This guide explains what has changed, where online stores are most exposed, and what to fix first.
Privacy reform is now a real business risk
Does the Privacy Act apply to your store?
The Privacy Act 1988 (Cth) includes a small business exemption that generally excludes businesses with annual turnover of $3 million or less. Online, that exemption is narrower than most operators assume.
It does not apply if your business is related to a body corporate that is not a small business, which captures many franchisees and brands operating under a parent. It also does not apply if you trade in personal information, which can include sharing customer data with brand partners, running data-matching with an ad platform, or buying and selling lists. Providing a health service, which includes online pharmacy and some supplement and telehealth models, removes the exemption entirely.
Even where the exemption technically holds, it does not travel. If you sell into Europe or the UK, or use a platform that applies those standards to you by contract, you are meeting a higher bar anyway. And customers do not check your turnover before deciding whether to trust you.
What has changed under the privacy act?
Much stronger enforcement powers
The Privacy and Other Legislation Amendment Act 2024 significantly expanded the powers of the OAIC, including the ability to issue infringement notices for certain breaches, stronger investigation and information-gathering powers, and public inquiries into systemic privacy practices.
Significantly higher penalties
Maximum penalties for serious or repeated interferences with privacy have been increased to the greater of AU$50 million, three times the value of the benefit obtained, or 30 percent of adjusted turnover during the breach period.
Individuals can now sue
The statutory cause of action for serious invasions of privacy commenced on 10 June 2025. Individuals can take legal action where a privacy invasion was intentional or reckless, serious in nature, and where they had a reasonable expectation of privacy.
Consent standards have tightened
Consent must be voluntary, informed, current, specific and given by someone with capacity to give it. Pre-ticked boxes, consent bundled into terms and conditions, and consent implied from continued browsing do not meet that standard. This directly changes how cookie banners, sign-up forms and checkout flows have to be built.
WHY IT MATTERS
Why online stores are exposed
An online store collects more personal information, from more people, with less deliberation than almost any other kind of business. Most of it is collected automatically, by scripts the business did not write and often cannot fully explain.
A typical Australian store runs somewhere between five and fifteen third-party scripts: analytics, advertising pixels, chat widgets, review tools, heat mapping, email capture. Each one collects something. Most load before the consent banner is even visible. When the banner does appear, it frequently offers a single Accept button, which is not a choice and therefore not consent.
What makes this different from an in-store problem is that it is visible from the outside. A regulator, a competitor or a journalist can open your site, check what fires before consent, and see the gap in about thirty seconds. There is no need for an investigation to establish it.
The exposure compounds quietly. A store that has been trading for five years is holding abandoned carts from customers who never bought, accounts nobody has logged into since 2022, and marketing lists inherited from a platform migration. None of it is earning anything. All of it is in scope if something goes wrong, and all of it has to be disclosed to the people affected.
WHY IT MATTERS
What regulators have said
The OAIC has not yet issued a headline determination about tracking pixels on an Australian store. It has been very clear about the principle underneath them.
Its retail facial recognition determinations turned on two questions: could the business justify collecting the information at all, and did the people it collected from understand what was happening. Neither question is about cameras. Both apply directly to a script that starts collecting before anyone has agreed to anything.
On consent specifically, the OAIC's guidance is that it must be voluntary, informed, current and specific. A banner that only offers Accept fails the first test. A banner that says "we use cookies to improve your experience" without saying which cookies, or who receives the data, fails the second.
This is the part Savira handles: a banner that meets the standard, tags that hold until consent is given, and a record of what each visitor agreed to.
Key obligations under the Australian Privacy Principles
APP 1 - Privacy policy
Your store must have a clear, accurate and accessible privacy policy explaining what you collect, why, how it is used and disclosed, and how people can access or correct it. Most store policies are template text that does not match the tools actually running on the site.
APP 3 and 5 - Collection and notification
Only collect what is reasonably necessary, and tell people at or before collection. Newsletter forms, account sign-up and checkout are the everyday risk points. Asking for a date of birth or phone number you never use is over-collection.
