Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
If your website uses analytics, ad pixels, embedded videos, chat widgets, or ecommerce tools, there is a good chance cookies or similar tracking technologies are already collecting data before you realise it. That is where many New Zealand businesses get caught. Common mistakes include assuming a generic privacy policy is enough, loading marketing trackers as soon as the page opens, and forgetting that third party tools often set their own cookies behind the scenes.
A cookie compliance audit helps you find out what your site is actually doing, whether your disclosures match reality, and whether your consent settings make sense for your legal risk. For startups and SMEs, this matters before you spend money on ads, before you sign with a website developer, and before you roll out a new customer journey. The aim is not just to tidy up a banner. The aim is to make sure your website practices, privacy notices, contracts, and internal processes line up.
Overview
A cookie compliance audit is a practical review of the tracking technologies on your website, the personal information they collect, and the notices and consent tools you use to manage them. For New Zealand businesses, the main legal focus usually sits under privacy transparency, fair dealing with customers, and making sure website statements are accurate.
- Identify every cookie and tracking technology used on your site, including third party tools
- Classify which tools are essential, analytics based, functional, or marketing related
- Check what personal information is collected, where it is sent, and who receives it
- Review whether your cookie banner, consent settings, and privacy policy or cookie policy reflect what the site actually does
- Confirm whether non-essential tracking loads before user choice is captured
- Check contracts with developers, marketing agencies, and software providers for privacy and data handling responsibilities
- Record your findings so you can repeat the audit after site changes, campaigns, or platform upgrades
What Cookie Compliance Audit Means For New Zealand Businesses
A cookie compliance audit means checking the gap between what your website says and what your website does.
For many founders, cookies feel like a purely technical issue. In practice, they sit across privacy, customer communications, digital marketing, and supplier management. If you collect online behavioural data, even through ordinary website tools, you need to understand whether that information can identify an individual directly or indirectly and how you explain that use.
In New Zealand, the Privacy Act 2020 is often the starting point. It does not work like a website-specific cookie code, but it does require businesses to be open about collecting personal information, why they collect it, how it will be used, and who it may be shared with. If cookies or similar technologies collect information linked to identifiable people, your privacy disclosures need to reflect that.
The Fair Trading Act also matters. If your site says users can reject tracking, but non-essential cookies still fire immediately, that can create a misleading impression. The same issue comes up where a banner says you only use cookies for site performance, but your site also runs remarketing or audience profiling tools.
This is why a cookie compliance audit is not just an IT task. It is a legal and operational review.
What counts as a cookie or tracking technology?
A cookie is a small file stored on a user’s device, but an audit should not stop there. Many websites use broader tracking tools that work in similar ways or create similar privacy issues.
- Standard browser cookies
- Analytics tags and scripts
- Advertising pixels
- Session identifiers
- Embedded video and map trackers
- Live chat and support widgets
- Social media plug-ins
- SDKs in web apps or mobile apps
If your business sells online, books appointments, captures leads, or runs advertising campaigns, these tools often appear long before anyone has reviewed them properly.
Why SMEs often underestimate the issue
Most small business websites are built from templates, plugins, and external services. A founder may approve a homepage design without realising the site also contains Meta Pixel, Google Analytics, Hotjar-style behaviour tools, an ecommerce platform cookie, a review widget, and an email marketing tracker.
This is where founders often get caught. The website looks simple, but the data flows are not. One plugin update or marketing campaign can change what is collected overnight.
What an audit is trying to achieve
The goal is not perfection for its own sake. The goal is to reduce mismatch, avoid surprise, and make informed decisions about tracking.
A good audit should answer questions such as:
- What tools are active on the site right now?
- Which tools are necessary for the site to function, and which are optional?
- Does any tracking start before a user has made a choice?
- What personal information or device data is collected?
- Is data sent offshore, and if so, to which providers?
- Do your privacy and cookie notices explain the position clearly?
- Do your developer and marketing contracts allocate responsibility for setup, compliance, and changes?
If you cannot answer those questions, an audit is usually overdue.
When This Issue Comes Up
A cookie compliance audit usually becomes urgent when your website changes, your marketing becomes more sophisticated, or a customer asks awkward questions.
Many businesses only look at cookies after a complaint or a platform rollout. It is better to review earlier, especially before you sign a contract with a web agency, before you spend money on setup for paid advertising, or before you launch online to a wider audience.
Common trigger points
- You are building or redesigning a website
- You are moving to a new ecommerce platform or booking system
- You are adding ad retargeting, audience profiling, or conversion tracking
- You are embedding third party tools such as chat, maps, videos, or customer review widgets
- You are expanding overseas and want one website approach across markets
- You are updating your privacy policy or customer terms
- You are doing due diligence for investors, a sale, or a commercial partnership
These moments matter because technical settings are often locked in early. Once your site is live, it becomes harder and more expensive to unwind poor consent design or inaccurate disclosures.
Founder scenarios where this matters
A retail brand launches an online store and installs multiple apps to recover abandoned carts, track ads, and offer personalised product suggestions. No one checks whether each app starts tracking immediately or whether the privacy policy mentions the providers involved.
A professional services firm adds a chatbot and online booking widget. The tools collect behavioural data and contact details, but the website still uses an old policy copied from a template years ago.
A SaaS startup wants to start a business in New Zealand with offshore customers from day one. The product team focuses on registration, business structure, contracts, and trade mark protection, but treats cookie settings as an afterthought. That can create problems once users start signing up and marketing tools begin profiling behaviour.
