Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- 1. Audit every tracker on the site
- 2. Categorise cookies properly
- 3. Use clear wording in the banner
- 4. Offer a real reject option
- 5. Block non-essential cookies until the user chooses
- 6. Match the banner to your privacy policy
- 7. Make preference changes easy
- 8. Keep records of consent settings
- 9. Review third party contracts and vendor settings
- 10. Train the people who change the site
- Common mistakes New Zealand businesses make
- What about mobile apps and logged-in platforms?
- Key Takeaways
If your website uses analytics, advertising pixels, chat tools or embedded videos, your cookie banner is not just a design choice. It is one of the first places your privacy settings, marketing practices and customer trust show up in public. New Zealand businesses often get this wrong in a few predictable ways: they load tracking cookies before visitors choose, they hide the reject option, or they use vague wording that does not explain what is actually happening on the site.
Those mistakes can create privacy risk, misleading marketing risk and a poor user experience. They also tend to happen right before launch, after money has already been spent on a website build. This guide explains what cookie banners that comply usually look like for New Zealand sites, when you need one, what to say, how to set up consent settings in practice, and where founders often get caught before they sign off on a website or ad campaign.
Overview
A compliant cookie banner for a New Zealand business should be clear, honest and matched to what the site actually does in the background. The legal issue is not only the banner itself, but whether your privacy disclosures, consent settings and marketing tools all line up.
- Identify every cookie and tracking technology used on your site, including tools added by developers and marketing teams.
- Separate essential cookies from analytics, advertising and personalisation tools.
- Do not set non-essential cookies before the user has made a real choice, where consent is the basis you are relying on.
- Offer a genuine reject option, not just an accept button and a buried settings page.
- Use plain English to explain what each category does and who may receive the data.
- Make sure your privacy policy matches your banner and consent preferences.
- Keep records of the choices users make and review the setup after website changes.
What Cookie Banners That Comply Means For New Zealand Businesses
For New Zealand businesses, cookie banners that comply usually mean giving people a fair and informed choice about non-essential tracking, then making sure your site respects that choice.
There is no single New Zealand statute that says every website must display a cookie banner in the same format. The real position is more practical than that. If your website collects personal information, uses tracking tools that identify or single out users, or shares data with third party platforms, your business needs to think carefully about transparency, consent, fairness and how your disclosures stack up under New Zealand privacy and marketing rules.
The Privacy Act 2020 matters because website tracking can involve personal information. A cookie does not stop being relevant just because it is technical. If it can identify a person directly or indirectly, or be linked with account details, device identifiers, browsing activity or behavioural profiles, privacy obligations can come into play.
The main questions are usually:
- What information are you collecting?
- Why are you collecting it?
- Who receives it?
- What legal basis or user choice are you relying on?
- Have you told users clearly enough before the tracking starts?
The Fair Trading Act also matters. If your banner says users can reject tracking, but the site keeps dropping marketing cookies anyway, that can create a misleading conduct problem. The same issue comes up if a banner says cookies are used only to improve user experience, while the site also sends data to advertising platforms for retargeting.
This is why founders should stop treating the banner as a pop-up added at the end of a build. It is a legal and operational settings issue.
What counts as a cookie banner?
A cookie banner is the notice or consent tool that appears when someone first visits your website and is asked about tracking preferences. It may include buttons such as Accept, Reject or Manage Preferences. It often sits alongside a cookie policy or privacy policy, but it is not the same thing.
The banner handles the immediate choice. Your privacy documents explain the broader details.
What are cookies and similar tracking tools?
Cookies are small text files stored on a user’s device, but the same legal concerns often apply to similar technologies as well. Your website may use:
- session cookies that keep a shopping cart working
- analytics cookies that measure traffic and user behaviour
- advertising or retargeting pixels
- social media plug-ins
- heatmapping and session replay tools
- chat widgets
- device fingerprinting or similar identifiers
If your site uses any of these tools, the label on your banner matters less than whether you are explaining them properly and controlling them properly.
Do all New Zealand websites need a cookie banner?
No, not every site will need the same banner setup. A basic brochure website that uses only essential functionality and no non-essential tracking may not need a full consent banner in the same way an ecommerce brand, SaaS platform or media site does.
But many businesses assume their site is simple when it is not. A standard website build can easily include analytics, embedded maps, video players, Meta pixels, Google tags, CRM integrations and chatbot software. Once those tools are active, a banner may be appropriate and sometimes necessary if you want users to make a meaningful choice before those tools run.
