When the Regulator Runs the Scan: Australia's Tracking-Pixel Ruling
For three years, the tracking-pixel story was a lawsuit story — plaintiff firms in California scanning websites, sending demand letters, collecting settlements. In June 2026, Australia's privacy regulator did something different: it ran the scan itself, and formally found two health providers had breached the Privacy Act by loading tracking pixels without consent. A cookie banner, it held, was not enough. Here is exactly what the OAIC decided, and why it turns the pixel problem from a private-litigation risk into a regulatory one — worldwide.
Key takeaways
- A regulator, not a plaintiff, made the finding. Australia's Office of the Australian Information Commissioner (OAIC) handed down two determinations in June 2026 against health providers Monash IVF and Medmate for running third-party tracking pixels without consent.
- The breaches were of the Privacy Act 1988, via the Australian Privacy Principles — specifically APP 3.3, APP 5.1 and APP 7.1. This is Australian law, entirely separate from the US wiretapping statutes driving American litigation.
- A cookie banner was expressly found insufficient. One provider had a banner; the OAIC held it did not constitute valid consent for pixels and did not adequately notify users.
- Deploying a pixel counts as "collecting" and "holding" data — even though the data flowed straight to Meta, Google and TikTok servers. The website operator was responsible.
- The remedy centred on prevention: cease using the pixels until proper consent and notification are in place, destroy the sensitive data collected, and report back to the regulator.
What this article covers
- What the OAIC actually did
- The findings: seven pixels, a decade, and sensitive data
- The legal reasoning that should worry every website
- The banner finding: why a pop-up wasn't enough
- The remedy: prevention, not a fine
- The shift that matters: plaintiffs, then regulators
- What this means for your website
- Frequently asked questions
What the OAIC actually did
On 11 June 2026, Australia's Privacy Commissioner, Carly Kind, handed down two determinations — published on 24 June — against two health service providers: Monash IVF, a fertility provider, and Medmate, a telehealth platform. Both were found to have breached the Privacy Act 1988 (Cth) by using third-party tracking pixels on their websites to collect and share personal and sensitive information without consent.
These were not lawsuits brought by individuals. They were Commissioner-Initiated Investigations — the regulator opened them on its own motion, gathered the evidence, and issued binding determinations. In practical terms, the OAIC did the thing that US plaintiff firms have industrialised: it looked at what these websites actually loaded in a visitor's browser, and it built a case on the answer. The difference is that in Australia, the entity doing the looking is the government.
The investigations did not appear from nowhere. The OAIC had flagged third-party tracking pixels as an area of regulatory concern back in 2024, publishing formal guidance on tracking pixels in November of that year and opening these investigations in December 2024. Alongside the determinations, the regulator released a companion report with a title that leaves little to interpretation: "Your life, pixelated: how tracking pixels watch your every click." For that report, the OAIC inspected the websites of 50 health service providers — a scan, in other words, of an entire sector.
We are a consent-infrastructure company, not a law firm, and nothing here is legal advice. But we read privacy determinations closely because each one tells website operators something concrete about where the risk is moving. This one moves it a long way.
The findings: seven pixels, a decade, and sensitive data
The factual findings are worth stating plainly, because their specificity is the point. This was not a regulator reacting to a vague privacy complaint. It was a regulator describing, tag by tag, what these sites did.
Monash IVF: seven pixels over more than a decade
The OAIC found that Monash IVF's website ran seven separate third-party tracking pixels, some in place from as early as 30 July 2012 through to 9 December 2024 — more than twelve years. The pixels were:
The seven trackers found on the fertility provider's site
The pages carrying these pixels were not neutral. They included pages on egg freezing, sperm and egg donation, and fertility health checks. According to the determination, women who visited those pages were subsequently targeted with advertising for IVF services, egg-freezing programs, and nurse consultations. The inference a regulator can draw from that is direct: the fact that someone was reading a fertility-treatment page is itself information about their health — and it was being used to advertise to them.
The determination went further into the mechanics. Monash IVF had, at points, enabled Meta's Advanced Matching feature, which transmits hashed customer information — usernames, email addresses, phone numbers — captured from form submissions. The provider could not fully account for when this feature had been switched on, or for how long. It had also uploaded Custom Audience lists containing names and contact details to Meta, and could not confirm the source of that data. When an organisation cannot reconstruct what it sent, to whom, or when, that is not a mitigating detail in a privacy investigation. It is an aggravating one.
