Personalisation used to be simple. You collected data, you used it, and customers rarely asked questions. That approach does not work anymore. Australian consumers have grown sharply more cautious about data, regulators have sharpened the rules, and AI has raised the stakes on both sides. This guide walks through what is actually happening with cookies, consent and customer trust in 2026, and how you can keep personalising your marketing without putting your business at risk.
The State of Third-Party Cookies in 2026 (It’s Not What You Think)
Most business owners still assume third-party cookies are on their way out. That is not quite what happened, and the real story matters for how you plan your marketing.
Why Google Abandoned Its Cookie Deprecation Plan, and What Changed Instead
Google spent years promising to phase out third-party cookies in Chrome. In July 2024, it dropped that plan entirely. Instead of blocking cookies by default, Chrome now gives users a choice over whether to allow them, shifting control to the individual rather than the browser.
Safari and Firefox Already Block Third-Party Cookies by Default
While Chrome kept cookies alive, Apple’s Safari and Mozilla’s Firefox blocked third-party cookies by default years ago. A meaningful share of Australian web traffic has already been cookieless for some time, whether marketers noticed or not. This has quietly pushed good SEO practice further up the priority list, since organic visibility does not depend on tracking that a growing number of browsers already block.
Why “Post-Cookie” Is a Trust Shift, Not a Technology Shift
The technology behind cookies has not disappeared, but the assumption that you can quietly track anyone has. The real change is that consent now decides who gets tracked, which means your personalisation strategy depends on trust, not just tools.
How Australians Actually Feel About Data and Personalisation
Before you build any personalisation strategy, it helps to know how your customers actually think about their data. The numbers are worth sitting with.
Why Most Australians Value Privacy Over a Personalised Experience
A Honeycomb Strategy survey found that 77 per cent of Australians value their privacy over a personalised experience, up five percentage points on the previous year. Convenience does not automatically win against caution, especially once a customer feels exposed.
Trust in AI Companies Is Low, and Getting Lower
The OAIC’s 2026 Australian Community Attitudes to Privacy Survey found only 4 per cent of Australians rate AI companies as very trustworthy with their data. If your marketing leans on AI-driven personalisation, you are working against a trust deficit before your first campaign even launches.
Where Australians Do See Value in Personalisation (and Where They Don’t)
Personalisation is not rejected outright. Research into Australian online shopping habits shows real appetite for personalised discounts and tailored recommendations, and the same openness shows up in video and social content, an area we unpack in our look at what’s actually driving video and social commerce results in Australia. The resistance grows sharply once personalisation feels intrusive, particularly around biometric tracking, which we cover shortly.
Australia’s Privacy Act Reforms: What SMBs Need to Know Right Now
Privacy law in Australia is changing quickly, and several deadlines land in 2026. Here is what actually applies to your business.
The Privacy and Other Legislation Amendment Act 2024, Explained Simply
This Act received Royal Assent on 10 December 2024 and represents the biggest overhaul of Australian privacy law in decades. It introduced a new statutory tort for serious invasions of privacy, which took effect on 10 June 2025, giving individuals a direct right to sue over serious breaches.
The $3 Million Small Business Exemption Is Narrowing, Not Disappearing
The exemption for businesses turning over less than $3 million still exists, but it is being worn down from multiple directions. From 1 July 2026, changes to anti-money laundering law bring more than 100,000 small businesses in sectors like real estate, legal and accounting under the Privacy Act, regardless of turnover.
New Automated Decision-Making Disclosure Rules Coming December 2026
From 10 December 2026, businesses using software to make decisions that significantly affect individuals, including AI-powered screening tools or automated pricing, must disclose this in their privacy policy. If your marketing stack uses AI to score leads or personalise offers automatically, this rule will likely apply to you.
What Penalties Look Like If You Get This Wrong
Serious or repeated breaches can bring penalties of up to $50 million, three times the benefit gained, or 30 per cent of adjusted turnover, whichever is highest. The OAIC can also issue infringement notices of up to $66,000 for smaller failures, like not maintaining a compliant privacy policy.
Building a Consent-First Data Strategy for Your Business
Once you understand the legal and trust landscape, the next step is building a data strategy that works within it rather than against it.
First-Party Data: What It Is and Why It Matters More Than Ever
First-party data is information customers give you directly, through your website, email sign-ups or purchase history. It is more reliable than third-party data and it is entirely yours, which matters as external tracking becomes less consistent, an approach we help SMBs build through CRM and retention strategy.
