Cookie Policies for New Zealand Business Websites

Alex Solo
byAlex Solo11 min read

If your business has a website, chances are it uses cookies, even if you never set them up yourself. Analytics tools, shopping carts, chat widgets, advertising platforms and embedded videos often drop cookies in the background. A common mistake is assuming a privacy policy covers everything. Another is copying a generic cookie policy from an overseas website that does not match New Zealand law or your actual tracking tools. A third is using a cookie banner that says one thing while your site does another.

That creates a practical risk. If your site collects personal information through cookies, your disclosures need to be accurate, your consent settings need to match your wording, and your team should understand what happens before you launch online or spend money on marketing. This guide explains what a cookie policy does, when New Zealand businesses usually need one, what to include, and the common mistakes that catch founders and SMEs out.

Overview

A cookie policy explains how your website uses cookies and similar tracking technologies, what data they collect, why they are used, and what choices users have. For New Zealand businesses, the main legal focus is usually transparency under privacy law, plus making sure your website disclosures are not misleading.

  • Identify every cookie or tracking tool your website uses, including third party tools
  • Check whether those cookies collect personal information or track users across websites
  • Explain what each category of cookie does, such as essential, analytics, functionality or advertising
  • Make sure your cookie banner, privacy policy and actual website settings all match
  • Give users a genuine way to manage non essential cookies where consent is being relied on
  • Review your setup before you launch online, redesign your website or add new marketing tools

A cookie policy is a practical transparency document for your website, not just a technical add-on. It tells visitors what small data files or similar technologies are being placed on their device, what those tools are for, and what control they have over them.

For many New Zealand businesses, cookies sit inside a broader privacy compliance picture. The Privacy Act 2020 requires businesses that collect personal information to be open about what they collect, why they collect it, how it will be used, and who it may be shared with. Cookies do not always collect personal information on their own, but many modern website tools can identify or single out a user when combined with other data.

That means a cookie policy often works alongside your privacy policy. The privacy policy covers your wider personal information handling. The cookie policy deals specifically with website tracking technologies and gives visitors clearer detail about what happens on your site.

What Are Cookies?

Cookies are small pieces of data stored on a user's browser or device when they visit a website. Some are essential for the website to function. Others are used to remember preferences, measure traffic, personalise content, or deliver advertising.

You may also hear about similar technologies, such as:

  • pixels
  • tracking scripts
  • software development kits in web apps
  • local storage tools
  • tag managers

From a practical drafting perspective, businesses usually refer to cookies and similar tracking technologies together so the policy reflects what the site actually uses.

Why This Matters Under New Zealand Law

The main issue in New Zealand is honesty and transparency. If your website collects personal information through cookies, visitors should not be left guessing about it.

Your legal exposure may come from several directions:

  • privacy disclosures that are incomplete or inaccurate
  • misleading statements about what your website tracks or shares
  • consent tools that do not reflect what is really happening in the background
  • poor internal processes when marketing, website and legal documents are all handled separately

The Fair Trading Act can also matter if your website statements are misleading. For example, saying you only use cookies for website performance when advertising trackers are active could create a problem. The issue is not just what your policy says. It is whether your actual practices match your wording.

Not always. Some small websites only use strictly necessary cookies and can cover this clearly in a well-drafted privacy policy. But many business websites now use enough third party tools that a separate cookie policy is the cleaner and safer approach.

This is especially true if your business:

  • sells online through an ecommerce site
  • uses Google Analytics or similar analytics tools
  • runs Meta, Google or other digital advertising campaigns
  • uses remarketing or audience tracking
  • has a customer portal or logged in area
  • embeds videos, maps, calendars or social media plugins
  • uses chatbots, helpdesk widgets or booking software

A dedicated cookie policy can also help when you are dealing with overseas customers, third party payment platforms, software providers or agency partners. It forces your business to document what your site actually does before you sign a contract with a developer or spend money on setup.

