the exemptions and expanding the obligations that used to let many small businesses treat privacy compliance as an afterthought. This isn't legal advice — talk to a lawyer about your specific obligations — but from a website-build perspective, here's what we're routinely finding needs fixing when we audit small business sites in 2026.

Person reviewing a legal or compliance document on a laptop
Most website privacy gaps are technical oversights, not deliberate — an old form, a tracking script no one revisited, a policy copied years ago.

An out-of-date or copy-pasted privacy policy

A privacy policy that was copied from a template years ago and never revisited is one of the most common gaps. It should accurately describe what you actually collect, why, how long you keep it, who you share it with (including any third-party tools like CRMs, ad platforms and analytics), and how someone can request their data be corrected or deleted.

Forms collecting more than they need

Data minimisation — only collecting what you genuinely need — is a core privacy principle and an easy thing to get wrong. Audit every form on your site: contact forms, quote requests, newsletter signups, job applications. If a field isn't actually used for anything, remove it.

Cookie and tracking consent

Many Australian sites still drop analytics and advertising cookies before any consent is given, or bury consent options behind confusing UI. A clear, genuine choice — not a dark pattern that nudges everyone to 'accept all' — is both the safer and the more defensible approach as enforcement tightens.

Data protection and cybersecurity concept on a screen
Cookie consent, data minimisation and a genuinely current privacy policy are the three most common gaps we find.

Third-party tools and where data actually goes

Your CRM, email platform, live chat widget, and ad pixels are all data processors under your privacy obligations. Know what each one collects, where it's stored, and make sure your privacy policy actually reflects your real tool stack — not just the tools you had when the policy was written.

Data breach readiness

Notifiable data breach obligations mean having at least a basic plan: how you'd detect a breach, who's responsible for assessing it, and the process for notifying affected individuals and the regulator if required. Most small businesses don't have this written down anywhere until they need it.

Security basics that support compliance

Compliance and security overlap heavily. HTTPS everywhere, current CMS and plugin versions, strong admin credentials, and encrypted storage for anything sensitive are baseline expectations, not nice-to-haves — and they materially reduce your actual breach risk, not just your paperwork risk.

This compounds with trust, not just risk

A visibly clear, accurate, well-implemented privacy approach is also a trust signal to customers and to Google — vague or contradictory privacy practices are exactly the kind of thing that undermines E-E-A-T and customer confidence alike. Getting this right serves more than one purpose at once.

Where to start

Start with an honest audit of what you actually collect and why, get your privacy policy genuinely current, and fix consent and form-field bloat. If you'd like your site reviewed for these common gaps as part of a broader build or refresh, our web design team in Sydney can flag what needs attention — get in touch (and we'll always tell you when something needs a lawyer, not a developer).

Related reading

← Back to all posts
START A PROJECT

Tell us about your briefwe'll reply in 24h.

Step 1 of 4 About you
Please tell us your name.
Enter a valid email address.
Classic services
AI services
Pick at least one service.
Choose a budget range.
Pick a timeline.
Please give us a few details about the project.
0 + 0 = Spam shield
Not quite — try again.

Thanks — we've got your brief.

We've opened WhatsApp with your project details pre-filled. Hit send and we'll respond within 24 hours (Australian business hours).