Two new cases demonstrate the risk from pixels, the reality of digital harms, and how the regulator is testing the boundaries of the law, with implications for all
Do you know if your organisation’s website is leaking sensitive information about your customers, to third parties, which could be used to harm your customers and undermine your own objectives?
Time to check for third-party tracking pixels on your website. Marketing or web dev teams may have placed pixels on your website without operational business areas even knowing, let alone understanding what is going on, as the OAIC has found. (Social media platforms offer website builders code to enable tracking pixels for integration and use on their websites, and dashboards to offer insights about website users’ behaviour. It is such standard industry practice that entities may need to actively request their web developers to not add the code to their website.)
And if you are using third-party tracking pixels, next step is to check if you have lawful authority to use them, given the Privacy Act’s restrictions under APP 3 (collection), APP 6 (disclosure) and APP 7 (direct marketing). Or: just stop using them.
Don’t believe claims about the data you are sharing via those pixels being ‘de-identified’. And certainly don’t believe anyone who tells you that you can get your customers’ consent for your data-sharing habits via your Privacy Policy.
Otherwise, without your customers’ valid consent, you might find yourself in breach of the Privacy Act, as Australia’s Privacy Commissioner found in cases this week against health service providers Monash IVF (fertility services) and Medmate (telehealth).
These two OAIC determinations establish that the use of tracking pixels “to track website visitors to health-related websites, and to subsequently target them with advertising on social media platforms”, constituted a collection of sensitive information, which occurred without the individuals’ consent.
Along with the two determinations, the OAIC released a research report, which details their parallel inspection of 50 health service provider websites. They found that 52% used a third-party tracking pixel.
Through further targeted engagement with health service providers across the industry, the OAIC found that many organisations believed that the web browsing data they collected was “de-identified, hashed or pseudonymised” and that therefore “privacy obligations did not apply”.
But these claims about anonymity did not hold water once inspected: “Notably, we observed instances where:
- when an individual is logged into their social media account (either by phone app or web browser) browsing activity is linked to their profile
- form fields including hashed name, address or telephone numbers were being shared with social media platforms. This information is used to match this to individuals and their profile, even where they are not logged in.”
The OAIC criticised the “use of tracking pixels without appropriate due diligence”, stating in the Medmate case for example: “All entities that have embedded tracking pixels on their website are encouraged to understand how the product works, identify the potential privacy risks involved and implement measures to mitigate those risks”.
The implications of these two cases, and the OAIC’s accompanying research report, are significant. Here are our four key takeaways.
The harms from online tracking are real – but need to be articulated better
The hyper-personalisation of content consumed in the digital environment causes real harms. Some are at the individual level, while others impact communities and nations as a whole.
Disturbingly, the OAIC research report reveals that many of the health service providers they spoke with did not understand that their use of tracking pixels could hurt the very same people they were trying to help:
“Many organisations underestimate the potential harms associated with tracking technologies. Some organisations we engaged with viewed the use of tracking technologies as a way to engage with particular audiences on the platforms they regularly frequent to provide information about services they may need, rather than a mechanism that may enable individuals to be extensively profiled. However, without careful consideration, individuals may be exposed to unintended harms, particularly where individuals’ profiles can be used to exploit their interests and vulnerabilities.”
In the health space this problem is particularly acute, and a wicked policy problem that stalks us all on the internet.
Say you are running a non-profit counselling service which aims to help people with a gambling addiction. Obviously, you want to be able to encourage prospective clients to not just look at your website, but to take the next steps to engage with your services. Standard marketing advice tells you to track who browses your website by using third party tracking pixels, then place ads on those social media platforms which can be targeted to those same individuals (as well as to ‘lookalike’ audiences).
So someone new – let’s call them User XYZ – browses your website. Your tracking pixel sucks up data about User XYZ, and sends it to the related social media platform. User XYZ then starts seeing ads for your service when they check their social media feed.
This type of ad targeting works precisely because the social media platform can ‘reasonably identify’ User XYZ, such that the person can be tracked, profiled, then targeted with ads and other content. Your non-profit counselling service doesn’t need to know their name, and the social media company doesn’t need to know their name either; being able to distinguish your prospective client from everyone else on its platform is all the social media company needs to do, in order to enrich their user profile and then target User XYZ with ads and content tailored to their profile.
But by leaking information to the social media platform that User XYZ has been browsing a website about gambling addiction, you have effectively told the social media company that XYZ (probably) has a gambling addiction.
And who else might find that information valuable, and will therefore pay handsomely to target their ads or content to User XYZ?
Gambling companies.
So your non-profit anti-gambling service has just delivered the very person you are trying to help, into the arms of the companies that will seek to exploit them and worsen their addiction.
