Savira -- Making Compliance Easy
Be the business people trust

Privacy compliance for Australian online stores

Give customers visibility and control over their data.

Every online store collects personal information before a customer has bought anything. Analytics scripts, advertising pixels, newsletter forms and abandoned carts all gather data, often before anyone has agreed to it. Consent standards have tightened, and penalties for serious breaches reach $50 million.

Making Compliance easy

This guide explains what has changed, where online stores are most exposed, and what to fix first.

Key takeaways

Privacy reform is now a real business risk

Penalties up to $50M

Serious or repeated privacy breaches can attract penalties up to AU$50 million, 30 percent of adjusted turnover, or three times the benefit gained.

Consent has to be real

Bundled, buried or pre-ticked consent no longer meets the standard. Cookie banners, loyalty sign-ups and checkout forms all have to give people a genuine choice, and you have to be able to show what they chose.

Most stores track before they ask

On a typical store, advertising and analytics scripts fire the moment the page loads, well before anyone touches the banner. That is collection without consent, and it is the single most common problem we see.

Your data leaves the country

Ecommerce platforms, email tools, payment providers and ad networks are mostly overseas. Sending customer data to them is a disclosure, and you are responsible for what happens to it.

Individuals can sue

The statutory cause of action for serious invasions of privacy has been in force since 10 June 2025. Online breaches tend to affect thousands of customers at once, which is what makes class actions viable.

Your website collects too

Guest checkouts, abandoned carts, dormant accounts and old marketing lists all sit in your systems long after they are useful. Everything you keep is something you can lose.

Penalties up to $50M

Serious or repeated privacy breaches can attract penalties up to AU$50 million, 30 percent of adjusted turnover, or three times the benefit gained.

Consent has to be real

Bundled, buried or pre-ticked consent no longer meets the standard. Cookie banners, loyalty sign-ups and checkout forms all have to give people a genuine choice, and you have to be able to show what they chose.

Most stores track before they ask

On a typical store, advertising and analytics scripts fire the moment the page loads, well before anyone touches the banner. That is collection without consent, and it is the single most common problem we see.

Your data leaves the country

Ecommerce platforms, email tools, payment providers and ad networks are mostly overseas. Sending customer data to them is a disclosure, and you are responsible for what happens to it.

Individuals can sue

The statutory cause of action for serious invasions of privacy has been in force since 10 June 2025. Online breaches tend to affect thousands of customers at once, which is what makes class actions viable.

Your website collects too

Guest checkouts, abandoned carts, dormant accounts and old marketing lists all sit in your systems long after they are useful. Everything you keep is something you can lose.

Does this apply to you?

Does the Privacy Act apply to your store?

The Privacy Act 1988 (Cth) includes a small business exemption that generally excludes businesses with annual turnover of $3 million or less. Online, that exemption is narrower than most operators assume.

It does not apply if your business is related to a body corporate that is not a small business, which captures many franchisees and brands operating under a parent. It also does not apply if you trade in personal information, which can include sharing customer data with brand partners, running data-matching with an ad platform, or buying and selling lists. Providing a health service, which includes online pharmacy and some supplement and telehealth models, removes the exemption entirely.

Even where the exemption technically holds, it does not travel. If you sell into Europe or the UK, or use a platform that applies those standards to you by contract, you are meeting a higher bar anyway. And customers do not check your turnover before deciding whether to trust you.

What has changed under the privacy act?

Much stronger enforcement powers

The Privacy and Other Legislation Amendment Act 2024 significantly expanded the powers of the OAIC, including the ability to issue infringement notices for certain breaches, stronger investigation and information-gathering powers, and public inquiries into systemic privacy practices.

Significantly higher penalties

Maximum penalties for serious or repeated interferences with privacy have been increased to the greater of AU$50 million, three times the value of the benefit obtained, or 30 percent of adjusted turnover during the breach period.

Individuals can now sue

The statutory cause of action for serious invasions of privacy commenced on 10 June 2025. Individuals can take legal action where a privacy invasion was intentional or reckless, serious in nature, and where they had a reasonable expectation of privacy.

Consent standards have tightened

Consent must be voluntary, informed, current, specific and given by someone with capacity to give it. Pre-ticked boxes, consent bundled into terms and conditions, and consent implied from continued browsing do not meet that standard. This directly changes how cookie banners, sign-up forms and checkout flows have to be built.

WHY IT MATTERS

Why online stores are exposed

An online store collects more personal information, from more people, with less deliberation than almost any other kind of business. Most of it is collected automatically, by scripts the business did not write and often cannot fully explain.

