Your best-performing audiences might be your biggest liability

by | Aug 13, 2026

Your best-performing audiences might be your biggest liability
13 min read

Australia’s privacy regulator, the OAIC, has ruled that data collected by everyday tracking pixels (page views, form fills, bookings, purchases) may be personal information, even when no name is attached. Being able to single someone out and retarget them is enough. The business that deploys the pixel owns the obligation, regardless of who set it up or where the data sits, and the first two companies caught by this ruling were ordered to stop collecting, destroy or de-identify the data, and rebuild their consent before resuming.

For marketers, there is direct exposure: these are the same signals your retargeting, lookalike audiences, conversion tracking and attribution are built on. If your site runs a Meta pixel, a TikTok pixel or similar, this applies to you, whatever industry you’re in.

The “individuation” test

The OAIC’s determinations run on the “individuation” test. In plain terms, an organisation doesn’t need to know a website visitor’s name for the OAIC to classify it as personal information. It’s enough that the data lets the business, or platform (Meta, etc.) single that person out and treat them individually.

Technical identifiers, behavioural signals, device fingerprints, hashed emails, and social media handles used for targeting are all now within the definition of personal information, where they enable individuation.

For example:

  • Someone browsing alcohol retailers daily may imply a drinking problem
  • A fertility clinic’s booking page implies a health condition
  • A lender’s page views can imply financial hardship
  • A publisher’s content consumption could imply political views
  • And more

If your website can single out a visitor and something can be inferred from what they did, what they looked at, an event that was triggered, etc., then this is now classed as personal information, and the OAIC is cracking down on it. Any argument that ‘we only see aggregated or anonymised data’ needs to be re-examined against this new standard.

Before you decide the new OAIC’s rulings don’t apply to you, answer the following questions.

Quick test to check your compliance

  1. Do you know every pixel, tag, and SDK currently firing on your website? Not what your team installed intentionally. What’s actually there, including anything added by a vendor, a plugin, or an agency three campaigns ago.
  2. Do you know exactly what data each one sends, and to whom? Page views are rarely “just” page views. Depending on configuration, that data can include form field content, product or service names, and enough context to reconstruct what a visitor was doing.
  3. Could any of that data be used to single out and re-target a specific individual, even without their name? If the answer is yes, or you’re not sure, that’s the exposure the OAIC has just put a legal definition around.

Most marketing teams can’t answer all three with confidence. That’s not a criticism. Pixel sprawl happens quietly, through years of campaigns, agencies, and platform updates. But the OAIC’s own rewrite of APP 3 explicitly closed this gap: the “we didn’t realise” defence has been retired. If your stack generates, infers, or observes personal information, that’s a collection event, whether you meant it to be one or not.

And the OAIC is already finding and determining companies that are breaching the rules.

The background

If you saw the headlines about the OAIC’s rulings against Monash IVF and Medmate, you probably filed them under “health sector compliance issue” and moved on. That’s a mistake.

The Office of the Australian Information Commissioner didn’t rule that health websites are special. It ruled on how tracking pixels work. These two health providers just happened to be first. The reasoning underneath applies to any business that runs a Meta Pixel, a TikTok Pixel, or similar tracking tools on its site. Which, per the OAIC’s own numbers, is nearly everyone.

What actually happened

In twin determinations, the OAIC found that Monash IVF and Medmate breached the Privacy Act by:

  • Collecting sensitive information through tracking pixels without proper consent
  • Failing to adequately notify users that this was happening
  • Using or disclosing that information for direct marketing and retargeting

The regulator’s logic: ordinary marketing signals (page views, form fills, bookings, cart activity, purchases) can themselves constitute personal or sensitive information once they’re fed into a platform’s ad-targeting system. Not because the data has a name attached, but because it can be used to single someone out and act on what that implies about them. 

These are the exact signals most retargeting pools, lookalike audiences, and attribution models are built on. The regulator isn’t looking at some obscure data trail. It’s looking at your stack.

Where responsibility sits

In the ruling against Medmate and Monash IVF, the OAIC made clear that responsibility sits with the website operator who deployed the pixel.

Both Medmate and Monash made the argument that they were not the ‘collector’ of the data because it sat on the pixel providers’ servers. The Commissioner rejected this.

The fact that day-to-day campaign management was outsourced to external marketing agencies made no difference to the ruling. The responsibility sits solely with the website operators as the entities that chose to embed the pixels. ‘Our agency handles that’ is not a defensible position.

