Guides · Privacy & tracking

The privacy regulator just ruled a cookie banner isn't consent for a tracking pixel.

In June 2026 the OAIC handed down determinations against two Australian health businesses over Facebook and TikTok tracking pixels running quietly on their websites. Both businesses had a cookie banner. The regulator ruled that wasn't good enough. Here's what the determinations actually found, who they bind today, and the checks worth doing on your own site this week.

What happened

Late in 2024, the Office of the Australian Information Commissioner (OAIC) swept 50 Australian health-sector websites to see what tracking technology they were quietly running. The results, published by Privacy Commissioner Carly Kind, were stark: 96% of the sites used some form of tracking technology, and 52% had a third-party advertising pixel — code from Meta, TikTok or a similar platform, dropped in to measure ad performance, that fires the moment a page loads and reports back to the platform.

One health provider, contacted after the sweep, told the OAIC it had 50 active tracking pixels it had never authorised and didn't know were there — including one still quietly sending visitor data to a Facebook page the business had disabled years earlier, planted by a third-party web vendor.

The sweep led to formal investigations into two providers: fertility clinic operator Monash IVF and telehealth platform Medmate. According to reporting on the OAIC's findings, Monash IVF had run tracking pixels since July 2012 and could not account for when its Meta "Advanced Matching" feature — which transmits hashed names, email addresses and phone numbers straight from form submissions — had been switched on, or for how long. It had also uploaded Custom Audience lists containing customers' names and contact details to Meta, without being able to confirm the source of that data. Medmate, meanwhile, had a TikTok pixel that transmitted full page-URL strings containing specific health details — searches that identified contraception, urinary tract infection treatment and bacterial vaginosis assessments.

A cookie pop-up that says "we use cookies to improve your experience" does not tell a visitor that a Meta or TikTok pixel is reading their page path and reporting it to that platform. The regulator has now formally said so.

The OAIC's determinations, handed down 11 June 2026, found both businesses had breached Australian Privacy Principles 3.3 (collection of sensitive information), 5.1 (notifying individuals what's being collected) and 7.1 (using personal information for direct marketing without consent). The Medmate ruling is the more instructive one for any business with a cookie banner already in place: Medmate had introduced a consent pop-up in the weeks before the investigation began, stating it used cookies "to enhance your browsing experience, serve personalised ads or content, and analyse our traffic." The OAIC found that wording did not constitute valid consent for the tracking pixels, because it referred only to cookies — never mentioning pixels, Meta or TikTok by name, or explaining that data was leaving the site to an external platform. For consent to be valid, the Commissioner held, it must be informed, voluntary, current and specific — a generic reference to "cookies" or "analytics" in a privacy policy or pop-up isn't specific enough to cover a tracking pixel.

Where you stand under the Privacy Act

The Privacy Act doesn't bind every Australian business the same way, so it's worth being precise about who these determinations reach directly today, versus who they should still prompt into action.

Who's covered right now

  • Health service providers, regardless of turnover. The OAIC defines this broadly — allied health, pharmacies, clinics, complementary therapists, childcare centres and private schools are all included. Monash IVF and Medmate were both bound by the Act on this basis alone, and so is any similar business, however small.
  • Businesses that have exceeded $3 million annual turnover in any year since 2002. The Privacy Act generally applies to you, so the same notification (APP 5) and direct-marketing (APP 7) obligations these determinations turned on are already live for your site's tracking too.
  • Smaller, non-health businesses under $3 million turnover are currently outside the Privacy Act under the small-business exemption — that hasn't changed. A proposal to remove this exemption is under discussion as part of Tranche 2 privacy reform, but it is not law and no start date has been set. Don't treat it as a current obligation. That said, an undisclosed pixel is still the kind of thing that damages trust when a customer notices it — regardless of which side of $3 million you sit on.

Why it matters even if you're technically exempt

Most small-business tracking pixels aren't malicious — they're usually installed by a marketer or agency chasing better ad performance, then forgotten. That's exactly the pattern the OAIC found: pixels nobody currently at the business remembered authorising, running for years, quietly reporting page visits, form fills and sometimes names and emails to an advertising platform. A generic "we use cookies" banner was written for a different, older problem (browser cookies you can clear) and simply wasn't built to disclose what a pixel actually does.

The fix here is genuinely cheap. Unlike a lot of compliance work, this doesn't need a lawyer or a rebuild — it needs someone to open the site, see what's actually firing, and update two documents to say so plainly.

What to check on your own site this week

1

Find out what's actually running

What

List every tracking pixel, tag and analytics script your site loads — not just "we have Google Analytics," but specifically a Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, or anything a marketer, agency or plugin has added over the years. If someone else manages your site or marketing, ask them directly: "Send me a list of every tracking pixel currently firing on our site."

Why it matters

The OAIC's sweep found a health provider running 50 pixels it had never authorised and didn't know existed. You can't disclose what you don't know is there.

2

Read your own consent notice like a stranger would

What

Open your site in a private/incognito browser window and read whatever cookie or consent notice appears. Does it specifically mention tracking pixels, Meta, TikTok or similar platforms by name — or does it just say something generic like "we use cookies to improve your experience"?

Why it matters

The Medmate determination found near-identical generic wording invalid for exactly this reason. This isn't a cautious interpretation of the rule — the regulator has now formally ruled on this scenario.

How to go further

If your consent tool supports categories, add a line naming your advertising pixels and what they do — e.g. "we use a Meta Pixel and TikTok Pixel for advertising; declining will stop these from loading."

3

Check your privacy policy names the tracking, not just "cookies"

What

Search your privacy policy for the words "pixel," "Meta," "Facebook," "TikTok," "advertising" and "third party." If none of those appear, your policy likely has the same gap the OAIC flagged.

Why it matters

APP 5 requires you to notify people what's being collected and why. A policy that only mentions "cookies" in the abstract doesn't do that for a pixel sending data to an external advertising platform.

4

If you handle sensitive information, treat pixels as opt-in, not default

What

Health, legal, financial and similar businesses should follow the OAIC's own advice here: audit what each pixel actually collects, minimise it, and consider not running third-party pixels at all on pages where sensitive detail — a specific service, condition or matter type — could appear in the page path or content.

Why it matters

Medmate's TikTok pixel transmitted full page URLs that named specific health conditions and medications. That's the failure mode the OAIC is most concerned about, and it's avoidable by not sending sensitive pages to a pixel in the first place.

5

Put a recurring check in the calendar

What

Pixels get added by a new agency, a new campaign or a new plugin — and rarely get reviewed again. A short quarterly check ("what's actually firing on our site right now, and does our privacy notice say so?") closes that gap before it becomes a surprise.

Why it matters

Monash IVF's pixel had been running, unreviewed, for over a decade. Nobody sets out to be in that position — it happens by simply never checking again.

Where a scan fits in

The AegorIQ Scorecard — including the free tier — detects the analytics and advertising tools actually loading on your site and checks whether a consent mechanism is present, exactly the two elements at the centre of these determinations. Paid tiers name each tool we find (so you know it's specifically a Meta Pixel or TikTok Pixel, not a guess), and flag it plainly when tracking is running without a consent banner at all. What a scan can't do is read the exact wording of your consent notice and judge whether it's specific enough to name Meta or TikTok — that's a judgement call, which is exactly what a human review in our Expert tier adds. Every check we run, and what we don't check, is published here.

Sources

If you'd like a second pair of eyes

Find out what your website is quietly sending to advertisers.

The free Scorecard runs 35 checks against your live site — including which tracking tools are running and whether a consent mechanism is present — and emails you the result. No payment details, no obligation.