Medmate: fewer pixels, full URLs, and a late banner
The telehealth provider Medmate was found to have used Meta and TikTok pixels on its website between April 2021 and 9 December 2024. The detail that stands out is that Medmate's TikTok pixel transmitted full URL strings — the complete web address of the page a visitor was on. On a telehealth site, a URL can reveal the specific condition, medication, or service a person was looking at. Transmitting that to a third-party advertising platform, without consent, is precisely the harm the Privacy Act's sensitive-information rules exist to prevent.
Medmate's case carries an extra lesson, and it is the one most directly relevant to any operator who believes they have already solved this. In the weeks before the OAIC's investigation began, Medmate had implemented a cookie consent banner. It did not save them. We will come back to exactly why in a moment, because it is the single most instructive part of the whole determination.
The legal reasoning that should worry every website
The factual findings are striking, but the legal reasoning is what makes this determination matter beyond Australia's borders — and beyond healthcare. Both providers ran essentially the same defence, and the OAIC rejected all of it. Each rejection closes a door that website operators everywhere have quietly relied on.
"We didn't collect the data — it went straight to Meta"
Both providers argued that they hadn't really collected anything, because the pixel sent data directly from the visitor's browser to the third party's servers. It never sat on the provider's own systems. The OAIC rejected this. It held that deploying and controlling a pixel that causes data to be transmitted is itself an act of collection. You chose the tool, configured it, and pointed it at your visitors; the fact that the data's destination was someone else's server does not make you a bystander to your own tracking.
"We don't hold the data — Meta and TikTok do"
Relatedly, the providers argued they couldn't be responsible for data they didn't physically hold. The OAIC found that they did "hold" the information within the meaning of the Privacy Act, because they had commissioned the pixel, configured what it captured, and instructed its use for retargeting. Holding, in this reading, is about control and authority over the data's purpose — not about which company's hard drive it lands on. This tracks the OAIC's earlier reasoning in its Bunnings and I-MED / RentTech-style matters on what it means to "hold" personal information.
"The data wasn't personal — we couldn't identify anyone"
This was the providers' central defence: without a name or direct identifier, the browsing data wasn't "personal information" at all. The OAIC rejected it comprehensively, and this is the finding with the widest reach. It held that an absence of a direct identifier does not prevent information from being personal. It is enough that an individual can be singled out or distinguished in a way that affects their rights or interests. The organisation does not need to be able to tie the data back to a named customer in its own records; the capacity to isolate and target a person is sufficient.
Layer the sensitivity on top and the exposure sharpens. The OAIC found that browsing a health-service website can reveal or allow the inference of health information — and health information is "sensitive information" under the Privacy Act, carrying the highest bar for consent. Using it to serve health-related advertising was found to be direct marketing, engaging APP 7. The three principles the providers were found to have breached map cleanly onto the conduct:
| Principle | What it requires | What the OAIC found |
|---|---|---|
| APP 3.3 | Sensitive information may only be collected with consent (and where reasonably necessary) | Sensitive information was collected via pixels without consent |
| APP 5.1 | Reasonable steps must be taken to notify individuals, or ensure they are aware, of collection | Individuals were not adequately notified that pixels were collecting and transmitting their data |
| APP 7.1 | Personal information must not be used or disclosed for direct marketing without consent (with narrow exceptions) | Data was used for direct marketing — retargeted health ads — without consent |
There is one more piece of reasoning worth surfacing, because it is subtle and consequential: the OAIC treated the transmission of data across a third party's server as the creation of a "record" under the Act. That is the doctrinal move that ties everything together — it is what lets a fleeting browser-to-server transmission become regulated personal information that an operator "holds." For anyone who has followed the parallel debate in US courts about whether a pixel "intercepts" a communication, the shape of the argument will feel familiar, even though the statute and the vocabulary are completely different.
The banner finding: why a pop-up wasn't enough
Here is the part every website operator should read twice. Medmate had a cookie consent banner. It had implemented one in the weeks before the investigation began. And the OAIC found it did not fix the problem — for reasons that are worth spelling out precisely, because they are the same reasons a great many "compliant-looking" banners fail.
The regulator's concerns with the banner were specific:
- It referred to "cookies" — but the tracking at issue was done by pixels, which are a distinct technology. A visitor reading about cookies was not being told about pixels.
- It did not name the third parties — Meta and TikTok — receiving the data.
- It did not explain that data was being transmitted to external servers at all.
