Key Takeaways
- On 31 August 2026, the Australian Government opened consultation on the Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026. Feedback closes 18 September 2026.
- This is not law. The Attorney-General’s Department says the Bill remains subject to further government consideration.
- Ordinary direct marketing may still sit closer to opt-out in places. The sharper shift is around disclosure / trade for advertising and marketing purposes.
- Consentmo already covers Australia & New Zealand with regional banners, geotargeting, Compliance Score, and related tools. Do not change Australian defaults today solely because of this draft.
Why this consultation matters
Australia is already a live market for many Shopify stores. Consentmo includes Australia (and New Zealand) in regional compliance coverage: geotargeted banners, consent models by region, Compliance Score checks, privacy tooling, and cookie categorisation.
The new consultation is still a policy development step, not a go-live date for new rules. The story worth watching is narrower and more practical than “Australia becomes GDPR overnight.”
The draft points at a possible future where disclosing personal information through certain advertising cookies and pixels needs clearer opt-in consent, even if not every marketing activity flips to EU-style consent.
What opened on 31 August 2026?
The government released:
- Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026
- A supporting Consultation Paper
- A public call for submissions
From the consultation overview:
- The reforms aim to modernise privacy law for the digital age.
- Feedback will inform what government considers when finalising reforms.
- “The Bill remains subject to further consideration by government.”
Current Australian position (what still applies today)
Until Parliament passes something new (and it commences), the existing Privacy Act framework and OAIC guidance remain the practical baseline for many merchants.
APP 7 and direct marketing
Under APP 7, organisations can use or disclose personal information for direct marketing in defined circumstances. Prior consent is not always required. Where information was collected from the individual and they would reasonably expect the marketing use, a simple opt-out can be enough, subject to the rest of APP 7.
Tracking pixels today
OAIC guidance on tracking pixels explains that third-party pixels used for targeted advertising still need to comply with the APPs, including APP 7. It does not set a blanket GDPR-style “block all marketing cookies until consent” rule for Australia.
OAIC guidance: Tracking pixels and privacy obligations.
That is why Consentmo can still treat Australia as a largely opt-out-oriented region for many ordinary advertising setups, depending on the merchant’s actual processing, disclosures, and integrations. Merchant-specific legal advice still matters.
The draft change Consentmo is watching closest: consent to “trade”
What “trade” points at
The Exposure Draft introduces a stronger line around obtaining consent before “trading” personal information. In the consultation framing, “trade” is cast broadly: disclosure for money or other consideration, or for direct-marketing purposes.
The consultation material then calls out disclosures that support direct marketing, including language around cookies or pixels in programmatic advertising processes.
That wording is unusually direct for Australian privacy reform, and it is the core CMP angle.
Proposed practical split (as drafted for consultation)
ActivityDirection in the draft / paperOrdinary direct marketingConsent not inherently required in every case; simple opt-out still centralDisclosure / trading of personal information for direct marketingConsent required in covered casesProgrammatic advertising involving cookie/pixel disclosureCalled out as potentially falling under tradeSensitive informationConsent generally expectedNecessary service processingPossible exceptionsProcessor acting only on controller instructionsPossible carve-out from “trade”
So Australia is not simply proposed as “everything non-essential needs consent.” Advertising pixels and cookie-based disclosures into the ad ecosystem could still move much closer to opt-in.
Current law vs proposed direction
What this could mean for cookie banners and ad pixels
If enacted substantially as discussed in the consultation materials, a defensible before / after consent picture for many storefronts could look like:
Before consent
- Essential cookies: generally allowed
- Analytics: depends on how data is handled and whether it is disclosed
- Advertising / marketing pixels that disclose personal information into ad-tech: potentially blocked pending consent
- Sensitive-data tracking: blocked without valid consent
After valid consent
- Marketing and ad-tech disclosure becomes easier to justify, if the consent meets the new standard
Consentmo already surfaces Australia & New Zealand as a covered region in Compliance Score, with checks for banner state, regional consent model, geotargeting, Consent Mode, and cookie categorisation.
