← Back to Debrief
Industry Trends

Australia's Privacy Act Reforms Make Cookie IDs Personal Information

Filip Ivanković··1 min read
1 min read

What changed

The definition of personal information now explicitly includes IP addresses, device IDs and cookie identifiers
Consent must be voluntary, informed, current, specific and unambiguous
Pre-ticked boxes and dark patterns are restricted
Targeting children is prohibited except where it's in their best interests

What it means

Every Australian business running Google Analytics, Meta Pixel, LinkedIn Insight Tag or any tracking pixel is now collecting personal information under the expanded definition. If your cookie consent banner uses pre-ticked boxes or doesn't clearly explain what you're collecting, you're non-compliant. The "she'll be right" approach to AU privacy is over.

What to do

Audit your cookie consent implementation. Replace pre-ticked opt-ins with clear opt-in flows.
Update your privacy policy to explicitly cover device IDs and cookie identifiers.
If you're targeting users under 18 with ads, stop.
Check your CMP (OneTrust, Cookiebot, etc.) is configured for AU requirements, not just GDPR defaults.

Source: Privacy and Other Legislation Amendment Act 2024 via Didomi

ShareLinkedInX

Debrief

Get the next one

No spam. No fluff. Just the next article, straight to your inbox.

Filip Ivanković
Filip IvankovićFounder, New Rebellion

10+ years leading performance marketing across agencies and in-house teams in Australia. Writes about the gap between marketing activity and commercial outcomes, and what it takes to close it.

Keep reading

All articles →

If this resonated

Let's talk about your marketing

30 minutes with a senior strategist. No pitch deck, no obligation. Just an honest conversation about what you need.