A typical Australian store runs somewhere between five and fifteen third-party scripts: analytics, advertising pixels, chat widgets, review tools, heat mapping, email capture. Each one collects something. Most load before the consent banner is even visible. When the banner does appear, it frequently offers a single Accept button, which is not a choice and therefore not consent.

What makes this different from an in-store problem is that it is visible from the outside. A regulator, a competitor or a journalist can open your site, check what fires before consent, and see the gap in about thirty seconds. There is no need for an investigation to establish it.

The exposure compounds quietly. A store that has been trading for five years is holding abandoned carts from customers who never bought, accounts nobody has logged into since 2022, and marketing lists inherited from a platform migration. None of it is earning anything. All of it is in scope if something goes wrong, and all of it has to be disclosed to the people affected.

WHY IT MATTERS

What regulators have said

Person reading The Australian newspaper article about Australian privacy compliance on a tablet device

The OAIC has not yet issued a headline determination about tracking pixels on an Australian store. It has been very clear about the principle underneath them.

Its retail facial recognition determinations turned on two questions: could the business justify collecting the information at all, and did the people it collected from understand what was happening. Neither question is about cameras. Both apply directly to a script that starts collecting before anyone has agreed to anything.

On consent specifically, the OAIC's guidance is that it must be voluntary, informed, current and specific. A banner that only offers Accept fails the first test. A banner that says "we use cookies to improve your experience" without saying which cookies, or who receives the data, fails the second.

This is the part Savira handles: a banner that meets the standard, tags that hold until consent is given, and a record of what each visitor agreed to.

THE APPS

Key obligations under the Australian Privacy Principles

APP 1 - Privacy policy

APP 1 - Privacy policy

Your store must have a clear, accurate and accessible privacy policy explaining what you collect, why, how it is used and disclosed, and how people can access or correct it. Most store policies are template text that does not match the tools actually running on the site.

APP 3 and 5 - Collection and notification

APP 3 and 5 - Collection and notification

Only collect what is reasonably necessary, and tell people at or before collection. Newsletter forms, account sign-up and checkout are the everyday risk points. Asking for a date of birth or phone number you never use is over-collection.

APP 6 - Use and disclosure

APP 6 - Use and disclosure

Information collected for one purpose cannot be used for another without consent. Uploading your customer list to build a lookalike audience, or feeding purchase history into ad targeting, is the most common breach point in ecommerce.

APP 7 - Direct marketing

APP 7 - Direct marketing

Personal information cannot be used for direct marketing without consent or a clear, functional opt-out. This covers email, SMS and push. Abandoned cart emails to someone who never completed checkout are worth a specific look.

APP 8 - Cross-border disclosure

APP 8 - Cross-border disclosure

When customer data goes to overseas platforms, including your store platform, email tool, ad networks and analytics, you must take reasonable steps to ensure comparable protections apply. Relying on the provider's standard terms alone is increasingly insufficient, and you remain accountable for what they do.

APP 11 - Security

APP 11 - Security

You must take reasonable steps to protect personal information from misuse, loss and unauthorised access, and destroy or de-identify it when it is no longer needed. That second half is where most stores fall down, because nothing is ever deleted.

YOUR COMPLIANCE ROADMAP

What online stores should do now

Privacy compliance requires a structured approach across three timeframes. Immediate actions address critical gaps, medium-term work builds governance capability, and strategic initiatives embed privacy into how your store operates.

Immediate (0-3 months)

Fix critical privacy gaps now

Medium term (3-12 months)

Build governance and processes

Strategic (12-18 months)

Embed long-term privacy strategy

Immediate: 0 to 3 months

  • List every third-party script running on your store. Most operators find tools they had forgotten about, or that a previous agency installed.
  • Check what fires before consent. Open your store in a private window and watch the network tab, or ask whoever maintains the site to do it.
  • Fix the cookie banner so it offers a genuine choice, not a single Accept button, and so declining actually stops the tags.
  • Update your privacy policy so it matches the tools you actually run, including which ones send data overseas.
  • Review your sign-up and checkout forms and remove any field you do not use.
  • Confirm every marketing list has documented consent and a working unsubscribe, consistent with the Spam Act 2003.

Medium term: 3 to 12 months

  • Appoint a privacy lead and document a privacy management plan.
  • Map your data flows across the store platform, payment provider, email tool, ad platforms and analytics.
  • Set retention periods for guest checkout data, abandoned carts, dormant accounts and old marketing lists, and actually delete to them.
  • Review contracts with your platform and key vendors for privacy and security coverage, particularly around cross-border transfer.
  • Build a process for access and correction requests so a customer email does not become a scramble.
  • Write and test a data breach response plan aligned to the Notifiable Data Breaches scheme.

