Australian organisations have spent several years treating website tracking as a marketing decision with a legal footnote. In June 2026 the Privacy Commissioner made determinations against Medmate and Monash IVF, finding that both breached privacy law through the use of tracking pixels — and establishing that health providers must obtain consent before collecting sensitive information this way.
In the same month, an OAIC sweep found that several Australian health service websites had been covertly tracking visitors and transmitting sensitive health information to social media platforms.
Taken together, these are not a marketing footnote. They are a regulator establishing, with determinations rather than guidance, that the mechanics of your website are a privacy control.
Why sensitive information changes everything
Under the Australian Privacy Principles, sensitive information is a distinct and more tightly controlled category than personal information. It includes health information, and health information is defined broadly — it captures information about an individual’s health, disability, or health services they have received or sought.
APP 3 sets a materially higher bar for sensitive information: an entity generally must not collect it unless the individual consents and the information is reasonably necessary for the entity’s functions. There is no equivalent of the “reasonably necessary” collection test standing alone. Consent is the gate.
The privacy problem with a tracking pixel on a health service page is not the fact of tracking. It is that the URL itself is often the sensitive information. A page path that names a condition, a treatment, a service line or a specialist appointment discloses health information about the person requesting it, by the act of requesting it. When that URL is transmitted to a third-party advertising platform alongside a persistent identifier, a collection of sensitive information has occurred — by the third party, and arguably by the site operator who arranged it.
What the path itself discloses: That the person requesting this page is seeking fertility treatment. Health information is sensitive information under the Privacy Act, and the URL alone conveys it — before a single form is filled in.
The collection has already occurred. Not by the clinic — by the third party, at the moment the page loaded, arranged by the site operator.
What the path itself discloses: That the person is seeking advice about a domestic violence order. Not sensitive information under the statutory definition in every case — but the reasoning in the determinations is about what the path conveys, and a firm would struggle to argue this one is neutral.
Retargeting is the visible symptom people notice. The privacy problem occurred at page load, not at the advertisement.
What the path itself discloses: That the person is in financial difficulty. Combined with an identifier already held by the advertising platform, this is an inference about an identifiable individual’s financial position.
APP 8 requires overseas recipients to be identified. Most policies name none of the destinations above.
What the path itself discloses: That the person is seeking disability support. Disability information is expressly captured by the definition of sensitive information.
Tag managers routinely load vendors nobody in the organisation has heard of. The inventory question is not what you configured — it is what a browser observes.
What valid consent actually requires
The OAIC’s longstanding position is that consent has four elements. Each is a problem for the standard implementation:
- The individual is adequately informed before giving consent. A banner reading “we use cookies to improve your experience” does not inform anyone that health-related page requests will be transmitted to an advertising platform.
- The consent is given voluntarily. A dialogue where “Accept All” is a prominent button and refusal requires navigating a preferences panel is a design that shapes the outcome. This is the same reasoning that ran through the 2Apply dark patterns matter.
- The consent is current and specific. Consent obtained once, for an undefined set of purposes, does not remain valid indefinitely across changing vendor arrangements.
- The individual has capacity. Relevant wherever a service is used by, or on behalf of, people who may not.
There is a fifth practical failure that no amount of banner drafting fixes: on a very large number of Australian sites, the third-party scripts fire before the visitor interacts with the banner at all. Where the transmission has already occurred, the consent mechanism is decorative.
This is externally observable — which cuts both ways
The uncomfortable and useful fact about this class of exposure is that it requires no privileged access to identify. A public web page is public. What it loads, where it connects, and what it sends can be observed by anyone, including a regulator running a sweep, a journalist, a plaintiff’s lawyer, or a competitor.
The OAIC did not need cooperation to conduct its June sweep. It needed a browser.
The corollary is that any organisation can run the same check on itself, at low cost, before someone else does. A passive assessment of a public web estate can establish:
- Every third-party destination the site transmits to, including those loaded indirectly by other scripts — tag managers routinely load vendors nobody in the organisation has heard of
- Whether transmission occurs before any consent interaction
- Whether URL paths carrying sensitive context are included in those transmissions
- Which persistent identifiers accompany them
- Whether the destinations are disclosed in the published privacy policy, and whether overseas recipients are identified as APP 8 requires
The second breach: your privacy policy is now wrong
Most of the commentary on these determinations has focused on consent. There is a second, quieter exposure that almost nobody is naming, and it is easier for a regulator to establish.
If your website transmits to destinations your privacy policy does not disclose, the policy itself is inaccurate — and that is a separate contravention.
APP 1.3 requires an APP entity to maintain a clearly expressed and up-to-date privacy policy. APP 1.4 sets out what it must contain, including the kinds of personal information collected, how it is collected, the purposes, and whether information is likely to be disclosed to overseas recipients — and if practicable, the countries in which those recipients are located.
Run the comparison honestly and most Australian privacy policies fail on four counts at once:
- Undisclosed recipients. The policy names an analytics provider. The page loads six vendors, three of them pulled in indirectly by a tag manager that nobody has audited.
- Undisclosed overseas disclosure. Nearly every tracking destination is US-based. APP 8 is engaged and the policy is silent.
- Inaccurate collection description. The policy describes collection through forms and enquiries. It does not describe collection that occurs automatically, on page load, before any interaction.
- Out of date on its face. The policy was drafted by lawyers describing intended practice. The tag configuration was built by marketing solving attribution. The two documents have never been reconciled, and the tag configuration changed more recently.
There is a third-order problem behind it. An inaccurate privacy policy is evidence that nobody in the organisation knows what the website does. That is not a drafting failure — it is a governance failure, and it invites the obvious follow-up question about every other system.
Who should treat this as urgent
Health providers first — the determinations are directly on point, and the sweep tells you the regulator is already looking. But the reasoning is not confined to health. Any organisation whose website paths disclose a sensitive attribute should read these determinations as applying to them. That includes:
- Legal practices — family law, criminal, immigration and employment practice areas disclose a great deal about the person browsing them
- Financial services and insurers — hardship, claims and specific product pages
- Aged care and disability providers — service enquiry paths disclose health and disability information
- Education providers — student support, wellbeing and disability service pages
- Government agencies — where service pages disclose eligibility for a benefit or support programme
Four steps this quarter
- Inventory what actually loads. Not what the tag manager configuration says should load — what a browser observes on a live page. Include indirectly loaded vendors.
- Identify sensitive paths. Which URLs on your estate disclose a health, disability or other sensitive attribute simply by being requested?
- Confirm ordering. Does anything transmit before consent is registered? If so, the consent mechanism is not functioning regardless of its wording.
- Reconcile against the published policy. Is every recipient disclosed? Is every overseas recipient identified? Is the description of collection accurate as at today, not as at the date it was drafted?
None of this is expensive. All of it is evidence. And after June 2026, the absence of it is a finding waiting to be made by somebody else.