20 August 2026
6 min read
Published by:
You search for information about fertility treatment, speak with friends about trying to conceive or buy pregnancy vitamins online. Soon after, ads for pregnancy products and fertility clinics begin appearing in your social feeds. You might wonder, how did that happen?
For individuals, that experience can feel intrusive, particularly where it relates to fertility, pregnancy, pregnancy loss or reproductive health. For businesses, it raises a more serious question – what personal information is actually being collected, inferred or disclosed through website tracking, advertising technology and third-party tracking pixels?
The recent determination concerning Monash IVF is a timely reminder that online tracking data may still be regulated under the Privacy Act, even where organisations consider it to be de-identified, hashed or collected indirectly. Where that data reveals or suggests sensitive health information, the compliance risks are even higher.
In June, the Australian Privacy Commissioner, Carly Kind, determined that Monash IVF had breached several privacy obligations in its use of third-party tracking pixels. Evidence gathered during the investigation showed that Monash re-targeted ads to individuals who had previously visited its website through other platforms based on information such as their interests, age and gender.
In particular campaigns, Monash re-targeted individuals on Meta platforms with:
The information collected was found to be ‘about’ individuals and that the individuals were reasonably identifiable. Therefore, the Australian Privacy Principles (APPs) applied.
Further, the information collected included health data, which is classified as sensitive information under the Privacy Act. Individuals who visited Monash IVF’s website were also not found to have explicitly or impliedly consented to their sensitive information being collected. Quite the contrary, the Commissioner found that consent could not be established as the tracking pixels were designed to be ‘invisible’ and there was a lack of specific information and notices about this collection on Monash IVF’s website. Monash was therefore held to have contravened APP 3.3, which requires organisations to obtain consent when collecting sensitive information unless an exception applies.
In determining whether Monash had contravened APP 5, which requires organisations to notify individuals of certain matters prior to collection, the Commissioner considered that “infertility poses complex emotional and psychological challenges for individuals”. The Commissioner pointed out that this misuse of personal information via tracking pixels could result in negative consequences for individuals and determined that Monash should take steps to notify these individuals of the collection of sensitive personal information. The fact Monash IVF’s privacy policy referred to the re-marketing of information with Google Analytics, stating that Monash uses analytics data and cookies to serve ads based on an individual’s prior visits to the website, was not enough. Instead, the Commissioner expected notification of the relevant APP 5.2 matters at the time the individual enters the website through means such as a website pop-up.
There was some dispute by Monash as to whether it even ‘held’ this data, but the Commissioner determined that the company had the right or power to the deal with the record created as a result of using tracking pixels. Monash also provided instruction to, and paid, pixel providers for advertising services and instructed them to re-target ads based on the parameters it had set. It consequently ‘held’ the data.
There are other examples of this type of information being used to target advertising to individuals in enforcement actions pursued overseas.
In 2021, a settlement was reached in the US with Flo Health, a popular fertility app used by individuals to track ovulation and record a range of sensitive information. The Federal Trade Commission (FTC) found that the app had misled consumers about a range of claims it had made to protect personal information. The app included tools from numerous third-party marketing and analytics firms, including Facebook and Google, that gathered app users’ sensitive health information. If a user entered pregnancy-related information, Flo Health disclosed that information to the analytics divisions of those third parties. According to the complaint considered by the FTC, Flo Health’s disclosures of sensitive information about users’ pregnancies or periods broke its privacy assurances to users and violated several of the third parties’ own terms of service.
In 2019, the Information Commissioner's Office (ICO) imposed a £400,000 fine on Bounty UK Limited, a pregnancy ‘club’. The organisation collected data through member registrations on its website and mobile application, as well as from new mothers while they were still in hospital through merchandise claiming cards, free samples and vouchers. The ICO launched an investigation into Bounty and found that the company was not just gathering data for the purposes of the club, but was also operating as a data broker that supplied this information to third parties for direct electronic marketing purposes. Bounty was also found to have shared and sold personal data relating to pregnancy, new parents, mothers-to-be, and the birth dates and gender information of children belonging to 14 million individuals without their explicit consent.
There is no doubt that health information centred around pregnancy is becoming increasingly more exposed in data breaches, with recent statistics released by the Office of the Australian Information Commissioner (OAIC) showing that health service providers are among the organisations most affected by data hacks.
In the 2022 Medibank Private breach, hackers published a list of data on the dark web labelled abortions.csv which was said to include member claims for the broader Medicare item 303. This is shocking to consider. While this example is an extreme outlier, all pregnancy-related information should be carefully protected.
Individuals certainly need power over how they are profiled and how they can turn off tracking pixels and other tracking tools and the recent OAIC enforcement actions will hopefully help to bring this about.
While many brands and agencies in Australia do the right thing and employ data ethics and privacy protections into their product design and advertising campaigns, the OAIC investigation that led to the Monash IVF (and Medmate) determinations highlights some misconceptions.
Many organisations assume web browsing data is de-identified, hashed or pseudonymised and that privacy obligations did not apply because it was not ‘personal information’. Other organisations the OAIC engaged with were not even aware of the tracking pixels on their website.
With increasing awareness and enforcement, the clearing up of these misconceptions will hopefully lead to increased protection of sensitive information.
When considering tracking pixels, it is important to consider notice and consent (if the information collected is sensitive). The Commissioner said in the Monash IVF decision that visitors should at least be notified of the collection of the information, the purposes of collection and any usual disclosures of that information (to pixel providers). More broadly, businesses should conduct a technical review of their digital infrastructure to ensure that privacy compliance is built into the design of its websites and applications.
If your business uses third-party tracking pixels and needs assistance with assessing compliance risks or reviewing privacy policies, please contact us here.
Disclaimer
The information in this article is of a general nature and is not intended to address the circumstances of any particular individual or entity. Although we endeavour to provide accurate and timely information, we do not guarantee that the information in this article is accurate at the date it is received or that it will continue to be accurate in the future.
Published by: