Introduction

Have you wondered why when you visit a website, the next time you are on Instagram the algorithm suspiciously begins to show you more and more of that same product? We just cannot seem to escape the morning’s ‘perfumes on sale’ search. This is the result of tracking pixels.

Tracking pixels are key players in today’s advertising and can be particularly useful for charities which rely on public fundraising to support their causes. Meta, Google, and countless other players offer customers the chance to embed tracking pixels on their websites that will then be used to target advertisements to customers on social media platforms such as Instagram.

The way they work is that social media platforms such as Meta offer organisations tracking pixels to integrate into their website. The pixels are then linked to a pixel provider dashboard (Dashboard).  Organisations can control the use of the pixels through the Dashboard including controlling what information is collected and create advertisements to retarget their website visitors on the social media platforms.

Charities can, and many already do, harness this technology to better improve client engagement with their causes, keep their charity front of mind and maximise fundraising opportunities.

However, as the adage goes, with great power comes great data privacy responsibility.

At the end of 2024, the Australian Information Commissioner launched an investigation into the use of tracking pixels by health service providers.

This culminated in 2 determinations released in June 2026 against major players in the health industry – Monash and Medmate – with significant consequences on how APP organisations are expected to use tracking pixels.

Facts of the case

Monash and Medmate are health service providers offering fertility services and treatments and health consultations respectively.

The investigations revealed the use of tracking pixels by Monash and Medmate for:

  • collecting website analytics and behaviour data;
  • measuring the effectiveness of advertising campaign and tracking users who visited the website with ads on social media; and
  • generating campaigns for self-described ‘non-personally identifiable audiences’.

The determinations rested on whether the entities breached the following Australian Privacy Principles (APP) in the Privacy Act 1988 (Cth):

APP 3 – collection of solicited personal information;

APP 5 – notification of the collection of personal information; and

APP 7 – direct marketing?

Did the entities collect personal information that was not reasonably necessary for one of its functions or activities in breach of APP3?

To answer whether the collection of personal information breached the requirements in APP3, the Commissioner first considered whether there was a collection of personal information in the first place.

Collection occurs when an entity collects the information for inclusion in a ‘record’.

As described above, information gathered by the tracking pixel is sent to the Dashboard as opposed to an entity’s internal system.

The Commissioner emphasised that the entities had control and authority over whether the pixel data was collected because:

  • the collection only occurred because the entities commissioned the pixels from the pixel providers;
  • the entities exercised and controlled the deployment and embedment of the pixels on their websites; and
  • the entities could customise the pixels to adjust the information collected.

Ultimately, the Dashboard was taken to be an electronic device and therefore a ‘record’ for the purposes of the Privacy Act 1988 (Cth). The Commissioner noted that this was a ‘logical progression of the legislative interpretation’ to keep up with advancing technology.

The next question was whether the data gathered by the pixels was ‘personal information’.

Personal information is ‘information or an opinion about an identified individual, or an individual who is reasonably identifiable:

  • whether the information or opinion is true or not; and
  • whether the information or opinion is recorded in a material form or not.’

Two requirements must be met – the information must be about an individual, and the individual must be ‘reasonably identifiable’ through that information.

The Commissioner held that because the pixels track the behaviour of individuals, the first limb was met.

Regarding whether individuals were ‘reasonably identifiable’, the entities argued that the individuals could not be specifically identified through the information collected by the pixels and therefore they were not ‘reasonably identifiable’.

The Commissioner rejected this argument taking a broad view to the interpretation of ‘reasonably identifiable’.

According to the Commissioner, the phrase is concerned with whether the information allows ‘individuation’:

‘That is to say, the information permits an entity to ‘single out’ or ‘distinguish’ an individual from others in a way that affects an individual’s rights or interests.’

As such, individuals were reasonably identifiable because the tracking pixels allowed the entities to retarget ads to those individuals through social media platforms thereby affecting their rights or interests.

The last preliminary question is whether the personal information collected was also ‘sensitive information’ such that its collection required the consent of the individual unless an exception applied.

