What happened
Late in 2024, the Office of the Australian Information Commissioner (OAIC) swept 50 Australian health-sector websites to see what tracking technology they were quietly running. The results, published by Privacy Commissioner Carly Kind, were stark: 96% of the sites used some form of tracking technology, and 52% had a third-party advertising pixel — code from Meta, TikTok or a similar platform, dropped in to measure ad performance, that fires the moment a page loads and reports back to the platform.
One health provider, contacted after the sweep, told the OAIC it had 50 active tracking pixels it had never authorised and didn't know were there — including one still quietly sending visitor data to a Facebook page the business had disabled years earlier, planted by a third-party web vendor.
The sweep led to formal investigations into two providers: fertility clinic operator Monash IVF and telehealth platform Medmate. According to reporting on the OAIC's findings, Monash IVF had run tracking pixels since July 2012 and could not account for when its Meta "Advanced Matching" feature — which transmits hashed names, email addresses and phone numbers straight from form submissions — had been switched on, or for how long. It had also uploaded Custom Audience lists containing customers' names and contact details to Meta, without being able to confirm the source of that data. Medmate, meanwhile, had a TikTok pixel that transmitted full page-URL strings containing specific health details — searches that identified contraception, urinary tract infection treatment and bacterial vaginosis assessments.
The OAIC's determinations, handed down 11 June 2026, found both businesses had breached Australian Privacy Principles 3.3 (collection of sensitive information), 5.1 (notifying individuals what's being collected) and 7.1 (using personal information for direct marketing without consent). The Medmate ruling is the more instructive one for any business with a cookie banner already in place: Medmate had introduced a consent pop-up in the weeks before the investigation began, stating it used cookies "to enhance your browsing experience, serve personalised ads or content, and analyse our traffic." The OAIC found that wording did not constitute valid consent for the tracking pixels, because it referred only to cookies — never mentioning pixels, Meta or TikTok by name, or explaining that data was leaving the site to an external platform. For consent to be valid, the Commissioner held, it must be informed, voluntary, current and specific — a generic reference to "cookies" or "analytics" in a privacy policy or pop-up isn't specific enough to cover a tracking pixel.
Where you stand under the Privacy Act
The Privacy Act doesn't bind every Australian business the same way, so it's worth being precise about who these determinations reach directly today, versus who they should still prompt into action.
Who's covered right now
- Health service providers, regardless of turnover. The OAIC defines this broadly — allied health, pharmacies, clinics, complementary therapists, childcare centres and private schools are all included. Monash IVF and Medmate were both bound by the Act on this basis alone, and so is any similar business, however small.
- Businesses that have exceeded $3 million annual turnover in any year since 2002. The Privacy Act generally applies to you, so the same notification (APP 5) and direct-marketing (APP 7) obligations these determinations turned on are already live for your site's tracking too.
- Smaller, non-health businesses under $3 million turnover are currently outside the Privacy Act under the small-business exemption — that hasn't changed. A proposal to remove this exemption is under discussion as part of Tranche 2 privacy reform, but it is not law and no start date has been set. Don't treat it as a current obligation. That said, an undisclosed pixel is still the kind of thing that damages trust when a customer notices it — regardless of which side of $3 million you sit on.
Why it matters even if you're technically exempt
Most small-business tracking pixels aren't malicious — they're usually installed by a marketer or agency chasing better ad performance, then forgotten. That's exactly the pattern the OAIC found: pixels nobody currently at the business remembered authorising, running for years, quietly reporting page visits, form fills and sometimes names and emails to an advertising platform. A generic "we use cookies" banner was written for a different, older problem (browser cookies you can clear) and simply wasn't built to disclose what a pixel actually does.
The fix here is genuinely cheap. Unlike a lot of compliance work, this doesn't need a lawyer or a rebuild — it needs someone to open the site, see what's actually firing, and update two documents to say so plainly.
What to check on your own site this week
Find out what's actually running
What
List every tracking pixel, tag and analytics script your site loads — not just "we have Google Analytics," but specifically a Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, or anything a marketer, agency or plugin has added over the years. If someone else manages your site or marketing, ask them directly: "Send me a list of every tracking pixel currently firing on our site."
Why it matters
The OAIC's sweep found a health provider running 50 pixels it had never authorised and didn't know existed. You can't disclose what you don't know is there.
Read your own consent notice like a stranger would
What
Open your site in a private/incognito browser window and read whatever cookie or consent notice appears. Does it specifically mention tracking pixels, Meta, TikTok or similar platforms by name — or does it just say something generic like "we use cookies to improve your experience"?
Why it matters
The Medmate determination found near-identical generic wording invalid for exactly this reason. This isn't a cautious interpretation of the rule — the regulator has now formally ruled on this scenario.
How to go further
If your consent tool supports categories, add a line naming your advertising pixels and what they do — e.g. "we use a Meta Pixel and TikTok Pixel for advertising; declining will stop these from loading."
Check your privacy policy names the tracking, not just "cookies"
What
Search your privacy policy for the words "pixel," "Meta," "Facebook," "TikTok," "advertising" and "third party." If none of those appear, your policy likely has the same gap the OAIC flagged.
Why it matters
APP 5 requires you to notify people what's being collected and why. A policy that only mentions "cookies" in the abstract doesn't do that for a pixel sending data to an external advertising platform.
If you handle sensitive information, treat pixels as opt-in, not default
What
Health, legal, financial and similar businesses should follow the OAIC's own advice here: audit what each pixel actually collects, minimise it, and consider not running third-party pixels at all on pages where sensitive detail — a specific service, condition or matter type — could appear in the page path or content.
Why it matters
Medmate's TikTok pixel transmitted full page URLs that named specific health conditions and medications. That's the failure mode the OAIC is most concerned about, and it's avoidable by not sending sensitive pages to a pixel in the first place.
Put a recurring check in the calendar
What
Pixels get added by a new agency, a new campaign or a new plugin — and rarely get reviewed again. A short quarterly check ("what's actually firing on our site right now, and does our privacy notice say so?") closes that gap before it becomes a surprise.
Why it matters
Monash IVF's pixel had been running, unreviewed, for over a decade. Nobody sets out to be in that position — it happens by simply never checking again.
Where a scan fits in
The AegorIQ Scorecard — including the free tier — detects the analytics and advertising tools actually loading on your site and checks whether a consent mechanism is present, exactly the two elements at the centre of these determinations. Paid tiers name each tool we find (so you know it's specifically a Meta Pixel or TikTok Pixel, not a guess), and flag it plainly when tracking is running without a consent banner at all. What a scan can't do is read the exact wording of your consent notice and judge whether it's specific enough to name Meta or TikTok — that's a judgement call, which is exactly what a human review in our Expert tier adds. Every check we run, and what we don't check, is published here.
Sources
- OAIC — Tracking pixels and privacy obligations (guidance, published 4 November 2024)
- iTnews — OAIC sweep unearths health sites' covert user tracking, 24 June 2026 (sweep results, Monash IVF/Medmate determination details, 11 June 2026 determination date)
- Bird & Bird — Tiny Pixels, Bigger Problems: what the OAIC's tracking pixel determinations mean for your business
- Allens — Tracking pixels, targeted advertising and compliance — lessons from recent OAIC determinations
- OAIC — Small business and the Privacy Act ($3 million turnover threshold and health-provider coverage)