1. Who the GDPR catches
  2. The targeting test: when a website is aimed at the EU
  3. Establish a lawful basis for each collection
  4. Give clear privacy information
  5. Honour the rights of EU individuals
  6. Secure the data and report breaches
  7. The price of non-compliance
  8. How the GDPR sits alongside Australian privacy law
  9. A compliance checklist for your website
  10. Where a privacy lawyer helps
  11. The trigger most Australian sites miss

If your website collects personal data from people in the European Union, the EU's General Data Protection Regulation (the GDPR) can apply to your business even though you are based in Australia. The GDPR has applied since 25 May 2018, and it reaches much further than most Australian business owners expect. Unlike the Australian Privacy Principles, the GDPR has no size threshold: the turnover of your business is irrelevant to whether the regulation catches you.

What matters is where the people are whose data you process, and what you are doing with it. If the GDPR does apply, the consequences of getting it wrong are significant. Fines can reach €20 million or 4% of your total worldwide annual turnover, whichever is higher. This article sets out who the GDPR catches, the test regulators use to decide whether your website is aimed at the EU, the duties you must meet if you are caught, and where a privacy lawyer can help.

Who the GDPR catches

Article 3 of the GDPR sets out the territorial scope of the regulation. A business falls within it in three situations:

  • Established in the EU: The GDPR applies to processing carried out in the context of the activities of any establishment you have in the EU, such as an office, branch or subsidiary. This applies regardless of whether the processing itself happens in the EU or elsewhere.
  • Offering goods or services to people in the EU: The GDPR applies if you offer goods or services to individuals in the EU, irrespective of whether a payment is required. A free service or a free tier of an app still counts.
  • Monitoring behaviour in the EU: The GDPR applies if you monitor the behaviour of individuals based in the EU, as far as their behaviour takes place within the EU. This limb catches a great deal of ordinary website activity, which we return to below.

There is no minimum size for any of these limbs. A two-person Australian business with a website that takes orders from EU customers is caught in exactly the same way as a multinational. This is a sharp contrast with Australian privacy law, where businesses with an annual turnover of $3 million or less are generally exempt from the Australian Privacy Principles under s 6D of the Privacy Act 1988 (Cth).

You can run a quick self-assessment. If any of the following is true, the GDPR is likely to apply to your business:

  • Your business has an establishment of any kind in the EU.
  • Your website offers goods or services to people in the EU, whether paid or free.
  • Your website tracks, profiles or otherwise monitors the behaviour of visitors located in the EU.

If none of these apply, the GDPR is unlikely to regulate your website. But the second and third limbs are broader than they look, so it is worth working through them properly.

The targeting test: when a website is aimed at the EU

If you have no establishment in the EU, the key question for the goods and services limb is whether your website is aimed at people in the EU. Mere accessibility is not enough. Recital 23 of the GDPR makes clear that the fact that an EU resident can load your website, email you, or find your contact details does not by itself show an intention to deal with EU customers. The regulation targets businesses that envisage offering goods or services to people in the EU.

Regulators look for objective indicators of that intention. The factors Recital 23 points to include:

  • Using a language or currency commonly used in one or more EU member states, together with the possibility of ordering goods or services in that language.
  • Mentioning customers or users who are in the EU.
  • Offering delivery to EU countries.
  • Advertising aimed at EU markets, including geo-targeted ads.

A website in English only, priced in Australian dollars, offering delivery only within Australia and New Zealand, is unlikely to be treated as targeting the EU. Change any one of those features, however, and the analysis shifts. If you add a euro price list, or a checkout that accepts EU addresses, or testimonials from German customers, you are signalling an intention to deal with the EU, and the GDPR will follow.

The monitoring limb does not depend on targeting at all. Tracking what EU visitors do on your website can amount to monitoring their behaviour within the EU, even if you sell nothing to them. This is not a theoretical risk. In 2022 the Italian data protection authority fined Clearview AI, a United States company with no establishment in Italy, €20 million for scraping and processing the biometric data of people in Italy without a lawful basis. The European Data Protection Board recorded that Article 3(2) applied: the company was caught by the GDPR despite having no presence in the EU.

