The Office of the Australian Information Commissioner (OAIC) declared in 2024 that the use of third party tracking pixels on websites was an area of concern and regulatory focus. Investigations commenced later that year and have culminated in two determinations handed down in June 2026 against health service providers Medmate Australia Pty Ltd (Medmate)[1] and Monash IVF Pty Ltd (Monash IVF).[2]
The two determinations relate to the use of third party social media tracking pixels on healthcare websites and the collection, holding and sharing of personal information (including sensitive information) by the healthcare providers. These determinations follow the OAIC’s earlier Bunnings and RentTech determinations,[3] which also considered what it means to ‘hold’ personal information. Together, these four determinations provide important clarification of the OAIC’s position on two keystones of Australia’s privacy laws under the Privacy Act 1988 (Cth) (Privacy Act) and its Australian Privacy Principles (APPs): what constitutes ‘personal information’ and when does an APP entity ‘hold’ it.
Tracking pixels collecting ‘personal information’
A tracking pixel is a small piece of code, often made available by social media organisations such as Meta or TikTok, that an organisation embeds in its website. When a visitor loads a page from that website, the pixel transmits data to the pixel platform’s servers, including: URLs visited, time on page, device and IP information, form inputs and cart additions. The pixel platform can then match that data against the individual’s social media profile, allowing it to retarget advertisements to those individuals or build audience profiles.
The OAIC’s broader review of 50 health provider websites that preceded the Medmate and Monash IVF Determinations exposed a pattern: third party tracking pixels were commonly installed on regulated entity’s websites, whether by marketing agencies or web development teams, as part of digital advertising campaigns, without proper consideration of the organisation’s privacy obligations. This was due to a commonly held view that data collected by tracking pixels (and other website technology) is “anonymous”.
This was the response from both Medmate and Monash IVF to the OAIC’s investigations: they did not believe the information collected by the social media tracking pixels on their websites was ‘personal information’, as neither organisation could identify individuals by direct identifiers (such as name). However, the OAIC found that the absence of direct identifiers did not prevent the information from being personal information regulated by the Privacy Act.
Further, the information collected by the tracking pixels was sensitive information; a category of personal information that requires a higher standard of care under the APPs. The OAIC found in both determinations that individuals visiting healthcare websites are often in circumstances of vulnerability and researching medical conditions (such as seeking fertility treatment, exploring mental health support or purchasing prescription medication). The mere fact that the individuals are visiting websites offering health services means any information collected about them by the tracking pixels will be health information (and therefore sensitive information for the purposes of the Privacy Act). As such, active consent is required to collect sensitive information in this context, and in the case of Medmate and Monash IVF, the required consents were not obtained.
Medmate and Monash IVF determinations
Medmate is an online telehealth and prescription platform whose website operated Meta and TikTok tracking pixels.[4] Meta’s Advanced Matching feature was also enabled, collecting hashed contact details from individuals and matching them to their social media profiles even when they were not logged in. The TikTok pixel transmitted full page URLs that in some cases disclosed the specific health condition or medication an individual was researching. Medmate ran targeted advertising campaigns on Meta and TikTok during the relevant period, including campaigns directed at individuals who had purchased particular types of medication or previously sought weight management services.[5]
Monash IVF provides fertility services and treatments,[6] and from as early as July 2012 had deployed tracking pixels on its website, operating up to seven simultaneously at various times during the relevant period. Custom Meta pixels were configured on pages concerning egg freezing, sperm and egg donation, fertility health checks and IVF consultations. Monash IVF used that data to run retargeting campaigns on Meta, directing fertility-related advertisements at individuals based on their browsing behaviour, age, gender and prior interactions with specific pages. Custom Audience lists containing names, email addresses, phone numbers and gender were also uploaded directly to Meta.[7]
Neither entity conducted any privacy impact assessment before deploying its pixels.[8]
Both determinations considered the same three issues:
- collection of sensitive information without consent (APP 3.3);
- inadequate notification of individuals at the time of collection (APP 5.1); and
- use of sensitive information for direct marketing without consent (APP 7.4).
What the Medmate and Monash IVF determinations found
The Privacy Commissioner made five significant findings:
- Visiting a health website is itself health information
In both cases, the Commissioner found that engaging with a health or fertility services website, including browsing sub-pages about specific conditions, medications, treatment types or appointment types, constitutes health information under the Privacy Act, because it reveals or permits an inference to be formed about an individual’s health.[9] Simply visiting Monash IVF’s egg-freezing or endometriosis pages, or Medmate’s online prescription sub-domains for contraception or UTI treatment, was sufficient. - Reminder that personal information is not limited to a named individual
Both entities argued they did not know the person targeted through the use of the tracking pixels and could not identify them from pixel data. Consistent with earlier OAIC determinations,[10] the Commissioner rejected that argument, interpreting ‘reasonably identifiable’ broadly:[11] where an organisation can single out and treat an individual differently, including by retargeting them with tailored advertisements, the information is ‘personal information’, even without knowing their name. That is, even if the individual cannot be identified by name, the individual is still ‘reasonably identifiable’ and the data is ‘about’ such reasonably identifiable individual, where the purpose of data collection is to profile and differentially target that individual. This interpretation of ‘personal information’ is reflective of a broader scope that was proposed to be codified in amendments to the Privacy Act under the long-awaited ‘Tranche 2’ reforms; that is, to replace the words ‘about an individual’ in the definition of personal information with ‘relate to an individual’. In the absence of such reform, it is clear the OAIC has demonstrated a willingness to use enforcement to advance interpretations that reform has yet to deliver. - The entity that deploys the pixel ‘holds’ the data.
