OAIC draws a hard line on tracking pixels and sensitive data

This is not just another privacy reminder. The OAIC has now shown that third-party tracking pixels on sensitive-service websites can cross the line into privacy interference where they collect sensitive information and feed targeted advertising.

Published on 24 June 2026, the Privacy Commissioner’s determinations against Medmate Australia Pty Ltd and Monash IVF Pty Ltd conclude a year-long investigation into how those websites collected sensitive information. The decision matters well beyond the two providers: it speaks directly to any APP entity using adtech, analytics or tracking pixels in ways that may touch health or other sensitive information.

The Board-Level Take

The practical message is simple. If your digital channels are collecting sensitive information through tracking pixels, consent is not optional. The OAIC has tied the use of advanced online tracking to the ordinary requirements of the Privacy Act 1988 (Cth), and that means privacy, marketing and technology teams now need to be aligned on where pixels are deployed, what they collect and what evidence exists to support consent.

For boards and executives, this is a governance issue as much as a privacy issue. The risk is not just regulatory scrutiny after a complaint or investigation. It is also weak control over vendor tools, unclear ownership between digital, legal and compliance teams, and incomplete visibility over how sensitive data may be flowing through a website stack.

What the OAIC Is Really Signalling

Tracking pixels are no longer a low-risk marketing afterthought

The Commissioner’s decision establishes that using tracking pixels on health-related websites to track visitors and target them with social media advertising can amount to collecting sensitive information. That matters because sensitive information is treated differently under privacy law and requires a higher standard of handling.

For organisations, the key implication is that pixels, tags and similar tools need to be governed as part of the privacy risk framework, not left to campaign teams alone. The question is no longer whether the technology is common. It is whether the way it is configured, disclosed and consented to stands up under regulatory scrutiny.

The OAIC has said website providers must obtain consent where tracking pixels are used to collect sensitive information. In practice, that means leaders should be testing whether their consent design is clear, informed and capable of being evidenced if challenged.

If the organisation cannot explain what the pixel collects, why it is there, who receives the data and how consent is obtained, then the control environment is likely too weak for a sensitive-data use case.

The inspection report suggests this is a broader sector issue

Alongside the determinations, the OAIC published a report on its inspection of 50 health service provider websites. That is an important sign that the regulator is looking beyond two named entities and into the wider digital ecosystem.

For risk teams, this should trigger a broader review of website architecture, marketing tags, privacy notices, third-party scripts and governance over changes to digital assets. The exposure often sits across multiple teams, which is exactly why it can be missed.

Questions Risk and Governance Teams Should Ask Now

  • Where are third-party tracking pixels or similar tools deployed across our websites and landing pages?
  • Could any of those tools collect sensitive information, directly or indirectly, from user behaviour on our sites?
  • Do we have a clear and evidenced consent process for any sensitive-data use case?
  • Who owns approval of new tags, pixels and vendor scripts, and is privacy sign-off mandatory?
  • Are our privacy notices, consent prompts and vendor arrangements consistent with how data is actually being collected and used?
  • If asked by the regulator, what evidence could we produce to show the privacy risk has been assessed and controlled?

Why This Needs Attention Now

The release is current and operationally important because it pairs a formal determination with practical inspection findings and guidance. That combination usually means the regulator is not simply clarifying the law in the abstract; it is setting expectations for how organisations should already be managing this risk.

For teams that rely on digital acquisition, analytics or targeted advertising, the work starts now: inventory the tools, assess the data flows, test consent, tighten approvals and document the rationale. Waiting for a complaint or investigation is the expensive option.

Turning Regulatory Signal Into Board-Ready Action

The Innovation of Risk Reading Room tracks OAIC, APRA, ASIC and other regulatory developments as they move from guidance to enforcement.

If your board or risk team wants a practical way to assess privacy, cyber and operational risk maturity, and to identify where evidence is thin before a regulator does, that is the place to start.

More from the Reading Room

Regulator sharpens the warning on facial recognition

The OAIC has updated its facial recognition guidance for APP entities using biometric technology in high-volume, publicly accessible retail spaces. The update reflects the ART’s March 2026 Bunnings decision and reinforces that each deployment needs…

Risk Maturity in Action: Turning Customer Promises into Reliable Outcomes

Two recent ASIC matters provide a useful opportunity to think differently about risk management. They can be read as stories about compensation, penalties and compliance...

APRA grants Revolut an ADI licence — a reminder that prudential entry standards still matter

APRA has granted an authorised deposit-taking institution (ADI) licence to Revolut. This is a substantive licensing decision and a current prudential development for boards, risk teams and governance functions watching new entrants into the banking…

The Qantas privacy finding: a positive lesson in third-party oversight

A serious data breach does not automatically mean governance failed. The more important question is whether an organisation can demonstrate that it understood the risks,...