Tracking Pixels and the APPs: The OAIC’s Latest Determinations 

Published
01 Jul 2026
Read time
21 min read
Category

Two recent determinations by the Australian Privacy Commissioner have found that health providers Monash IVF and Medmate breached the Privacy Act 1988 (Cth) through their use of third-party tracking pixels on their websites. The findings establish important principles that apply well beyond health providers and probably affect most Australian organisations.

In this article, we look at some of the privacy issues with pixels, the OAIC’s tracking pixel guidance from 2024 and list some of the important takeaways from the two new Determinations for all Australian organisations.

Key Findings at a Glance

  • Both Monash IVF and Medmate were found to have breached APP 3.3 (collection of sensitive information without consent or another lawful basis), APP 5.1 (failure to notify individuals of collection), and APP 7.1/7.4 (use or disclosure of sensitive information for direct marketing without consent).
  • The collection of certain types of browsing activity on a health-related website can constitute collection of sensitive health information (which needs consent if another exemption can’t be relied on).
  • A privacy policy alone does not satisfy the notification obligation under APP 5. A specific pop-up or banner at the time of collection is recommended.
  • A generic cookie consent pop-up that does not specifically name the tracking pixels or pixel providers in use is unlikely to meet the APP 5 Collection Notice requirements.
  • Using pixel data to retarget individuals with advertising on social media constitutes direct marketing under APP 7 and requires consent where sensitive information is involved.
  • Responsibility for compliance sits with the organisation deploying the pixel, not the pixel provider.

Core Privacy Issues with Online Tracking

A tracking pixel is a piece of code that organisations embed into their websites, often for marketing and analytics purposes. Tracking pixels are invisible to website visitors, meaning individuals are often unaware that their data is being collected and transmitted to third-party platforms. When a user visits a webpage, the pixel sends data, including IP addresses, URLs visited, form inputs and browsing behaviour, to the pixel provider’s servers. The provider (which might be a third party such as Meta, TikTok, X and Pinterest) then matches this data against existing user profiles to enable targeted advertising.

Third-party tracking pixels can be configured for a variety of purposes and can be calibrated to track the webpages you go to, every click on those pages, everything you put in your cart, and in some circumstances, information you enter into forms. 

Tracking technologies are not a new phenomenon, and tracking pixels are just one of these technologies used by many social media companies and other digital platforms to help with their advertising endeavours.

Tracking pixels are distinct from cookies in that you cannot delete them. While you can easily clear your browser cookies or adjust your settings to block cookies entirely, tracking pixels are embedded into the coding of the website you visit. Without screening tools, most users are not even aware that a tracking pixel is operating on the website they are browsing.

This lack of transparency has been of particular concern under the APPs, particularly where it involves sensitive information (where express opt-in consent is generally needed before collecting and disclosing that information via tracking pixels).

What do Australians Think About Tracking and Targeted Advertising?

The OAIC’s 2026 Australian Community Attitudes to Privacy Survey, cited in both determinations, reveals the strength of community feeling on these issues:

  • 91% of people considered targeted advertising based on sensitive information to be neither fair nor reasonable.
  • 87% of people want more control and choice over the collection and use of their personal information.
  • Social media companies and data brokers were rated as some of the least trustworthy industry sectors for protection of personal information, with just 3% and 5% of people finding them trustworthy, respectively.

In light of these strong community expectations, it is clear why the OAIC has made pixel tracking a regulatory priority.

OAIC Guidance on Tracking Pixels

In early November 2024 the OAIC issued Guidance on Tracking Pixels, which confirmed that although the Privacy Act 1988 (Cth) does not prohibit tracking pixels, they must be configured and used in compliance with the APPs.

In that Guidance, the OAIC identified key privacy risks with using tracking pixels, as well as potential implications under the APPs, including:

  • Collection notices. Publishing a privacy policy alone does not satisfy the notification obligations under APP 5. Organisations must take active steps to notify individuals at or before the time of collection, for example through a banner or pop-up when a user first visits the site.
  • Direct marketing. Using tracking pixel data to retarget individuals with advertising on third-party platforms constitutes direct marketing under APP 7. Organisations must ensure that individuals would reasonably expect this use of their data and provide a simple opt-out mechanism. Where sensitive information is handled, organisations must obtain consent before using sensitive information for this purpose.
  • Third-party disclosure. Organisations must be transparent about which third-party platforms receive personal information via pixels and must take reasonable steps to ensure overseas recipients comply with the APPs.

