Last Updated on 31/07/2026 by Damin Murdock
The legal obligations around data collection and use evolve with the evolution of digital technologies, such as user tracking technologies like cookies, pixels and analytics tools.
In Australia, public and private sector entities have to comply with strict requirements under the Privacy Act 1988 and the Australian Privacy Principles (APPs). In this article, we cover the key compliance obligations, technical implementation measures and the best legal practices to use tracking technologies in Australia.
Key Compliance Pillars: Notice, Consent and Safeguards
- Transparency and APP 5 Notice Requirements
Organisations must provide clear and upfront notice to users before or at the time of the use of tracking technologies. The privacy notice must explicitly state the following to comply with APP 5:
- The purpose of data collection and/or data tracking
- How the data will be used
- If the data will be shared with third parties, and if so, who those parties are.
Any data collection must be fair and lawful without unreasonable intrusion on users’ privacy.
- Cookie Consent and Data Collection Practices
When using advanced tracking tools, consent is essential. Organisations have to seek users’ consent if tracking data is combined from different sources to profile users. They also must support the data collection with robust internal governance, including regular staff training, administrative controls, technical security measures and regular audits.
- Technical Implementation of Tracking Cookies
If your organisation uses advertising, marketing or analytics cookies, you should make sure that these technical guardrails are in place:
- Ensure data is stored on a pseudonymous basis to limit direct identification.
- Maintain a clear distinction between personal information and non-personal tracking data.
- Obtain specific consent if tracking activities are tied back to identifiable, logged-in user accounts.
The Medmate and Monash IVF Example
Telehealth provider Medmate and fertility clinic Monash IVF embedded third-party tracking code on pages where users searched for sensitive treatments, filled prescriptions or completed web forms. Data containing specific researched medical conditions, emails and phone numbers were then shared with social media platforms for ad targeting.
The Australian Privacy Commissioner found that website browsing habits, searched URLs, and cart activities constitute sensitive health information under the Privacy Act. Therefore, the parties needed explicit, voluntary and informed consent from users before collecting and/or sharing this data. Generic disclaimers or hidden policy texts were found to be legally lacking. Medmate and Movash IVF were found to have “interfered with the privacy of individuals whose sensitive information was collected via third-party tracking pixels”
Monitoring, Documentation and Privacy Audits
- Monitoring Obligations
Government agencies are required to conduct regular compliance monitoring under the Privacy (Australian Government Agencies – Governance) APP Code 2017 (Cth). While this requirement isn’t for the private sector, commercial entities are encouraged to review their practices to comply with OAIC standards.
- Privacy Documentation
Organisations should maintain an updated privacy policy on their website and content-specific notices at the point of data collection as required by APP 1 and APP 5. Internal data logs showing when, how and why user tracking occurs should also be maintained, including technical justifications and evidence of compliance.
Risk Management and Privacy Impact Assessments (PIA)
Organisations should proactively conduct PIAs for any new data tracking or collection technologies they employ or any digital marketing campaigns. This mitigates the risk of OAIS enforcement action and ensures compliance.
Legal Exemptions and Limitations
There are some exemptions where tracking compliance may be bypassed, including for law enforcement or public safety purposes, prejudice to the vital interests of an individual or specific legal authorisations. However, these exemptions are interpreted very narrowly by Australian regulators and should be used carefully with legal counsel.
Best Practices
Ensure that your digital team implements the following best practices to protect your organisation from legal risk:
- Transparent cookie banners, preferences, and easy opt-out options.
- Regular audits to prevent and detect data leaks.
- Limit the collection of personal information to the minimum necessary for the business function.
- Continuously train teams on data ethics, privacy laws and secure handling of data.
At Leo Lawyers, we help our clients navigate the complex and multifaceted requirements of privacy compliance. If you require tailored legal advice, feel free to contact Damin Murdock at Leo Lawyers via our website, on (02) 8201 0051 or at office@leolawyers.com.au. Further, if you liked this article, please subscribe to our newsletter via our Website, and subscribe to our YouTube, LinkedIn, Facebook and Instagram. If you liked this article or video, please also give us a favourable Google Review.
DISCLAIMER: This is not legal advice and is general information only. You should not rely upon the information contained in this article, and if you require specific legal advice, please contact us.
Damin Murdock (J.D | LL.M | BACS - Finance) has over 17 years of experience as a commercial lawyer. He helps businesses navigate construction and technology law. Damin has held several big leadership roles, including serving as a director of a national law firm and the Chief Legal Officer for Lawpath.
He has personally helped more than 2,000 startups and small businesses. With over 300 five-star reviews, his clients clearly value his practical advice and simple way of explaining things. Damin has also hosted over 100 webinars that thousands of people have watched to get reliable legal help.
