Most Australian business websites are running at least three tracking pixels right now. A Meta pixel for retargeting, Google Analytics 4 for reporting, a Google Ads tag for conversions. They usually go in during a website build, someone ticks the box, and nobody looks at them again for years.

That habit has just become a business risk.

On 24 June 2026, the Australian Privacy Commissioner published two determinations finding that telehealth provider Medmate Australia and fertility provider Monash IVF interfered with the privacy of individuals whose sensitive information was collected through third party tracking pixels. The decisions concluded a year long investigation by the Office of the Australian Information Commissioner.

If your business has nothing to do with healthcare, it is tempting to file this under someone else's problem. That would be a mistake. The reasoning applies to any organisation covered by the Privacy Act, and the OAIC finished its announcement by encouraging all APP entities to review how they use tracking pixels and to understand their obligations.

What the OAIC actually decided

The core finding is short and worth reading twice. Using tracking pixels to follow visitors around a health related website, and then targeting those people with advertising on social media, counts as collecting sensitive information. Sensitive information requires consent.

Both providers were found to have breached three Australian Privacy Principles:

  • APP 3.3 by collecting sensitive information without consent
  • APP 5.1 by failing to take reasonable steps to notify people, or make them aware, that the collection was happening
  • APP 7.1 by using or disclosing sensitive information for direct marketing without consent

The technical setup involved was not exotic. Monash IVF had seven tracking tools live on its site, including the Meta Pixel, Google Ads, Google Analytics 4, Matomo, Hotjar and Pinterest. Medmate ran Meta and TikTok pixels. Neither stack would look unusual to anyone who has opened Google Tag Manager on an Australian business site in the last five years.

The Privacy Commissioner also pointed to community attitudes research showing that 9 in 10 Australians consider it neither fair nor reasonable to be targeted on the basis of their sensitive health data. Alongside the two determinations, the OAIC published a separate report based on an inspection of 50 health service provider websites, called Your life, pixelated: how tracking pixels watch your every click.

This did not come out of nowhere. The regulator issued guidance on tracking pixels and privacy obligations back in November 2024. The 2026 determinations are the enforcement follow through.

Why this matters even if you are not a health business

Three parts of the reasoning travel well beyond healthcare.

Sensitive information covers more than you think

Under the Privacy Act, sensitive information is not limited to medical records. The Commissioner specifically mentioned health, political opinions, race and ethnicity as examples. The definition also reaches things like religious beliefs, sexual orientation, criminal record and trade union membership.

Think about which Australian businesses touch that territory without considering themselves health providers:

  • Physiotherapy, chiropractic, dental and psychology clinics
  • NDIS and disability support providers
  • Migration agents and immigration lawyers
  • Family law and criminal law firms
  • Addiction, rehabilitation and mental wellbeing services
  • Religious schools and faith based organisations
  • Fertility, cosmetic and weight management clinics

That is a large slice of the Australian services economy, and a large slice of the sites we see running standard retargeting stacks.

It is the inference that matters, not the form submission

This is the part most business owners miss. Nobody has to fill in a form for the problem to exist. If a visitor browses a page about a specific condition, treatment or service, and that page view is sent to an advertising platform, the platform can infer something sensitive about that person. The determinations turned on exactly that kind of inference from browsing behaviour, page visits, scroll depth, clicks and device data.

So a service page can create the same exposure as an enquiry form.

The tag is on your site, so the obligation is yours

Meta and TikTok received the data, but the Commissioner found that Medmate and Monash IVF were the ones doing the data collection. Deploying somebody else's code on your own website does not move the responsibility to them.

If you outsourced your website development or your ad account, that does not change the position either. The obligation sits with the business whose domain the pixel fires on.

What to check on your own website this month

None of this requires a legal team to start. It requires somebody to actually look at what is installed. Here is the order we work through it with clients.

  1. Run a full tag audit. Open Google Tag Manager and your site's source code and list every tag, pixel and script currently firing. Most businesses find at least one tool nobody remembers adding, often left over from an agency that stopped working with them years ago. Remove anything you cannot justify.
  2. Map what each tag sends and when. For every tag that stays, work out which pages it fires on and what data it transmits. Pay particular attention to service pages, booking pages, form confirmation pages and anything with a URL that names a condition, product or situation.
  3. Fix your notice before you touch anything else. Your privacy policy needs to describe third party tracking in language a customer can follow, not a single line about cookies buried at the bottom. If your site collects anything in the sensitive category, the notice has to say so and consent needs to be genuine, specific and given before collection starts.
  4. Review your customer list uploads. Uploading names, emails, phone numbers and location data to build custom or lookalike audiences was part of what the OAIC examined. Ask whether the people on that list agreed to being used this way.
  5. Check your remarketing audiences. Audiences built from visits to sensitive pages are the highest risk item in most accounts. If you cannot explain the consent basis for an audience, pause it and rebuild.

We generally handle this alongside a technical review of the site itself, because tag sprawl and consent problems usually sit next to speed, structure and tracking accuracy issues in the same website build.

The bigger shift this points to

Regulatory pressure is only part of the story. Third party signals have been degrading for years, browsers keep tightening, and consent rates vary wildly by industry. Businesses that lean entirely on platform tracking are building on ground that keeps moving.

The practical response is to own more of your data. That means consented email lists, a CRM that actually records lead source, offline conversion imports so your ad platforms learn from real revenue rather than form fills, and server side tracking configured properly. Done well, this improves campaign performance at the same time as it reduces compliance risk, which is a rare combination.

It also changes the maths on channel mix. Organic search and content build an asset you keep, while paid media rents attention that depends on third party signals continuing to work. We covered that trade off in more detail in our comparison of SEO and Google Ads returns, and it is worth revisiting with privacy in mind.

Worth noting too: professional service providers including real estate agents, accountants, conveyancers and lawyers are being brought under the Privacy Act from 1 July 2026 through the AML and CTF reforms. Plenty of Australian small businesses are about to have privacy obligations they have never had before.

What this ruling does not mean

A few things are worth saying plainly, because the commentary around these determinations has been overheated in places.

You do not need to remove Google Analytics. You do not need to stop retargeting. Australia has not adopted a European style cookie consent regime, and there is no requirement for every site to run a consent banner. The determinations concerned sensitive information collected without consent on health related pages, not analytics as a category.

We are a marketing agency, not a law firm, so treat this article as a prompt to review rather than as legal advice. For anything genuinely borderline, talk to a privacy lawyer. But the review itself is marketing work, and most businesses can do a large part of it in an afternoon.

Getting your tracking in order

Cubic Digital works with Australian businesses on the whole picture, from organic search visibility through to paid advertising campaigns, and tracking sits underneath both. We audit what is firing on your site, clean up the tags you no longer need, rebuild conversion tracking around first party data, and make sure your reporting still tells you what is working.

If you are not sure what is currently installed on your website, that is the first thing worth finding out. Get in touch with our team and we will take a look.