Taking Control of Cross-Device Tracking by Ad Networks
Ad networks have spent the last decade stitching your phone, laptop, smart TV and tablet into a single profile that follows you from a Sydney commute to a Melbourne café and back to the lounge room. The mechanism behind that stitching is called cross-device tracking, and most Australians interact with it every day without realising that an advert seen on a phone in Bondi can resurface as a sponsored post on a work laptop in Parramatta an hour later. The practice sits at the centre of the modern advertising economy and, as recent analysis of the uncomfortable business model behind the web shows, it is not going away voluntarily. What can shift is the amount of data you feed it, and how much of that stitching you can quietly undo.
The good news for people in Australia is that the regulatory framework, though imperfect, gives you a handful of meaningful levers. The Privacy Act 1988, the Australian Privacy Principles, the Notifiable Data Breaches scheme, and guidelines from the Office of the Australian Information Commissioner all create obligations that ad networks and data brokers occasionally have to honour, particularly when you write to them directly. Layered on top of this is a growing patchwork of platform-level controls, from Apple's App Tracking Transparency to Android's advertising ID settings, that you can configure yourself in under an hour. This article walks through what cross-device tracking actually is, what your rights are under Australian law, and the concrete settings, scripts and habits that reduce its reach on the devices you use every day.
What cross-device tracking actually does
Cross-device tracking is the broad term for the set of techniques ad networks use to recognise that the same human is sitting behind a phone, a laptop, a connected TV and a tablet. The most accurate method is deterministic matching, where a network links activity using a shared login such as a Google account, an Apple ID or an email address logged into a media site. If you read a news article on your iPhone in Brisbane while signed into a Google account, then open YouTube on your work laptop in the same session, deterministic matching ties those two events to one person with very high confidence.
The second method is probabilistic matching, which relies on signals such as IP address ranges, Wi-Fi network names, device model, operating system version, battery level, fonts installed, and the time zones a device reports. Ad networks combine dozens of these signals into a fingerprint that often identifies a household with surprising accuracy. A laptop on the iiNet network in Adelaide at 9:47pm ACST, paired with a phone on Telstra reporting the same Wi-Fi SSID, is enough for a probabilistic engine to guess that the two devices belong to the same family. Once that guess is made, an advert for a product viewed on the phone can reappear moments later on the laptop, in a connected TV's break, or as an out-of-home display ad the next time you pass through a shopping centre.
The Australian regulatory landscape and your rights
Australia's privacy framework does not yet contain a single, dedicated law against cross-device tracking, but several existing instruments constrain how it can be deployed. The Privacy Act 1988 and the thirteen Australian Privacy Principles require organisations that collect personal information to handle it transparently, use it only for the purpose it was collected, and give individuals a way to opt out of direct marketing. The Office of the Australian Information Commissioner has consistently taken the view that a device identifier combined with behavioural data counts as personal information, which means a tracking profile tied to a Mobile Advertising ID is covered by the Act. The Australian Competition and Consumer Commission's digital advertising inquiry also flagged cross-device tracking as a concern, recommending stronger consent requirements that have not yet been fully implemented.
For everyday Australians, this translates into a few practical rights. You can request that a data broker or ad network tell you what information it holds about you, ask for it to be corrected, and in many cases demand that it be deleted. Some networks honour these requests through online forms, others require a formal email. Following the Twenty of Time habit of keeping a written record of every opt-out request makes it easier to track which companies have replied and which have stalled. The OAIC can investigate persistent non-compliance, although in practice the more effective pressure is usually a polite, well-documented request followed by a complaint to the regulator if no answer arrives within thirty days.
Resetting and restricting advertising identifiers
Every modern phone and most modern tablets carry an advertising identifier that ad networks use as a kind of name tag. On iPhones and iPads it is the Identifier for Advertisers (IDFA), and on Android devices it is the Google Advertising ID (GAID). Both can be reset, restricted or zeroed out, which forces ad networks to start building a fresh profile from scratch. Resetting regularly is not a perfect defence, but it dramatically shortens the length of any profile an ad network can build about you, and it makes deterministic matching across devices far harder when the identifier changes between sessions.
On an iPhone running iOS 17 or later, the relevant path is Settings, then Privacy and Security, then Tracking. From there you can switch off Allow Apps to Request to Track, which prevents apps from even asking for the IDFA. For finer control, the Advertising section under Privacy and Security lets you tap Reset Advertising Identifier, a button worth using once a month. On Android, the equivalent path is Settings, then Google, then All Services, then Ads, where you can delete the GAID and switch on Opt out of Ads Personalisation. Australian carriers such as Telstra, Optus and Vodafone AU also inject their own identifier headers on some mobile networks; switching off Wi-Fi calling or using a reputable VPN can reduce how often these headers leak, although a VPN is no substitute for the platform-level resets above.
