Episode 08 · Data pipeline integration · Australia · United Kingdom · Southeast Asia
The Consent Layer
Data privacy updates landing in Australia, the UK and Singapore in 2026 — and why consent has to be built into the data pipeline, not bolted onto the website.
This episode is scheduled. Audio, transcript and video highlight publish with the episode.
Why this episode, why now
Three of the firm's operating regions change their privacy rules in the same twelve months, and the changes point the same way. In Australia, the first tranche of Privacy Act reform has a hard date: from 10 December 2026 any APP entity whose computer programs use personal information to make, or substantially assist, decisions that could significantly affect someone must say so in its privacy policy, and the OAIC must register the Children's Online Privacy Code by the same day — with a second tranche of reform still to come. In the United Kingdom, the Data (Use and Access) Act 2025 took most of its data-protection provisions into force on 5 February 2026, added a mandatory complaints procedure from 19 June 2026, exempted aggregate-statistics analytics cookies from consent while leaving advertising firmly inside it, and raised PECR fines to the UK GDPR ceiling of £17.5 million or four per cent of global turnover. In Singapore the PDPA's penalty cap now runs to S$1 million or ten per cent of local turnover, the PDPC has moved from warnings to financial penalties, and every private organisation must stop using NRIC numbers for authentication by 31 December 2026.
The platforms moved in the same year. On 15 June 2026 Google changed how advertising data flows out of Google Analytics 4: the Google Signals setting no longer governs Google Ads collection, and the ad_storage consent-mode parameter alone does. A startup whose consent banner and tag configuration were not aligned before that date lost remarketing audiences and attribution quality without a line of code changing. And Chrome, after years of signalling deprecation, kept third-party cookies with user controls — so the cookieless future arrived not as an event but as a slow erosion, which is harder to plan for.
This is not a compliance episode, and Daniel will say on air that nothing in it is legal advice. It is an architecture episode. The Drakopoulos Ventures framework puts data pipeline integration third, after the go-to-market blueprint and the stack, precisely because consent is a property of the pipeline: a consent state has to be captured once, stored somewhere authoritative, and propagated to every tool that reads or writes customer data — the CRM, the email platform, the product analytics, the ad platforms, the warehouse. A banner is the surface. The consent layer is the system. Daniel's early career across agencies and seed-stage startups in London and Singapore, and his firm's work across all three regions since 2017, is exactly the vantage point for a conversation about building one consent model that holds in three jurisdictions at once.
- Three dates
10 December (Australia), 5 February and 19 June (UK), 31 December (Singapore): what actually changes, stated plainly.
- The June 15 lesson
how one GA4 setting change exposed which startups had a consent layer and which had a banner.
- Consent is a pipeline property
where consent state is captured, where it lives, how it propagates to every tool.
- Advertising stays inside consent
the DUAA analytics exemption, what it does and does not free up, and why first-party data is the strategy that survives all three regimes.
- One model, three jurisdictions
designing a single consent schema for Australia, the UK and Singapore without building three stacks.
- The seed
stage checklist — what a team of eight must have done before December, in order.
- Closing question and sign
off.
The facts and sources this episode is built on.
- 01
Australia — automated decision-making disclosure from 10 December 2026. Under the Privacy and Other Legislation Amendment Act 2024, APP entities that have arranged for a computer program to use personal information to make, or do a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests must include specified information about it in their APP privacy policy from 10 December 2026; the OAIC is consulting on guidance for the obligation.
- 02
Australia — Children's Online Privacy Code by 10 December 2026. The OAIC is required to develop and register the Privacy (Children's Online Privacy) Code by 10 December 2026, following a 60-day public consultation; the Code will set specific requirements for how covered online services handle children's personal information.
- 03
Australia — tranche one done, tranche two pending. The POLA Act ("tranche one") reforms commenced in December 2024; the Government has committed to further "tranche two" reforms, which remain unlegislated as of mid-2026.
- 04
UK — DUAA commencement dates. The Data (Use and Access) Act 2025 became law on 19 June 2025; most remaining data-protection provisions commenced on 5 February 2026, with the requirement for every controller to operate a formal data-subject complaints procedure (30-day acknowledgement) commencing 19 June 2026.