APP 6 - Use and disclosure
Information collected for one purpose cannot be used for another without consent. Uploading your customer list to build a lookalike audience, or feeding purchase history into ad targeting, is the most common breach point in ecommerce.
APP 7 - Direct marketing
Personal information cannot be used for direct marketing without consent or a clear, functional opt-out. This covers email, SMS and push. Abandoned cart emails to someone who never completed checkout are worth a specific look.
APP 8 - Cross-border disclosure
When customer data goes to overseas platforms, including your store platform, email tool, ad networks and analytics, you must take reasonable steps to ensure comparable protections apply. Relying on the provider's standard terms alone is increasingly insufficient, and you remain accountable for what they do.
APP 11 - Security
You must take reasonable steps to protect personal information from misuse, loss and unauthorised access, and destroy or de-identify it when it is no longer needed. That second half is where most stores fall down, because nothing is ever deleted.
What online stores should do now
Privacy compliance requires a structured approach across three timeframes. Immediate actions address critical gaps, medium-term work builds governance capability, and strategic initiatives embed privacy into how your store operates.
Immediate (0-3 months)
Fix critical privacy gaps now
Medium term (3-12 months)
Build governance and processes
Strategic (12-18 months)
Embed long-term privacy strategy
Immediate: 0 to 3 months
- List every third-party script running on your store. Most operators find tools they had forgotten about, or that a previous agency installed.
- Check what fires before consent. Open your store in a private window and watch the network tab, or ask whoever maintains the site to do it.
- Fix the cookie banner so it offers a genuine choice, not a single Accept button, and so declining actually stops the tags.
- Update your privacy policy so it matches the tools you actually run, including which ones send data overseas.
- Review your sign-up and checkout forms and remove any field you do not use.
- Confirm every marketing list has documented consent and a working unsubscribe, consistent with the Spam Act 2003.
Medium term: 3 to 12 months
- Appoint a privacy lead and document a privacy management plan.
- Map your data flows across the store platform, payment provider, email tool, ad platforms and analytics.
- Set retention periods for guest checkout data, abandoned carts, dormant accounts and old marketing lists, and actually delete to them.
- Review contracts with your platform and key vendors for privacy and security coverage, particularly around cross-border transfer.
- Build a process for access and correction requests so a customer email does not become a scramble.
- Write and test a data breach response plan aligned to the Notifiable Data Breaches scheme.
Strategic: 12 to 18 months
- Move to consent-aware tracking as standard, so tags are wired to consent state rather than added ad hoc by whoever is running campaigns.
- Review personalisation, segmentation and any automated decision-making against APP 6 and community expectations.
- Assess AI tools used for recommendations, support or content before deploying them against customer data.
- Integrate privacy risk into business reporting, vendor review and insurance cycles.
- Monitor reform work on automated decision-making, children's privacy and data brokers.
If you also sell in store
Most of what is above applies to the physical side of your business too. Collect only what you need, tell people why, and keep it no longer than necessary.
Two things are different in store. Loyalty sign-ups at the counter give people very little time to understand what they are agreeing to, so the collection notice on the form matters more than it does online. And any camera system that analyses faces rather than simply recording footage collects sensitive information, which carries a much higher bar. The OAIC has issued determinations against major retailers on exactly that point, and it is an area where you should get specialist advice rather than working it out yourself.
Practical checklist
Use this as an accountability tool. Assign an owner in your team to each item and track progress against it.
What businesses like yours ask
What Savira does
Savira helps Australian online stores handle the parts of privacy compliance that are ongoing rather than one-off. Generate and maintain a privacy policy that matches the tools you actually run, put compliant cookie consent on your store, and keep an auditable record of who agreed to what and when, so you can answer a customer or a regulator without digging through inboxes.
Whether you are a sole practitioner or a national network, Savira gives you the compliance foundations without needing a consultant or a developer.
Staying current with privacy reform
This guide was last updated 29 August 2026 to reflect current OAIC guidance on consent and enforcement priorities. Australian privacy law continues to evolve. Register to stay across regulatory changes affecting online stores.