Consent quality would look more CMP-like
The draft discussion of valid consent points at requirements such as:
- voluntary
- informed
- current
- specific
- unambiguous
Bundled consent, interfaces that make refusal unreasonably hard, and pre-ticked optional settings are poor fits for that standard.
That aligns with product patterns merchants already use in Consentmo:
- separate cookie categories instead of one bundled “yes to everything”
- Accept / Reject / Preferences
- optional categories not preselected
- easy preference changes and withdrawal
- consent records
- refreshed consent when processing changes in a material way
The materials also stress that consent does not need a fixed automatic expiry date, but it must stay current. A material change in handling can make old consent stale. That is useful context for any future re-consent or expiry settings.
Broader “personal information,” direct marketing, notices, and UX
Identifiers and behavioural data
Moving from information about a person toward information that relates to a person, plus stronger recognition of singling-out, weakens arguments like “it’s only a pseudonymous cookie ID, so it isn’t personal information.”
For cookie scanning and category guidance, advertising IDs, persistent device IDs, and behavioural profiles should be treated as high-risk candidates for the personal-information framework.
Direct marketing definition
Draft framing of direct marketing includes advertising directed at an individual based on personal information, including audience, segment, or cohort targeting. Examples discussed in the materials include email, SMS, telemarketing, targeted social ads, and online behavioural advertising based on browsing history.
Even where consent is not required, a simple, clear opt-out remains central. Preference centres and honest banner UX still help.
Fair and reasonable processing + dark patterns
Collection, use, and disclosure would need to be fair and reasonable. Considerations include reasonable expectations, transparency, minimisation, genuine choice, proportionality, and children’s best interests.
Choice may fail where people face take-it-or-leave-it terms, suffer detriment for refusing, or are steered by dark patterns.
Banner anti-patterns to keep avoiding:
- hidden Reject
- misleading visual hierarchy
- preselected optional consent
- painful withdrawal
- confusing preference flows
Collection notices
Notices would focus on:
- the fact and circumstances of collection
- the purposes of use or disclosure
Burying a practice only in a long privacy policy does not automatically make it transparent or reasonably expected. Layered disclosure fits better:
Cookie banner → contextual explanation → preference centre → privacy / cookie policy
That is the same stack Consentmo supports with Smart Cookie Policy, Smart Privacy Center, scanner-driven descriptions, and category explanations. See also What Is a Cookie Policy?
Precise geolocation and children
- Precise geolocation tracking over time within a 500 metre radius is discussed as sensitive information (generally consent-based). More relevant for apps, location SDKs, and proximity marketing than a basic storefront, but worth a future guidance entry.
- Children’s best interests as a primary consideration sits alongside work on a Children’s Online Privacy Code under the 2024 reform track. Monitor; no need for a net-new Consentmo feature from this consultation alone.
Small business exemption
Australia still has a small business exemption (generally annual turnover A$3 million or less, with exceptions).
Trading personal information is already a sensitive exception area. The Exposure Draft’s use of “trade” (including for direct marketing) may interact with who can rely on the exemption. That needs Australian counsel before it becomes merchant guidance copy. It is larger than “only stores over A$3m need a better banner.”
What Consentmo currently covers for Australia & New Zealand
Australia is not a blank region in the app. Consentmo already treats Australia & New Zealand as a dedicated compliance region in Compliance Score, with a regional score, risk label, issue count, and a clear split between issues found and passing checks.
These checks are about your live store configuration today. They do not claim the Exposure Draft is already law. Scores and issue lists are store-specific. A high score with “Low risk” still leaves room for open items; fix those before you treat the region as done.

Conclusion
The 31 August 2026 Exposure Draft is a serious signal for advertising cookies, pixels, consent quality, and dark-pattern-free choice. It is also still a consultation draft. Australian law for ordinary storefront tracking has not flipped overnight.
Consentmo already supports Australia as a covered region. Merchants can keep strengthening transparency and preference UX now, while treating this Bill as a regulatory watch item through 18 September 2026 and beyond. When the final text lands, we will revisit Australia defaults with the same care we use for other regional updates.
This article is general information for Shopify merchants, not legal advice. For obligations on your store, speak with qualified Australian privacy counsel.



