Blog
August 31, 2026
7 mins
Privacy Laws
Trending topics

Australia’s Privacy Reform Exposure Draft: What Shopify Merchants Need to Know About Cookies, Pixels, and Consent

Australia’s Privacy Amendment Bill 2026 is in consultation until 18 Sep. What cookies, pixels, and consent could mean for Shopify, and what Consentmo already covers for AU & NZ.

Key Takeaways

  • On 31 August 2026, the Australian Government opened consultation on the Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026. Feedback closes 18 September 2026.
  • This is not law. The Attorney-General’s Department says the Bill remains subject to further government consideration.
  • Ordinary direct marketing may still sit closer to opt-out in places. The sharper shift is around disclosure / trade for advertising and marketing purposes.
  • Consentmo already covers Australia & New Zealand with regional banners, geotargeting, Compliance Score, and related tools. Do not change Australian defaults today solely because of this draft.

Why this consultation matters

Australia is already a live market for many Shopify stores. Consentmo includes Australia (and New Zealand) in regional compliance coverage: geotargeted banners, consent models by region, Compliance Score checks, privacy tooling, and cookie categorisation.

The new consultation is still a policy development step, not a go-live date for new rules. The story worth watching is narrower and more practical than “Australia becomes GDPR overnight.”

The draft points at a possible future where disclosing personal information through certain advertising cookies and pixels needs clearer opt-in consent, even if not every marketing activity flips to EU-style consent.

What opened on 31 August 2026?

The government released:

  • Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026
  • A supporting Consultation Paper
  • A public call for submissions

From the consultation overview:

  • The reforms aim to modernise privacy law for the digital age.
  • Feedback will inform what government considers when finalising reforms.
  • “The Bill remains subject to further consideration by government.”

Current Australian position (what still applies today)

Until Parliament passes something new (and it commences), the existing Privacy Act framework and OAIC guidance remain the practical baseline for many merchants.

APP 7 and direct marketing

Under APP 7, organisations can use or disclose personal information for direct marketing in defined circumstances. Prior consent is not always required. Where information was collected from the individual and they would reasonably expect the marketing use, a simple opt-out can be enough, subject to the rest of APP 7.

Tracking pixels today

OAIC guidance on tracking pixels explains that third-party pixels used for targeted advertising still need to comply with the APPs, including APP 7. It does not set a blanket GDPR-style “block all marketing cookies until consent” rule for Australia.

OAIC guidance: Tracking pixels and privacy obligations.

That is why Consentmo can still treat Australia as a largely opt-out-oriented region for many ordinary advertising setups, depending on the merchant’s actual processing, disclosures, and integrations. Merchant-specific legal advice still matters.

The draft change Consentmo is watching closest: consent to “trade”

What “trade” points at

The Exposure Draft introduces a stronger line around obtaining consent before “trading” personal information. In the consultation framing, “trade” is cast broadly: disclosure for money or other consideration, or for direct-marketing purposes.

The consultation material then calls out disclosures that support direct marketing, including language around cookies or pixels in programmatic advertising processes.

That wording is unusually direct for Australian privacy reform, and it is the core CMP angle.

Proposed practical split (as drafted for consultation)

ActivityDirection in the draft / paperOrdinary direct marketingConsent not inherently required in every case; simple opt-out still centralDisclosure / trading of personal information for direct marketingConsent required in covered casesProgrammatic advertising involving cookie/pixel disclosureCalled out as potentially falling under tradeSensitive informationConsent generally expectedNecessary service processingPossible exceptionsProcessor acting only on controller instructionsPossible carve-out from “trade”

So Australia is not simply proposed as “everything non-essential needs consent.” Advertising pixels and cookie-based disclosures into the ad ecosystem could still move much closer to opt-in.

Current law vs proposed direction

Topic Current position (high level) Proposed direction (Exposure Draft stage)
Targeted ads using personal information Often workable on reasonable expectation + opt-out under APP 7. Ordinary direct marketing may remain closer to an opt-out model.
Sharing data into ad ecosystems APP use/disclosure rules + APP 7. A new trade concept may require consent where the activity is covered.
Advertising cookies / pixels No blanket prior-consent cookie rule comparable to the EU ePrivacy/GDPR stack. Cookie and pixel disclosures in programmatic advertising are explicitly part of the reform debate.
Consent quality OAIC consent concepts: voluntary, informed, current, specific, and given with capacity. More explicit statutory standards, including unambiguous consent.
Dark patterns / genuine choice Relevant under existing privacy principles. Stronger fair and reasonable and genuine-choice framing.
“Personal information” Information about an identifiable or reasonably identifiable individual. Broader “relates to” framing and stronger singling-out language in the draft debate.
Shopify AU defaults in Consentmo Australia can remain largely opt-out, assessed case by case. Some marketing integrations may eventually require prior consent if the draft wording survives.

What this could mean for cookie banners and ad pixels

If enacted substantially as discussed in the consultation materials, a defensible before / after consent picture for many storefronts could look like:

Before consent

  • Essential cookies: generally allowed
  • Analytics: depends on how data is handled and whether it is disclosed
  • Advertising / marketing pixels that disclose personal information into ad-tech: potentially blocked pending consent
  • Sensitive-data tracking: blocked without valid consent

After valid consent

  • Marketing and ad-tech disclosure becomes easier to justify, if the consent meets the new standard

Consentmo already surfaces Australia & New Zealand as a covered region in Compliance Score, with checks for banner state, regional consent model, geotargeting, Consent Mode, and cookie categorisation.

