Skip to content

Platform reviews · No. 03

The Consent Layer

Data privacy updates landing in Australia, the UK and Singapore in 2026 — and why consent has to be built into the data pipeline, not bolted onto the website.

The Consent Layer

Why this matters now

Three of the firm's operating regions change their privacy rules in the same twelve months, and the changes point the same way. In Australia, the first tranche of Privacy Act reform has a hard date: from 10 December 2026 any APP entity whose computer programs use personal information to make, or substantially assist, decisions that could significantly affect someone must say so in its privacy policy, and the OAIC must register the Children's Online Privacy Code by the same day — with a second tranche of reform still to come. In the United Kingdom, the Data (Use and Access) Act 2025 took most of its data-protection provisions into force on 5 February 2026, added a mandatory complaints procedure from 19 June 2026, exempted aggregate-statistics analytics cookies from consent while leaving advertising firmly inside it, and raised PECR fines to the UK GDPR ceiling of £17.5 million or four per cent of global turnover. In Singapore the PDPA's penalty cap now runs to S$1 million or ten per cent of local turnover, the PDPC has moved from warnings to financial penalties, and every private organisation must stop using NRIC numbers for authentication by 31 December 2026.

The platforms moved in the same year. On 15 June 2026 Google changed how advertising data flows out of Google Analytics 4: the Google Signals setting no longer governs Google Ads collection, and the ad_storage consent-mode parameter alone does. A startup whose consent banner and tag configuration were not aligned before that date lost remarketing audiences and attribution quality without a line of code changing. And Chrome, after years of signalling deprecation, kept third-party cookies with user controls — so the cookieless future arrived not as an event but as a slow erosion, which is harder to plan for.

This is not a compliance episode, and Daniel will say on air that nothing in it is legal advice. It is an architecture episode. The Drakopoulos Ventures framework puts data pipeline integration third, after the go-to-market blueprint and the stack, precisely because consent is a property of the pipeline: a consent state has to be captured once, stored somewhere authoritative, and propagated to every tool that reads or writes customer data — the CRM, the email platform, the product analytics, the ad platforms, the warehouse. A banner is the surface. The consent layer is the system. Daniel's early career across agencies and seed-stage startups in London and Singapore, and his firm's work across all three regions since 2017, is exactly the vantage point for a conversation about building one consent model that holds in three jurisdictions at once.

Evidence

Findings

Numbered facts, each with its source.

  1. 01

    Australia — automated decision-making disclosure from 10 December 2026. Under the Privacy and Other Legislation Amendment Act 2024, APP entities that have arranged for a computer program to use personal information to make, or do a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests must include specified information about it in their APP privacy policy from 10 December 2026; the OAIC is consulting on guidance for the obligation.

    OAIC · Johnson Winter Slattery · Lander & Rogers

  2. 02

    Australia — Children's Online Privacy Code by 10 December 2026. The OAIC is required to develop and register the Privacy (Children's Online Privacy) Code by 10 December 2026, following a 60-day public consultation; the Code will set specific requirements for how covered online services handle children's personal information.

    AMLCompliant · McCullough Robertson

  3. 03

    Australia — tranche one done, tranche two pending. The POLA Act ("tranche one") reforms commenced in December 2024; the Government has committed to further "tranche two" reforms, which remain unlegislated as of mid-2026.

    Ashurst · Corrs Chambers Westgarth · Rules Mate

  4. 04

    UK — DUAA commencement dates. The Data (Use and Access) Act 2025 became law on 19 June 2025; most remaining data-protection provisions commenced on 5 February 2026, with the requirement for every controller to operate a formal data-subject complaints procedure (30-day acknowledgement) commencing 19 June 2026.

    ICO · DLA Piper · The Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026

  5. 05

    UK — analytics cookies out of consent, advertising still in. DUAA section 112 exempts certain analytics and functionality cookies from the PECR consent requirement — storage or access whose sole purpose is collecting aggregate statistics to improve a website or service may run on an opt-out basis — but advertising-related uses remain outside the exemptions; the new "recognised legitimate interests" lawful basis does not cover commercial marketing.

    Usercentrics · Harper James · Clym

  6. 06

    UK — PECR fines rise to GDPR levels. DUAA Schedule 13 brings PECR penalties in line with UK GDPR — up to the greater of £17.5 million or 4 per cent of global annual turnover, up from £500,000.

    ICO · Skadden

  7. 07

    Singapore — penalties and enforcement posture. The PDPA's financial penalty cap is S$1 million or 10 per cent of the organisation's annual turnover in Singapore, whichever is higher; 2026 commentary records the PDPC shifting from warnings to immediate financial penalties, with six-figure fines issued, and advertising that relies on profiling or behavioural analysis of identifiable individuals generally requiring clear opt-in consent (deemed consent by notification available in narrower cases).

    Chambers and Partners · Vucense · Hashmeta

  8. 08

    Singapore — NRIC numbers out of authentication by 31 December 2026. On 2 February 2026 the PDPC announced that private organisations must cease using full or partial NRIC numbers for authentication by 31 December 2026, with stepped-up enforcement — directions and financial penalties — from 1 January 2027; this follows the June 2025 PDPC–CSA joint advisory.

    PDPC · Baker McKenzie · Allen & Gledhill

  9. 09

    Platform — GA4's 15 June 2026 consent change. From 15 June 2026 the Google Signals setting in GA4 no longer governs Google Ads data collection; the Consent Mode ad_storage parameter alone does. Sites whose consent banner was not correctly wired to Consent Mode before that date risk losing conversion accuracy, remarketing audiences and attribution; UTM parameters are read before cookie logic, so tagged traffic still attributes under denied consent.

    Digital Applied · Flux Full Circle · LinkUTM

  10. 10

    Platform — Chrome kept third-party cookies. After testing deprecation, Chrome pivoted in 2025 to retain third-party cookies with user controls while continuing Privacy Sandbox alternatives (Topics, Attribution Reporting); in 2026 the shift is gradual erosion rather than a cut-over.

    Consenteo · Studio Stray

Sources