PUBLICATIONS circle 10 Aug 2026

Every click leaves a trace: What the Privacy Commissioner's tracking pixel decisions mean for Australian businesses

By Morgan Lane, Samyuktha Rajagopalan and Max Lee

The OAIC’s latest tracking pixel decisions confirm that website activity data may constitute personal or sensitive information under the Privacy Act 1988 (Cth). Businesses using cookies, pixels and targeted advertising technologies should review their privacy and consent practices to ensure compliance.


In brief 

On 11 June 2026, the Privacy Commissioner handed down two significant determinations and an accompanying standalone report on the use of tracking pixels. In the decisions, the Commissioner made it clear that businesses cannot treat tracking pixels as merely a marketing tool. Where website activity reveals, or is capable of revealing, information about an individual's health, the collection and disclosure of that information may constitute the handling of personal and/or sensitive information under the Privacy Act 1988 (Cth) (Privacy Act).  

While the Office of the Australian Information Commissioner (OAIC) decisions in this respect arose from the healthcare sector, their implications are far broader. For any business using Meta Pixel, Google Ads tags, Google Analytics or similar technologies, these determinations serve as a timely reminder that privacy compliance must extend beyond traditional databases and forms to include the often-overlooked technologies operating behind a website.  

The message from the OAIC is clear: if a tracking tool allows individuals to be singled out and targeted, privacy obligations will follow. 

What is a tracking pixel? 

A tracking pixel is a small piece of code, or a 1×1 transparent image, embedded in a website, email or digital advertisement that enables user activity to be tracked. Because pixels operate in the 'background', individuals are often unaware that their interactions are being monitored. 

When a user visits a webpage containing a tracking pixel, information about their activity is automatically transmitted to the pixel provider. At a basic level, this may include the webpage visited, timestamp, user IP address, device and browser information. More advanced implementations can collect additional data such as search queries, items viewed, form submissions, button clicks and contact details entered by the user. 

The OAIC investigations  

Following a preliminary scan of 50 health service provider websites by the OAIC in 2024, the Commissioner commenced investigations into Medmate Australia Pty Ltd and Monash IVF Pty Ltd on 9 November 2024 concerning their use of tracking pixels. 

Monash IVF, a provider of fertility services and treatments across Australia, used seven different tracking pixels on its website between 30 July 2012 and 9 December 2024. The Commissioner found that individuals who visited fertility-related webpages could reasonably be identified as seeking information about reproductive health services. As a result, information about those website interactions revealed details concerning an individual's health status or health concerns and therefore constituted sensitive information under the Privacy Act (being a subset of personal information). 

Medmate, which provides online healthcare services, used tracking pixels on its website between April 2021 and 9 December 2024. These technologies collected information about website visitors and their interactions with health-related content. Similar to the findings in relation to Monash IVF, the Commissioner considered that the information generated through those interactions could disclose an individual's health interests, conditions or concerns and therefore amounted to 'sensitive information' subject to the Act. 

A notable aspect of both investigations was that neither Medmate nor Monash IVF conducted a Privacy Impact Assessment (PIA) before implementing tracking pixels on their websites. The Commissioner identified this as a significant governance failing, particularly given the heightened privacy risks associated with collecting and disclosing sensitive health information through online tracking technologies. 

The Privacy Commissioner's decision  

'Reasonably identifiable'? 

The Commissioner found that website interaction data could render individuals reasonably identifiable when combined with information held by social media platforms and other third parties. Further, where those interactions related to health-related webpages, they could reveal information about an individual's health status, concerns or treatment interests. As a result, the information fell within the definition of health information and therefore, 'sensitive information' subject to the Act. In both determinations, the Commissioner stated the following:  

'I observe that new technologies provide entities with new ways to affect the privacy of individuals by collecting, using and disclosing a range of types of information. Many of those types of information may historically not have been considered personal information, such as technical identifiers, social media handles, email addresses, or physical characteristics. However, as technology has evolved to make it possible for entities to use such information to track and target individuals, both in online and offline environments, our understanding of “identifiability” has evolved in parallel.' 

