Does Australia’s Children’s Online Privacy Code Apply to My Business?
You have no office in Australia. No employees there. No Australian entity.
So Australian privacy law is not your problem, right?
Not necessarily.
Australia’s Privacy Act can apply to overseas companies with an “Australian link.” That means an Australian user base can bring an overseas business within the law even when the company has no physical presence in the country.
The issue is becoming more important as Australia moves toward stronger protections for children’s online privacy.
You May Be Covered Even Without an Australian Office
Australia’s Privacy Act has extraterritorial reach through Section 5B.
An overseas company can fall within the law when it carries on business with Australian users. Your incorporation location does not automatically remove you from Australia’s privacy requirements.
That means a startup built and operated entirely in the United States could still need to assess its Australian privacy obligations if Australians can use its service.
The practical question is therefore not simply: “Do we have an Australian office?”
It is: “Do we have an Australian link under the Privacy Act?”
Your Service Does Not Have to Be Designed for Children
Another common assumption is that children’s privacy rules apply only to social media platforms or apps specifically marketed to children.
The Code uses a broader test.
It applies on a per-service basis where a service is “likely to be accessed by children.”
That can bring very different types of products into the discussion.
Examples are: gaming platforms without age gates, family photo-sharing apps, baby-monitor and childcare apps, and school management or education software.
So your intended audience is not the only consideration.
If children can reasonably access the service, you need to assess whether the Code applies.
The December 10, 2026 Deadline Matters
The OAIC released the exposure draft of the Children’s Online Privacy Code on March 31, 2026.
Mandatory registration under the Code is scheduled for December 10, 2026.
That gives businesses a limited period to understand whether their services are covered and identify gaps in their data practices.
Waiting until the final version is registered may leave little time to make changes.
For startups, the first step is not necessarily rewriting every privacy policy.
It is understanding what data your product actually handles.
Start With Your Data
Before determining whether you can comply with the Code, you need visibility into your own systems.
You should know:
- Who can access data belonging to children or families using your service.
- Whether your product collects geolocation data.
- How precise that location information is.
- Where the data is stored.
- Which employees, contractors, vendors, or systems can access it.
These questions sound straightforward.
Many startups cannot answer all of them without first reviewing their systems, vendors, data flows, and internal access controls.
That makes data mapping an important first step.
Common Founder Mistakes
- Assuming no Australian entity means no obligation: Founders may believe an Australian privacy requirement cannot apply because the company has no Australian office, employees, or subsidiary. But Section 5B gives Australia’s Privacy Act extraterritorial reach for businesses with an Australian link. Your physical location does not settle the question.
- Assuming “not social media” means exempt: Founders may associate children’s online privacy rules with major social networks and overlook their own products. The Code uses a per-service test based on whether the service is likely to be accessed by children. That can bring gaming, family, childcare, and education products into the analysis.
- Waiting for the Code to be finalized: Treating the exposure draft as a reason to wait can create a compressed compliance timeline. The draft was released on March 31, 2026, with mandatory registration scheduled for December 10. Companies that have not started reviewing their data practices may have little time to address problems once the Code is registered.
- Failing to map child and family data: A company cannot properly assess its obligations if it does not know what information it collects, where that information is stored, or who can access it. Geolocation data can require particular attention because the precision of the location information may matter. Without a clear data map, privacy compliance can quickly become guesswork.
10-Minute Australia Privacy Self-Check
Before assuming the Code does not apply to your business, ask:
- Do we have users in Australia even though we have no local office?
- Could children reasonably access our service?
- What age groups can use the product?
- What geolocation information do we collect and how precise is it?
- Where is child or family-related data stored?
- Who can access that information?
- Have we assessed the Section 5B Australian-link test?
- Do we have a plan for the December 10, 2026 registration deadline?
If you cannot answer these questions confidently, you may not yet know whether your business falls within the Code’s reach.
Bottom Line
Being located outside Australia does not automatically keep your business outside Australian privacy law.
The Australian-link test can bring overseas companies within the Privacy Act, while the Children’s Online Privacy Code uses a broad per-service test based on whether a service is likely to be accessed by children.
With mandatory registration scheduled for December 10, 2026, startups should not wait until the deadline is close to determine whether they are affected.
Start by mapping your Australian users and understanding exactly what your product does with child and family data.
Ready to Map Your Data Before the Deadline?
Download our free Data Mapping Worksheet to identify where personal information is collected, stored, and transferred across your business.
Get the free worksheet: Data Mapping Worksheet