Recommendations from the OAIC provided in the Guide include:

  • Conduct a Privacy Impact Assessment before deploying any tracking pixel to identify and mitigate privacy risks.
  • Adopt a data minimisation approach, configuring pixels to collect only the minimum information necessary.
  • Implement a mechanism to manage opt-outs and consent where required under APP 7, such as a pop-up that clearly identifies the pixel providers in use, explains what data is collected and why, and gives users a genuine choice, particularly where sensitive information may be collected.
  • Review privacy policies and collection notices to ensure they specifically address the use of tracking pixels, not just cookies, and accurately describe the data collected and third parties involved.

The OAIC emphasised that responsibility for compliance sits with the organisation deploying the pixel, regardless of what the pixel provider’s own terms may say.

Notwithstanding this Guidance, it is likely that very few organisations have implemented its findings since its release. Anecdotally, we have found that few websites provide the type of notice or consent mechanism envisioned by the 2024 Guidance.

Your Life, Pixelated: How Tracking Pixels Watch Your Every Click

Fast forward to 2026… At the same time as the OAIC released its pixel determinations about Medmate and Monash IVF (discussed in more detail in the next section), the Privacy Commissioner presented findings, case studies and recommendations from an inspection of use of tracking pixels by 50 healthcare providers in its report: Your life pixelated: how tracking pixels watch your every click.  

The scan took place in October and November 2024, around eighteen months prior to the release of the report and connected Determinations, but at around the same time as the release of the 2024 Guidance.

The report provides a useful snapshot of then-current practices (which have not changed that much). Of the websites scanned:

  • 96% used tracking technologies
  • 52% used a third-party tracking pixel
  • Of the entities that used a third-party tracking pixel, 77% did not mention the use of third-party tracking pixels within their privacy policy.

Following the scan, the OAIC conducted a closer inspection of 12 websites. Of those sites:

  • all used more than 1 tracking pixel provided by a third party
  • 50% used more than 1 tracking pixel provided by social media platforms
  • all used the third-party tracking pixel provided by Meta, 50% used the TikTok tracking pixel, and 25% used the Snapchat tracking pixel.

Generally, the OAIC found that very limited information around the use of pixels was included in privacy policies.  From engagement with the organisations under review, the OAIC noted that:

  • Many organisations assumed that web browsing data is ‘de-identified’’;
  • None of the organisations had completed a privacy impact assessment on the use of pixels; and
  • Organisations were not aware that there were tracking pixels on their websites, nor were they aware of the potential harms.

OAIC Determinations: Medmate and Monash IVF

Following its review, the OAIC commenced more detailed investigations into two of the health care providers in the sweep:

  • Monash IVF, a long-established fertility services provider, registered in 1988 and part of the publicly listed Monash IVF Group.
  • Medmate, a much newer business, registered in 2018, operating as a telehealth platform offering online prescriptions, medical certificates and mental health support.

These investigations resulted in formal Determinations released in early June 2026.

Findings

The findings in both determinations are similar. Both Monash IVF and Medmate were found to have collected sensitive (health) information without individuals’ consent, contrary to APP 3.3 and to have used or disclosed sensitive information for the purpose of direct marketing, without individuals’ consent, contrary to APP 7.1 and 7.4. Both were found to have breached APP 5.1.

However, there were some differences between the two cases:

  • Monash’s breach period was significantly longer (over 12 years from July 2012) while Medmate’s relevant period ran for roughly three and a half years. Medmate’s website also received more visitors than Monash IVF.
  • Monash deployed seven different tracking pixels at various times: Meta, Google Ads, Google Analytics 4, Matomo, Jet Interactive, Hotjar and Pinterest. Medmate used only two active pixels at the time of investigation: Meta and TikTok.

The Commissioner ordered each organisation to: 

  • within 60 days, cease collecting sensitive information via tracking pixels;  
  • prior to recommencing the use of tracking pixels, ensure that compliant consent and notice measures are in place;
  • destroy the data already collected; and 
  • report compliance to the OAIC within 90 days. 

While no financial penalty was applied, the case has attracted attention in the media and on social media. 