Consent quality would look more CMP-like

The draft discussion of valid consent points at requirements such as:

  • voluntary
  • informed
  • current
  • specific
  • unambiguous

Bundled consent, interfaces that make refusal unreasonably hard, and pre-ticked optional settings are poor fits for that standard.

That aligns with product patterns merchants already use in Consentmo:

  • separate cookie categories instead of one bundled “yes to everything”
  • Accept / Reject / Preferences
  • optional categories not preselected
  • easy preference changes and withdrawal
  • consent records
  • refreshed consent when processing changes in a material way

The materials also stress that consent does not need a fixed automatic expiry date, but it must stay current. A material change in handling can make old consent stale. That is useful context for any future re-consent or expiry settings.

Broader “personal information,” direct marketing, notices, and UX

Identifiers and behavioural data

Moving from information about a person toward information that relates to a person, plus stronger recognition of singling-out, weakens arguments like “it’s only a pseudonymous cookie ID, so it isn’t personal information.”

For cookie scanning and category guidance, advertising IDs, persistent device IDs, and behavioural profiles should be treated as high-risk candidates for the personal-information framework.

Direct marketing definition

Draft framing of direct marketing includes advertising directed at an individual based on personal information, including audience, segment, or cohort targeting. Examples discussed in the materials include email, SMS, telemarketing, targeted social ads, and online behavioural advertising based on browsing history.

Even where consent is not required, a simple, clear opt-out remains central. Preference centres and honest banner UX still help.

Fair and reasonable processing + dark patterns

Collection, use, and disclosure would need to be fair and reasonable. Considerations include reasonable expectations, transparency, minimisation, genuine choice, proportionality, and children’s best interests.

Choice may fail where people face take-it-or-leave-it terms, suffer detriment for refusing, or are steered by dark patterns.

Banner anti-patterns to keep avoiding:

  • hidden Reject
  • misleading visual hierarchy
  • preselected optional consent
  • painful withdrawal
  • confusing preference flows

Collection notices

Notices would focus on:

  1. the fact and circumstances of collection
  2. the purposes of use or disclosure

Burying a practice only in a long privacy policy does not automatically make it transparent or reasonably expected. Layered disclosure fits better:

Cookie banner → contextual explanation → preference centre → privacy / cookie policy

That is the same stack Consentmo supports with Smart Cookie Policy, Smart Privacy Center, scanner-driven descriptions, and category explanations. See also What Is a Cookie Policy?

Precise geolocation and children

  • Precise geolocation tracking over time within a 500 metre radius is discussed as sensitive information (generally consent-based). More relevant for apps, location SDKs, and proximity marketing than a basic storefront, but worth a future guidance entry.
  • Children’s best interests as a primary consideration sits alongside work on a Children’s Online Privacy Code under the 2024 reform track. Monitor; no need for a net-new Consentmo feature from this consultation alone.

Small business exemption

Australia still has a small business exemption (generally annual turnover A$3 million or less, with exceptions).

Trading personal information is already a sensitive exception area. The Exposure Draft’s use of “trade” (including for direct marketing) may interact with who can rely on the exemption. That needs Australian counsel before it becomes merchant guidance copy. It is larger than “only stores over A$3m need a better banner.”

What Consentmo currently covers for Australia & New Zealand

Australia is not a blank region in the app. Consentmo already treats Australia & New Zealand as a dedicated compliance region in Compliance Score, with a regional score, risk label, issue count, and a clear split between issues found and passing checks.

Check What it means / typical next step
Cookie banner is active Visitors in the region can see and interact with your consent banner.
Consent model matches region requirements The opt-in / opt-out model assigned to AU & NZ fits how Consentmo maps this region today.
Cookie state before consent is compliant Non-allowed cookies are handled correctly before the visitor chooses.
Explicit consent where required Where the regional model needs a clear yes, the setup supports it.
Smart geotargeting is enabled The right regional experience can show for visitors from Australia and New Zealand.
Google Consent Mode v2 configured Consent signals can flow to Google tags in line with your Consent Mode setup.
Cookies are well-categorized Scanned cookies sit in sensible categories for banner and preference UI.
Privacy request pages missing Add privacy request / DSAR-style pages, for example through Privacy Center tooling.
Cookie widget disabled Enable the cookie widget so shoppers can reopen preferences after their first choice.
Multilingual banner disabled Turn on multilingual banner support if you serve AU/NZ traffic in more than one language.

These checks are about your live store configuration today. They do not claim the Exposure Draft is already law. Scores and issue lists are store-specific. A high score with “Low risk” still leaves room for open items; fix those before you treat the region as done.

Consentmo Compliance Score for Australia & New Zealand

Conclusion

The 31 August 2026 Exposure Draft is a serious signal for advertising cookies, pixels, consent quality, and dark-pattern-free choice. It is also still a consultation draft. Australian law for ordinary storefront tracking has not flipped overnight.

Consentmo already supports Australia as a covered region. Merchants can keep strengthening transparency and preference UX now, while treating this Bill as a regulatory watch item through 18 September 2026 and beyond. When the final text lands, we will revisit Australia defaults with the same care we use for other regional updates.

Get your Shopify store compliant in Australia with Consentmo

Set up region-aware consent, cookie controls, privacy request tools, and tracking preferences for Australian visitors without building the workflow from scratch.

Install Consentmo on Shopify →

This article is general information for Shopify merchants, not legal advice. For obligations on your store, speak with qualified Australian privacy counsel.

Mariya Petrova
Growth & Product Marketing
With over 7 years of experience in advertising across agencies and e-commerce brands, Mariya has made marketing her core element. Today, she supports Consentmo users by guiding them through the realms of compliance, Shopify, and all things marketing.