

Two recent determinations by the Australian Privacy Commissioner have found that health providers Monash IVF and Medmate breached the Privacy Act 1988 (Cth) through their use of third-party tracking pixels on their websites. The findings establish important principles that apply well beyond health providers and probably affect most Australian organisations.
In this article, we look at some of the privacy issues with pixels, the OAIC’s tracking pixel guidance from 2024 and list some of the important takeaways from the two new Determinations for all Australian organisations.
A tracking pixel is a piece of code that organisations embed into their websites, often for marketing and analytics purposes. Tracking pixels are invisible to website visitors, meaning individuals are often unaware that their data is being collected and transmitted to third-party platforms. When a user visits a webpage, the pixel sends data, including IP addresses, URLs visited, form inputs and browsing behaviour, to the pixel provider’s servers. The provider (which might be a third party such as Meta, TikTok, X and Pinterest) then matches this data against existing user profiles to enable targeted advertising.
Third-party tracking pixels can be configured for a variety of purposes and can be calibrated to track the webpages you go to, every click on those pages, everything you put in your cart, and in some circumstances, information you enter into forms.
Tracking technologies are not a new phenomenon, and tracking pixels are just one of these technologies used by many social media companies and other digital platforms to help with their advertising endeavours.
Tracking pixels are distinct from cookies in that you cannot delete them. While you can easily clear your browser cookies or adjust your settings to block cookies entirely, tracking pixels are embedded into the coding of the website you visit. Without screening tools, most users are not even aware that a tracking pixel is operating on the website they are browsing.
This lack of transparency has been of particular concern under the APPs, particularly where it involves sensitive information (where express opt-in consent is generally needed before collecting and disclosing that information via tracking pixels).
The OAIC’s 2026 Australian Community Attitudes to Privacy Survey, cited in both determinations, reveals the strength of community feeling on these issues:
In light of these strong community expectations, it is clear why the OAIC has made pixel tracking a regulatory priority.
In early November 2024 the OAIC issued Guidance on Tracking Pixels, which confirmed that although the Privacy Act 1988 (Cth) does not prohibit tracking pixels, they must be configured and used in compliance with the APPs.
In that Guidance, the OAIC identified key privacy risks with using tracking pixels, as well as potential implications under the APPs, including:
Recommendations from the OAIC provided in the Guide include:
The OAIC emphasised that responsibility for compliance sits with the organisation deploying the pixel, regardless of what the pixel provider’s own terms may say.
Notwithstanding this Guidance, it is likely that very few organisations have implemented its findings since its release. Anecdotally, we have found that few websites provide the type of notice or consent mechanism envisioned by the 2024 Guidance.
Fast forward to 2026… At the same time as the OAIC released its pixel determinations about Medmate and Monash IVF (discussed in more detail in the next section), the Privacy Commissioner presented findings, case studies and recommendations from an inspection of use of tracking pixels by 50 healthcare providers in its report: Your life pixelated: how tracking pixels watch your every click.
The scan took place in October and November 2024, around eighteen months prior to the release of the report and connected Determinations, but at around the same time as the release of the 2024 Guidance.
The report provides a useful snapshot of then-current practices (which have not changed that much). Of the websites scanned:
Following the scan, the OAIC conducted a closer inspection of 12 websites. Of those sites:
Generally, the OAIC found that very limited information around the use of pixels was included in privacy policies. From engagement with the organisations under review, the OAIC noted that:
Following its review, the OAIC commenced more detailed investigations into two of the health care providers in the sweep:
These investigations resulted in formal Determinations released in early June 2026.
The findings in both determinations are similar. Both Monash IVF and Medmate were found to have collected sensitive (health) information without individuals’ consent, contrary to APP 3.3 and to have used or disclosed sensitive information for the purpose of direct marketing, without individuals’ consent, contrary to APP 7.1 and 7.4. Both were found to have breached APP 5.1.
However, there were some differences between the two cases:
The Commissioner ordered each organisation to:
While no financial penalty was applied, the case has attracted attention in the media and on social media.
It is worth considering the application of the different APPs in the circumstances in more detail.
One of the issues for consideration was whether there was a collection by the relevant entity. It was determined that there was because the entity had control over the placement of the pixels via its selected pixel providers, which then transmitted data to the relevant server.