Application of the APPs

It is worth considering the application of the different APPs in the circumstances in more detail.

Collection

One of the issues for consideration was whether there was a collection by the relevant entity. It was determined that there was because the entity had control over the placement of the pixels via its selected pixel providers, which then transmitted data to the relevant server.

The Commissioner also considered whether there was a legal basis for collection (other than consent, which was not present).  The Commissioner’s view was that the functions or activities of the organisations could include marketing their services and analysing the effectiveness of its marketing campaigns. Accordingly, the Commissioner accepted that the collection of pixel data may be reasonably necessary for the performance of the organisation’s functions and activities.

Is it personal information?

This was a very important issue for decision. The OAIC looked at this question in two parts:

  • Is the information about an individual?
  • Is the individual reasonably identifiable by the information?

The answer to the first element was pretty straight forward, while the second was more contentious.

In relation to the second element, both investigated entities submitted that from the information collected, it was not possible to identify an individual in the sense of ‘’knowing or using resources available to it or gain access to direct identifiers.’’  The Commissioner noted that the definition of personal information ”does not expressly require that an individual be specifically identifiable, or identifiable by direct identifiers such as their legal name, passport or driver’s licence number, or date of birth.” Accordingly, the question of whether an individual is ‘reasonably identifiable’ in the circumstances still needed to be considered, even though neither entity possessed direct identifiers (such as name, address etc).

The Commissioner’s reasoning noted that technology has evolved so that many types of information, such as technical identifiers, social media handles, email addresses, and physical characteristics can now be used to track and target individuals, both in online and offline environments, and without direct identifiers.

Importantly, the Commissioner’s view was that the phrase ‘reasonably identifiable’ ought to be interpreted as applying to circumstances where information facilitates ‘individuation’. That is to say, the information permits an entity to ‘single out’ or ‘distinguish’ an individual from others in a way that affects an individual’s rights or interests. The Commissioner’s view is that this interpretation is supported by the text of s 6 of the Privacy Act, its legislative context, and the purpose of the definition.

The usability of the information was seen as crucial by the Commissioner to reasonable identifiability, who noted that ‘if there is a reasonable prospect that information about an individual held by an entity may be used by the entity to affect that individual’s rights or interests, the information is personal information.”

Because each organisation could retarget ads to individuals who visited their respective websites on the pixel providers’ platforms, they were able to distinguish individuals from others in a way that affected their rights or interests by targeting them with advertising  on an individualised basis, even without their identity being known. 

This meant that, based on the Commissioner’s test, the information collected via the pixels was personal information for the purposes of the Act.

This is a really important finding and an addition to current thinking of what is covered by the definition of personal information under the Privacy Act. It will be interesting to see whether this aspect is subject to further review.

Is the personal information collected sensitive information?

The issue of whether the personal information collected was also sensitive information was important because of the greater restrictions around the collection and use of sensitive information (which includes health information).

The Commissioner’s view was that engagement with a health service provider’s website may reveal an individual’s health information, or allow an inference or opinion be formed about an individual’s health, based on the individual’s interest in the provision of a particular health-related service. 

The determinations noted in particular that some of the tracking pixels collected and transmitted URLs that could reveal an individual’s searches or activity on the website, including health conditions or medication sought. The Commissioner additionally noted that the fact that Medmate and Monash had used that information to target health service advertising to these individuals indicated that they had formed an opinion about that individual’s health (i.e. that they were experiencing a health issue relevant to the services that Medmate and Monash provide). (Personal information is defined to include an opinion).

It might be argued that visitation to certain parts of the providers’ websites does not necessarily always mean that the individual has the particular health issue that the website is addressing. Again, this is an aspect of the decisions that may be subject to further review.  However, the Commissioner is relying on the fact that an inference was made and an opinion formed and acted upon, regardless of whether that is correct or not.

Collection notice (APP 5.1/5.2)

One of the key issues across both determinations was the notice provided to website visitors about the use of tracking pixels.

In Monash’s case, the Commissioner held that individuals were not provided any notice about the collection of their personal information via tracking pixels, other than the information transmitted via Google Analytics/Ads via the reference in Monash’s Privacy Policy.

Additionally, as the first point of collection takes place when an individual first enters the website, the Commissioner’s view was that an APP 5 collection notice should have been given at the time the individual enters the website, through means such as a website pop up.

