OAIC Determinations and Their Implications for Digital Advertising
1. Executive summary
Recent determinations by the Office of the Australian Information Commissioner (OAIC), including matters involving Monash IVF and Medmate, reinforce the application of the Privacy Act 1988 (Cth) to modern digital tracking technologies, including third-party pixels and similar adtech implementations.
While the factual contexts of these determinations involved sensitive health information, the OAIC’s reasoning provides broader insight into how obligations under the Australian Privacy Principles (APPs) apply to digital data collection ecosystems. In particular, they reinforce that accountability for personal information handling remains with the organisation that collects or discloses the information, regardless of reliance on third-party vendors or platforms.
2. Regulatory context
Under the Privacy Act 1988 (Cth), organisations must comply with the Australian Privacy Principles (APPs), including:
- APP 3 (Collection of solicited personal information): requiring lawful and necessary collection practices
- APP 5 (Notification of collection): requiring transparency at or before the point of collection
- APP 6 (Use or disclosure): governing downstream sharing with third parties, including service providers and adtech platforms
Where sensitive information is involved (including health information, political opinions, racial or ethnic origin, and other categories defined under the Act), additional restrictions apply, including generally higher thresholds for consent and handling.
3. Regulatory findings relevant to tracking technologies
The OAIC determinations highlight several key principles relevant to the use of tracking pixels and similar technologies:
3.1 Accountability is non-delegable
An organisation remains responsible for the collection and disclosure of personal information, even where third-party technologies (such as pixels, SDKs, or conversion APIs) are used to facilitate data flows.
Engagement of vendors or agencies does not transfer regulatory accountability.
3.2 Transparency and notice obligations extend to implementation
APP 5 obligations require that individuals are notified of the collection of personal information at or before the time it occurs. In practice, this includes data collected via embedded technologies such as tracking scripts and pixels.
The adequacy of notice is assessed in relation to actual data flows, not solely published privacy policies.
3.3 Sensitivity of information materially affects regulatory scrutiny
Where collected data constitutes or can reasonably infer sensitive information, the threshold for compliance is elevated. This includes both direct collection and inferred profiling derived from behavioural or contextual signals.
While recent determinations arose in a healthcare context, the underlying principles apply to any environment where sensitive information may be collected or inferred through digital tracking systems.
4. Interpretation for modern adtech and analytics environments
Modern digital marketing and measurement ecosystems commonly involve:
- Client-side and server-side tagging architectures
- Third-party pixels and SDKs
- Conversion APIs and platform integrations
- Cross-domain tracking and attribution systems
- Data clean rooms and probabilistic matching techniques
These systems may transmit identifiers such as IP addresses, device identifiers, and behavioural event data. In many circumstances, this information may constitute “personal information” under s 6(1) of the Privacy Act where an individual is reasonably identifiable, particularly when combined with other datasets.
Accordingly, the use of such technologies requires ongoing assessment of:
- what data is collected
- how it is processed and combined
- where it is disclosed
- whether such use is reasonably expected by individuals
5. Shared responsibility and governance expectations
Digital data ecosystems typically operate under a distributed implementation model involving internal teams, agencies, and third-party platforms.
However, under the APP framework:
- The organisation collecting or disclosing personal information retains primary accountability
- Vendor or agency involvement does not displace statutory obligations
- Governance must extend to externally implemented systems where organisational data is processed or transmitted
This creates a requirement for continuous oversight of data flows across marketing and analytics infrastructure.
6. Implications for organisational governance
The OAIC determinations reinforce that privacy compliance is not solely a policy function, but an operational governance requirement.
Organisations should be able to demonstrate clear visibility and accountability over:
- Active tracking technologies across digital properties
- Categories of data collected and their classification under the Privacy Act
- Data sharing relationships with third parties and platform providers
- Consent mechanisms and their alignment with actual data practices
- Internal ownership of privacy and data governance functions
- Ongoing monitoring of configuration changes and “compliance drift”
The primary governance risk identified in modern environments is not the existence of tracking technologies in isolation, but the lack of traceability and control over how those technologies interact with personal information.
7. Risk considerations for boards and executive teams
From a governance perspective, key risk areas include:
- Regulatory risk: non-compliance with APP obligations relating to collection, notice, and disclosure
- Operational risk: limited visibility into complex or fragmented data ecosystems
- Vendor dependency risk: reliance on third-party configurations outside direct organisational control
- Reputational risk: consumer sensitivity to data use and perceived opacity in tracking practices
Effective oversight requires the ability to evidence not only documented policies, but also implemented technical controls and governance mechanisms aligned with actual system behaviour.
8. Practical governance measures
Organisations should consider implementing the following controls:
- Comprehensive audit of tracking technologies (pixels, tags, SDKs, APIs) across all digital properties
- Privacy Impact Assessments (PIAs) for data collection and activation workflows
- Mapping of data flows from collection through to third-party disclosure
- Review and validation of consent and notice mechanisms against live implementations
- Formal assignment of ownership for privacy and data governance oversight
- Scheduled revalidation of configurations to manage system and vendor-driven change
9. Concluding observations
The OAIC’s recent determinations reinforce a consistent regulatory position: accountability for personal information handling remains with the organisation, regardless of the technical complexity of its data ecosystem or the involvement of third-party service providers.
As digital measurement architectures continue to evolve toward more distributed and automated models, governance expectations increasingly focus on demonstrable control, transparency, and ongoing oversight rather than static policy compliance.