Timeline

  • November 2024 – The OAIC publishes dedicated pixel guidance, covering pixel responsibility, data minimisation, sensitive information, and being “identifiable without a name”.
  • 13 May 2026 – OAIC publishes APP 3 rewrite. First rewrite in over a decade; tracking pixels named directly for the first time.
  • June 2026 – Monash IVF & Medmate determinations. First public test case for a “singling out” reading that the OAIC had been building toward for some time.
  • 10 Dec 2026 – Automated Decision Making obligations take effect. Whatever your current setup looks like, the standard it’s held to moves again.

Given the timeline, no one can claim they were blindsided. The regulator gave the industry eighteen months of warning and then did exactly what it said it would.

Why “it’s a health thing” is the wrong read

The OAIC’s determinations turn on the “individuation” test. In plain terms: an organisation doesn’t need to know a website visitor’s name to be holding their personal information. It’s enough that the data lets the business, or a platform like Meta, single that person out and treat them differently.

This isn’t a new rule invented for these two cases. The reasoning has been building for some time, the updated APP 3 guidance is where the OAIC named tracking pixels directly for the first time, but the underlying position on individuation predates it. Which means this isn’t a narrow, one-off reading. It’s where the regulator has been heading for a while, and Monash IVF and Medmate are simply the first public test of it.

If your website can single out a visitor and something can be inferred from what they did there, the same reasoning the OAIC applied to Monash IVF and Medmate applies to you. Health was simply the cleanest place for the regulator to start.

And this isn’t a one-off. The OAIC scanned 50 health-sector websites before these determinations landed. It found tracking technology on 96% of them, third-party pixels on 52%, and, among the sites using third-party pixels, 77% never disclosed that in their privacy policy. Two companies got the determination. The other 48 are still exposed.

Again, this is not just a health industry issue. Every site that uses tracking technology (almost all) are potentially exposed.

What matters now

This isn’t a slow-moving compliance issue you can schedule for next quarter. Two things are happening at once:

  1. Enforcement is already live. On 13 May 2026, the OAIC published its rewrite of APP 3 guidance, naming tracking pixels directly, alongside a clear data-minimisation expectation, and it’s backed by guidance with real determinations, not just commentary.
  2. Further change is coming. New requirements relating to Automated Decision Making take effect on 10 December 2026. Whatever your current setup looks like, the standard it’s being held to is about to move again.

The OAIC published guidance for organisations that deploy tracking pixels or similar technologies on a website that handles “personal” or sensitive information, including:

  1. Knowing what tracking technologies are in place and where
  2. Assessing the sensitivity of data (actual and inferred) and configuring pixels appropriately
  3. Ensuring transparency and valid consent mechanisms are in place
  4. Implementing a privacy by design approach

What you did last year to “handle privacy” may no longer be enough, and you won’t necessarily know that until someone else finds it for you.

Next steps and help

You can’t fix what you can’t see. Before anyone can tell you whether you’re compliant, someone needs to map what’s actually running on your site, what data it captures, and where that data goes.

That’s what a Privacy Compliance Health Check is for, a technical audit of your full tracking stack (every pixel, tag and SDK, what each one collects, and where it flows), paired with legal guidance on what that means for your obligations.

It’s worth being clear about what’s actually at risk if this stays unresolved. It isn’t only the compliance question. The same pixels and signals under regulatory scrutiny are the ones your retargeting, your lookalike audiences, and your attribution reporting depend on. 

Marketing teams already lose an estimated 30% to 50% of attribution signal to existing consent management, depending on category, and tighter enforcement only compounds that. Leave the exposure unaddressed, and you’re not just carrying legal risk, you’re running campaigns on data you may not be allowed to use, and reporting numbers you can’t fully trust. Fix it, and the outcome isn’t only a clean bill of compliance. It’s cleaner data and measurement you can actually stand behind.

If you can’t confidently answer the three questions in our quick test above, the fastest way to find out where you actually stand is to get a Privacy Compliance Health Check today.

Book a Privacy Compliance Health Check

Kirsten Tanner
Categories

Recommended for you

Get Our Newsletter

Sign up for our newsletter and receive monthly updates on what we’ve been up to, digital marketing news and more.

Your personal information will not be shared, and we don’t like mail spam or pushy salesmen either!