ICO · DLA Piper · The Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026
- 05
UK — analytics cookies out of consent, advertising still in. DUAA section 112 exempts certain analytics and functionality cookies from the PECR consent requirement — storage or access whose sole purpose is collecting aggregate statistics to improve a website or service may run on an opt-out basis — but advertising-related uses remain outside the exemptions; the new "recognised legitimate interests" lawful basis does not cover commercial marketing.
- 06
- 07
Singapore — penalties and enforcement posture. The PDPA's financial penalty cap is S$1 million or 10 per cent of the organisation's annual turnover in Singapore, whichever is higher; 2026 commentary records the PDPC shifting from warnings to immediate financial penalties, with six-figure fines issued, and advertising that relies on profiling or behavioural analysis of identifiable individuals generally requiring clear opt-in consent (deemed consent by notification available in narrower cases).
- 08
Singapore — NRIC numbers out of authentication by 31 December 2026. On 2 February 2026 the PDPC announced that private organisations must cease using full or partial NRIC numbers for authentication by 31 December 2026, with stepped-up enforcement — directions and financial penalties — from 1 January 2027; this follows the June 2025 PDPC–CSA joint advisory.
- 09
Platform — GA4's 15 June 2026 consent change. From 15 June 2026 the Google Signals setting in GA4 no longer governs Google Ads data collection; the Consent Mode ad_storage parameter alone does. Sites whose consent banner was not correctly wired to Consent Mode before that date risk losing conversion accuracy, remarketing audiences and attribution; UTM parameters are read before cookie logic, so tagged traffic still attributes under denied consent.
- 10
Platform — Chrome kept third-party cookies. After testing deprecation, Chrome pivoted in 2025 to retain third-party cookies with user controls while continuing Privacy Sandbox alternatives (Topics, Attribution Reporting); in 2026 the shift is gradual erosion rather than a cut-over.
- OAIC — Consultation on Guidance for Transparency in Automated Decision Making
- Johnson Winter Slattery — Practical implications of the new transparency requirements for automated decision making
- Lander & Rogers — Australian Privacy Law Update: what APP entities need to know in 2026
- Sibenco Legal & Advisory — Automated decisions and privacy policies: new transparency obligations from December 2026
- AMLCompliant — Privacy Act Changes 2026: every date your Australian business needs on the calendar
- McCullough Robertson — Data Privacy Week: privacy reflections and projections
- Ashurst — Australia's first tranche of privacy reforms — a deep dive and why they matter
- Corrs Chambers Westgarth — Australia's ongoing privacy reforms: bolstering Australia's privacy regulatory framework
- Rules Mate — The second tranche of Privacy Act reforms: what's proposed and what's still uncertain
- ICO — Statement on the commencement of the Data (Use and Access) Act (DUAA)
- ICO — The Data (Use and Access) Act 2025 — what does it mean for organisations?
- DLA Piper — UK: commencement of the data protection provisions in the Data (Use and Access) Act
- legislation.gov.uk — The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026
- RPC — The Data (Use and Access) Act 2025 commencement update
- Usercentrics — UK Data (Use and Access) Act 2025: what's required for compliance now
- Harper James — DUAA cookie consent changes: what marketers need to know
- Clym — Data Use and Access Act 2025: what changes in 2026?
- Skadden — Cookie consent: unpacking the UK ICO's proposed new approach to online advertising
- Chambers and Partners — Data Protection & Privacy 2026 — Singapore: trends and developments
- Vucense — Singapore PDPA Guide 2026: fines, DPO & 3-day breach rule
- Hashmeta — PDPA marketing compliance: complete Singapore data protection guide for marketers
- PDPC — Organisations to cease the use of NRIC numbers for authentication by 31 December 2026
- PDPC — PDPC to step up enforcement action against misuse of NRIC numbers and issues new advisory on data protection
- Baker McKenzie — Singapore: PDPC to ban NRIC authentication use by end-2026
- Allen & Gledhill — Private organisations must cease use of NRIC numbers for authentication by 31 December 2026
- Digital Applied — GA4's June 15 consent change can break your tracking
- Flux Full Circle — Google Analytics Consent Mode update (June 2026)
- LinkUTM — Google Analytics Consent Mode news: 2026 update explained
- Consenteo — Third-party cookies in 2026: what actually happened after Google's reversal
- Studio Stray — Third-party cookies in 2026 — what's actually changed