Australia's ongoing Privacy Act reforms are steadily narrowing the exemptions and expanding the obligations that used to let many small businesses treat privacy compliance as an afterthought. This isn't legal advice — talk to a lawyer about your specific obligations — but from a website-build perspective, here's what we're routinely finding needs fixing when we audit small business sites in 2026.
An out-of-date or copy-pasted privacy policy
A privacy policy that was copied from a template years ago and never revisited is one of the most common gaps. It should accurately describe what you actually collect, why, how long you keep it, who you share it with (including any third-party tools like CRMs, ad platforms and analytics), and how someone can request their data be corrected or deleted.
Forms collecting more than they need
Data minimisation — only collecting what you genuinely need — is a core privacy principle and an easy thing to get wrong. Audit every form on your site: contact forms, quote requests, newsletter signups, job applications. If a field isn't actually used for anything, remove it.
Cookie and tracking consent
Many Australian sites still drop analytics and advertising cookies before any consent is given, or bury consent options behind confusing UI. A clear, genuine choice — not a dark pattern that nudges everyone to 'accept all' — is both the safer and the more defensible approach as enforcement tightens.
Third-party tools and where data actually goes
Your CRM, email platform, live chat widget, and ad pixels are all data processors under your privacy obligations. Know what each one collects, where it's stored, and make sure your privacy policy actually reflects your real tool stack — not just the tools you had when the policy was written.
Data breach readiness
Notifiable data breach obligations mean having at least a basic plan: how you'd detect a breach, who's responsible for assessing it, and the process for notifying affected individuals and the regulator if required. Most small businesses don't have this written down anywhere until they need it.
Security basics that support compliance
Compliance and security overlap heavily. HTTPS everywhere, current CMS and plugin versions, strong admin credentials, and encrypted storage for anything sensitive are baseline expectations, not nice-to-haves — and they materially reduce your actual breach risk, not just your paperwork risk.
This compounds with trust, not just risk
A visibly clear, accurate, well-implemented privacy approach is also a trust signal to customers and to Google — vague or contradictory privacy practices are exactly the kind of thing that undermines E-E-A-T and customer confidence alike. Getting this right serves more than one purpose at once.
Where to start
Start with an honest audit of what you actually collect and why, get your privacy policy genuinely current, and fix consent and form-field bloat. If you'd like your site reviewed for these common gaps as part of a broader build or refresh, our web design team in Sydney can flag what needs attention — get in touch (and we'll always tell you when something needs a lawyer, not a developer).