These examples show why cookie audits often sit alongside other startup legal requirements. Selling online, customer terms, privacy wording, supplier terms, and platform configuration all intersect.
Why timing matters
It is easier to fix cookie issues before launch than after a complaint. Early review also helps when you are negotiating with developers or software vendors, because you can set requirements around consent tools, data mapping, and documentation from the start.
If your site is already live, the next best time is before the next campaign, redesign, or feature release.
Practical Steps And Common Mistakes
The most useful cookie compliance audit is part technical review, part legal review, and part process clean-up.
You need to know what appears on the site, why it is there, and whether your business has approved it. A founder does not need to personally inspect source code, but someone in the business should own the outcome.
1. Build a tracking inventory
Start with a list of every tool that stores information on user devices or tracks behaviour across sessions or services.
Your inventory should include:
- The cookie or tool name
- Its provider
- Its purpose
- Whether it is first party or third party
- Its duration
- What data it collects
- Whether it is essential or optional
- Whether data is disclosed to an overseas provider
Do not rely only on what your developer thinks is installed. Test the live site as well. Many tools come through tag managers, app stores, plugins, and embedded content.
2. Sort tools into sensible categories
Not all cookies carry the same risk. Essential site functions are different from advertising or profiling tools.
Most businesses will end up with categories such as:
- Strictly necessary cookies for security, login, payments, or site stability
- Functional cookies that remember settings or preferences
- Analytics cookies that measure usage and performance
- Marketing cookies used for ads, retargeting, or audience building
This classification matters because your banner, settings, and notices should reflect the real distinction between necessary and optional tracking.
3. Review your consent setup
If your website offers choices about cookies, those choices need to work properly.
Key questions include:
- Do non-essential trackers wait until the user opts in, or do they load immediately?
- Can users reject optional categories as easily as they can accept them?
- Are category descriptions clear and specific?
- Can users revisit their choices later?
- Does the banner record consent decisions in a reliable way?
A common mistake is using a banner that looks compliant but does nothing meaningful in the background. Another is bundling analytics and marketing into vague wording such as “improve your experience”, which tells users very little.
4. Check your privacy documents against reality
Your privacy policy, website terms, and cookie notice should match the live site.
Review whether those documents explain:
- What personal information is collected online
- How cookies and similar tools are used
- Why the information is collected
- Whether third parties receive the data
- Whether information is stored or processed outside New Zealand
- How users can contact you or exercise privacy-related rights
The main risk is inconsistency. If your policy says one thing and your tracking setup does another, the problem is not solved by nicer drafting alone. You may need both legal updates and technical changes.
5. Review third party providers and contracts
Your website often depends on agencies, developers, ecommerce providers, SaaS tools, and ad platforms. Their contracts matter.
Before you sign, check who is responsible for:
- Installing or approving tracking tools
- Configuring consent settings
- Notifying you of changes to tags or plugins
- Responding to privacy complaints
- Handling cross-border data transfers
- Keeping records of technical settings
This step gets overlooked because businesses assume the web agency has “done compliance”. Often the agency has only implemented a plugin and left the legal decisions to you.
6. Document the audit and assign ownership
An undocumented review is hard to repeat and hard to rely on. Keep a simple audit record that shows what you checked, what you found, what you changed, and who approved the result.
Assign responsibility internally. That may sit with an operations lead, marketing manager, founder, or privacy contact, depending on business size.
Common mistakes to avoid
- Copying a cookie banner or policy from another business without checking your own site setup
- Treating analytics as always harmless and never reviewing what user-level data is involved
- Ignoring third party embeds because they seem minor
- Failing to retest after a site update, campaign launch, or new plugin install
- Using broad or confusing language that does not explain the actual purpose of tracking
- Leaving legal review until after launch, when customer data is already being collected
Cookie compliance is not a one-time document exercise. It needs periodic review, especially if your digital marketing changes often.
FAQs
Do New Zealand businesses always need a cookie banner?
Not always in the same way, but many businesses using optional tracking tools will need a clear notice and a sensible consent mechanism. The right setup depends on what your site collects, which tools are essential, and how your users are targeted.
Are analytics cookies treated the same as advertising cookies?
No. Analytics tools and advertising tools can raise different risk levels, although both still need review. The key issue is what data is collected, whether it can identify users, and whether tracking starts before any choice is made.
Is a privacy policy enough on its own?
No. A privacy policy is important, but it does not replace proper technical configuration. If your site offers consent choices, those choices need to work in practice.
How often should a business do a cookie compliance audit?
Review your setup whenever there is a major website change, a new marketing tool, a redesign, or a shift in data use. Even without major changes, a periodic check is sensible because plugins, tags, and embedded services can change over time.
Does this only matter for ecommerce businesses?
No. Service businesses, SaaS companies, consultancies, franchisors, and any business generating leads online may use cookies or similar tracking. If your website collects behavioural data or contact information, an audit can still be relevant.
Key Takeaways
- A cookie compliance audit checks whether your website tracking, consent tools, and privacy disclosures match what actually happens on the site
- For New Zealand businesses, the main issues usually involve privacy transparency, accurate customer communications, and third party data handling
- The most common problems are hidden third party trackers, banners that do not control anything, and privacy documents that no longer reflect the live website
- The best time to review cookies is before launch, before you sign a web or marketing contract, and before you spend money on setup for new campaigns or features
- A useful audit covers technical testing, legal wording, supplier responsibilities, and an internal process for future changes
If your business is dealing with cookie compliance audit and wants help with privacy policies, website terms, supplier contracts, consent wording, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.







