Privacy commissioner updates guidance on facial recognition technology in retail spaces

New guidance explains consent requirements, statutory exceptions and governance expectations

Privacy commissioner updates guidance on facial recognition technology in retail spaces

The Office of the Australian Information Commissioner (OAIC) has published updated guidance for organisations covered by the Australian Privacy Principles (APPs) that are considering using facial recognition technology (FRT) in high-volume, publicly accessible physical spaces such as retail shopfronts.

The revised guidance implements the findings of the Administrative Review Tribunal (ART) in the Bunnings Group Limited matter, which concerned the retailer’s use of facial recognition technology in 62 of its stores between 2018 and 2021. The ART’s findings confirmed that there is a high bar for using facial recognition technology in Australia.

In a media release, the OAIC explained that the new guidance makes clear that the Privacy Act neither prohibits nor expressly permits facial recognition technology. Instead, entities must demonstrate that any use complies with the APPs. It confirms that biometric templates and facial images used for automated identification are considered sensitive information and generally attract stronger privacy protections.

The OAIC states that entities should adopt a "privacy by design" approach before introducing facial recognition technology. It recommends conducting a privacy impact assessment at the outset of any project to identify, manage and minimise privacy risks, and encourages entities to publish the assessment where possible. Businesses operating facial recognition systems across multiple premises should assess whether each location presents different privacy or security considerations rather than relying on a single blanket assessment.

The updated guidance also provides more detailed direction on the lawful collection of biometric information. It says entities must generally obtain an individual's valid consent unless a narrow statutory exception applies. The OAIC emphasises that prominent signage alone will not normally constitute consent, while implied or opt-out consent should rarely be relied upon for the collection of sensitive information.

Where businesses seek to rely on an exception to the consent requirement, they must show that facial recognition is reasonably necessary and proportionate. The guidance says businesses should consider whether less privacy-intrusive alternatives, such as CCTV, security guards, employee training or closer engagement with police, could achieve the same objective before deploying facial recognition technology. It also requires organisations to balance the privacy impacts against the benefits of using the technology.

The OAIC further states that retailers must clearly notify customers whenever facial recognition technology is in use. General references to CCTV or video surveillance are insufficient. Customers should be informed that their biometric information is being collected, why it is being collected and, wherever practicable, before collection occurs. The guidance also requires businesses to address the accuracy of facial recognition systems, mitigate risks of bias and discrimination, and protect biometric information through appropriate security measures and timely deletion once it is no longer required.

“The Bunnings decision by the ART provided important clarification on certain aspects of the Privacy Act, and this updated guidance incorporates those points of clarification. The guidance remains clear, however, that each proposed deployment of FRT will need to be assessed against the requirements of the Act”, said Privacy Commissioner Carly Kind.

Kind also said Australian law requires a precautionary approach to the deployment of facial recognition technology. She noted that this reflects growing public concern, with the 2026 Australian Community Attitudes to Privacy Survey showing that 45% of Australians now regard facial recognition technology as one of the biggest privacy risks they face, up from 27% in 2023.

Although the Bunnings matter concluded with the ART's decision in March 2026, a separate determination issued by the Privacy Commissioner against Kmart in August 2025 remains under review before the ART. Hearings in that matter are scheduled for early 2027.