It is also worth thinking about the wider ecosystem around those identifiers. Browsers, smart TVs, gaming consoles, and even some cars now carry their own advertising IDs, and resetting only the phone leaves the rest of the household profile intact. Most Samsung, LG and Hisense smart TVs sold in Australia expose an advertising ID buried in the Settings menu under Support, then Terms and Privacy, then Interest-Based Advertisements, and Apple TVs and Amazon Fire Sticks have similar toggles inside their privacy settings. Resetting each of these in turn, on a Saturday morning, takes about twenty minutes and is one of the most effective single steps a household can take.
Browser and app defences against trackers
Outside the device-level identifiers, the day-to-day vectors for cross-device matching are the browsers and apps you spend most of your time in. Chrome, Safari, Firefox, Edge and Brave all expose some form of anti-tracking feature, although they are not all equally aggressive. Safari's Intelligent Tracking Prevention strips a large amount of cross-site scripting data, Firefox's Enhanced Tracking Protection blocks known fingerprinting scripts by default, and Brave goes further by randomising the fingerprint each site sees. Chrome, owned by the same company that runs the largest ad network in the world, is the weakest of the four for privacy, and Australians who want a meaningful reduction in cross-device matching should consider switching the default browser on at least one device to Firefox or Brave.
Within the browser itself, a small set of extensions does the heavy lifting. uBlock Origin blocks the requests that ad networks use to exchange identifiers, Privacy Badger learns which domains are tracking you and isolates them, and Decentraleyes serves common script files locally to prevent yet another fingerprinting vector. On the iPhone, the equivalent is the Safari content blocker, with 1Blocker and AdGuard being two of the more popular Australian-friendly options in the App Store. The endpoint discipline described in this ransomware protection guidance applies just as much to phones and laptops as it does to traditional PCs, and a hardened browser is a meaningful part of that posture.
Apps deserve a separate pass. Many Australians keep the same social, news and shopping apps installed for years without revisiting their permissions, which means a great deal of cross-device matching happens inside the app rather than in the browser. The Settings app on both iOS and Android now groups permissions by type, including Tracking, which is the one to focus on. If a weather app or a flashlight is asking for tracking permission, the answer is always no, and the same logic applies to the handful of apps that ship with the Telstra, Optus or Vodafone AU account portals. Removing tracking permissions from apps that have no business asking is one of the highest-yield changes you can make in a single sitting.
Opting out of data brokers and ad networks
The final layer, and the one that takes the most persistence, is opting out of the data brokers and ad exchanges that sit underneath the major ad networks. In Australia, brokers such as Acxiom, Experian, Equifax, illion and the local arm of Oracle Data Cloud hold rich profiles stitched together from public records, loyalty cards, browsing data and the cross-device graphs they buy from the larger ad networks. Opting out of each one individually is tedious, but it is also the single most effective way to shrink a household profile, because brokers are the source from which many smaller ad networks and publishers draw their targeting data.
The starting point is a simple inventory. The OAIC's Notifiable Data Breaches register and the Australian Cyber Security Centre's resources list the largest local brokers, and each maintains its own opt-out form. For the major international exchanges such as The Trade Desk, LiveRamp, Criteo and Taboola, the curated reading list collected at Twenty of Time has step-by-step links and the right email templates to use. The process generally involves an identity check, a confirmation email and a waiting period of a few weeks, after which the broker must, under the Privacy Act, suppress your profile from most downstream uses. The catch is that suppression often applies only to the broker itself, so writing to the same company's advertising arm as well is worth the extra half hour.
There is one Australian-specific trap to watch for. Several large retailers and loyalty programs, including the Woolworths Everyday Rewards and Coles flybuys schemes, share data with ad networks in ways that are not always obvious from the loyalty program's own privacy policy. Logging into either program's privacy portal and switching off personalised marketing and data sharing with third parties is a small but meaningful step, and it feeds directly into the same household profile the brokers are building. Once a quarter, repeat the process, because these settings have a habit of quietly reverting after app updates.
The single most useful thing to do this week is to open your iPhone, your Android phone and the browser you use most often, reset every advertising identifier you can find, switch off Allow Apps to Request to Track, and install uBlock Origin or a Safari content blocker on each one. That trio takes under fifteen minutes, costs nothing, and immediately severs many of the deterministic and probabilistic links that ad networks rely on to stitch your devices into a single profile, giving you a cleaner baseline from which to work through the broker opt-outs over the following month.