Article originally published by Anna Johnston, Director at Helios Salinger.
Two new cases demonstrate the risk from pixels, the reality of digital harms, and how the regulator is testing the boundaries of the law, with implications for all.
Do you know if your organisation’s website is leaking sensitive information about your customers, to third parties, which could be used to harm your customers and undermine your own objectives?
Time to check for third-party tracking pixels on your website. Marketing or web dev teams may have placed pixels on your website without operational business areas even knowing, let alone understanding what is going on, as the OAIC has found. (Social media platforms offer website builders code to enable tracking pixels for integration and use on their websites, and dashboards to offer insights about website users’ behaviour. It is such standard industry practice that entities may need to actively request their web developers to not add the code to their website.)
And if you are using third-party tracking pixels, next step is to check if you have lawful authority to use them, given the Privacy Act’s restrictions under APP 3 (collection), APP 6 (disclosure) and APP 7 (direct marketing). Or: just stop using them.
Don’t believe claims about the data you are sharing via those pixels being ‘de-identified’. And certainly don’t believe anyone who tells you that you can get your customers’ consent for your data-sharing habits via your Privacy Policy.
Otherwise, without your customers’ valid consent, you might find yourself in breach of the Privacy Act, as Australia’s Privacy Commissioner found in cases this week against health service providers Monash IVF (fertility services) and Medmate (telehealth).