The Commissioner described this approach as a "logical progression" in the interpretation of the Privacy Act, recognising that established privacy principles must evolve alongside increasingly sophisticated tracking and advertising technologies. 

Breach of the Australian Privacy Principles (APPs)  

In the decision, the Commissioner focused on regulatory compliance with APP 3.3 (collection of sensitive information), APP 5.1 (reasonable steps to notify individuals) and APP 7.1 (direct marketing).  

APP 3.3: Collection of Sensitive Information 

APP 3.3 provides that an organisation must not collect sensitive information unless the individual consents and the collection is reasonably necessary for its functions or activities.  

The Commissioner found that neither Medmate nor Monash IVF had obtained express or implied consent to collect sensitive information through tracking pixels. Both organisations argued that the information collected was not personal information and therefore could not be sensitive information. The Commissioner rejected that argument, concluding that the collection of health-related browsing data through tracking pixels amounted to the collection of sensitive information without the required consent. 

APP 5.1: Notification of Collection 

APP 5.1 requires organisations to take reasonable steps to notify individuals, at or before the time personal information is collected, of the matters set out in APP 5.2. This includes the fact of collection, the purposes for which information is collected and any usual disclosures to third parties. 

The Commissioner found that neither organisation adequately informed individuals that tracking pixels were collecting their information, why that information was being collected, or that it would be disclosed to third-party advertising platforms such as Meta and TikTok. 

Importantly, the Commissioner made clear that a privacy policy alone will rarely satisfy APP 5. Organisations must provide clear, timely and contextual notice at or before the point of collection. Medmate's cookie banner, introduced only 24 days before the investigation commenced, was also found to be inadequate because it failed to identify the specific tracking technologies in use or explain the involvement of third-party platforms. 

In reaching this conclusion, the Commissioner noted that both organisations had access to readily available consent and notification tools provided by the tracking pixel vendors themselves but failed to implement them effectively. 

APP 7.1: Direct Marketing  

APP 7.1 provides that an organisation must not use or disclose personal information for the purpose of direct marketing. For sensitive information, consent is required.  

Both Medmate and Monash IVF used tracking pixels to retarget advertisements to individuals based on their interactions with health-related webpages. The Commissioner held that this activity constituted direct marketing because the information collected was used to deliver personalised advertisements to identified or identifiable individuals. 

Because the information involved was sensitive information, APP 7 required consent before it could be used or disclosed for direct marketing purposes. Neither organisation had obtained that consent. As a result, the Commissioner concluded that both organisations had used and disclosed sensitive information for direct marketing in breach of the Privacy Act. 

The message from these decisions is clear: organisations cannot assume that website analytics and advertising technologies sit outside the Privacy Act. Where tracking technologies can identify an individual (e.g. the user IP address) and reveal information about an individual's health, interests or circumstances, the information collected may well be sensitive information, triggering some of the Privacy Act's most stringent compliance obligations. 

The Commissioner's orders 

The Commissioner made the same orders against each of Medmate and Monash IVF under section 52(1A) of the Privacy Act whereby they each must: 

  • Within 60 days of the determination: 

  • cease collecting individuals' sensitive information through tracking pixels until appropriate compliance measures had been implemented; and 

  • to the extent permitted by law, destroy all sensitive information collected via tracking pixels and stored within the relevant pixel provider dashboards. 

  • Before recommencing the use of tracking pixels: 

  • implement measures to obtain valid consent for the collection of sensitive information in compliance with APP 3; 

  • implement measures to obtain valid consent for the use or disclosure of sensitive information for direct marketing purposes in compliance with APP 7; and 

  • take reasonable steps to notify individuals of the matters required under APP 5.2 and ensure individuals are aware of those matters, in compliance with APP 5. 

