Australia’s privacy regulator has updated its guidance for facial recognition in shops and other commercial spaces, incorporating a tribunal decision that narrowed one part of its earlier position on consent.
The Office of the Australian Information Commissioner says facial images and biometric templates used for automated verification or identification are sensitive information under the Privacy Act. Organizations must have a lawful basis for collecting them and comply with the Australian Privacy Principles even when data is held only briefly.
The update reflects the Administrative Review Tribunal’s February decision involving Bunnings. The tribunal found that the hardware retailer could rely on limited exceptions to consent requirements for combating retail crime and protecting staff and customers from violence, abuse and intimidation. It nevertheless upheld findings that Bunnings failed to provide adequate notification and transparency.
That result partially overturned the original privacy determination rather than giving retailers general permission to deploy facial recognition without consent. OAIC’s revised guidance says exception pathways are narrow and must be assessed against the facts of each use case.
Organizations considering a system are advised to complete a privacy impact assessment before deployment and document whether the proposed use is necessary and proportionate. They should also examine less intrusive alternatives, system effectiveness, image and watchlist accuracy, demographic bias, data security and deletion practices.
Transparency remains required whether collection relies on consent or an exception. Regulated entities must take reasonable steps to tell people what information is being collected and why. They also need governance arrangements that are implemented, documented and reviewed as the system or operating conditions change.
The regulator first issued the retail facial-recognition guidance in 2024, when it emphasized consent, proportionality and privacy-by-design controls. The new version preserves those principles while accounting for the tribunal’s interpretation of permitted collection in a narrowly defined security context.
The document applies to facial identification in physical commercial settings. OAIC notes that age assurance and other biometric uses may collect different information and require a separate analysis.
A 2025 privacy determination concerning Kmart Australia’s facial-recognition use is still under review by the tribunal. Its outcome could further clarify how the Privacy Act applies to watchlist-based retail deployments.
Sources: Office of the Australian Information Commissioner, Administrative Review Tribunal
–
By the ID Tech Editorial Team








Follow Us