[widget id="surstudio-translator-revolution-3"]

OAIC sweep highlights ad-tech privacy risks: Determinations against Medmate and Monash IVF’s use of tracking pixels

8 July 2026
Antoine Pace, Partner, Melbourne Raisa Blanco, Special Counsel, Melbourne

OAIC sweep highlights ad-tech privacy risks: determinations against Medmate and Monash IVF’s use of tracking pixels

The Office of the Australian Information Commissioner (OAIC) has drawn a clear line in the sand regarding the use of online tracking technologies in Australia, in its recent determinations following commissioner-initiated investigations into Medmate Australia Pty Ltd (Medmate)[1] and Monash IVF Pty Ltd (Monash IVF)[2].

The determinations each found that Medmate and Monash IVF’s use of tracking pixels interfered with the privacy of individuals by collecting sensitive information without clear consent or appropriate notices and then using that information for direct marketing purposes.  This amounts to a contravention of the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth) (Privacy Act), with each entity therefore required to cease these activities until they could rectify their non-compliance. The OAIC did not comment on whether it would seek penalties in this respect.

At the same time, the OAIC has also published a report (Your life, pixelated: how tracking pixels watch your every click) on the application of the Privacy Act to tracking pixels, including guidance to help APP entities manage the privacy risks arising from these tracking technologies, following the OAIC’s scan of 50 health service providers’ websites in November 2024.

The determinations and the report highlight the OAIC’s technology-neutral application of the Privacy Act, and the increasing granularity with which the regulator considers application of the APPs – including the need for robust privacy processes where individuals are unaware of the extent to which their personal information may be tracked, processed and monetised.

Key takeaways

The determinations clarified that:

  1. tracking pixels are regulated under the Privacy Act to the extent they collect personal information. APP entities must therefore treat them as another method of collection – not only a tool used by ad-tech providers to collect personal information
  2. when working out if a tracking pixel collects personal information, APP entities should note that an individual will be ‘reasonably identifiable’ where the pixel facilitates the singling out or distinguishing of an individual from others “in a way that affects an individual’s rights or interests”[3] – a broad interpretation of the definition of ‘personal information’ under the Privacy Act
  3. consent must be obtained before the collection of sensitive information and before using it for direct marketing purposes
  4. cookies and tracking pixels are distinct online tracking technologies and must be dealt with in privacy policies as separate collection methods and uses
  5. the first point of collection for tracking pixels is when an individual first visits a website. Accordingly, deploying banners or pop-ups with a compliant privacy collection notice upon opening the website would likely meet the requirements of APP 5.[4]

Relevant Facts

Medmate’s use of tracking pixels

Medmate used third-party tracking pixels offered by Meta and TikTok to serve retargeting ads to website visitors through social media.[5]

While these tracking pixels collected technical information such as page views, purchases and viewed content, certain personal information was also collected. In particular, the TikTok tracking pixel enabled the collection of full URLs, email addresses and phone numbers. These collected URLs sometimes included health conditions or medications sought based on an individual’s website interactions.[6]

The collected information was disclosed to the pixel providers, who then used it to provide advertising services to Medmate, including targeted advertising campaigns.

Monash IVF’s use of tracking pixels

Monash IVF’s website embedded multiple third-party tracking pixels, including pixels provided by Meta, Google, Pinterest, Matomo, Jet Interactive and Hotjar.[7]

The information these tracking pixels captured included page visits, time spent, scroll behaviour, clicks, form submissions and device, IP address and browser data.[8] Such data was sufficient to reveal health information, specifically inferences about individuals’ fertility concerns.

Similarly, the collected information was disclosed to the pixel providers, who subsequently used it to provide Monash IVF with advertising services and conduct targeted advertising campaigns.[9]

Decision and analysis

Both determinations turned on the following four core legal issues.

Whether the data collected was personal and sensitive information

In both determinations, the Commissioner concluded that tracking pixel data was personal information and sensitive information for the purposes of the Privacy Act.

Notably, the Commissioner found that the phrase ‘reasonably identifiable’ ought to apply not only when an individual is directly identifiable, but when information allows an APP entity to “single out or distinguish an individual from others in a way that affects their rights or interests”.[10]

The data collected by tracking pixels in each scenario was also determined to be sensitive information because it was an individual’s health information, or otherwise allowed an inference or opinion to be made about an individual’s health.[11]

Whether valid consent was obtained for the collection of sensitive information

The OAIC determined that neither Medmate nor Monash IVF had sought or obtained consent to collect the above sensitive information, and that they had therefore contravened APP 3.3.[12]

For consent to be valid, it must be informed, voluntary, current, specific and given by an individual with the requisite capacity.[13]  Consent can be express or implied. However, the Commissioner commented that the general expectation is for APP entities to seek express consent before handling sensitive information,[14] given the particular harm that can arise where it is misused.

While Medmate had implemented a cookie consent pop-up, the Commissioner was not satisfied that this led to consent that was:[15]

  1. Informed – The pop-up did not refer to tracking pixels, as distinct from cookies. As a result, an individual is unlikely to be adequately informed about the nature of tracking pixels, or the implications of consent.
  2. Specific – The level of specificity was insufficient to clarify the collection, use or disclosure of the individual’s sensitive information in this way.