The Commissioner also considered whether there was a legal basis for collection (other than consent, which was not present). The Commissioner’s view was that the functions or activities of the organisations could include marketing their services and analysing the effectiveness of its marketing campaigns. Accordingly, the Commissioner accepted that the collection of pixel data may be reasonably necessary for the performance of the organisation’s functions and activities.
This was a very important issue for decision. The OAIC looked at this question in two parts:
The answer to the first element was pretty straight forward, while the second was more contentious.
In relation to the second element, both investigated entities submitted that from the information collected, it was not possible to identify an individual in the sense of ‘’knowing or using resources available to it or gain access to direct identifiers.’’ The Commissioner noted that the definition of personal information ”does not expressly require that an individual be specifically identifiable, or identifiable by direct identifiers such as their legal name, passport or driver’s licence number, or date of birth.” Accordingly, the question of whether an individual is ‘reasonably identifiable’ in the circumstances still needed to be considered, even though neither entity possessed direct identifiers (such as name, address etc).
The Commissioner’s reasoning noted that technology has evolved so that many types of information, such as technical identifiers, social media handles, email addresses, and physical characteristics can now be used to track and target individuals, both in online and offline environments, and without direct identifiers.
Importantly, the Commissioner’s view was that the phrase ‘reasonably identifiable’ ought to be interpreted as applying to circumstances where information facilitates ‘individuation’. That is to say, the information permits an entity to ‘single out’ or ‘distinguish’ an individual from others in a way that affects an individual’s rights or interests. The Commissioner’s view is that this interpretation is supported by the text of s 6 of the Privacy Act, its legislative context, and the purpose of the definition.
The usability of the information was seen as crucial by the Commissioner to reasonable identifiability, who noted that ‘if there is a reasonable prospect that information about an individual held by an entity may be used by the entity to affect that individual’s rights or interests, the information is personal information.”
Because each organisation could retarget ads to individuals who visited their respective websites on the pixel providers’ platforms, they were able to distinguish individuals from others in a way that affected their rights or interests by targeting them with advertising on an individualised basis, even without their identity being known.
This meant that, based on the Commissioner’s test, the information collected via the pixels was personal information for the purposes of the Act.
This is a really important finding and an addition to current thinking of what is covered by the definition of personal information under the Privacy Act. It will be interesting to see whether this aspect is subject to further review.
The issue of whether the personal information collected was also sensitive information was important because of the greater restrictions around the collection and use of sensitive information (which includes health information).
The Commissioner’s view was that engagement with a health service provider’s website may reveal an individual’s health information, or allow an inference or opinion be formed about an individual’s health, based on the individual’s interest in the provision of a particular health-related service.
The determinations noted in particular that some of the tracking pixels collected and transmitted URLs that could reveal an individual’s searches or activity on the website, including health conditions or medication sought. The Commissioner additionally noted that the fact that Medmate and Monash had used that information to target health service advertising to these individuals indicated that they had formed an opinion about that individual’s health (i.e. that they were experiencing a health issue relevant to the services that Medmate and Monash provide). (Personal information is defined to include an opinion).
It might be argued that visitation to certain parts of the providers’ websites does not necessarily always mean that the individual has the particular health issue that the website is addressing. Again, this is an aspect of the decisions that may be subject to further review. However, the Commissioner is relying on the fact that an inference was made and an opinion formed and acted upon, regardless of whether that is correct or not.
One of the key issues across both determinations was the notice provided to website visitors about the use of tracking pixels.
In Monash’s case, the Commissioner held that individuals were not provided any notice about the collection of their personal information via tracking pixels, other than the information transmitted via Google Analytics/Ads via the reference in Monash’s Privacy Policy.
Additionally, as the first point of collection takes place when an individual first enters the website, the Commissioner’s view was that an APP 5 collection notice should have been given at the time the individual enters the website, through means such as a website pop up.
In Medmate’s case, they had included a cookie consent pop up in November 2024, which stated that cookies were being used to ‘serve personalised ads or content, and analyse our traffic.’ However, the Commissioner did not think this was sufficient to meet the requirements of APP 5. In particular, she noted that:
APP 7 applies where personal information is used or disclosed for direct marketing purposes. It sets out distinct rules depending on whether the information that is used or disclosed is personal information or sensitive information.