Underpinning those specifics was a broader holding: a cookie pop-up does not, by itself, constitute valid consent for tracking pixels. The OAIC was explicit that pixels are not the same as cookies — cookies can be viewed, configured, and deleted by a user; a pixel fires and transmits regardless. A banner that addresses one does not obtain consent for the other. And a banner is not automatically sufficient to notify a user under APP 5 either, if it doesn't actually describe what is being collected and where it is going.
Valid consent, in the regulator's framing, must be adequately informed, given voluntarily, current, and specific.
— The OAIC's articulated standard for consent under the Privacy ActIf that standard sounds familiar, it should. It is almost word-for-word the conclusion that US plaintiff attorneys have built an entire practice around — that a banner which looks like consent, but doesn't actually gate the tracking or accurately describe it, is not consent at all. We wrote about that pattern in detail in why most cookie consent banners are fake — the failure modes there (a banner that renders while trackers fire underneath, an opt-out that isn't wired to anything, a notice that names nothing) are precisely the deficiencies the OAIC identified in a live regulatory action. What was a litigation theory on one continent is now a regulatory finding on another.
There is a constructive reading of the banner finding, and it matters. The OAIC did not say banners are useless — it indicated that an operator may use a banner or pop-up to provide the specific information APP 5 requires, provided it actually does the job: naming the pixels, naming the recipients, explaining the transmission, and — for sensitive information — obtaining genuine, specific, opt-in consent before anything fires. The banner isn't the problem. A banner that describes cookies while pixels transmit health data to advertising platforms is the problem. That distinction — between what a banner says and what a site does — is the entire subject of our piece on cookie banner versus real compliance, and this determination is the clearest regulatory illustration of it we have seen.
What does your site actually send — and to whom?
The OAIC's case turned on pixels firing and transmitting before consent. See which trackers load on your site before a visitor agrees, and where the data goes — the same view a regulator or plaintiff scanner would start from. About 10 seconds, no account.
Scan your site free →The remedy: prevention, not a fine
One of the most revealing aspects of the determinations is what the OAIC ordered — and what it didn't. There were no fines. The Commissioner did not comment on whether penalties would be sought. Instead, the remedies were built around stopping the conduct and cleaning up the data. Both providers were required to:
- Cease using the tracking pixels until proper consent and notification mechanisms are in place.
- Not repeat or continue the conduct — a formal declaration to that effect.
- Destroy the sensitive information collected via the pixels, where legally permitted, including data held in the pixel providers' dashboards.
- Report back to the OAIC within 90 days confirming compliance.
- Before switching pixels back on: obtain consent to collect sensitive information and to use or disclose it for direct marketing, and take reasonable steps to notify individuals.
The absence of a fine should not be read as leniency, and it should not be read as the ceiling of exposure. The OAIC has stronger civil-penalty powers available in appropriate cases, and it pointedly declined to say whether it would use them here. What the remedy communicates is the regulator's priority: it wants the pre-consent firing to stop, and it wants the improperly collected data gone. That is a prevention-first posture — and prevention-first is a far more demanding standard to meet than "pay and carry on," because it requires you to actually change what your website does.
An OAIC spokesperson, speaking to Australian trade press after the determinations, put the practical bar plainly: organisations should generally seek express opt-in consent where sensitive information is likely to be collected and disclosed through a pixel. Valid consent, in the regulator's words, must be "adequately informed, given voluntarily, current and specific." That is a high bar, and it is deliberately so.
The shift that matters: plaintiffs first, then regulators
Step back from the Australian detail and the larger pattern comes into view. For the past three years, the dominant tracking-pixel story has been an American, private-litigation story. Plaintiff firms in California built an assembly line: automated scans of websites, network logs showing pixels firing before consent, demand letters citing the state's wiretapping statute, and settlements. The engine was private lawyers acting on behalf of individuals. We track that side of the pattern continuously in our CIPA lawsuit tracker, and it shows no sign of slowing.
The Australian determinations mark a different phase. Here, the actor is not a plaintiff's lawyer chasing statutory damages — it is a government regulator conducting its own investigation, on its own initiative, and issuing binding findings. That changes the character of the risk in three concrete ways.
1. It is not opt-in. It comes to you.
A plaintiff-driven system depends on someone deciding to sue. A regulator-driven one does not. The OAIC scanned 50 health-provider websites proactively and opened investigations off the back of what it found. There is no demand letter to negotiate, no plaintiff to settle with — there is a regulator with statutory powers deciding, on its own timetable, to look at your sector.
