INTELLIGENCE BRIEF
firm for AML Failings FATF grey-lists three new jurisdictions ahead of plenary session New EU AMLD6 implementation deadline configuration FATF grey-lists three new jurisdictions ahead of plenary session firm for AML Failings FATF grey-lists three new jurisdictions ahead of plenary session New EU AMLD6 implementation deadline configuration FATF grey-lists three new jurisdictions ahead of plenary session
vol VII . ISSUE 24 . 24 JUN 2026
Australian Privacy Commissioner Draws a Line on Tracking Pixels and Health Data
Breaking . AML

Australian Privacy Commissioner Draws a Line on Tracking Pixels and Health Data

Insight . Intelligence . Accountability

32 Views
0 Comments
News & Analysis 25 Jun, 2026

A new wave of professionals is transforming Governance, Risk, and Compliance from a rigid framework into a dynamic force for trust, innovation, and resilience. Governance, Risk, and Compliance (GRC) has long been associated with boardrooms and bureaucracy—a domain reserved for executives and auditors. But that image is changing fast.

By GRC Report Staff

Key Takeaways
  • Consent Required for Sensitive Data Tracking: The Privacy Commissioner found that using tracking pixels to collect and use sensitive health-related information for targeted advertising requires user consent under Australia's Privacy Act.

  • Medmate and Monash IVF Found to Have Interfered with Privacy: Separate determinations concluded that both organizations breached privacy obligations through their use of third-party tracking technologies on healthcare-related websites.

  • Ruling Extends Beyond Health Information: The Commissioner made clear that the same consent requirements apply when tracking technologies collect other forms of sensitive information, including political opinions and racial or ethnic data.

  • Common Advertising Technologies Remain Subject to Privacy Law: The decisions reinforce that widespread use of tracking pixels does not exempt organizations from complying with legal obligations governing the collection of sensitive personal information.

Deep Dive

Two privacy determinations released Thursday by the Australian Privacy Commissioner found that health service providers Medmate and Monash IVF interfered with individuals' privacy through their use of third-party tracking pixels. The decisions conclude a year-long investigation by the Office of the Australian Information Commissioner into how the two companies collected information from visitors to websites offering telehealth and fertility services.

Tracking pixels are among the most common tools on the modern internet. They help companies understand who visits their websites, what those visitors do, and whether advertising campaigns are working. They also help fuel the targeted advertising ecosystem that follows people from website to website and platform to platform.

In both determinations, the Privacy Commissioner concluded that using tracking pixels to monitor visitors to health-related websites and then target those individuals with advertising on social media platforms amounted to the collection of sensitive information under Australia's Privacy Act. That finding carries a straightforward consequence: consent is required.

The ruling may sound obvious to many Australians. The online advertising industry has spent years normalizing forms of tracking that would have seemed intrusive not long ago. People have learned to live with advertisements that appear moments after they browse a product, search for a service, or visit a website. What remains far less settled is whether that same machinery can be applied to information that reveals something deeply personal.

The Commissioner's office pointed to its own community attitudes research, which found that nine in ten Australians do not consider it fair or reasonable to be targeted with advertising based on sensitive health information.

"Australians have become accustomed to pervasive online tracking and targeted advertising, but that doesn't mean that they're comfortable with it," the Privacy Commissioner said.

The findings go beyond telehealth appointments and fertility services.

More Than a Health Sector Decision

Health information happened to be at issue in these cases, but the reasoning reaches much further. The Commissioner explicitly stated that website operators must obtain consent when tracking technologies are used to collect other forms of sensitive information, including political opinions, racial or ethnic origin, and similar protected categories of data.

That matters because the same advertising infrastructure appears across vast portions of the internet. The pixels embedded on a healthcare website are often not fundamentally different from those found on news sites, advocacy organizations, educational platforms, or countless other online services. What changes is the nature of the information they are capable of revealing.

"Today's decision establishes that the advanced technology used for tracking and targeted advertising in the online realm still has to be used in compliance with the Privacy Act," the Commissioner said.

A Message for Organizations Beyond Australia

Privacy regulators around the world have spent the past several years scrutinizing the use of tracking technologies, particularly when they intersect with health information. What makes these determinations notable is not that they introduce a new theory of privacy harm. They do not.

Instead, they take a practice that became commonplace and apply a familiar legal principle to it. The message is difficult to misunderstand. Just because a technology has become routine does not mean it exists outside the reach of privacy law. If a tracking tool collects sensitive information, organizations cannot treat consent as optional simply because the collection happens invisibly in the background.

For years, many privacy disputes have turned on complicated questions of data flows, platform architecture, and technical implementation. These decisions are remarkably direct. A person's health information remains sensitive information, even when it is collected by a few lines of code embedded in a webpage.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

Leave a comment

Your email address will not be published. Required fields are marked with *

Similar Articles
A network that laundered more than four million euros from scams by sending the money to Nigeria falls

A network that laundered more than four million euros from scams by sending the money to Nigeria falls

Spanish Police Bust €4 Million International Money Laundering Ring Bound for Nigeria. The Spanish Civil Guard has dismantled a criminal network responsible for laundering over €4 million generated through cyber fraud, CEO scams, and identity theft across Europe. The organization utilized "smurfing"—splitting large illicit funds into more than 9,200 small-wire transfers using falsified passports and stolen identities—to bypass anti-money laundering controls and funnel cash into Nigeria. The two-phase operation led to 20 arrests, investigations into 11 others, and raids targeting key leaders in Bilbao as well as several complicit money transfer agencies.

Read Full Brief
07 Aug 2026
U.S. Regulators Hit UBS With $173 Million in Coordinated AML Enforcement Action

U.S. Regulators Hit UBS With $173 Million in Coordinated AML Enforcement Action

Eight years after promising regulators it would fix persistent weaknesses in its anti-money laundering controls, UBS is paying for what those regulators say it failed to finish.

Read Full Brief
04 Aug 2026
FATF's June Plenary Trims the Grey List — Africa's Compliance Burden Isn't Going Away

FATF's June Plenary Trims the Grey List — Africa's Compliance Burden Isn't Going Away

The Financial Action Task Force closed its June 2026 plenary by removing Algeria and Namibia from its list of jurisdictions under increased monitoring, while adding Bosnia and Herzegovina and Iraq. For African compliance functions, the headline delisting matters less than what it confirms about the direction of travel.

Read Full Brief
04 Aug 2026
RegTech Won't Save You From a Bad Governance Model. It Will Just Automate It Faster.

RegTech Won't Save You From a Bad Governance Model. It Will Just Automate It Faster.

Every compliance leader I meet is being asked, in some form, what their AI strategy is. Almost none of them are being asked the more important question first: what is your governance model for the AI you already have?

Read Full Brief
04 Aug 2026
The EU AI Act's August Deadline Arrives — Just Not the One Everyone Expected

The EU AI Act's August Deadline Arrives — Just Not the One Everyone Expected

High-risk AI obligations for financial services have been pushed back sixteen months. Transparency rules for chatbots and synthetic media have not moved at all — and enforcement power against general-purpose AI providers switches on this week.

Read Full Brief
04 Aug 2026
Third-Party Risk Is a Board Issue Now, Not a Procurement Checklist

Third-Party Risk Is a Board Issue Now, Not a Procurement Checklist

Outsourcing does not outsource accountability. Regulators have said this for years. Boards are only now starting to act as though they believe it.

Read Full Brief
04 Aug 2026
Recommended Articles
See all

No recommended articles found.