The Commissioner found that the transmission of data to Meta, TikTok and other platforms, which was then used to link an individual’s website activity to their social media profile and serve them targeted advertising based on that activity, constituted direct marketing. This was despite submissions by both respondents that their campaigns involved only a ‘general, non-personally identifiable audience’.
Where personal information (which is not sensitive) is used for direct marketing in this way, APP 7.2 and 7.3 generally permit this where:
Where the individual would not reasonably expect the use or disclosure or the information is collected indirectly, consent is needed unless it is impracticable to obtain that consent (and an opt out mechanism must again be provided).
Stricter requirements apply where sensitive information, such as health information, is involved under APP 7.4. Sensitive information cannot be used for direct marketing without consent. Reasonable expectation and an opt out mechanism are not sufficient.
As covered above, the Commissioner decided that Monash IVF and Medmate collected sensitive information. Therefore, their use for direct marketing purposes, without consent and where no other exception applied, meant that both organisations had contravened APP 7.1 and 7.4.
It was worth noting that the Commissioner was not satisfied that consent could be inferred from a privacy policy or a generic cookie consent mechanism in circumstances where neither adequately disclosed that sensitive information was being collected and used for the purpose of targeted advertising.
These determinations are important for most organisations and not just those in the health sector or which collect sensitive information.
Our recommended next steps for Australian organisations to make sure their practices are aligned with these two determinations include:
Both determinations and the OAIC tracking pixel guidance raise the question of whether tracking pixels are appropriate in certain contexts. For organisations handling sensitive health information or serving vulnerable communities, the bar for justifying pixel use is very high. Organisations should consider whether first-party marketing approaches, such as email marketing to individuals who have clearly consented, might achieve their marketing objectives without the privacy risks that third-party tracking pixels create.
The Commissioner’s findings make clear that organisations cannot simply assume that browsing data is anonymous or de-identified or remain ignorant of what is running on their own sites. Organisations should:
Neither Monash nor Medmate conducted privacy impact assessments before deploying their pixels, and both determinations treat this as a significant failing. A PIA should be conducted before any new pixel is deployed and should address:
Both determinations found that consent was not validly obtained. To obtain valid consent, organisations must ensure it is:
For health-related websites in particular, organisations should implement an express opt-in mechanism before any tracking pixel is used. Pixel providers including Meta and Google offer consent mode functionality that prevents pixels from firing until consent is obtained, and both determinations note this was readily available to the respondents.
Both determinations found that privacy policies alone are insufficient to meet the notification obligations under APP 5. Organisations should:
Where privacy policies refer only to cookies or Google Analytics, they are likely to be inadequate following these determinations. Policies should:
Both determinations found that using pixel data to retarget individuals with advertising on social media platforms constitutes direct marketing under APP 7. Organisations must:
Both cases reveal that tracking pixels can often be deployed or configured by external marketing agencies without adequate oversight. Organisations should:
While both determinations involved health service providers, the legal principles they establish are not confined to the health sector.
The Commissioner’s interpretation of ‘reasonably identifiable’ as encompassing ‘individuation’ (i.e. the ability to single out or distinguish an individual in a way that affects their rights or interests) applies wherever tracking pixels are used to target individuals with advertising.
More significantly, the finding that recording certain types of browsing activity on a website can constitute sensitive information will apply to any organisation whose website content could allow an inference to be drawn about a visitor’s sensitive characteristics. This could include, for example, a religious organisation, an addiction support service, trade associations, or a political party website. Any organisation in these or similar categories should treat these determinations as directly relevant to their own practices and review their use of tracking pixels accordingly.
To help organisations work through their obligations following these determinations, we have prepared a practical Tracking Pixels Privacy Compliance Checklist. The checklist is structured around the ten key compliance areas identified in the Monash IVF and Medmate determinations, from initial assessment and pixel auditing through to consent mechanisms, collection notices, privacy policy updates, direct marketing obligations and marketing agency governance. It is designed to be used by privacy teams, legal counsel and marketing managers alike.
Download the Tracking Pixels Privacy Compliance Checklist and share it with the teams responsible for your website, marketing and privacy compliance.
If you would like assistance reviewing your organisation’s use of tracking pixels or updating your privacy policies and consent mechanisms, please contact us at hello@privacy108.com.au.
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.