INSIGHT

Tracking pixels, targeted advertising and compliance—lessons from recent OAIC determinations

By Valeska Bloch, David Rountree, Isabelle Guyot, Jessica Nimmo
Data & Privacy Healthcare Risk & Compliance Technology, Media & Telecommunications

Businesses must review their use of tracking pixels 15 min read

The Office of the Australian Information Commissioner (the OAIC) has issued two landmark determinations finding that the use of tracking pixels by two health service providers contravened the Australian Privacy Principles (the APPs) under the Privacy Act 1988 (Cth).1

The Commissioner found that Medmate Australia Pty Ltd and Monash IVF Pty Ltd had each interfered with the privacy of individuals through their use of tracking pixels by:

  • collecting sensitive information without individuals' consent, in contravention of APP 3.3;
  • failing to take reasonable steps to notify, or ensure individuals' awareness, in contravention of APP 5.1; and
  • using or disclosing sensitive information for direct marketing purposes without consent, in contravention of APP 7.1.

Although these determinations concern health service providers, the Commissioner's analysis has significant implications for businesses across all sectors. In particular, organisations will need to carefully consider how they use tracking pixels and cookies and the information that individuals provide. In this Insight, we consider the implications for those using tracking pixels and/or cookies for marketing purposes.

Who in your organisation needs to know about this?

Legal and compliance, marketing teams and IT teams involved in sign-off, preparation and configuration of pixels and cookies.

Key takeaways 

  • The determinations expand the existing interpretation of the Privacy Act and the APPs in a number of respects.
  • The Commissioner has adopted individuation, which is the ability to single out a specific individual and treat them differently on an individualised basis (even if the business does not know who that individual is), as the operative test for 'reasonably identifiable' under the Act. This is a considerable expansion of the concept of 'personal information' under the Act and will impact organisations' handling of information beyond pixels. Organisations that have previously assumed their use of pixel data does not engage the Act—whether because they do not 'know' the individuals behind the data, or because they reviewed their practices against the November 2024 guidance and concluded they were compliant—should urgently reassess that position.
  • Retargeting individuals based on their online behaviour constitutes use of personal information for direct marketing purposes under APP 7.1, even where the recipients are not directly identifiable by the business (due to the application of individuation).
  • Businesses are themselves the holders of tracking pixel data for the Act's purposes. A business's control over the deployment and configuration of tracking pixels that collect personal information is sufficient to constitute the collection and holding of personal information, even where a third-party pixel provider retains physical custody of the data (and it is only the third-party pixel provider that is actually able to identify the individual).
  • A generic cookies consent banner is insufficient where sensitive information is collected via tracking pixels. Consent must be express, informed and specific, and directed at tracking pixel use in particular.
  • A privacy policy published in isolation does not satisfy APP 5.1 notification obligations. Where tracking pixels are active upon entry to a website, notification must be provided at that point (eg via a banner or pop-up that specifically addresses pixel collection).

Background

The OAIC published guidance on the use of tracking pixels in November 2024, and subsequently confirmed advertising technology as a regulatory priority for FY 2025–26. The Commissioner commenced investigations into Medmate and Monash following a preliminary scan of 50 health service provider websites and their use of tracking pixels.

Although the Commissioner has publicly acknowledged that the relevant decisions are likely to go to appeal or review, this is likely to take at least a year.

What is a tracking pixel?

A tracking pixel is a piece of code that pixel providers place on an organisation's website or other digital platforms to collect information on a visitor's activity.

Depending on the way in which the pixel is set up, collected pixel data can be matched with existing information held by the organisation and/or the pixel provider (often social media organisations), and used to target those individuals with advertising on the pixel provider's website or platform.

Tracking pixels differ from cookies in that they operate by transmitting data directly to the pixel provider's server each time a webpage is loaded, whereas cookies are small data files stored locally on a user's device that record browsing activity and preferences over time.

Medmate's use of tracking pixels

Medmate provides a range of health services, including telehealth consults, online prescriptions and mental health support. During the period the subject of the OAIC's investigation, Medmate had two active tracking pixels on its website. Both collected information about individuals' engagement with the website, such as when an individual viewed a website page and the specific content they engaged with, as well as details related to any purchases the individual made. One of the pixels also enabled full URLs, phone numbers and hashed email addresses to be transmitted to the pixel provider when users used the Medmate website. The investigation identified that the URLs transmitted from the pixel sometimes included sensitive information, including health conditions or medication sought.