When This Issue Comes Up

Cookie policy issues usually surface when a business updates its website, turns on marketing tools, or expands how it uses customer data. Founders often discover the problem late, after the site is live and ad spend has already started.

Launching A New Website

A website build is one of the most common trigger points. Your developer may install analytics, a consent tool, embedded content and ecommerce apps as part of the build. If no one maps those tools properly, your legal documents can fall behind from day one.

This is where startups often get caught. The focus is on branding, registration, business structure, trade mark protection, customer terms and customer contracts. Website tracking settings can be treated as a technical detail, even though they affect privacy compliance and customer trust.

Selling Online

If you are selling online in New Zealand, cookies can support key parts of the customer journey, such as remembering shopping cart items, recognising repeat visits and measuring conversion rates. Once you add analytics and advertising tags, your site may start collecting more information than customers realise.

That matters because ecommerce businesses often combine cookie data with account information, purchase history and email marketing records. At that point, the distinction between anonymous website data and personal information can get blurry in practice.

Using Advertising And Retargeting

Advertising tools are a major reason businesses need a clearer cookie policy. Retargeting works by tracking visitor behaviour, then using that information to show ads later. If your business uses these tools, your policy should say so in plain English.

Common examples include:

  • tracking visitors who viewed a product page
  • building custom audiences for advertising campaigns
  • measuring ad performance across platforms
  • linking website visits with social media or search advertising data

These tools often involve third party providers and cross site tracking. That is exactly the kind of activity that should not be buried in vague wording.

Adding Third Party Website Features

A site can start using cookies without the business consciously deciding to. A booking plugin, a live chat feature, a customer review tool or an embedded video may introduce additional trackers.

That is why a cookie review should happen whenever you add:

  • a new ecommerce app
  • a customer support widget
  • a booking or scheduling tool
  • a marketing automation platform
  • social media embeds
  • video hosting tools

If your website is managed by an external agency, this review is worth building into your contracts and change request process.

Expanding Overseas

New Zealand businesses with overseas users may also face stricter expectations from other markets. Even if your main legal home is New Zealand, you may still decide to use stronger cookie disclosures and consent controls because your customers are in Australia, the United Kingdom, the European Union or elsewhere.

The point is not to copy overseas templates blindly. The point is to make sure your website setup suits your real audience, your tools and your risk level.

Practical Steps And Common Mistakes

The best cookie policy starts with a technical audit, not a template. If you do not know what your website is doing, you cannot describe it accurately.

Step 1: Audit Your Website Cookies And Trackers

List every cookie and tracking technology that appears on your site. This should cover both first party tools and third party providers.

Your audit should identify:

  • the name of the cookie or tracking tool
  • who sets it, your business or a third party
  • what it does
  • whether it is essential or non essential
  • what data it collects
  • how long it stays active
  • whether data is shared with another provider

Do not rely only on what your developer remembers. Website plugins and tag managers can change over time, and old scripts often stay in place after campaigns end.

Step 2: Separate Essential Cookies From Optional Ones

Not all cookies serve the same purpose. A customer login or shopping cart cookie may be necessary for the site to work. An advertising tracker usually is not.

That distinction affects how you describe user choices and how any consent banner should operate. If your banner suggests visitors can reject optional tracking, your technical setup needs to respect that choice. This is where legal wording and technical implementation must line up.

Step 3: Draft A Policy In Plain English

Your cookie policy should be easy for a customer, supplier or investor to understand. Legal jargon and copied lists from overseas sites usually make the policy less useful, not more.

A practical cookie policy often includes:

  • what cookies are
  • the categories of cookies your site uses
  • why each category is used
  • whether third parties place cookies through your site
  • how users can manage preferences
  • how the cookie policy interacts with your privacy policy
  • when the policy was last updated

If your site uses specific third party services for analytics or advertising, say so clearly where appropriate. General statements like “we may use cookies from time to time” are often too vague to be helpful.

