Digital Marketing, Spam & Privacy
Tracking pixels and Australian privacy law: a practical checklist
Tracking pixels can disclose more than a page visit. This guide helps Australian organisations map pixel data, identify sensitive-information risks, test consent and keep website tracking controls working after launch.
When tracking pixels create an Australian privacy risk
Privacy determinations published on 24 June 2026 confirmed breaches involving third-party tracking pixels and health-related information used for targeted advertising. The wider lesson is not limited to health services: privacy compliance depends on the information actually collected, inferred, matched and disclosed through the live website.
A tool described as analytics or advertising technology may still handle personal information. The legal assessment turns on the complete data flow and surrounding context, not the label attached to the technology or the marketing team's intended purpose.
Map what the technology actually sends
A pixel, tag, software development kit or server-side event may transmit page addresses, event names, form interactions, account identifiers, device information, IP addresses, transaction details or hashed contact information. A third-party platform may be able to connect those signals with information it already holds.
Seemingly ordinary events can become sensitive when they reveal or strongly indicate health, disability, racial or ethnic origin, political opinions, religious beliefs or another protected attribute. The page visited, event name and account context may be revealing even when a sensitive field is not deliberately collected.
Assess consent, transparency and purpose together
Consent and notice cannot be assessed in isolation from the technical configuration. A privacy policy that generally mentions analytics or advertising will not fix a deployment that collects information the organisation did not understand, need or have a lawful basis to disclose.
Before relying on consent, confirm what the person was told, when the choice was presented, whether the action was genuinely voluntary and whether the consent covers collection and disclosure of the particular information. For sensitive information, a cautious design usually prevents the data from entering third-party advertising systems rather than relying on a broad notice.
Run a pre-deployment tracking-pixel review
- Create a complete inventory of pixels, tags, SDKs, cookies and server-side marketing events.
- Map each data element, trigger, recipient, purpose, retention position, overseas flow and onward use.
- Test whether a page, URL, event or data combination can reveal personal or sensitive information.
- Confirm whether collection is reasonably necessary and remove fields that are not needed.
- Review tag-manager rules, consent-platform settings, vendor terms and default configurations using real customer journeys.
- Prevent form contents, free text, health details, account data and other high-risk information from entering advertising tools.
- Align collection notices, privacy policies and direct-marketing statements with the verified data flow.
- Record the owner, approval, testing evidence and conditions for deployment.
Keep the control working after launch
Tracking configurations change when websites, campaigns, consent tools, vendors and tag-manager containers change. Schedule recurring scans and journey tests, investigate unexpected network requests and require privacy review before high-risk pages or events are added.
Keep an emergency disable process for pixels that transmit unexpected information. Record what was changed, when data transmission stopped, whether retained data must be addressed and what evidence supports closure.
Questions to ask
Focus on the decision and the evidence.
- 01
Do we know exactly what every tracking tool sends to every recipient?
- 02
Could the page, event or data combination reveal sensitive information?
- 03
Is the required consent obtained before collection or disclosure occurs?
- 04
Can we prove that our notices, settings and live customer journey match?
Primary sources
Check the controlling material.
Recommended training
Watchdog PRO Certificate: Privacy Officer
Learn how to map tracking data, assess privacy risk and control marketing technology through the live customer journey.
- Map information, systems, purposes and data flows
- Review collection, use, disclosure and retention
- Conduct practical privacy impact assessments
Practical support
Apply the guidance to your facts.
Identify the exact product, claim, customer journey, supplier, legal entity or process involved. Preserve the information that supports the current position, record unresolved facts, assign an owner and confirm the point at which specialist review is required.
Tell us how this issue affects your organisation and receive a tailored recommendation for the most useful next step.
Important information
Check the current position.
This resource is general information, not legal advice. Laws, official guidance and proposals can change. Do not rely on a title or summary alone to decide whether a requirement applies to a particular entity, product or activity.