During the relevant period, Medmate paid for online advertising campaigns on the pixel provider's platforms that leveraged the tracking pixel data. These campaigns had target audience and demographic parameters, such as individuals that had purchased certain types of medicine by state or had previously made use of Medmate telehealth services. It also created custom audience functions to retarget individuals based on their interaction with the website, and to track individuals that submitted forms and viewed website pages.

Monash's use of tracking pixels

Monash provides fertility treatments and assessments, including assisted reproductive treatments. It had various pixels deployed during the period of time that was the focus of the OAIC's investigation. These collected information about individuals' engagement with the Monash website, including when an individual viewed a page, the specific content they engaged with, and whether they began or submitted a webform, or booked an appointment. One pixel also enabled full URLs visited, IP addresses, and device and browser information to be transmitted to the pixel provider when users visited the website. A custom pixel was enabled on URLs containing webforms, meaning that where an individual navigated to a page relating to a specific IVF-related service, and began or completed a form on that page, that behaviour was individually tracked and transmitted. The Advanced Matching feature on the pixel, which enabled the matching of website visitors to the pixel provider's user profiles, was also active for an unknown period. The investigation identified that the URLs transmitted from the tracking pixels included pages relating to specific fertility and reproductive health services sought.

During the relevant period, Monash paid for online advertising campaigns on a number of pixel provider platforms and other digital advertisers that used the tracking pixel data collected from the website. These campaigns had target audience and demographic parameters, including individuals' interests, age range, location, and prior visits to the website within a specified period; as well as excluded audiences, based on individuals' prior interaction with Monash or particular webpages on the website.

In the twelve months before the investigation commenced, Monash ran campaigns on a social media platform relating to specific fertility and reproductive health services, including egg donation and freezing, endometriosis, IVF and sperm donation. It also created custom audience lists using other sources of customer information, including names, email addresses, phone numbers, gender and location, and uploaded these to the pixel provider's dashboard to retarget advertising to existing or known customers.

What is personal information and sensitive information? 

Individuation and personal information—what is reasonably identifiable?

A key issue for businesses is whether data collected by tracking pixels and cookies constitutes personal information under the Act.

Medmate and Monash submitted to the Commissioner that individuals were not reasonably identifiable from the tracking pixel data because the organisations did not have access to direct identifiers such as names, passport numbers or dates of birth. The Commissioner rejected this argument, noting that the definition of personal information under the Act does not expressly require that an individual be specifically identifiable by direct identifiers. 

She instead adopted a new formulation of 'reasonably identifiable' focused on individuation rather than identification.  

In the Commissioner's view, an individual is 'reasonably identifiable' when an entity can single out or distinguish that individual from others in a way that affects their rights or interests.  

Crucially, this means an organisation does not need to know, or be able to reasonably identify, the name of an individual (or other direct identifiers) to have collected their personal information. It is sufficient that the entity can use the collected information to treat that person differently on an individualised basis (such as personalised advertisements).  

Applying this standard, the Commissioner found that both organisations had collected personal information from individuals via the deployment of tracking pixels. Specifically:

  • Medmate had deployed tracking pixels that captured data about website users' activity, including searches for particular medications and conditions. Pixel providers matched this data against their own platform data to identify users who were logged into their accounts. Those users were then served targeted health-related advertising based on their prior activity on Medmate's website.
  • Monash had deployed tracking pixels that captured data about users' browsing behaviour on its website. That data was shared with pixel providers, which used it to serve IVF-related advertisements to female visitors aged 25–45 who had visited IVF-related pages within the preceding days and were logged into their accounts on the provider's platform.

In each case, the ability to deliver individualised advertising based on tracking pixel data was sufficient to satisfy the 'reasonably identifiable' threshold, even without the identity of targeted individuals being known to Medmate or Monash.

This interpretation of 'reasonably identifiable' goes materially further than many practitioners and organisations had understood, and the implications are significant. Organisations that have previously assumed their use of pixel data does not engage the Act—whether because they do not 'know' the individuals behind the data, or because they reviewed their practices against the November 2024 guidance and concluded they were compliant—should urgently reassess that position.

The broader implications may be even more significant. The Privacy Act Review Report specifically contemplated that individuation should remain outside the definition of personal information,2 citing concerns about limiting valuable uses of data in ways that do not harm or affect the individuated person. There were also practical questions raised about how the Act's remaining protections are to apply to such data—eg how organisations are to respond to information access requests or complaints, or notify individuals of a data breach, in circumstances where the organisations are not in fact able to identify the individual.