Strategic: 12 to 18 months

  • Move to consent-aware tracking as standard, so tags are wired to consent state rather than added ad hoc by whoever is running campaigns.
  • Review personalisation, segmentation and any automated decision-making against APP 6 and community expectations.
  • Assess AI tools used for recommendations, support or content before deploying them against customer data.
  • Integrate privacy risk into business reporting, vendor review and insurance cycles.
  • Monitor reform work on automated decision-making, children's privacy and data brokers.

If you also sell in store

Most of what is above applies to the physical side of your business too. Collect only what you need, tell people why, and keep it no longer than necessary.

Two things are different in store. Loyalty sign-ups at the counter give people very little time to understand what they are agreeing to, so the collection notice on the form matters more than it does online. And any camera system that analyses faces rather than simply recording footage collects sensitive information, which carries a much higher bar. The OAIC has issued determinations against major retailers on exactly that point, and it is an area where you should get specialist advice rather than working it out yourself.

Free tool

Practical checklist

Use this as an accountability tool. Assign an owner in your team to each item and track progress against it.

AreaImmediate PriorityNext Phase
Third-party scriptsList everything running on the storeReview before anything new is added
Cookie consentFix the banner; ensure declining stops the tagsKeep consent records auditable and reviewable
Privacy policyUpdate to match the tools you actually runSchedule annual review; assign a named owner
Forms and checkoutRemove fields you do not use; add collection noticesStandardise compliant templates across the store
MarketingConfirm consent and opt-out on all listsConduct full CRM governance and list hygiene review
Cross-borderMap which tools send data overseasReview contracts; update policy disclosures
RetentionSet periods for carts, guest data and dormant accountsAutomate deletion where the platform allows
SecurityEnforce multi-factor authentication on admin accountsCommission periodic risk assessment
Breach readinessDocument who to notify and whenTest the plan; build into governance reporting
Third-party scripts
Immediate PriorityList everything running on the store
Next PhaseReview before anything new is added
Cookie consent
Immediate PriorityFix the banner; ensure declining stops the tags
Next PhaseKeep consent records auditable and reviewable
Privacy policy
Immediate PriorityUpdate to match the tools you actually run
Next PhaseSchedule annual review; assign a named owner
Forms and checkout
Immediate PriorityRemove fields you do not use; add collection notices
Next PhaseStandardise compliant templates across the store
Marketing
Immediate PriorityConfirm consent and opt-out on all lists
Next PhaseConduct full CRM governance and list hygiene review
Cross-border
Immediate PriorityMap which tools send data overseas
Next PhaseReview contracts; update policy disclosures
Retention
Immediate PrioritySet periods for carts, guest data and dormant accounts
Next PhaseAutomate deletion where the platform allows
Security
Immediate PriorityEnforce multi-factor authentication on admin accounts
Next PhaseCommission periodic risk assessment
Breach readiness
Immediate PriorityDocument who to notify and when
Next PhaseTest the plan; build into governance reporting
Common questions

What businesses like yours ask

It depends on what you collect directly. If you have your own site, mailing list or customer accounts, you are collecting personal information and the obligations apply to that. If you sell exclusively through a marketplace and never handle customer data yourself, your exposure is lower, though the platform's terms will usually pass some obligations to you.
Open the store in a private browser window and watch what loads before you touch the banner. If advertising or analytics scripts fire before consent, the banner is decorative. A banner that only offers Accept has the same problem, because consent has to be a genuine choice.
Treat both the same way. The test is whether the tool is necessary to make the site work, not whether it is labelled analytics or advertising. Most analytics tools set identifiers and share data with a third party, so the safe position is that they wait for consent.
Not automatically, but it is a cross-border disclosure under APP 8 and you remain accountable for what happens to the data. You need to take reasonable steps to ensure comparable protections apply, and your privacy policy should disclose that data goes offshore.
Only where you have consent to email that person. Someone entering an email address at checkout has not necessarily agreed to marketing, and an abandoned cart email is marketing. Ask for consent separately at the point of collection, and include a working unsubscribe.

What Savira does

Savira helps Australian online stores handle the parts of privacy compliance that are ongoing rather than one-off. Generate and maintain a privacy policy that matches the tools you actually run, put compliant cookie consent on your store, and keep an auditable record of who agreed to what and when, so you can answer a customer or a regulator without digging through inboxes.

Whether you are a sole practitioner or a national network, Savira gives you the compliance foundations without needing a consultant or a developer.

Staying current with privacy reform

This guide was last updated 29 August 2026 to reflect current OAIC guidance on consent and enforcement priorities. Australian privacy law continues to evolve. Register to stay across regulatory changes affecting online stores.