The 2026 Australian Compliance Checklist is the editorial list of privacy, consumer-law, AML and tax obligations an Aussie operator owes themselves a quiet hour with each year. It is not legal advice; it is the structure of obligations so you can scope what to handle in-house and what to escalate to your accountant or lawyer. Langa is an editorial site, not a law firm, so each item below is framed as "what you owe", "how to know if you owe it", and "when to professionalise it".
Who the checklist is for
The checklist fits an Australian operator running a content or SaaS business who is collecting any personal data, taking any payment for goods or services, or making any endorsement on a monetised surface. That is most Aussie operators — even the smallest creator business is on the hook for Privacy Act compliance, ACL accuracy on monetised claims, and BAS-ready bookkeeping the moment they cross the GST registration threshold ($A 75,000 in revenue). Below that threshold, the items still apply in spirit, but the registration triggers do not.
Three categories of obligation
- Mandatory — failure to comply creates a real regulatory risk. Privacy collection notices under the Privacy Act 1988, GST registration once you cross the threshold, and ACCC-compliant disclosure on every monetised page fall into this category.
- Strongly recommended — failure to comply is not unlawful but materially weakens your posture. Cookie and tracking consent flows, a written data retention policy, and a documented affiliate-disclosure practice sit here.
- Defer — useful only once you reach a scale where the marginal cost is worth absorbing. SOC 2 readiness, a dedicated DPO, and formal vendor-risk reviews fall into this bucket until you have enterprise-grade customers or a headcount crossing 25.
The mandatory items
A privacy collection notice on every form that captures an email address or any other personal data; a current privacy policy reachable from every page footer; GST registration (and BAS lodgement) once revenue crosses the threshold; an ACCC-compliant endorsement statement on every monetised page (above the fold, in plain English); accurate pricing displayed in AUD with the GST treatment called out where it differs; and a Cyber Incident Response Plan even at the one-page level — the Notifiable Data Breaches scheme requires it.
The strongly recommended items
A cookie consent banner that fires before any non-essential tracking; a written data retention and deletion policy that you can produce on request from the OAIC; basic terms of service covering refunds, chargebacks and dispute resolution; an affiliate disclosure practice that names the funding model (commission, sponsorship, free product) on every commercial post; and an annual review date with a single calendar entry — compliance drifts faster than you think.
Frequently asked questions
Is this legal advice?
No — Langa is an editorial site, not a law or accounting firm. The checklist is the structure of what Australian operators typically owe at this scale; the actual handling of your specific situation requires an accountant and, where privacy or ACL risk is in play, an Australian-licensed lawyer. If the items below are not yet in scope for your business, treat the list as a checklist for the year they do land in scope rather than something to action now.
How often do I need to re-check this?
At minimum once per year, against the OAIC and ACCC published guidance at the time of the review. Both update guidance more often than you would expect, and a privacy policy citing a five-year-old scheme will read as stale to the OAIC. Calendar the review for the same week each year — Friday before the BAS is due works for most operators.
This checklist is editorial guidance, not legal or tax advice. Confirm your specific obligations with an Australian accountant and, where applicable, a licensed Australian lawyer.
Verdict
Map your obligations into the three categories above, action the mandatory bucket first, calendar the strongly recommended bucket for the same week each year, and keep a clear record of when each item was last reviewed. Most Australian operators can hold this whole checklist within an honest afternoon a year — the cost of doing it is trivial relative to the cost of an OAIC investigation or an ACCC infringement notice.
Explore Langa
Read the editorial seat, then dive into the picks
Every link below opens an existing Langa page — the explainer frames the editorial position, the contact form opens a direct line to the team, and the FAQ answers the questions cold visitors raise most often.