  • Report to the OAIC: 

  • within 90 days of the determination, confirm compliance with the above requirements; and 

  • before recommencing the use of tracking pixels, notify the OAIC of their intention to do so and the steps taken to achieve compliance with the Privacy Act. 

Key takeaways 

Website browsing data can be sensitive information 

Historically, organisations may have viewed browsing activity as anonymised or relatively innocuous activity of data analytics. Consent and Privacy Impact Statements have not always been high on the agenda for businesses engaging in pixel use / data tracking activities. However, these OAIC decisions demonstrate that where tracking a user's website activity can identify a user (IP address) and track their browsing of health services, fertility treatment, medical conditions or other sensitive matters online, the resulting data may reveal highly personal and sensitive information about an individual. Then to use that data to send targeted ads to the user without consent will attract the attention of the privacy regulator. Businesses can no longer assume that information collected through cookies, pixels or advertising technologies falls outside the enhanced protections afforded to sensitive information under the Privacy Act. 

Targeted advertising may constitute direct marketing 

These decisions reinforce the OAIC's longstanding position that targeted advertising may amount to direct marketing for the purposes of APP 7. 

Many businesses have traditionally distinguished between sending marketing communications directly to individuals and using digital advertising platforms to deliver targeted advertisements. The Commissioner's findings suggest that where personal information is used to facilitate personalised advertising, compliance with APP 7 will be required. Where sensitive information is involved, organisations must obtain consent before that information is used or disclosed for advertising purposes. 

Privacy policies alone are not enough 

A key theme across both decisions is that a privacy policy alone will not satisfy an organisation's privacy obligations. 

The Commissioner emphasised that APP 1 (maintaining a privacy policy) is distinct from APP 5 (notifying individuals about collection practices). Organisations must provide clear and timely notice at or before the point of collection, including how tracking technologies operate, why information is collected and who it is shared with. 

In practice, this may require layered privacy notices, consent tools and point-of-collection disclosures. Generic cookie banners are unlikely to be sufficient, particularly where sensitive information may be collected or inferred. 

The Commissioner reinforced that PIAs are a key mechanism for identifying, assessing and mitigating privacy risks associated with new technologies, data collection practices and information-handling activities. 

The implications extend beyond healthcare 

Although both matters involved health service providers, the reasoning is likely to extend much further. 

The Commissioner commented that sensitive information could include information revealing political views, ethnicity, race or other protected categories where tracking technologies collect information that identifies individuals or enables them to be singled out for advertising purposes. Organisations operating websites relating to mental health, religion, political advocacy, disability services, union membership or similar subject matter should therefore review their tracking practices carefully.  

What should businesses do now? 

For businesses that rely on digital advertising which uses tracking, monitoring or surveillance technology, the message is clear: widespread industry use does not mean compliance. 

For businesses that do (or wish to do so) they should: 

  • audit all tracking pixels, cookies and similar technologies operating on their websites; 

  • identify what information is being shared with advertising and analytics providers; 

  • assess whether any of that information may constitute personal information and whether it includes sensitive information; 

  • conduct a PIA where appropriate; 

  • review whether valid and compliant consent mechanisms are in place; 

  • ensure privacy policies, cookie notices and collection notices accurately describe tracking practices; and 

  • review arrangements with third-party advertising and analytics providers. 

These determinations demonstrate that the privacy risks associated with tracking technologies are continuing to evolve. Organisations must focus not only on the information they collect, but also on what that data reveals, how it is disclosed and whether individuals have been provided with appropriate notice and choice. 

If you have questions about the use of tracking technologies within your organisation, or would like assistance reviewing your privacy practices, collection notices or privacy policies, please get in touch with our Privacy & Data team.

This is commentary published by Colin Biggers & Paisley for general information purposes only. This should not be relied on as specific advice. You should seek your own legal and other advice for any question, or for any specific situation or proposal, before making any final decision. The content also is subject to change. A person listed may not be admitted as a lawyer in all States and Territories. Colin Biggers & Paisley, Australia 2026

Stay connected

Connect with us to receive our latest insights.