Again, taking a wide approach, the Commissioner found that the act of simply engaging with a health service provider’s website itself constitutes sensitive information because it indicates an individual’s interest in a specific health service.

Once the above was determined, the Commissioner readily found that there was a breach of APP 3 because the collection of the sensitive information was done without the consent of the individuals visiting the website.

It is worth noting that had the information merely been personal information, all that would have been required for its collection is that it be ‘reasonably necessary for one or more of the entity’s functions.

The Commissioner accepted that marketing through tracking pixels was reasonably necessary for the provision of health services for a profit. However, the added layer of protection afforded to sensitive information rendered this a moot point.

Did the entities provide notice of collection of personal information to individuals as required under APP 5?

APP 5 requires entities to at or before the time or if not practicable, as soon as practicable after, notify individuals of matters relevant to the collection of their personal information as set out in APP 5.2 or to otherwise ensure that individuals are aware of the matters.

The Commissioner found that Monash limited the disclosure in its privacy policy to cookies and google analytics while Medmate mentioned the use of analytics and marketing providers in its privacy policy.

Regardless of the nuances, both entities were considered to be in breach of APP 5 because individuals were not given notice to the collection of their personal information.

Significantly, the Commissioner again highlighted that a privacy policy is a separate APP (APP 1) and cannot, on its own, be relied on to meet obligations set under APP 5.

As the pixels were embedded on the entities’ websites, a simple solution would have been utilising a pop up on the website notifying website visitors of the collection (and requiring their consent).

Were the entities engaging in direct marketing in breach of APP 7?

APP 7 is a prohibition against direct marketing unless an exception applies.

Key to the exception is the ability for individuals to opt out in the case of personal information and in the case of sensitive information an individual must provide their informed consent before their sensitive information can be used for direct marketing.

Having already determined that the entities collected sensitive information, the relevant question was whether the use of targeted advertising using tracking pixels was a form of direct marketing?

The Commissioner found that tracking pixels allowed the entities to retarget ads to specific individuals on social media platforms including relying on ‘Custom Audience lists’ which amounted to direct marketing.

Accordingly, because the consent of individuals was never sought for this form or marketing, the entities were also found to have breached APP 7.

Key takeaways

The determinations are in line with the Office of the Australian Information Commissioner’s (OAIC) commitment to ensuring privacy protection on the online environment precipitated by rapid technological advancement.

However, they represent an apparent shift in terms of the interpretation of the APPs and application in the technology environment.

The Commissioner began the determinations with a wide reminder to all:

‘all entities that have embedded tracking pixels on their website are encouraged to understand how the product works, identify the potential risks involved and implement measures to mitigate those risks.’

Organisations need to be alive to the privacy assessment and risks arising from the adoption of new technologies and more importantly for charities, adopt a protective governance model.

OAIC released its guideline on tracking pixels and privacy obligations in 2024.[1]

The message coming out of OAIC is clear – technology should not be adopted at a pace that exceeds strong underlying governance structures, and the Commissioner is willing to adopt a flexible approach to interpretation to ensure the protection of individuals’ personal information.

Post-script: more reform coming

On 31 August 2026, the Commonwealth Government released an exposure draft of a bill (Privacy Amendment (Personal Data Protection) Bill 2026: Tranche 2) (Bill) to amend the Privacy Act.

Reponses to the bill are due on 18 September 2026.

Broadly, the bill intends to:

  • shift the requirement for the collection, use and disclosure of personal information from a consent-based model to one where the collection, use or disclosure is ‘fair and reasonable in the circumstances’;
  • expand the definition of personal information to encompass situations where an individual’s name or legal identity is not known but the individual can still be singled out through, for example, characteristics or preferences;
  • introduce new categories of sensitive information including ‘precise geolocation tracking data‘;
  • expand the definition of consent to be:
    • voluntary;
    • informed;
    • current;
    • specific; and
    • unambiguous; and
  • introduce an exception for non-profit organisations (NFP) from requiring consent to collect sensitive information where the information is strictly necessary for their activities and relates to the members of the NFP or individuals in regular contact with the NFP.

[1] https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/tracking-pixels-and-privacy-obligations#section-key-points.