2. It doesn't need a private right of action.
Much of the commentary about where US pixel litigation goes next fixates on whether particular statutes allow private lawsuits, and on legislative efforts to narrow them. A regulator sidesteps that entire debate. The OAIC didn't need anyone to have a private right of action; it has enforcement authority of its own. Wherever a data-protection authority has similar powers — and most do — the "can individuals sue?" question becomes beside the point.
3. It travels across borders more naturally than litigation.
A California wiretapping claim is, for all its reach, tethered to California. A data-protection principle like "you must have consent to collect sensitive information" is close to universal. When one respected regulator applies that principle to tracking pixels and publishes a detailed roadmap of its reasoning, every other regulator now has a template. The determination is written in a legal vocabulary that the EU's supervisory authorities, the UK's ICO, Canada's privacy commissioners, and others share. That is why we treat this as a global signal, not an Australian footnote.
It is worth being precise about the limits of this, because overclaiming would be its own kind of inaccuracy. Two determinations against two health providers do not mean every website on earth is now under regulatory threat. Health data drew the OAIC's attention precisely because it is the most sensitive category, and the consent bar for sensitive information is the highest. A general e-commerce site in a jurisdiction with a different consent regime faces a genuinely different analysis. But the direction is unmistakable: the reasoning the OAIC used is not confined to healthcare, the technology it examined is on the overwhelming majority of commercial websites, and regulators talk to each other. The safe assumption is that this is an early move in a longer sequence, not a one-off.
What this means for your website
If you operate a website that runs any third-party tracking — and virtually every commercial website does — the Australian determinations translate into a short, practical checklist. None of it is jurisdiction-specific, because the underlying principle isn't.
Know what actually fires, and when
The OAIC's entire case rested on what these websites loaded in a visitor's browser. You cannot manage what you cannot see. The first step is always the same: open your site in a clean browser session and watch what transmits before any consent is given. Which pixels fire? What do they send? To whom? Most operators are genuinely surprised by the answer, because tags accumulate over years — Monash IVF's went back to 2012 — and nobody keeps a running inventory.
Treat pixels as distinct from cookies
The single sharpest lesson from Medmate is that a cookie banner does not cover pixels. If your consent tooling and your privacy policy talk about "cookies" while pixels quietly transmit data to advertising platforms, you have the exact gap the OAIC penalised. Pixels and cookies are different technologies with different behaviours, and they need to be handled and disclosed as such. We unpack the distinction in tracking pixel versus cookie.
Gate the tracking, don't just describe it
A banner that names your pixels but doesn't stop them from firing before consent solves the notification problem and leaves the collection problem wide open. Genuine consent for sensitive data means the tracking does not fire until the visitor has given specific, informed, opt-in agreement. Description without enforcement is the failure mode that unites the fake-banner litigation in the US and the banner finding in Australia.
Name names, and be specific
"We use analytics and advertising tools" is exactly the kind of vague notice the OAIC found wanting. Real notice identifies the specific tools (Meta Pixel, TikTok pixel, Google Ads) and the fact that data is transmitted to those third parties' servers. Specificity is not a nicety here; it was decisive.
Keep an evidence trail
Part of what sank Monash IVF was an inability to reconstruct its own configuration — when Advanced Matching was enabled, where Custom Audience data came from. A consent system that records, page by page, what was gated and what the visitor agreed to turns an unanswerable regulatory question into a producible record. That is the difference between defending your site with facts and defending it with hopeful assumptions.
The reassuring part — and it is genuinely reassuring — is that the fix for the thing the OAIC actually penalised is well understood. Block non-essential trackers until the visitor consents. Describe what you run, accurately and specifically. Honour the choice the visitor makes. Keep a record of it. Do those things and you are no longer presenting the fact pattern that a regulator's scan, or a plaintiff's, is built to find.
Frequently asked questions
What did the Australian privacy regulator actually decide about tracking pixels?
In June 2026, Australia's Office of the Australian Information Commissioner (OAIC) handed down two determinations finding that health providers Monash IVF and Medmate breached the Privacy Act 1988 by using third-party tracking pixels to collect and share personal and sensitive information without consent. The breaches were of Australian Privacy Principles 3.3, 5.1 and 7.1. The regulator held that deploying a pixel amounts to collecting and holding the data, that browsing data can be personal and sensitive even without a direct identifier, and that a cookie banner did not constitute valid consent for the pixels.
Is this the same as a CIPA lawsuit in the United States?