Zero-Party Data: Getting Customers to Tell You What They Want
Zero-party data goes a step further. Instead of inferring preferences, you ask customers directly, through preference centres, quizzes or simple surveys. This method sidesteps a lot of privacy risk because customers hand over the information knowingly.
Getting the Opt-In Moment Right: Consent Flows That Don’t Kill Conversion
A clunky consent banner can tank your sign-up rate. Keep the language plain, explain the actual benefit of opting in, and avoid pre-ticked boxes. Clear, honest asks tend to convert better than vague or buried ones.
What “Fair and Reasonable” Data Use Actually Looks Like in Practice
Australia’s privacy reforms are moving toward a “fair and reasonable” test for data use, regardless of consent. In practice, this means asking whether an ordinary customer would be surprised or upset to learn how you used their data. It is a standard we hold to across our approach to compliant, trust-first marketing, and it is worth applying to every campaign you run, not just the ones with obvious risk.
Using AI for Personalisation Without Losing Customer Trust
AI can make personalisation faster and sharper, but it also raises the risk of getting things wrong at scale. Here is how to use it responsibly.
Where AI-Driven Personalisation Genuinely Improves Customer Experience
AI works well for tasks like recommending relevant products, tailoring email send times, or flagging when a customer is likely to churn. These uses are grounded in data the customer has already shared, which keeps them on safer ground, a shift we explore further in our piece on how AI is reshaping Australian marketing.
The Line Between Helpful Personalisation and “Creepy” Targeting
If a customer feels like your business knows more about them than they expected, you have crossed a line, even if every data point was technically collected with consent. Ask whether your personalisation still makes sense if the customer saw exactly how you built it.
Why Transparency About AI Use Is Becoming a Legal Requirement, Not Just Good Practice
With the December 2026 disclosure rules approaching, telling customers when AI drives a decision will soon be compulsory in many cases. Getting ahead of this now, rather than scrambling later, protects both your reputation and your compliance position.
Sensitive Data and AI: Why Biometric and Behavioural Tracking Need Extra Care
Trust in businesses using biometric data has fallen from 24 per cent in 2023 to just 13 per cent in 2026, according to the OAIC. Comfort with retail facial recognition for product recommendations sits at only 11 per cent. If your business handles any biometric or detailed behavioural tracking, treat it as a high sensitivity area, not a standard feature.
Practical Alternatives to Third-Party Cookie Targeting
You do not need third-party cookies to run effective campaigns. Several approaches work well without relying on cross-site tracking.
Contextual Advertising: Targeting Content Instead of People
Contextual advertising places your ads next to relevant content rather than following individual users around the web. It respects privacy by design and still gets your message in front of the right audience, particularly through well-planned programmatic advertising.
CRM-Led Personalisation Using Data You Already Own
Your CRM likely holds more useful data than you realise, including purchase history, enquiry patterns and engagement levels. Use it to personalise emails, offers and follow-ups without needing any external tracking at all.
Loyalty Programmes and Login Walls as First-Party Data Sources
Loyalty schemes and account sign-ins give customers a clear reason to share information directly with you. This works especially well for local businesses building suburb-level relationships, something we detail in our guide to hyper-local marketing for Australian SMEs.
What to Do If Your Current Ad Strategy Still Relies Heavily on Third-Party Data
If most of your targeting still depends on third-party signals, start shifting spend toward first-party and contextual approaches now. Waiting until tracking becomes unreliable puts you behind competitors who have already made the move.
Designing a Privacy-Respecting Customer Experience
Good CX and good privacy practice are not in conflict. Done well, they reinforce each other.
Ongoing Transparency: Communicating Data Use After the Opt-In, Without Overwhelming Customers
Consent is not a one-off tick box. Give customers simple, occasional reminders of what you collect and why, without turning every touchpoint into a legal disclaimer. This kind of honesty ties closely into the values-driven decisions Australians increasingly make, covered in our article on values-based branding and how Aussie consumers pick brands now.
Giving Customers Real Control Without Breaking Your Personalisation Strategy
Let customers adjust their preferences easily, including opting out of certain types of personalisation while keeping others. Businesses that make this simple tend to retain more trust, and more data, than those that make it difficult.
Turning Privacy Practices Into a Point of Difference, Not Just Compliance
Given how low trust in AI and data handling currently sits across Australia, being visibly careful with customer data can set you apart. Strong branding and authority building increasingly includes how honestly you handle personal information, not just your visual identity.
What This Means for Your Marketing and Ad Spend
Shifting away from third-party tracking changes how you plan and measure your budget, and it is worth understanding the trade-offs.