Rinse and repeat for every particularly damaging health issue you can imagine: depression, anxiety, eating disorders, suicide ideation, smoking, alcohol dependence, unplanned pregnancy, fertility concerns, substance abuse, family violence.
The OAIC has found that health services working in the public interest, trying to reach their target audience online to maximise reach for their good work, are inadvertently leaking data about individuals that can trigger ads and content that exacerbate the relevant health condition, or exploit vulnerable individuals, rather than helping.
A novel interpretation: ‘individuation’ articulated by the regulator as the legal test
In Australia, our information privacy rights turn on the threshold definition of ‘personal information’. If a regulated entity is handling data that meets the definition of ‘personal information’, there will be privacy obligations attached to that data; otherwise, all bets are off.
The components of the definition include that the information must be ‘about an individual’, and that the individual must be ‘identified … or … reasonably identifiable’.
This legal definition reflects the shaky assumption on which our privacy laws are based: that people can only suffer privacy harm if they can first be ‘identified’. Yet since the drafting of the GDPR in 2016, with its concept of ‘singling out’, there has been a growing understanding that you can hurt someone without ever knowing who they are.
In this week’s determinations, Privacy Commissioner Carly Kind notes that:
“the definition of personal information does not expressly require that an individual be specifically identifiable, or identifiable by direct identifiers such as their legal name, passport or driver’s licence number, or date of birth. Accordingly, it is necessary to consider whether an individual may still be ‘reasonably identifiable’ in circumstances where an APP entity does not possess personal information that includes (or can be easily paired with) such direct identifiers”.
For the past decade, I have argued that our privacy laws are too narrowly focussed on ‘can be identified’ as the proxy for ‘someone whose privacy and autonomy can be harmed’. We should instead re-think the scope of our privacy laws to encompass all behaviour in which individuals can be tracked, profiled and targeted at an individual level, regardless of whether their ‘identity’ is known.
In a 2016 blog I first introduced the one word I have used ever since, to try and encapsulate this concept of ‘being able to distinguish one individual from all others even without knowing their name and as a result being able to do something that could impact that individual in some way’: individuation.
And ever since I have been arguing that the Australian statutory definition of ‘personal information’ needs to explicitly incorporate individuation.
Over much of that time the OAIC has also been at pains to point out (via published guidance in 2017 as well as through a series of previous determinations) – and in 2023 the Government accepted – that the legal test under the Privacy Act as it stands today is that an individual is ‘reasonably identifiable’ if they can be distinguished from all others in a group, even if their identity is not known.
So what’s new about these two cases? This week’s determinations mark the first time that the OAIC has used the word ‘individuation’ not only to describe the concept, but to say that individuation is embedded in the law already.
The Privacy Commissioner has clearly stated her view that the definition of ‘personal information’, as the legislation stands today, incorporates individuation:
“In my view, in the current context, the phrase ‘reasonably identifiable’ ought to be interpreted as applying to circumstances where information facilitates ‘individuation’. That is to say, the information permits an entity to ‘single out’ or ‘distinguish’ an individual from others in a way that affects an individual’s rights or interests” (Monash IVF para 72, and Medmate para 73).
So, data can be identifiable without revealing identity: being able to individuate an individual is enough to render an individual ‘reasonably identifiable’ for the purposes of Australian privacy law.
In other words: if you can track, profile or target people at an individual level, “in a way that affects an individual’s rights or interests”, then you are dealing in ‘personal information’ – and all of the obligations under the APPs kick in. And the converse is also true: Commissioner Kind has stated that “the Privacy Act does not capture information about a person in circumstances in which the collecting entity cannot use the information about an individual in any meaningful way that would affect an individual’s rights or interests” (para 74 of the Medmate decision).
Commissioner Kind has acknowledged that this is a fresh interpretation: “the acts and practices under scrutiny in this matter give rise to potentially novel applications of the term ‘reasonably identifiable’ as they arise in the context of advanced tracking technologies” (para 75 of the Medmate decision).
But she has also smartly defended taking this ‘novel’ position as “a logical progression of the legislative interpretation”. When you have legislation that has been deliberately drafted on the principle of technical neutrality, so as to be able to flex to reflect changes of technology and community expectations, then as technology evolves so should interpretation of the law.
The Commissioner’s determinations may of course be appealed, which could lead to further judicial interpretation of the definition – a result which Kind has invited through this strategic enforcement action, while also noting in the press that resolution of any appeal could take years.
(Which is a good reason for the Government to bring forward the promised Tranche 2 reform proposals, and make the OAIC’s and the Government’s own position about the definition absolutely explicit in the Act itself. One sentence will do it.)