Step 4: Align Your Banner, Policy And Backend Settings

A common mistake is treating the banner as a design feature and the policy as a legal feature. They are part of the same compliance story.

For example, problems arise when:

  • the banner says users can reject non essential cookies, but the site loads them immediately anyway
  • the policy says only analytics cookies are used, but ad retargeting tags are active
  • the banner settings do not actually save or honour user preferences
  • the policy is updated, but the cookie tool is not

This mismatch is often created by different people handling different parts of the website. Marketing adds a new tag. Development installs it. Legal documents are never updated. Six months later, the site says something inaccurate.

Cookie compliance is not a one-off drafting exercise. It should be part of how your business handles website changes.

That is especially useful before you sign a contract with:

  • a web developer
  • a digital marketing agency
  • a CRM or email platform provider
  • an ecommerce app supplier
  • a data analytics vendor

Your internal process might require a quick privacy review whenever new website tools are added. That helps avoid a scramble later when customers ask questions or a platform update changes how tracking works.

Common Mistakes New Zealand Businesses Make

The main risk is usually not having no policy at all. It is having a policy that does not match reality.

Common mistakes include:

  • copying a foreign cookie policy that refers to laws or rights that do not fit your business
  • assuming the privacy policy makes a cookie policy unnecessary
  • failing to identify third party trackers embedded in plugins and widgets
  • using broad statements that do not explain analytics, advertising or profiling clearly
  • not updating the policy after a website redesign or new ad campaign
  • giving users choices in the banner that are not technically implemented
  • forgetting that online stores, apps and member areas may use more than browser cookies alone

Another practical mistake is leaving the policy to the final week before launch. At that stage, founders are also juggling supplier contracts, website terms, privacy wording, trade mark issues and customer checkout flows. Cookie compliance gets rushed, and rushed website disclosures are often inaccurate.

What Good Practice Looks Like

Good practice is clear, accurate and maintained over time. A customer should be able to understand what your website is doing without needing to decode vague technical language.

For most SMEs, that means:

  • mapping website tracking tools properly
  • using a cookie policy that reflects the actual site
  • keeping the policy and privacy disclosures consistent
  • reviewing consent settings when marketing tools change
  • assigning someone in the business to own updates

If your website is central to your sales process, this is worth treating as part of your normal commercial setup, alongside customer terms, privacy compliance and supplier contracts.

FAQs

Maybe, but many businesses benefit from having both. A privacy policy covers your broader handling of personal information, while a cookie policy gives specific detail about website tracking tools and user choices.

Are cookies always personal information?

No, not always. But some cookies and similar technologies can collect or contribute to personal information, especially when linked with account details, device identifiers, marketing profiles or browsing behaviour.

You can start with a template, but it needs to match your actual website setup and New Zealand context. The real problem with templates is usually inaccuracy, not the fact that they are templates.

What if my developer installed the tracking tools and I do not know what they do?

You should ask for a full list before you launch online or approve changes. Your business is still responsible for what appears on its website, even if a third party installed the tools.

Do small businesses need to worry about this?

Yes, especially if the website uses analytics, advertising tags, ecommerce plugins or booking tools. Small businesses often have simpler websites, but they still need accurate privacy disclosures if tracking tools are in use.

Key Takeaways

  • A cookie policy explains how your website uses cookies and similar tracking technologies, and what control users have over them
  • For New Zealand businesses, the main legal themes are transparency, privacy compliance and avoiding misleading website statements
  • You may need a separate cookie policy if your website uses analytics, advertising tags, ecommerce tools, embedded content or third party plugins
  • The policy, cookie banner and actual backend settings must match
  • The best starting point is a proper audit of all website cookies and trackers before you spend money on setup or launch online
  • Regular reviews matter because website tools and marketing integrations change over time

If your business is dealing with cookie policy and wants help with website privacy compliance, cookie policy drafting, privacy policies, website terms, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get your customer-facing terms right

What should your privacy and online terms cover?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Keep reading

Related Articles

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.