HomeCompliance risk

Compliance risk

OAIC draws a hard line on tracking pixels and sensitive data

OAIC has confirmed, through two determinations published on 24 June 2026, that Medmate and Monash IVF interfered with privacy by using third-party tracking pixels on health-related websites to collect sensitive information and target advertising. The…

OAIC determination puts insider privacy risk back in the spotlight

The OAIC found an organisation breached APP 11.1 after an employee accessed customer personal information without authorisation. With the Medibank civil penalty case before the Federal Court, OAIC enforcement on internal access controls is active and escalating.

Pricing governance is a customer trust control, not just a marketing decision

Coles, Woolworths and IAG each faced regulatory action over pricing for the same reason: a gap between what customers were told and what the pricing system actually did. This post uses those cases to ask whether your organisation can show how pricing decisions are owned, challenged and tested for customer outcomes — before a regulator does it for you.

Regulatory pressure often starts as an audit response before it becomes a broader operating expectation

The OAIC has published a formal response to the ANAO’s performance audit on administration of the Freedom of Information Act, signalling a review of FOI regulation, guidance, priorities and capabilities.

Transparency guidance for automated decision making and AI

OAIC has opened consultation on guidance for transparency in automated decision making, following the Privacy and Other Legislation Amendment Act 2024. The consultation closes on 15 June 2026 and is aimed at shaping guidance for…

Recent Privacy Awareness Week puts privacy complaints and dispute resolution under the spotlight

The OAIC Privacy Awareness Week centred on complaint handling, dispute resolution and building trust through privacy practice.