Analytics
The privacy obligations attached to analytics
When website analytics collects personal information under Australia's Privacy Act, and what that means for a small business assuming analytics is exempt.
Analytics data is not automatically outside the Privacy Act just because it looks like numbers and charts rather than a name and address — whether it counts as personal information depends on whether it is reasonably capable of identifying an individual, and some analytics data genuinely can be.
What makes analytics data “personal information”
The Privacy Act 1988 (Cth) defines personal information broadly, covering information about an identified individual, or an individual who is reasonably identifiable. Standard, aggregated analytics — total visits, most-viewed pages, device-type breakdowns — generally do not identify an individual and sit comfortably outside this definition. Where analytics data starts to include IP addresses, precise location data, or is combined with other information (a form submission linked to a specific session, for instance) that together could identify a person, the picture changes, and the Office of the Australian Information Commissioner has taken the view that an IP address can be personal information in circumstances where it is capable of identifying someone.
Where the small-business privacy exemption does and does not help
The Privacy Act’s Australian Privacy Principles do not apply to small business operators below a turnover threshold, with several specific exceptions that remove the exemption regardless of turnover — including businesses that trade in personal information for benefit, or that provide a health service, among others named in the Act. A business genuinely eligible for the exemption and not caught by one of those exceptions is not required to comply with the Australian Privacy Principles for its ordinary analytics data. A business that assumes it qualifies without checking against the actual exceptions, however, risks relying on an exemption that does not actually apply to its situation.
This exemption has been the subject of ongoing reform discussion, and its scope should be checked against current guidance rather than assumed to be permanent or unconditional — see the note on this in website accessibility in Australia, which covers the same reform context in more detail for a related obligation.
Google itself is a separate party collecting personal information, not just a tool
Using GA4 means data about a site’s visitors is also processed by Google, under Google’s own privacy policy and data processing terms, which is a separate relationship from the one between the business and its own website visitors. A business’s own privacy policy should reflect this honestly — naming the analytics tool used and linking to the provider’s own privacy documentation, rather than describing analytics data as if it never leaves the business’s own systems, because for a cloud-based analytics platform it genuinely does.
Minimising what is collected is good practice regardless of the exemption
Independent of whether the small-business exemption technically applies, choosing analytics configuration options that reduce identifiability where the tool allows it — limiting data retention to the shortest period that still serves the business’s genuine reporting needs, and avoiding combining analytics identifiers with directly identifying information such as a name or email address collected elsewhere — is a sound default practice. It reduces the amount of personal information at stake regardless of which side of the exemption threshold the business sits on, and it is generally simpler to implement correctly from the outset than to retrofit onto years of accumulated data later.
What actually belongs in a privacy policy about analytics
A privacy policy addressing analytics honestly should name the specific tool in use, describe in plain language what kind of data it collects (page views, general location at a country or region level, device type), state how long that data is retained, and link to the analytics provider’s own privacy policy for the detail of how the provider itself handles the data once collected. A generic, unspecific statement that a site “may use cookies or similar technologies” without naming what is actually deployed on the site falls short of this standard and is common enough to be worth checking an existing privacy policy against directly.
What this means practically for a small business collecting analytics data
Even where the small-business exemption technically applies, adopting privacy-conscious analytics practice by default is a reasonable position regardless of the formal exemption question — it avoids depending on an exemption that may not survive future reform, and it is generally simpler than assessing the exemption’s exact boundaries for every specific configuration. Practically, this means: minimising IP address retention where the analytics platform allows it, avoiding combining analytics data with personally identifying form submissions unless there is a clear, disclosed purpose for doing so, and being transparent in a privacy policy about what is collected and why, regardless of whether the exemption technically applies.
A short, checkable privacy policy list
| Question | Why it matters |
|---|---|
| Does the business genuinely fall under the turnover threshold, and does it avoid the named exceptions? | Determines whether the general small-business exemption actually applies |
| Is IP address data being retained longer than necessary, or combined with identifying information? | The point where aggregate analytics can become personal information |
| Does the privacy policy disclose what analytics data is collected and why? | Good practice regardless of the exemption’s technical application |
What to do next
Check the actual exceptions to the small-business exemption against the specific business — a business assuming it qualifies without checking is the most common gap here — using the OAIC’s own current guidance rather than general commentary. For how this plays out differently across regulated industries with additional privacy-sensitive obligations, the industries section covers where those obligations get tighter still.
Evidence for this page
This page exists because the demand below was measured, not assumed. The figures are search-market data about the topic — they are not prices.
- Entity this page targets
- privacy obligations website analytics australia
- Measured Google volume
- no data
- Keyword difficulty
- no data
- Advertiser cost per click
- no data
- AI assistant volume
- no data
- Advertiser competition
- no data
- Measured on
- 31 July 2026
- Search results inspected for intent
- No
2 other phrasings resolve to this same page
is google analytics data personal information · privacy act analytics small business
Not present in the measured keyword set. A genuine null.
Source: research/national-volume-au.json · DataForSEO Labs, location_code 2036 (Australia), language en · pulled 31 July 2026.
Provenance
Written by Australian Website Design. Published 2026-08-03, last updated 2026-08-03.
Sources
- Privacy Act 1988 (Cth) — Australian Privacy Principles (accessed 2026-08-03)
- OAIC — Small business and the Privacy Act (accessed 2026-08-03)