The Commissioner's adoption of individuation as the operative test for 'reasonably identifiable' moves the Australian position closer to the European approach to personal data protection under the General Data Protection Regulation (the GDPR). The GDPR defines 'personal data' (the equivalent of personal information under the Act) broadly, as any information relating to an identified or identifiable natural person, including indirect identifiers. European regulatory guidance has long recognised that the ability to 'single out' an individual—ie to distinguish them from others and treat them differently—is itself sufficient to render data personal data, even where the individual's name and/or other direct identifiers are not known. By adopting individuation as the threshold for 'reasonably identifiable', the Commissioner has brought the Australian position materially closer to this European standard without the legislative reform that would ordinarily be expected to effect such a change.

While the Privacy Act Review Report (and the Government's Response) agreed in principle to making changes to the targeting of individuals using personal information, the Commissioner appears to have decided not to wait for the long-promised legislative reform.

The Commissioner acknowledged that 'the acts and practices under scrutiny in th[ese] matter[s] give rise to potentially novel applications of the term "reasonably identifiable" in the context of advanced tracking technologies'.3

In the Commissioner's view, the individuation interpretation of reasonably identifiable is supported by the Act's principles-based nature and the fact that the APPs are technology neutral, allowing concepts to adapt to changing technologies and evolve with the times.   

Having accessed a health provider's website is likely to be sensitive information

In the current regulatory environment, the Commissioner is taking a broad view of what constitutes sensitive information.

The Commissioner found that information relating to an individual's engagement with a health service provider's website is sensitive information, and that both organisations had collected sensitive information of this nature via tracking pixels. In arriving at this conclusion, the Commissioner specifically referred to:

  • Use of information: Both Medmate and Monash had used the information collected via tracking pixels to retarget ads for health-related services to individuals that had previously visited their respective websites. The Commissioner considered this to be indicative of them having formed an opinion about the individual's health, a form of sensitive information.
  • Kinds of information collected: The Commissioner found that the collection of particular kinds of information from individuals via tracking pixels amounted to the collection of health information (a form of sensitive information). In particular, the Commissioner considered that information about whether individuals submitted registration or contact forms (Monash), or submitted applications, requested contact, viewed particular content, added items to their cart, initiated checkout or made a purchase (Medmate), indicated further steps towards obtaining health services and was itself health information.

The determinations establish that collection of information about an individual's engagement with a health service provider's website can be sensitive information, on the basis that it either:

  • reveals health information directly; or
  • allows an inference or opinion to be formed about an individual's health, as website engagement demonstrates an individual's interest in the provision of a particular health-related service.

This finding has considerable practical implications for any health service provider operating a website. It means that the mere act of visiting a health-related website—including viewing pages about services, medications or conditions—is likely to be treated as health (and therefore sensitive) information for the purposes of the Act, attracting the higher protections that apply to sensitive information.

Responsibility rests with the entity deploying the tracking pixel 

Although the tracking pixel data was held on the pixel providers' servers, the Commissioner found that Medmate and Monash had both collected the personal information via tracking pixels, because they each had control and authority over the collection of the tracking pixel data. This was because:

  • The collection would not have occurred had each entity not actively commissioned the tracking pixels through its selected pixel providers.
  • Each entity exercised control over the deployment and embedment of tracking pixels on the website.
  • After initial set-up, each entity could customise the tracking pixel to adjust the information collected.

This means that collection does not require the collector to have physical possession of the personal information. In the case of tracking pixels, an entity that has control over their deployment and customisation is deemed to have collected any personal information contained within the tracking pixel data.

As such, it is the responsibility of the organisation deploying a third-party tracking pixel to ensure it is configured and used in compliance with the Act. All businesses that have embedded tracking pixels on their websites should understand how they are using them and cookies, identify the potential privacy risks involved and implement measures to mitigate them. The Medmate and Monash determinations make clear that businesses are themselves the holders of tracking pixel data for the purposes of the Act, even where the pixel providers have physical possession of the data.

How to comply with APP 3 and APP 5 when using pixels

A generic cookies consent banner is not enough when collecting sensitive information

As Medmate and Monash were collecting sensitive information, they were required under APP 3.3 to obtain individuals' consent.

The determinations indicate that it will be challenging for organisations to successfully rely on implied consent in relation to the collection of sensitive information via tracking pixels.

The Commissioner was not satisfied that a cookies consent pop-up Medmate later introduced, which stated ‘[w]e use cookies to enhance your browsing experience, serve personalised ads or content, and analyse our traffic’, constituted valid consent. This was because:

  • Individuals were not adequately informed: the consent pop-up did not refer to tracking pixels (which are distinct from cookies) or pixel providers, and individuals were unlikely to be adequately informed about the implications of providing consent, or the collection, use or disclosure of their personal information via tracking pixels.
  • Consent was not specific: given sensitive information was involved, the level of specificity required was higher, and individuals should have been informed of the proposed collection, use or disclosure of their personal information.