In Medmate’s case, they had included a cookie consent pop up in November 2024, which stated that cookies were being used to ‘serve personalised ads or content, and analyse our traffic.’  However, the Commissioner did not think this was sufficient to meet the requirements of APP 5.  In particular, she noted that:

  • There was no reference to tracking pixels, which are distinct from cookies, or that personal information was being collected via tracking pixels;
  • The cookies referred to were stated to be Twitter (now known as X), Bing and Google, and did not include Meta or TikTok;
  • The cookie consent pop-up and the webpage linked to the ‘Customise’ option did not include any reference to tracking pixels or direction to more detailed information.

Use or Disclosure for Direct Marketing (APP 7)

APP 7 applies where personal information is used or disclosed for direct marketing purposes. It sets out distinct rules depending on whether the information that is used or disclosed is personal information or sensitive information.

The Commissioner found that the transmission of data to Meta, TikTok and other platforms, which was then used to link an individual’s website activity to their social media profile and serve them targeted advertising based on that activity, constituted direct marketing.  This was despite submissions by both respondents that their campaigns involved only a ‘general, non-personally identifiable audience’.

Where personal information (which is not sensitive) is used for direct marketing in this way, APP 7.2 and 7.3 generally permit this where:

  • the individual would reasonably expect their information to be used for that purpose, and
  • the organisation provides a simple means of opting out.

Where the individual would not reasonably expect the use or disclosure or the information is collected indirectly, consent is needed unless it is impracticable to obtain that consent (and an opt out mechanism must again be provided).

Stricter requirements apply where sensitive information, such as health information, is involved under APP 7.4. Sensitive information cannot be used for direct marketing without consent. Reasonable expectation and an opt out mechanism are not sufficient.

As covered above, the Commissioner decided that Monash IVF and Medmate collected sensitive information. Therefore, their use for direct marketing purposes, without consent and where no other exception applied, meant that both organisations had contravened APP 7.1 and 7.4.

It was worth noting that the Commissioner was not satisfied that consent could be inferred from a privacy policy or a generic cookie consent mechanism in circumstances where neither adequately disclosed that sensitive information was being collected and used for the purpose of targeted advertising.

What Does This Mean?

These determinations are important for most organisations and not just those in the health sector or which collect sensitive information. 

Our recommended next steps for Australian organisations to make sure their practices are aligned with these two determinations include:

Consider Whether Pixels Are Appropriate at All

Both determinations and the OAIC tracking pixel guidance raise the question of whether tracking pixels are appropriate in certain contexts. For organisations handling sensitive health information or serving vulnerable communities, the bar for justifying pixel use is very high. Organisations should consider whether first-party marketing approaches, such as email marketing to individuals who have clearly consented, might achieve their marketing objectives without the privacy risks that third-party tracking pixels create.

Understand What You Are Collecting

The Commissioner’s findings make clear that organisations cannot simply assume that browsing data is anonymous or de-identified or remain ignorant of what is running on their own sites. Organisations should:

  • Map all tracking pixels currently active on their website, including those deployed by third-party vendors or marketing agencies
  • Identify every type of data each pixel collects and transmits
  • Assess whether the nature of their website means that page visits alone could reveal sensitive information.

Conduct a Privacy Impact Assessment Before Deploying Pixels

Neither Monash nor Medmate conducted privacy impact assessments before deploying their pixels, and both determinations treat this as a significant failing. A PIA should be conducted before any new pixel is deployed and should address:

  • What information will be collected, including what could be inferred from URL structures and page visits
  • Whether sensitive information is likely to be captured and how that risk can be mitigated (including through proper configuration of tracking tools)
  • Which third-party platforms will receive the data and how they will use it
  • Whether the collection is reasonably necessary for the organisation’s functions, or whether less privacy-invasive alternatives exist

Obtain Valid Consent for Sensitive Information

Both determinations found that consent was not validly obtained. To obtain valid consent, organisations must ensure it is:

  • Informed: individuals must understand specifically what is being collected, by which pixel providers, and for what purpose. Generic references to cookies are insufficient, as the Medmate finding makes clear
  • Specific: particularly for sensitive information, consent must be directed at the specific handling in question, not bundled into broad general terms
  • Voluntary: individuals must have a genuine choice, with a clear option to decline which does not prevent them from accessing the website
  • Current: consent obtained through a privacy policy that individuals are unlikely to have read does not satisfy this requirement

For health-related websites in particular, organisations should implement an express opt-in mechanism before any tracking pixel is used. Pixel providers including Meta and Google offer consent mode functionality that prevents pixels from firing until consent is obtained, and both determinations note this was readily available to the respondents.

