Consent Is Not a Cookie Banner.
The tracking pixel determinations change the question.

Do you know every third party your website transmits visitor data to right now? A passive external assessment is where the honest answers begin: what you expose to the outside world, and who owns that risk.

Assess Your Exposure →

Australian organisations have spent several years treating website tracking as a marketing decision with a legal footnote. In June 2026 the Privacy Commissioner made determinations against Medmate and Monash IVF, finding that both breached privacy law through the use of tracking pixels — and establishing that health providers must obtain consent before collecting sensitive information this way.

In the same month, an OAIC sweep found that several Australian health service websites had been covertly tracking visitors and transmitting sensitive health information to social media platforms.

Taken together, these are not a marketing footnote. They are a regulator establishing, with determinations rather than guidance, that the mechanics of your website are a privacy control.

June 2026 — the determinations
0
landmark determinations issued in a single month
0
the APP that governs collection of sensitive information
0
consent obtained where scripts fire before the banner
0
browser needed for a regulator to find it
Sources: OAIC determinations concerning Medmate and Monash IVF (June 2026); OAIC sweep of Australian health service websites; Australian Privacy Principles.
The shiftThe question is no longer “do we have a cookie banner?” It is: what does our site actually transmit, to whom, before any choice is registered — and could we evidence valid consent for it?

Why sensitive information changes everything

Under the Australian Privacy Principles, sensitive information is a distinct and more tightly controlled category than personal information. It includes health information, and health information is defined broadly — it captures information about an individual’s health, disability, or health services they have received or sought.

APP 3 sets a materially higher bar for sensitive information: an entity generally must not collect it unless the individual consents and the information is reasonably necessary for the entity’s functions. There is no equivalent of the “reasonably necessary” collection test standing alone. Consent is the gate.

The privacy problem with a tracking pixel on a health service page is not the fact of tracking. It is that the URL itself is often the sensitive information. A page path that names a condition, a treatment, a service line or a specialist appointment discloses health information about the person requesting it, by the act of requesting it. When that URL is transmitted to a third-party advertising platform alongside a persistent identifier, a collection of sensitive information has occurred — by the third party, and arguably by the site operator who arranged it.

What a URL discloses — and to whom
A clinic page path is health information
APP 3 — sensitive information
https://clinic.example.com.au/services/fertility/ivf-consultation?ref=google

What the path itself discloses: That the person requesting this page is seeking fertility treatment. Health information is sensitive information under the Privacy Act, and the URL alone conveys it — before a single form is filled in.

Meta / Facebook Pixel
United States
Full URL plus a persistent browser identifier and, where present, a hashed email
Google Ads / DoubleClick
United States
Full URL, referrer, cookie identifier
Session replay tool
Varies
Complete recorded session including mouse movement and form entry

The collection has already occurred. Not by the clinic — by the third party, at the moment the page loaded, arranged by the site operator.

A practice area discloses a legal circumstance
Not health — but no less sensitive in effect
https://firm.example.com.au/practice-areas/family-law/domestic-violence-orders

What the path itself discloses: That the person is seeking advice about a domestic violence order. Not sensitive information under the statutory definition in every case — but the reasoning in the determinations is about what the path conveys, and a firm would struggle to argue this one is neutral.

LinkedIn Insight Tag
United States
Page URL, professional profile matching where the visitor is logged in
Google Analytics
United States
Page path, session, approximate location
Advertising retargeting
Varies
Sufficient to serve related advertising to the same person elsewhere

Retargeting is the visible symptom people notice. The privacy problem occurred at page load, not at the advertisement.

Hardship and claims pages disclose circumstance
Financial distress, inferred from a path
https://lender.example.com.au/support/financial-hardship/apply

What the path itself discloses: That the person is in financial difficulty. Combined with an identifier already held by the advertising platform, this is an inference about an identifiable individual’s financial position.

