OAIC finds tracking pixels on health provider websites breach privacy laws
The Australian Privacy Commissioner has found that fertility services provider Monash IVF and telehealth provider Medmate each breached the Privacy Act 1988 (Cth) through their use of third-party tracking pixels on their websites. The determinations are the OAIC’s first enforcement action specifically targeting tracking pixels and carry significant implications for any organisation whose website may reveal sensitive information about its visitors.
Findings
Both organisations deployed tracking pixels from social media platforms on their websites, transmitting browsing data – including URLs revealing specific health conditions or medications sought – to those platforms. The Commissioner found breaches of three APPs:
APP 3.3 (collection of sensitive information without consent). The Commissioner held that deploying a pixel constitutes ‘collecting’ personal information even though the data is stored on the platform provider’s servers, because the organisation controls whether the pixel fires and what data it collects. The browsing data constituted ‘Health Information’ (ie sensitive information) because it demonstrated visitors’ interest in particular health services and allowed an inference to be made about their health. Neither organisation obtained consent for this collection;
APP 5.1 (failure to notify). Neither organisation adequately informed visitors that tracking pixels were collecting and disclosing sensitive information to social media platforms. Privacy policies referred to cookies but not tracking pixels – which are different; and
APP 7.1 (direct marketing without consent). By retargeting visitors with health-related advertising on social media, both organisations used sensitive information for direct marketing without consent.
The Commissioner ordered both organisations to cease use of the pixels, destroy the unlawfully collected data, and implement consent mechanisms before resuming. There were no financial penalties.
Key issues for organisations
‘Reasonably identifiable’ now includes individuation
The Commissioner construed ‘reasonable identifiable’ as including scenarios where information 'facilitates individuation’ – ie permits an entity to ‘single out’ or ‘distinguish’ an individual from others in a way that affects their rights or interests – even without knowing their identity. Both organisations argued that they could not identify individuals from pixel data; but the mere ability to retarget them with personalised advertising was sufficient for the information collected to be considered personal information.
This is significant because the 2022 Privacy Act Review Report expressly declined to extend the definition of personal information to include individuation. Pending further clarity on the issue, organisations should now assume that if they can single out an individual for differential treatment – including targeted advertising – that individual is ‘reasonably identifiable’ for the purposes of the APPs.
Data from visits to health websites can constitute sensitive information
The Commissioner found that mere browsing activity data on a health provider’s website constitutes ‘health information’ because it allows an opinion to be formed about the visitor’s health. Interestingly, the fact that the organisations then used the data to retarget health-related advertising demonstrated that they had ‘formed an opinion’ about visitors’ health, which then caused the browsing data to qualify as personal information. This confirms that whether the information is personal information (or ‘Health Information’ or ‘Sensitive Information’, as was the case in these determinations) may depend not on the inherent character of the data, but on what the organisation does with it. Organisations that draw health-related (or other sensitive opinions) – and act on those inferences – risk converting otherwise non-sensitive information into sensitive information. Without properly characterising the data, an organisation may be liable for not treating it with the higher requirements in the APPs, such as obtaining consent for collection.
Cookie consent banners are not sufficient for pixel use
The Commissioner found that Medmate’s cookie consent pop-up was inadequate because it did not refer to tracking pixels (which are distinct from cookies), did not name the specific platform providers (eg Meta or TikTok), and did not address the collection of sensitive information with the requisite specificity. Any consent mechanism should specifically identify: (a) that tracking pixels are in use; (b) the platform providers to whom the data is disclosed; (c) the nature of the information collected; and (d) the purposes of that collection and disclosure.
Moreover, the consent must be obtained before the pixel fires. Pixel providers typically allow advertisers deploying them to adopt the ‘consent mode’ functionality for this purpose, but the level of informed, specific, consent required for sensitive information is a high bar.
Remedies were light, but don’t expect that to continue
As mentioned, no financial penalties were imposed. This likely reflects both organisations’ cooperation and the novelty of the Commissioner’s interpretations. It would be difficult to penalise organisations for failing to anticipate a legal position that had not previously been articulated. Future respondents who have had the benefit of these determinations (and the OAIC’s guidance on pixels) may not receive the same leniency.
Key actions to take now
Organisations (particularly those in health – but also in other sectors that are handling information that could reasonably give rise to sensitive inferences, such as financial, religious and political services) should:
audit all tracking technologies on their websites immediately;
assess whether any browsing data collected could constitute or give rise to inferences about sensitive information;
review privacy policies and collection notices to ensure that they specifically address tracking pixels (not just cookies, which are different) and name the relevant platform providers (eg TikTok or Meta);
implement reliable consent mechanisms that obtain informed, specific consent before any pixel fires, if sensitive information may be involved; and
consider whether third-party tracking pixels remain appropriate for the specific organisation’s marketing campaign.
The OAIC’s scan of 50 health provider websites found that 96 per cent used tracking technologies, 52 per cent used a third-party tracking pixel, and 77 per cent of those did not mention pixels in their privacy policy. These determinations make clear that the OAIC is actively monitoring this space.
This article was prepared with the assistance of Eva Cotsell, Law Graduate.
Contact