Unlike Medmate, Monash IVF did not have a cookie consent pop-up or other instrument to attempt to procure consent regarding the collection of sensitive information upon an individual accessing the website.

Whether appropriate privacy collection notices were provided

Both organisations failed to take reasonable steps to notify individuals of matters under APP 5.2, including the fact of collection, the purposes for which personal information would be used, and when/why it may be disclosed to third parties.[16]

To assess whether it was reasonable for Medmate and Monash IVF to take these steps, the Commissioner considered the following circumstances:[17]

  1. The sensitivity of the personal information collected – Since sensitive information was being collected, each entity should have afforded it a higher level of protection than other personal information, and “more rigorous steps” should have been taken to inform individuals of the collection.
  2. Possible adverse consequences – Due to the nature of these websites, and the sensitive information about medical conditions and treatment they relate to, complex emotional and psychological challenges may arise for individuals where their personal information is collected, used or disclosed.
  3. Nature of the APP entity – Both organisations are for profit entities, which spent a substantial amount on targeted ads.  They therefore should have taken reasonable steps to satisfy APP 5, given this significant effort.
  4. Practicability – Based on the time and cost involved, and considering the resources available to Medmate and Monash IVF, it was not impracticable to take steps to notify individuals of this collection.  The Commissioner opined that the website is typically the first point of contact with users, providing a clear and accessible opportunity to disclose pixel tracking practices.  Readily available technical solutions could also have been easily implemented, such as ‘consent mode’ (offered by pixel providers) to prevent tracking until notices are provided and/or consent is obtained.

The Commissioner therefore found that cookie alerts and privacy policies were not sufficient to satisfy APP 5 in this context, given pixels were a distinct technology from cookies.

Whether sensitive information was used for direct marketing without consent

The Commissioner determined in both cases that personal information was used for the purposes of direct marketing, by serving targeted/personalised ads.  Each entity was found to have contravened APP 7 given this use was not accompanied by consent (expressly or impliedly).[18]

The Commissioner additionally noted that targeted ads (in this case, for retargeting purposes) did meet the threshold of ‘direct marketing’ under the Privacy Act, given these ads were targeted to specific individuals based on their online behaviour when accessing Medmate or Monash IVF’s websites. This was distinct from general online advertising that does not rely on personal information for targeting.[19]

Ultimately, both Medmate and Monash IVF were found to have interfered with the privacy of individuals in respect of APPs 3, 5 and 7. Perhaps given this is a relatively novel determination, the Commissioner elected to require both entities to cease this collection within 60 days unless they could rectify the relevant non-compliances.  The Commissioner did not yet comment on whether penalties would apply, although we note recent privacy reforms grant the Commissioner expanded powers to potentially seek this.

Gadens regularly provides end-to-end advice on privacy, data protection and cyber security-related matters, and can assist with both the strategic management of tracking technologies and responding to regulatory developments. Please do not hesitate to get in touch to discuss your rights and obligations under Australian privacy law.

If you found this insight article useful and you would like to subscribe to Gadens’ updates, click here.


Authored by:

Antoine Pace, Partner
Raisa Blanco, Special Counsel
Chris Girardi, Associate
Millie Hogg, Seasonal Clerk
Zoe Cooke, Seasonal Clerk

[1]   Commissioner Initiated Investigation into Medmate Australia Pty Ltd (Privacy) [2026] AICmr 41 (11 June 2026).

[2]   Commissioner Initiated Investigation into Monash IVF Pty Ltd (Privacy) [2026] AICmr 40 (11 June 2026).

[3] [2026] AICmr 41 [73]; [2026] AICmr 40 (11 June 2026) [72].

[4] [2026] AICmr 41 [118].

[5] [2026] AICmr 41 [36]-[44].

[6] [2026] AICmr 41 [44].

[7] [2026] AICmr 40 (11 June 2026) [42].

[8] [2026] AICmr 40 (11 June 2026) [42].

[9] [2026] AICmr 40 (11 June 2026) [11] – [17].

[10] [2026] AICmr 41 [71]-[74]; [2026] AICmr 40 (11 June 2026) [72] – [74].

[11] [2026] AICmr 41 [82]-[85]; [2026] AICmr 40 (11 June 2026) [82]-[85].

[12] [2026] AICmr 40 (11 June 2026) [99].

[13] [2026] AICmr 41 [90].

[14] [2026] AICmr 41 [90].

[15] [2026] AICmr 41 [92]-[94].

[16] [2026] AICmr 41 [120]; [2026] AICmr 40 (11 June 2026) [113].

[17] [2026] AICmr 41 [105]; [2026] AICmr 40 (11 June 2026) [104].

[18] [2026] AICmr 41 [134]; [2026] AICmr 40 (11 June 2026) [138].

[19] [2026] AICmr 41 [131]-[133]; [2026] AICmr 40 (11 June 2026) [130]-[132].

This update does not constitute legal advice and should not be relied upon as such. It is intended only to provide a summary and general overview on matters of interest and it is not intended to be comprehensive. You should seek legal or other professional advice before acting or relying on any of the content.

Get in touch