The determination indicates that a generic cookies consent pop-up will be insufficient where sensitive information is collected via tracking pixels. Organisations that collect sensitive information in this way must implement consent mechanisms that are express, informed and specific, and that address tracking pixel use specifically, rather than relying on generic cookies consent language.

A privacy policy alone does not satisfy notification obligations

The Commissioner found that both Medmate and Monash failed to comply with APP 5.1, which requires an entity to take steps that are reasonable in the circumstances to notify individuals of specified matters in APP 5.2 at or before the time of collecting personal information, or, if not practicable, as soon as practicable after collection.

The Commissioner considered it was reasonable for Medmate and Monash to take steps to notify individuals of:

  • the fact that the entity was collecting individuals' sensitive information via tracking pixels and the circumstances of that collection (APP 5.2(b));
  • the purposes for which the entity collected the personal information—ie advertising and retargeting (APP 5.2(d)); and
  • the fact that pixel data, from which an individual's health information could be inferred, was disclosed to pixel providers (APP 5.2(f)).

In considering whether Medmate and Monash took reasonable steps, the Commissioner made the following observations that will be widely applicable to businesses that use tracking pixels:

  • The publication of a privacy policy in isolation is insufficient to notify individuals of the collection of their personal information.
  • An organisation's privacy policy should contain accurate, up-to-date information regarding the use of tracking pixels.
  • Where tracking pixels are used upon entering a website, individuals should be notified when they enter.
  • Notification could take the form of a banner or pop-up, which should provide notice of relevant APP 5.2 matters or direct individuals to where more detailed information is located.

Businesses should ensure that they have appropriate measures in place to notify individuals of the use of tracking pixels and cookies to collect personal information, and that they are not relying on their privacy policy alone to notify individuals. At a minimum, organisations should make sure to notify individuals:

  • that their personal information (or sensitive information where appropriate) is being collected via tracking pixels and the circumstances of collection;
  • of the purposes for which they collect the personal information; and
  • that this personal information was routinely disclosed to pixel providers.  

Retargeting advertising may qualify as direct marketing

APP 7.1 prohibits organisations from using personal information about individuals for the purpose of direct marketing without their consent. Direct marketing involves the use and/or disclosure of personal information to communicate directly with an individual to promote goods and services, and may occur through a variety of channels including online advertising.

Both Medmate and Monash disputed that APP 7.1 applied to their use of tracking pixel data. They sought to characterise it as for the purpose of general advertising, not direct marketing, on the basis that the advertising campaigns that relied on tracking pixel data were targeted at general, non-personally identifiable audiences.

The Commissioner disagreed, as:

  • Medmate and Monash's use of tracking pixels allowed them to retarget marketing advertisements to specific individuals that used pixel provider platforms.
  • Medmate had retargeted individuals based on their behaviour on their website, to remind them of incomplete bookings and promote relevant health services on the pixel provider platforms.

Importantly, this means that businesses may be considered to be engaging in direct marketing for the purposes of the Act even where recipients are not identifiable by the business, provided that it is targeting specific individuals via pixel providers.

Actions you can take now

The two determinations highlight the need for robust governance and transparency when implementing tracking pixels and cookies. Key steps for organisations include:

  • Conduct an audit of your use of tracking pixels and cookies: Organisations should audit their arrangements regarding cookies and tracking pixels to ensure they have clear visibility of all active tracking pixels and cookies on their websites, including which pixel and cookies providers are used, what data is collected, whether advanced matching or similar features are enabled, and how collected data is used and disclosed. Organisations should especially consider whether the pixels would be considered to collect personal (or sensitive) information and if there is any use for direct marketing.
  • Review and (if required) uplift your privacy policy and collection notices: Organisations should ensure their privacy policies and collection notices contain transparent and up-to-date information regarding the use of tracking pixels and cookies to collect, use and disclose personal information, including any direct marketing purposes.
  • Review and (if required) implement or uplift your consent mechanisms: Organisations that collect sensitive information via tracking pixels should ensure they have implemented consent mechanisms that are directed at tracking pixel use specifically, not just cookies.
  • Strengthen governance and design: Conduct privacy impact assessments before tracking pixels and cookies are deployed, and implement formal, documented policies and procedures to ensure any changes to the use of cookies and pixels is subject to review for Act and APP compliance. These determinations and the OAIC tracking pixel guidance are clear that organisations should not adopt a 'set and forget' approach. They should conduct regular reviews of the tracking technologies deployed on their websites to ensure they are configured appropriately, and that their ongoing use remains reasonable and necessary in the circumstances.