Why Contextual and First-Party Strategies Often Cost More to Set Up but Pay Off Longer Term
Building first-party data collection and contextual targeting takes more upfront work than relying on existing tracking. Over time, it gives you more stable, more compliant and more accurate targeting that does not depend on a browser’s cookie policy.
How to Measure ROI When You Can No Longer Track Everyone Everywhere
Attribution becomes harder without full tracking, so lean on aggregated performance data rather than individual-level tracking. Well-documented content marketing performance still gives you a solid read on what is genuinely resonating, even without cross-site data.
Budgeting for Compliance as Part of Your Marketing Plan, Not a Separate Cost
Treat privacy compliance as part of your marketing spend, not an afterthought. A properly built consent system and clean data practices cost far less than a breach, a fine, or the customer churn that follows either.
Common Mistakes Australian SMBs Make with Data and Personalisation
Even well-meaning businesses slip up here. These are the mistakes worth watching for.
Treating Privacy Policies as a Set-and-Forget Document
A privacy policy written years ago and never revisited is a red flag to regulators and a risk to your business. Review it whenever your tools, vendors or data practices change.
Over-Personalising Based on Assumptions Rather Than Explicit Consent
Guessing at a customer’s situation and personalising around it, rather than working from what they have actually told you, is one of the fastest ways to feel intrusive rather than helpful.
Ignoring Where Customer Data Actually Sits (CRM, Ad Platforms, AI Tools)
Many businesses do not fully know where their customer data lives once it is shared across CRM systems, ad platforms and AI tools. Map this out properly, because you cannot protect what you cannot locate.
What Happens When Trust Breaks: Lessons From Major Australian Data Breaches
Following the Optus and Medibank breaches, which affected 9.8 million and 9.7 million Australians respectively, more than a third of surveyed consumers switched providers, according to Honeycomb Strategy, even when their own data was not directly compromised. Trust, once broken, does not come back easily, which makes prevention worth far more than damage control.
Getting Started: A Practical Roadmap for Privacy-Safe Personalisation
Once you understand the risks and the opportunities, the final step is putting a simple plan into action.
A Simple Data and Consent Audit You Can Run This Month
List every place you collect customer data, check whether consent is properly recorded, and confirm your privacy policy reflects what you actually do. This single exercise surfaces most compliance gaps quickly.
Questions to Ask Your Marketing Agency About Data Handling and AI Use
Ask where your data is stored, whether any of it trains third-party AI models, and how AI-driven decisions in your campaigns are documented. If you are still comparing options, our roundup of leading content marketing agencies across Australia is a useful starting point for benchmarking how different providers handle client data.
A Checklist for Staying Ahead of the December 2026 Reforms
Confirm your privacy policy covers automated decision-making, review your consent flows, and check whether the AML/CTF changes bring your industry under the Privacy Act from July 2026. Getting this sorted early avoids a scramble later.
Privacy-safe personalisation is not about doing less with your data. It is about doing the right things with it, in a way customers can trust and regulators can verify. If you would like a clear, honest read on where your current data practices stand, start a conversation with our strategists and we will walk through it with you.
FAQs
Possibly. The $3 million turnover exemption still exists, but changes to anti-money laundering law bring over 100,000 small businesses in sectors like real estate and legal services under the Act from 1 July 2026, regardless of size.
Not entirely. Google abandoned its plan to phase them out in Chrome in 2024, moving instead to a user choice model. Safari and Firefox have blocked them by default for years, so a large share of traffic is already cookieless.
First-party data comes from customer behaviour on your own platforms, like purchases or browsing. Zero-party data is information customers tell you directly, such as preferences shared through a survey or account setting.
Yes, when it is used transparently and built on data customers knowingly shared. The distrust applies most strongly to opaque or intrusive uses, not to clearly explained, useful personalisation.
Any system using personal information to make decisions that significantly affect someone, including AI-powered screening, automated credit checks or algorithmic pricing, falls under the new disclosure requirements from December 2026.
Keep consent requests short, explain the specific benefit clearly, and avoid pre-ticked boxes. Honest, simple consent flows tend to perform better than vague or confusing ones.
Serious or repeated breaches can bring penalties of up to $50 million or 30 per cent of adjusted turnover, whichever is higher. Lower-level failures, like a non-compliant privacy policy, can bring infringement notices of up to $66,000.
Yes. Contextual advertising, CRM-led targeting using your own customer data, and first-party audience building all work well without relying on cross-site tracking.
Ask where data is stored, whether it feeds into any third-party AI training, and how they document AI-driven decisions in your campaigns. Clear, direct answers are a good sign you are working with the right partner.





