This is not just another privacy reminder. The OAIC has now shown that third-party tracking pixels on sensitive-service websites can cross the line into privacy interference where they collect sensitive information and feed targeted advertising.
Published on 24 June 2026, the Privacy Commissioner’s determinations against Medmate Australia Pty Ltd and Monash IVF Pty Ltd conclude a year-long investigation into how those websites collected sensitive information. The decision matters well beyond the two providers: it speaks directly to any APP entity using adtech, analytics or tracking pixels in ways that may touch health or other sensitive information.
The Board-Level Take
The practical message is simple. If your digital channels are collecting sensitive information through tracking pixels, consent is not optional. The OAIC has tied the use of advanced online tracking to the ordinary requirements of the Privacy Act 1988 (Cth), and that means privacy, marketing and technology teams now need to be aligned on where pixels are deployed, what they collect and what evidence exists to support consent.
For boards and executives, this is a governance issue as much as a privacy issue. The risk is not just regulatory scrutiny after a complaint or investigation. It is also weak control over vendor tools, unclear ownership between digital, legal and compliance teams, and incomplete visibility over how sensitive data may be flowing through a website stack.
What the OAIC Is Really Signalling
Tracking pixels are no longer a low-risk marketing afterthought
The Commissioner’s decision establishes that using tracking pixels on health-related websites to track visitors and target them with social media advertising can amount to collecting sensitive information. That matters because sensitive information is treated differently under privacy law and requires a higher standard of handling.
For organisations, the key implication is that pixels, tags and similar tools need to be governed as part of the privacy risk framework, not left to campaign teams alone. The question is no longer whether the technology is common. It is whether the way it is configured, disclosed and consented to stands up under regulatory scrutiny.
Consent, not convenience, is the control point
The OAIC has said website providers must obtain consent where tracking pixels are used to collect sensitive information. In practice, that means leaders should be testing whether their consent design is clear, informed and capable of being evidenced if challenged.
If the organisation cannot explain what the pixel collects, why it is there, who receives the data and how consent is obtained, then the control environment is likely too weak for a sensitive-data use case.
The inspection report suggests this is a broader sector issue
Alongside the determinations, the OAIC published a report on its inspection of 50 health service provider websites. That is an important sign that the regulator is looking beyond two named entities and into the wider digital ecosystem.
For risk teams, this should trigger a broader review of website architecture, marketing tags, privacy notices, third-party scripts and governance over changes to digital assets. The exposure often sits across multiple teams, which is exactly why it can be missed.
Questions Risk and Governance Teams Should Ask Now
- Where are third-party tracking pixels or similar tools deployed across our websites and landing pages?
- Could any of those tools collect sensitive information, directly or indirectly, from user behaviour on our sites?
- Do we have a clear and evidenced consent process for any sensitive-data use case?
- Who owns approval of new tags, pixels and vendor scripts, and is privacy sign-off mandatory?
- Are our privacy notices, consent prompts and vendor arrangements consistent with how data is actually being collected and used?
- If asked by the regulator, what evidence could we produce to show the privacy risk has been assessed and controlled?
Why This Needs Attention Now
The release is current and operationally important because it pairs a formal determination with practical inspection findings and guidance. That combination usually means the regulator is not simply clarifying the law in the abstract; it is setting expectations for how organisations should already be managing this risk.
For teams that rely on digital acquisition, analytics or targeted advertising, the work starts now: inventory the tools, assess the data flows, test consent, tighten approvals and document the rationale. Waiting for a complaint or investigation is the expensive option.
Turning Regulatory Signal Into Board-Ready Action
The Innovation of Risk Reading Room tracks OAIC, APRA, ASIC and other regulatory developments as they move from guidance to enforcement.
If your board or risk team wants a practical way to assess privacy, cyber and operational risk maturity, and to identify where evidence is thin before a regulator does, that is the place to start.