Meta / Facebook Pixel
United States
Full URL plus persistent identifier
Microsoft Advertising (UET)
United States
Page path and conversion signal
Marketing automation
Varies
Where a visitor is known, the path is appended to their record

APP 8 requires overseas recipients to be identified. Most policies name none of the destinations above.

Eligibility pages disclose entitlement
Support and wellbeing paths
https://agency.example.gov.au/services/disability-support/eligibility

What the path itself discloses: That the person is seeking disability support. Disability information is expressly captured by the definition of sensitive information.

Analytics platform
Varies
Full path, session identifier
Tag manager
United States
Loads further vendors the agency may not have inventoried
Social platform pixel
United States
Where present, links the visit to a logged-in account

Tag managers routinely load vendors nobody in the organisation has heard of. The inventory question is not what you configured — it is what a browser observes.

Select a page type to see what is transmitted
Illustrative examples constructed from publicly observable tracking behaviour. Domains are fictional. Sources: OAIC determinations (June 2026); OAIC APP Guidelines; OAIC sweep of Australian health service websites.

What valid consent actually requires

The OAIC’s longstanding position is that consent has four elements. Each is a problem for the standard implementation:

  • The individual is adequately informed before giving consent. A banner reading “we use cookies to improve your experience” does not inform anyone that health-related page requests will be transmitted to an advertising platform.
  • The consent is given voluntarily. A dialogue where “Accept All” is a prominent button and refusal requires navigating a preferences panel is a design that shapes the outcome. This is the same reasoning that ran through the 2Apply dark patterns matter.
  • The consent is current and specific. Consent obtained once, for an undefined set of purposes, does not remain valid indefinitely across changing vendor arrangements.
  • The individual has capacity. Relevant wherever a service is used by, or on behalf of, people who may not.

There is a fifth practical failure that no amount of banner drafting fixes: on a very large number of Australian sites, the third-party scripts fire before the visitor interacts with the banner at all. Where the transmission has already occurred, the consent mechanism is decorative.

This is externally observable — which cuts both ways

The uncomfortable and useful fact about this class of exposure is that it requires no privileged access to identify. A public web page is public. What it loads, where it connects, and what it sends can be observed by anyone, including a regulator running a sweep, a journalist, a plaintiff’s lawyer, or a competitor.

The OAIC did not need cooperation to conduct its June sweep. It needed a browser.

The corollary is that any organisation can run the same check on itself, at low cost, before someone else does. A passive assessment of a public web estate can establish:

  • Every third-party destination the site transmits to, including those loaded indirectly by other scripts — tag managers routinely load vendors nobody in the organisation has heard of
  • Whether transmission occurs before any consent interaction
  • Whether URL paths carrying sensitive context are included in those transmissions
  • Which persistent identifiers accompany them
  • Whether the destinations are disclosed in the published privacy policy, and whether overseas recipients are identified as APP 8 requires
The reconciliation that mattersMost privacy policies were written by lawyers describing intended practice. Most tag configurations were built by marketing teams solving attribution. Nobody has reconciled the two documents. The determinations make that reconciliation an obligation rather than an improvement.

The second breach: your privacy policy is now wrong

Most of the commentary on these determinations has focused on consent. There is a second, quieter exposure that almost nobody is naming, and it is easier for a regulator to establish.

If your website transmits to destinations your privacy policy does not disclose, the policy itself is inaccurate — and that is a separate contravention.

APP 1.3 requires an APP entity to maintain a clearly expressed and up-to-date privacy policy. APP 1.4 sets out what it must contain, including the kinds of personal information collected, how it is collected, the purposes, and whether information is likely to be disclosed to overseas recipients — and if practicable, the countries in which those recipients are located.