Why overseas standards still affect New Zealand businesses
Many New Zealand businesses sell online, target overseas users or use global platforms that are designed around stricter overseas consent rules. Even if your core customer base is in New Zealand, your developers or advertising tools may be using settings based on UK or EU expectations.
That does not mean you should copy a foreign banner word for word. It does mean a higher standard of consent and transparency is often the safest practical baseline, especially if your business is growing, selling online, or building a data-heavy marketing funnel before you spend money on setup and campaigns.
When This Issue Comes Up
Cookie consent issues usually come up at specific business moments, not in the abstract. The trigger is often a website change, a marketing upgrade or a new sales channel.
Before you launch a new website
This is the classic problem point. A founder approves the final design, the agency installs analytics and advertising tags, and nobody checks what loads on first visit. The banner appears polished, but the settings underneath are wrong.
Before you sign off on a new site, ask for a clear list of every script, plug-in and tracking tool that loads on each page type.
Before you run paid ads or retargeting
If you are planning Facebook, Instagram, Google or similar retargeting, your site may start collecting information for advertising audiences and conversion tracking. That changes the risk profile. Generic wording about improving site performance is usually not enough if the data is also being used for ad measurement or behavioural marketing.
When you add ecommerce or customer accounts
Online stores and account-based sites often combine website usage data with customer profiles, orders and log-in information. That can increase the privacy impact and make your privacy disclosures more important.
This also tends to be the point where founders review payment terms, consumer law obligations, customer terms, app terms or website terms and conditions. Cookie settings should be reviewed at the same time, not months later.
When your developer installs third party tools
Many privacy issues come from tools the business owner did not realise were active. A booking widget, customer support tool, video host or A/B testing platform may place cookies or collect behavioural data without being obvious from the front end of the site.
This is where founders often get caught. The legal wording says one thing, but the code does another.
When you collect leads through forms and landing pages
Lead generation pages often use analytics, ad tracking and CRM integrations together. If you are measuring conversions from campaigns and building audiences from site visits, your banner should reflect that. The same goes for downloadable guides, webinar registration pages and newsletter sign-up funnels.
When you expand overseas
If your New Zealand business starts serving customers in the UK, Europe or Australia, your banner may need a stricter approach. You may need geo-specific settings, clearer consent categories and more formal record keeping. That is worth sorting out before you spend money on international marketing.
Practical Steps And Common Mistakes
The best way to get cookie banners that comply is to map what your site actually does, then write and configure the banner around that reality.
1. Audit every tracker on the site
Start with a practical inventory. Ask your developer, marketing team or agency for a list of all cookies and similar technologies used across the site.
Your list should include:
- the tool name
- what it does
- whether it is essential or non-essential
- what data it collects
- whether data goes to a third party
- how long it lasts
- whether it loads before consent
Do not rely on assumptions. Many businesses think they use only analytics, but the site also contains ad pixels, embedded media cookies and customer support tracking.
2. Categorise cookies properly
Essential cookies are usually those needed for core site functionality, such as security, log-in sessions, checkout steps or load balancing. Analytics, advertising and personalisation cookies are often treated differently because users can often use the site without them.
If everything is labelled essential, that is a red flag. Regulators and users both tend to view over-classification as an attempt to avoid consent.
3. Use clear wording in the banner
Your banner should tell people what categories exist and what the choice means. Avoid vague lines like “We use cookies to improve your experience” if that is only part of the story.
Good wording usually covers:
- that the site uses cookies or similar technologies
- which categories are optional
- what those categories do, such as analytics or advertising
- that users can accept, reject or manage preferences
- where to find more detail in your privacy policy or cookie information
Plain English works better than technical language. Users should not need to decode legal jargon to understand what happens if they click Accept.
4. Offer a real reject option
A banner is much harder to defend if it makes acceptance easy and rejection difficult. If there is a large Accept button, there should generally be a comparable way to reject non-essential cookies or turn them off through clear settings.
Dark patterns are a common mistake. Examples include:
- making the reject option hard to find
- using colour and layout to push users toward acceptance
- pre-ticking optional categories
- describing advertising cookies as necessary for the site to work when they are not
If users are meant to have a choice, the design needs to support that.
5. Block non-essential cookies until the user chooses
This is one of the most common technical failures. The banner appears, but analytics or advertising cookies have already fired. In that situation, the wording does not match reality.
Before launch online, test the site using a clean browser and check which tags load on the first visit, on reject, and on accept. Repeat that test after major website updates.