No. This is Australian law — the Privacy Act 1988, enforced by the OAIC through Commissioner-initiated investigations. California's Invasion of Privacy Act (CIPA) is a US wiretapping statute enforced primarily through private lawsuits. They are separate legal regimes with different tests, remedies, and enforcers. What connects them is the underlying fact pattern: a tracking pixel transmitting a visitor's activity to a third party before consent. That same conduct is now actionable under multiple bodies of law in multiple countries.
Does having a cookie banner protect my website?
Not by itself. In the Australian determinations, one provider had implemented a cookie banner and it did not prevent a breach finding. The regulator's concerns were specific: the banner referred to "cookies" rather than the pixels actually in use, did not name the third parties receiving the data (Meta, TikTok), and did not explain that data was transmitted to external servers. A banner that does not accurately describe what the site does — and does not actually gate the tracking until consent — provides limited protection. Consent must be adequately informed, voluntary, current and specific.
Why does deploying a pixel count as "collecting" data if the data goes straight to Meta or TikTok?
The OAIC rejected the argument that operators weren't collecting or holding data because it flowed directly to third-party servers. It held that deploying and controlling a pixel — choosing it, configuring what it captures, and using it for retargeting — is itself an act of collection, and that the operator "holds" the information through that control and authority over its purpose. The destination server does not determine responsibility; the decision to deploy the tracking does.
Do I need a direct identifier like a name for browsing data to be "personal information"?
No. The OAIC held that the absence of a direct identifier does not stop information from being personal. It is enough that an individual can be singled out or distinguished in a way that affects their rights or interests, even if the operator cannot link the data to a named customer in its own records. On a health site, the fact that someone viewed a particular treatment page can also be sensitive information, which carries the highest consent bar under the Privacy Act.
Were the companies fined?
No fines were imposed in these determinations, and the Commissioner did not comment on whether penalties would be sought. The remedies were prevention-focused: cease using the pixels until proper consent and notification are in place, destroy the sensitive data collected (including data in the pixel providers' dashboards, where legally permitted), and report back to the OAIC within 90 days. The absence of a fine should not be read as the limit of potential exposure — regulators retain stronger penalty powers for appropriate cases.
My business isn't in Australia. Why should I care?
Because the reasoning travels. The core holdings — that deploying a pixel is collecting data, that you're responsible for what you control, and that you don't need a name to identify someone — are conclusions many data-protection regulators could reach under their own laws. A respected regulator has now applied these principles to tracking pixels and published a detailed roadmap of how. The technology it examined is on the overwhelming majority of commercial websites, and regulators share legal vocabulary and watch each other's enforcement. This is best read as an early move in a longer international sequence, not a local event.
The bottom line
The tracking-pixel problem used to have one dominant face: a plaintiff's lawyer in California with a network log. It now has a second: a government regulator with an investigation and a sector-wide scan. The Australian determinations didn't invent a new risk — they confirmed that the same conduct is actionable under a second, entirely separate body of law, initiated by an entirely different kind of enforcer.
And the mechanism that failed is the one many operators trust most. A cookie banner described the wrong technology, named none of the recipients, and gated nothing — and a regulator called it what it was. The lesson isn't "banners are bad." It's that a banner has to match what your site actually does, and gate the tracking it describes, or it protects no one.
The fix hasn't changed, wherever the pressure comes from: block non-essential trackers until consent, describe them accurately, honour the visitor's choice, and keep the record. That posture holds up under a plaintiff's scan and a regulator's alike — because it removes the thing both are looking for.
See what fires before consent on your site
The Australian case, and every pixel case before it, started with a tracker transmitting before the visitor agreed. Run the same first scan a regulator or plaintiff firm would — in about 10 seconds.
Scan your site free →About this article: This piece is published for informational purposes only and does not constitute legal advice. It summarises the OAIC's determinations in Monash IVF Pty Ltd [2026] AICmr 40 and Medmate Australia Pty Ltd [2026] AICmr 41 (handed down 11 June 2026, published 24 June 2026), the OAIC's accompanying materials including its report "Your life, pixelated," and reporting and analysis by Australian legal and trade publications. Statistics on community attitudes are drawn from the OAIC's Australian Community Attitudes to Privacy Survey 2026. This is Australian law (the Privacy Act 1988 and the Australian Privacy Principles) and is distinct from US statutes such as CIPA; nothing here should be read as conflating the two. ConsentPixel — Privacy · Verified is a consent-infrastructure provider, not a law firm; it does not make any website "fully compliant" with any regime. For advice on your specific circumstances, consult a qualified privacy professional.