Run the comparison honestly and most Australian privacy policies fail on four counts at once:

  • Undisclosed recipients. The policy names an analytics provider. The page loads six vendors, three of them pulled in indirectly by a tag manager that nobody has audited.
  • Undisclosed overseas disclosure. Nearly every tracking destination is US-based. APP 8 is engaged and the policy is silent.
  • Inaccurate collection description. The policy describes collection through forms and enquiries. It does not describe collection that occurs automatically, on page load, before any interaction.
  • Out of date on its face. The policy was drafted by lawyers describing intended practice. The tag configuration was built by marketing solving attribution. The two documents have never been reconciled, and the tag configuration changed more recently.
Why this matters more than the consent pointConsent is contestable. Reasonable people argue about whether a banner was sufficiently informed, sufficiently voluntary, sufficiently current. Whether your policy names the recipients your site actually transmits to is a matter of fact. It takes a regulator, a journalist, a plaintiff’s lawyer or a competitor one browser session to establish, and there is no argument available afterwards.

There is a third-order problem behind it. An inaccurate privacy policy is evidence that nobody in the organisation knows what the website does. That is not a drafting failure — it is a governance failure, and it invites the obvious follow-up question about every other system.

Who should treat this as urgent

Health providers first — the determinations are directly on point, and the sweep tells you the regulator is already looking. But the reasoning is not confined to health. Any organisation whose website paths disclose a sensitive attribute should read these determinations as applying to them. That includes:

  • Legal practices — family law, criminal, immigration and employment practice areas disclose a great deal about the person browsing them
  • Financial services and insurers — hardship, claims and specific product pages
  • Aged care and disability providers — service enquiry paths disclose health and disability information
  • Education providers — student support, wellbeing and disability service pages
  • Government agencies — where service pages disclose eligibility for a benefit or support programme
Does your policy match your website?
Eight statements. Tick every one you could evidence today.
We have a current list of every third-party destination our public pages transmit to, observed in a browser rather than read from a tag manager.
That list includes vendors loaded indirectly by other scripts.
Every one of those destinations is named in our privacy policy.
Every overseas recipient is identified, with the country stated where practicable.
No third-party script fires before the visitor interacts with our consent mechanism.
We have identified which of our URL paths disclose a health, disability, legal or financial circumstance.
Our privacy policy describes automatic collection on page load, not only collection through forms.
Someone reviewed the policy against the site configuration in the last twelve months.
Tick every statement that is true of your organisation

Four steps this quarter

  • Inventory what actually loads. Not what the tag manager configuration says should load — what a browser observes on a live page. Include indirectly loaded vendors.
  • Identify sensitive paths. Which URLs on your estate disclose a health, disability or other sensitive attribute simply by being requested?
  • Confirm ordering. Does anything transmit before consent is registered? If so, the consent mechanism is not functioning regardless of its wording.
  • Reconcile against the published policy. Is every recipient disclosed? Is every overseas recipient identified? Is the description of collection accurate as at today, not as at the date it was drafted?

None of this is expensive. All of it is evidence. And after June 2026, the absence of it is a finding waiting to be made by somebody else.

Passive only — no systems accessedBlackFlag Advisory privacy exposure assessments observe only what a public web property discloses to any visitor. No systems, networks or accounts are accessed, probed or tested. Findings are mapped to the Australian Privacy Principles and delivered in Board-ready form.
SourcesOffice of the Australian Information Commissioner determinations concerning Medmate and Monash IVF (June 2026); OAIC sweep of Australian health service websites (June 2026); Australian Privacy Principles and OAIC APP Guidelines; OAIC Notifiable Data Breaches reporting. This article is general information and is not legal advice. Analysis by BlackFlag Advisory.

Does Your Website Disclose More
Than Your Privacy Policy Admits?

A BlackFlag Advisory privacy exposure assessment identifies every third-party destination your public web properties transmit to, reconciles it against your published policy, and maps the gap to the Australian Privacy Principles.

Request an Assessment →
Passive Only — No Systems Accessed

All BlackFlag Advisory assessments use exclusively passive OSINT techniques and publicly available data sources. No systems, networks, or accounts are accessed, probed, or tested at any time. Board-ready output delivered within three to seven business days.