For years, Australian businesses treated tracking pixels as a marketing question. In June 2026, the Privacy Commissioner made them a legal one, ruling that two health providers had breached the Privacy Act through the Meta, TikTok and Google tags on their websites.

What the OAIC decided.

The Office of the Australian Information Commissioner looked at tracking pixels on the websites of 50 healthcare providers. It then made determinations against two of them, fertility provider Monash IVF and telehealth provider Medmate, published in June 2026.

Visitors' browsing on pages about health conditions had been sent to advertising platforms through pixels. The Commissioner found that tracking visitors on health-related websites and then targeting them with ads amounted to collecting sensitive information, which needs consent.

Both providers were ordered to stop collecting sensitive information through pixels within 60 days, to put proper notice and consent in place before using pixels again, and to destroy the data already collected.

One of the two had used seven different tags over time, including Meta, Google Ads, GA4, Hotjar and Pinterest. That's a typical marketing stack, not an unusual one.

The guidance behind it.

The rulings follow guidance the OAIC published in November 2024. Its main points apply to any business covered by the Privacy Act, not just health:

  • Pixel data can be personal information. An IP address or a page address can make a person reasonably identifiable once it's combined with what the platform already knows.
  • A privacy policy isn't enough notice. Visitors should be told about tracking at or before the point it happens, for example with a banner when they arrive.
  • Retargeting is direct marketing. Using pixel data to show people ads elsewhere needs a simple way to opt out, which has to work.
  • Sensitive information needs consent. Health, racial or ethnic origin, sexuality and similar categories need an express yes before collection.
  • The website owner is responsible. It's your job to configure each pixel properly, check what it sends, and review it regularly rather than set and forget.
  • Overseas disclosure counts. Most pixel providers are overseas, so the cross-border rules apply too.

Where sites usually go wrong.

  1. Pixels on every page, including pages about conditions, treatments or finances.
  2. Page addresses and titles that describe what the visitor was looking at, sent to every platform.
  3. Form tracking and session recording that capture what people type.
  4. An opt-out that's described in the privacy policy but doesn't stop any tag.
  5. Nobody checking what the tags send after launch.

What to check.

  1. List every pixel and tag, and which pages each one runs on.
  2. Look at what each sends. Your browser's developer tools show the requests and the page addresses inside them.
  3. Take advertising pixels off sensitive pages, or hold them until the visitor agrees.
  4. Add notice when visitors arrive, and an opt-out that reaches your tags.
  5. Consider server-side tagging, so data can be cleaned before any platform sees it.
  6. Write down what each tag does and when it was last checked.

Whether the Privacy Act covers your business, and what your notices must say, is for your lawyers. The rules on banners are in does an Australian website need a cookie banner? Marc Alexander makes the tracking match, for Australian businesses, and the GA4 mini audit shows what your tags send today.