This position from the Privacy Commissioner on individuation has implications for organisations well beyond the health sector, and for many types of data collection and data-matching technologies, well beyond tracking pixels.
Don’t believe the hashing hype
Medmate argued that it could not identify individuals from the information collected by the tracking pixels, in the sense of knowing, or using resources available to it to gain access to, direct identifiers. And in terms of what was disclosed to the social media platforms, the tracking pixels collected only ‘hashed’ versions of the personal information input by individuals on Medmate’s webpages, such as name, email addresses and phone numbers.
However hashing and other de-identification techniques do not offer the ‘privacy preserving’ outcomes that AdTech and Big Tech players would have you believe.
OAIC guidance on de-identification from 2018 notes that data will only be considered to no longer be ‘personal information’ (and thus, the privacy rules will no longer apply), if identifying an individual – which as noted above includes being able to distinguish one individual from the group – “is so impractical that there is almost no likelihood of it occurring.”
Pseudonyms such as hashed identifiers exist precisely to enable links to be drawn between unrelated datasets, such that with the required degree of confidence, the process can establish that User XYZ who has been browsing our non-profit counselling service’s website, and customer 12345 from Company A, and customer 67890 from Company B, and Instagram user ‘bobridesbikes1956’, are all the same person. And this way, social media platforms, data brokers and more learn that this one individual has a mortgage, likes Insta posts about horse racing, makes TikTok videos about cycling trips, and has been browsing a website about gambling addiction.
So it doesn’t matter that our non-profit health service doesn’t share the name of User XYZ with the social media company; they don’t need to. A hashed version of an email address, browser identifier, or mobile phone device identifier works just fine.
(To learn more about the relative strengths and weaknesses of different de-identification techniques like suppression, aggregation, hashing and more, see our 2025 recorded webinar: De-identification demystified for GRC, legal and privacy professionals).
As this week’s determinations make clear, hashing or encryption of data is not some magic get-out-of-jail-free card you get to play to avoid your legal responsibilities. Online identifiers such as tracking pixels facilitate the exchange of data which may still constitute ‘personal information’, and regulated entities therefore need to ensure that their collection, use and disclosure complies with APPs 3, 6 and 7.
The separate report from the OAIC which accompanies the two determinations offers this takeaway for organisations:
“privacy risks … are embedded in the online environment that we engage with on a day-to-day basis.
… protecting individuals’ privacy means you must not just understand the information you intentionally collect, but also the information your systems may be collecting and disclosing to third parties.
If your website uses and deploys tools like tracking pixels, it is your responsibility to ensure it is used in a way that is compliant with the Privacy Act. Non-compliance can have serious consequences for individuals using your service – and for your business”.
Broader implications – will data brokers be next?
In July 2025, the OAIC published its regulatory priorities for the year ahead, which included a “focus on sectors and technologies that compromise rights and create power and information imbalances”. The strategy document called out sectors and practices including “the rental and property, credit reporting and data brokerage, sectors”, “advertising technology (Ad tech) such as pixel tracking”, “excessive collection and retention of personal information”, and “facial recognition technology and forms of biometric scanning”.
Australian Privacy Commissioner Carly Kind has been diligently ticking items off that hit list. RentTech, done. Excessive data collection via website scraping, done. Facial recognition tech, done. And this week: Pixel tracking, done.
What’s next for the OAIC?
I suspect that most Australians are unaware, and would likely be horrified to learn, that intimate details about their life – including health conditions, financial and risk profiles and other vulnerabilities which can be exploited – are being collected from our online browsing habits and other sources, collated into customer profiles, monetised, traded between companies, and used by companies for direct, personalised marketing or other messaging, influencing or decision-making purposes, without our participation or consent.
Somewhere in the OAIC’s Commissioner Initiated Investigations team vault should be the 2022 complaint from ‘Justine’ which lays out the evidence trail we found when one woman wanted to find out how and why she was targeted with one piece of unsolicited health-related marketing. It’s a roller coaster ride through the typical industry arguments like ‘but the data is de-identified’ and ‘we got your consent’ to try and disguise what we alleged to be multiple breaches of APPs 3 and 6, by companies Justine had never directly dealt with.
Now that the OAIC has laid the jurisprudence groundwork in terms of clarifying what is personal information, the limits of de-identification to escape the APPs, when consent is required for direct marketing, and what a valid consent requires, I can only hope that the data brokerage industry, and the flimsy veneer of respectability offered by the so-called data clean room industry, are next in the Privacy Commissioner’s sights.
If you need assistance assessing the privacy implications of your platform, digital forms or new technologies – including conducting a PIA – please get in touch.
Photograph © Vadim Bogulov on Unsplash