Implement Adequate Collection Notices

Both determinations found that privacy policies alone are insufficient to meet the notification obligations under APP 5. Organisations should:

  • Deploy a banner or pop-up that activates when an individual first visits the website, before any pixel data is transmitted
  • Ensure the notice specifically identifies the tracking pixels in use and names the pixel providers, not just generic references to cookies or analytics
  • Explain clearly what data is collected and the purposes for which it will be used, including that it will be used for targeted advertising on third-party platforms
  • Include information about which third parties receive the data, satisfying the APP 5.2(f) requirement that was breached in both cases; and
  • Link through to a more detailed privacy policy for individuals who want further information.

Update Privacy Policies

Where privacy policies refer only to cookies or Google Analytics, they are likely to be inadequate following these determinations. Policies should:

  • Specifically name each tracking pixel and pixel provider in use
  • Accurately describe what data each pixel collects and how that data is used, including for retargeting and direct marketing purposes
  • Disclose that data is transmitted to and used by third-party social media platforms; and
  • Not contain inaccurate statements, such as assurances that information cannot be linked to individuals.

Comply With Direct Marketing Obligations

Both determinations found that using pixel data to retarget individuals with advertising on social media platforms constitutes direct marketing under APP 7. Organisations must:

  • Obtain consent before using sensitive information for direct marketing purposes, with the same standard of informed, specific and voluntary consent described above
  • Provide individuals with a simple and accessible opt-out mechanism; and
  • Honour opt-out requests promptly

Govern Your Marketing Agencies

Both cases reveal that tracking pixels can often be deployed or configured by external marketing agencies without adequate oversight. Organisations should:

  • Maintain a complete and current register of all tracking technologies deployed on their website, regardless of who deployed them
  • Require marketing agencies to obtain prior approval before adding or modifying any tracking pixel
  • Include privacy compliance obligations in contracts with marketing agencies, including requirements to conduct PIAs and configure pixels in accordance with the APPs
  • Conduct regular audits of website tracking technologies, treating pixels as an ongoing compliance responsibility rather than a set-and-forget tool

These Principles Extend Beyond Health Providers

While both determinations involved health service providers, the legal principles they establish are not confined to the health sector.

The Commissioner’s interpretation of ‘reasonably identifiable’ as encompassing ‘individuation’ (i.e. the ability to single out or distinguish an individual in a way that affects their rights or interests) applies wherever tracking pixels are used to target individuals with advertising.

More significantly, the finding that  recording certain types of browsing activity on a website can constitute sensitive information will apply to any organisation whose website content could allow an inference to be drawn about a visitor’s sensitive characteristics. This could include, for example, a religious organisation, an addiction support service, trade associations, or a political party website. Any organisation in these or similar categories should treat these determinations as directly relevant to their own practices and review their use of tracking pixels accordingly.

Download Our Free Tracking Pixels Privacy Compliance Checklist

To help organisations work through their obligations following these determinations, we have prepared a practical Tracking Pixels Privacy Compliance Checklist. The checklist is structured around the ten key compliance areas identified in the Monash IVF and Medmate determinations, from initial assessment and pixel auditing through to consent mechanisms, collection notices, privacy policy updates, direct marketing obligations and marketing agency governance. It is designed to be used by privacy teams, legal counsel and marketing managers alike.

Download the Tracking Pixels Privacy Compliance Checklist and share it with the teams responsible for your website, marketing and privacy compliance.

If you would like assistance reviewing your organisation’s use of tracking pixels or updating your privacy policies and consent mechanisms, please contact us at hello@privacy108.com.au.

Ready to turn insight into action?
Connect with Privacy 108.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Privacy 108 collects your name and contact details to respond to your enquiry and communicate with you about it. If you do not provide this information, we may be unable to respond. We do not disclose this information to third parties. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au.
Related articles
Subscribe to our Newsletter

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.