6. Match the banner to your privacy policy
Your privacy policy should explain your broader collection, use, storage and disclosure of personal information. If your banner mentions analytics and marketing cookies, your privacy policy should also deal with website tracking, third party providers, overseas disclosures where relevant, and user choices.
Inconsistency creates risk. It can also become a problem during procurement, due diligence or partnership discussions when another business reviews your legal documents before you sign a contract.
7. Make preference changes easy
Users should be able to revisit their choices. That may be through a floating icon, a footer control or an account setting, depending on how your site is built.
If a person withdraws consent for optional tracking, your systems should be set up to respect that as far as reasonably possible.
8. Keep records of consent settings
If your business is relying on consent for non-essential cookies, keep a record of what the user saw and what they chose. The level of detail will vary depending on your platform and risk profile, but you should be able to explain your setup if challenged.
This matters even more for businesses with larger ad budgets, recurring subscriptions, health-related data, children’s services or other sensitive contexts.
9. Review third party contracts and vendor settings
Your site may use external platforms for analytics, ads, customer messaging or embedded content. Review the settings and the contract terms where relevant. You want to know:
- what data the vendor collects
- whether it acts only on your instructions or for its own purposes as well
- whether information is sent overseas
- what controls you have over retention and deletion
This is where cookie consent links up with wider privacy compliance, commercial contracts and procurement.
10. Train the people who change the site
Compliance can break the moment someone adds a new plug-in. Your web team, agency and marketing staff should know that a new tool cannot just be switched on without checking whether the banner, settings and privacy wording need an update.
Common mistakes New Zealand businesses make
The usual problems are not obscure legal points. They are practical mismatches between the website, the banner and the business’s actual data use.
- Copying a banner from another site without checking the underlying tools.
- Using a consent platform but leaving default settings unchanged.
- Treating all cookies as essential.
- Collecting ad tracking data before the visitor chooses.
- Failing to mention third party advertising or analytics providers.
- Forgetting that embedded videos, maps and chat tools may also set cookies.
- Updating the website design without reviewing privacy settings.
- Assuming the developer or marketing agency has handled the legal side.
If your business has already launched, it is still worth fixing. The main risk is ongoing non-compliance, not just how the site looked on day one.
What about mobile apps and logged-in platforms?
The same principles often apply beyond standard websites. Apps, portals and SaaS dashboards may use SDKs, identifiers and in-app analytics rather than browser cookies, but users still need clear information about tracking and meaningful choices where appropriate.
If your product combines account data, behavioural data and marketing analytics, the privacy analysis becomes more important, not less.
FAQs
Do New Zealand websites legally need a cookie banner?
Not every website needs the same kind of banner, but many do need some form of clear disclosure and consent mechanism if they use non-essential tracking. The answer depends on what your site collects, what tools are active and whether users are given a real choice before optional tracking starts.
Can I use analytics without asking users first?
That depends on how the analytics tool works, what data it collects and the basis you are relying on. If the tool is non-essential and tracks identifiable or behavioural data, a consent-based approach is often the safer option. You should assess the setup carefully rather than assume analytics is always exempt.
Is an “Accept All” button enough?
No. If your banner is meant to give users a choice, there should usually be a fair way to reject non-essential cookies or manage preferences. A one-sided design can undermine the validity of the choice and create fairness concerns.
Do I need a separate cookie policy as well as a privacy policy?
Not always as a separate document, but you do need clear written information about website tracking. Some businesses include this in a privacy policy, while others use a dedicated cookie notice. The important point is that the explanation is accurate, accessible and consistent with the banner.
What should I do before my website goes live?
Before launch, confirm which scripts and cookies fire on first visit, test accept and reject settings, review your privacy wording, and make sure your developer and marketing team agree on what tools are active. That review is much easier before you sign off on the final build.
Key Takeaways
- Cookie banners that comply are not just about wording, they depend on whether your site actually respects user choices.
- New Zealand businesses should consider privacy transparency, fair marketing practices and how third party tracking tools operate in practice.
- Many websites use more trackers than founders realise, especially once analytics, ad pixels, chat tools and embedded content are added.
- A banner should clearly explain optional cookie categories, offer a genuine reject option and avoid loading non-essential tools before the user chooses, where consent is being relied on.
- Your privacy policy, vendor settings, website build and banner should all say the same thing.
- Review the setup before launch, before ad campaigns, before you sign a website handover, and whenever new tools are installed.
If your business is dealing with cookie banners that comply and wants help with privacy policies, website terms, consent settings, third party data arrangements, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.