Establish a lawful basis for each collection

If the GDPR applies to you, the central duty is to identify a lawful basis for every collection and use of personal data, before you start collecting. Article 6 of the GDPR sets out six possible bases:

  • Consent: The individual has given clear consent for a specific purpose.
  • Contract: Processing is necessary to perform a contract with the individual, or to take steps at their request before entering into a contract.
  • Legal obligation: Processing is necessary to comply with a legal obligation.
  • Vital interests: Processing is necessary to protect someone's vital interests.
  • Public interest: Processing is necessary for a task in the public interest or in the exercise of official authority.
  • Legitimate interests: Processing is necessary for your legitimate interests, unless those interests are overridden by the individual's rights and freedoms.

Each separate collection needs its own basis. Collecting an email address for a newsletter and collecting location data for analytics are different processing activities and may need different bases.

Consent is the basis most websites rely on, and it is the most tightly regulated. Under Article 7 of the GDPR, consent must be freely given, specific, informed and unambiguous, and you must be able to demonstrate that you obtained it. The practical consequences for your website are significant:

  • A pre-ticked checkbox is not valid consent. The individual must take a positive step.
  • You must tell people what they are consenting to before they consent, in clear and plain language.
  • Withdrawing consent must be as easy as giving it. A buried opt-out that takes six clicks to find will not pass.
  • Consent must not be bundled into a contract term. Making access to a service conditional on consent to unrelated processing is not freely given consent.

For a website, the standard pattern is a consent statement next to a tick box, with a link to the privacy policy. The statement should say what you will do with the data and name the lawful basis you are relying on.

Give clear privacy information

The GDPR's transparency obligations require you to tell individuals, at the point of collection, who you are, what personal data you collect, why you collect it, on what lawful basis, how long you keep it and what rights they have. The information must be in clear and plain language, not buried in dense legal text. Articles 12 to 14 of the GDPR set out these requirements.

For most businesses this means a substantial rewrite of the privacy policy, because an Australian Privacy Principles privacy policy is not automatically GDPR-compliant. The GDPR asks for specific items the APPs do not, such as the lawful basis for each processing activity, details of any transfers outside the EU, and contact details for your Data Protection Officer where one is required. You also need privacy information at the moment of collection, not only in a policy that sits behind a link.

Honour the rights of EU individuals

The GDPR gives individuals a set of enforceable rights over their personal data. These are set out in Articles 15 to 22 of the GDPR and include the right to:

  • Access a copy of the personal data you hold about them.
  • Have inaccurate data corrected.
  • Have data erased in certain circumstances, sometimes called the right to be forgotten.
  • Restrict how their data is processed.
  • Receive their data in a portable format and have it transferred to another provider.
  • Object to processing, including processing for direct marketing.

You need processes to recognise and respond to these requests, and to do so promptly. A request arriving by email from a customer in Germany is not something you can ignore because the business is in Australia. You also need to be able to find the data quickly, which is one reason GDPR compliance is as much about your systems as your documents.

Secure the data and report breaches

The GDPR requires you to keep personal data secure using appropriate technical and organisational measures, and to be able to demonstrate that you have done so. For a website, that generally means encryption in transit, access controls on any database, and keeping software patched.

If a data breach does occur, there is a hard deadline. Under Article 33 of the GDPR, a controller must notify the relevant supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals. The notification must describe the nature of the breach, the likely consequences, and the measures taken. You must also document every breach, even ones that do not need to be reported. Where the breach is likely to result in a high risk to individuals, you may also need to tell the affected individuals directly. If your core activities involve monitoring people on a large scale or processing sensitive categories of data, you may also be required to appoint a Data Protection Officer.

The price of non-compliance

The GDPR's enforcement regime is designed to hurt. Article 83 of the GDPR provides two tiers of administrative fines:

  • Up to €20 million or 4% of total worldwide annual turnover, whichever is higher: for breaches of the core principles, including the conditions for consent, the rights of individuals, and the rules on transferring data outside the EU.
  • Up to €10 million or 2% of total worldwide annual turnover, whichever is higher: for breaches of the operational obligations, including security of processing, breach notification, record-keeping and data protection officer requirements.

These are maximums, and regulators can also order you to stop processing, to delete data, or to change your practices. Fines are assessed against factors such as the nature and duration of the breach, the number of people affected, and whether the breach was intentional or negligent.