Even though the data flowed to Meta’s and TikTok’s servers, the Commissioner found that Medmate and Monash IVF ‘held’ the information because they had control and authority over what was collected.[12] They commissioned the pixels, configured them, and instructed the platforms to use the data for retargeted advertising. This is consistent with the OAIC’s earlier determinations in relation to Bunnings and RentTech: a regulated entity that has the right or power to deal with a record containing personal information holds it for the purposes of the Privacy Act, even where the record is stored on third party platform servers. - A generic cookie banner does not constitute consent.
Medmate introduced a cookie consent pop-up in the final weeks of the investigation period. However, the OAIC found this was not sufficient: the cookie consent pop-up did not expressly mention tracking pixels (and pixels are not the same as cookies), did not name Meta or TikTok, and did not explain that information was being disclosed to third party platforms for advertising matching and retargeting.[13] As the tracking pixels collected sensitive information, consent for such collection required that it be informed, voluntary, current and specific, and given with capacity. Just as a privacy policy is not an adequate consent mechanism, most ‘cookie consent’ pop-ups or banners will not satisfy the consent requirements, and adtech vendor claims of “GDPR compliance” will not always mean compliance with the APPs by the regulated entity. Where regulated entities are using tracking pixels on their website to collect sensitive information, close attention to the consent mechanism is required in order to avoid non-compliance with the APPs. - A privacy policy alone does not satisfy APP 5.
Medmate and Monash IVF’s privacy policies mentioned data collection for marketing purposes. However, the OAIC found this was insufficient in these circumstances to meet the regulated entities’ obligation under APP 5.1 to notify individuals at or before the time of collection.[14] A banner or pop-up at the point of website entry is expected.[15]
What this means for your organisation
While the Medmate and Monash IVF determinations related to healthcare websites, the OAIC has indicated that its focus extends to all regulated entities’ use of third party tracking pixels. The principles applied in the Medmate and Monash IVF determinations apply to all regulated entities and reinforce the application of core concepts under the Privacy Act to website technologies: the scope of ‘personal information’, responsibility and accountability for third party vendors, and the ‘notice and consent’ model.
The use of third party tracking pixels is also not limited to regulatory non-compliance risk. The Australian Community Attitudes to Privacy Survey 2026 found that 91% of Australians consider targeted advertising based on sensitive information to be neither fair nor reasonable,[16] and that social media companies were the least trusted sector for privacy, with just 3% of Australians trusting them.[17] For regulated entities, this is increasingly material to brand reputation, social licence and the trust of clients and customers.
The key questions your organisation should be asking now are as follows.
- Do you know what tracking technologies are on your website?
Pixels are commonly added over time and may not be subsequently reviewed. - What does your business do, and does that make browsing data sensitive?
Consider whether simply visiting your website could reveal or permit an inference about an individual’s sensitive information The same logic applies if your URL structures, page names, or form fields reveal the specific matter-type a visitor is enquiring about. - Is sensitive information being fed into advertiser targeting models?
The most significant harm identified in both determinations was not the collection itself, but the downstream use. - Do you have proper consent mechanisms and collection notices?
A published privacy policy and a generic cookie policy may not be sufficient to meet your obligations under the APPs or community expectations. - Not a set and forget: Treat pixel governance as an ongoing obligation
The determinations highlight the need to know what is running on your website and understand what personal information is being collected, held, used and disclosed about your website visitors. Governance around tracking pixel use requires a review and approval process prior to implementation (which could extend to a Privacy Impact Assessment), on-going technical audits and ensuring privacy policies, collection notices and consent mechanisms are kept current and accurate.
[1] Commissioner Initiated Investigation into Medmate Australia Pty Ltd (Privacy) [2026] AICmr 41 (11 June 2026) (Medmate Determination).
[2] Commissioner Initiated Investigation into Monash IVF Pty Ltd (Privacy) [2026] AICmr 40 (11 June 2026) (Monash IVF Determination).
[3] Commissioner Initiated Investigation into Bunnings Group Ltd (Privacy) [2024] AICmr 230 (29 October 2024); Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 (1 April 2026).
[4] Medmate Determination (n 1), [36].
[5] Ibid [42]-[47].
[6] Monash IVF Determination (n 2), [34].
[7] Ibid [36]-[49].
[8] Medmate Determination (n 1), [38]; Monash IVF Determination (n 2), [39].
[9] Medmate Determination (n 1), [83]-[85]; Monash IVF Determination (n 2), [83]-[85].
[10] Commissioner Initiated Investigation into Clearview AI, Inc. (Privacy) [2021] AICmr 54; Clearview AI Inc and Australian Information Commissioner [2023] AATA 1069.
[11] Medmate Determination (n 1), [66]-[70]; Monash IVF Determination (n 2), [66]-[72]; see also Privacy Commissioner v Telstra Corporation Limited [2017] FCAFC 4.
[12] Medmate Determination (n 1), [124]-[128], see also [54]-[58]; Monash IVF Determination (n 2), [122]-[126], see also [53]-[57].
[13] Medmate Determination (n 1), [92]-[94].
[14] Medmate Determination (n 1), [113]-[119]; Monash IVF Determination (n 2), [113]-[116].
[15] Medmate Determination (n 1), [118]; Monash IVF Determination (n 2), [115].
[16] Office of the Australian Information Commissioner, Australian Community Attitudes to Privacy Curvey (ACAPS) 2026 (May 2026) <https://www.oaic.gov.au/__data/assets/pdf_file/0023/264362/ACAPS-2026-Report.PDF>, p 54.
[17] Ibid, p 28.