The United Kingdom has its own version of the regulation. The UK GDPR, enforced by the Information Commissioner's Office, carries a higher maximum fine of £17.5 million or 4% of total worldwide annual turnover. If your website also attracts customers or visitors in the UK, you are dealing with two separate regimes at once.

There is also a structural point Australian businesses should understand. Australia is not among the countries the European Commission has recognised as providing adequate data protection. That matters when you receive EU personal data from an EU-based business, for example as a processor or service provider: because there is no adequacy decision for Australia, those transfers generally need another safeguard, such as standard contractual clauses. If you are processing EU data on behalf of an EU client, expect the contract to address this.

How the GDPR sits alongside Australian privacy law

Australian privacy law and the GDPR overlap but are not the same. The Privacy Act 1988 (Cth) and its 13 Australian Privacy Principles apply to most Australian businesses with an annual turnover above $3 million, together with some others regardless of size. The APPs cover similar ground to the GDPR, including collection, use and disclosure, security and access rights. But there are real differences:

  • No small business exemption: The GDPR has no turnover threshold at all. A business exempt from the APPs can still be fully caught by the GDPR.
  • Lawful basis: The GDPR requires an explicit lawful basis for every processing activity. The APPs work differently, through collection and use limitations.
  • Penalties: Australian penalties have increased sharply. Since the Privacy and Other Legislation Amendment Act 2024 (Cth), a serious or repeated interference with privacy under s 13G of the Privacy Act 1988 (Cth) can attract a maximum penalty for a body corporate of the greater of $50 million, three times the value of the benefit obtained, or 30% of adjusted turnover. The maximums are now in the same league as the GDPR, even if the enforcement machinery differs.

The practical effect is that if you are building GDPR compliance for EU-facing operations, you will usually end up ahead of the Australian requirements as well. The reverse is not true: an APP-compliant privacy policy is a starting point, not an endpoint, for GDPR work.

A compliance checklist for your website

If you have decided the GDPR applies to you, work through this list:

  • Audit what you collect: Document every place your website collects personal data, including enquiry forms, checkouts, newsletters, analytics, cookies, advertising pixels and customer support.
  • Map a lawful basis for each collection: Write down which of the six Article 6 bases applies to each processing activity, and keep that record.
  • Redraft your privacy policy: Make it GDPR-specific, covering lawful bases, transfers, retention and rights, in plain language.
  • Fix your consent mechanics: Replace pre-ticked boxes with positive opt-ins, add a consent statement with a link to the policy, and make withdrawal as easy as giving consent.
  • Check your tracking: Review analytics and advertising scripts. If they process the data of EU visitors, they engage the monitoring limb and need their own lawful basis and notice.
  • Build rights processes: Set up a mailbox and workflow for access, correction, erasure, portability and objection requests.
  • Prepare a breach response plan: Identify who is responsible for notifying the supervisory authority within 72 hours, and keep a breach register.
  • Review your EU client contracts: If you receive EU personal data from EU businesses, confirm whether standard contractual clauses or another safeguard are in place.

Where a privacy lawyer helps

Much of GDPR compliance is legal judgement, not just form-filling. A privacy lawyer can assess whether your website actually triggers the GDPR, which is the question most businesses get wrong in both directions: some assume they are caught because their site is globally accessible, and others assume they are exempt because they have no EU presence, when their tracking tools say otherwise.

A practitioner can also map your processing activities to lawful bases, redraft your privacy policy and consent flows for the GDPR, review your cookie and analytics arrangements, negotiate the data protection clauses in your contracts with EU clients and processors, and take charge of a breach notification if the worst happens. Given the size of the potential fines, the cost of a review is usually a fraction of the exposure it addresses.

The trigger most Australian sites miss

Most Australian businesses know they are not established in the EU, and most know they do not sell to EU customers. What they do not realise is that the monitoring limb can catch them anyway. Analytics, advertising pixels, heat-mapping tools and retargeting scripts all observe the behaviour of visitors, and if any of those visitors are in the EU, the GDPR treats that as monitoring their behaviour within the EU. That means the obligation can arise even for a business that has never made a euro of sales.

The first thing to do this week is to find out what your website actually collects from its visitors. Open your analytics and advertising accounts, list every script that runs on your site, and check whether any of them track EU visitors. If they do, you have a lawful basis question to answer and a consent or notice problem to fix. That single audit will tell you, more accurately than any assumption, whether the GDPR has you in its sights.