Facial Recognition in Retail: What the OAIC's Updated Guidance Actually Changes
Jason ScarboroughFor most of the last two years, Australian guidance on facial recognition technology (FRT) in retail settings was theoretical. The Office of the Australian Information Commissioner (OAIC) had laid out the principles, but no regulated entity had tested them in a tribunal. That changed in February 2026, when the Administrative Review Tribunal handed down its decision in the Bunnings case, and on 29 July 2026, the OAIC rewrote its FRT guidance to reflect it.
If you run physical premises and have ever wondered whether cameras that identify individuals are worth the privacy exposure, this update is the first real answer with a court-tested precedent behind it. Here's what changed, and what it means in practice.
What's actually new
The OAIC's guidance was originally published in November 2024. The July 2026 update folds in two things:
- The Bunnings decision. The Administrative Review Tribunal reviewed the Privacy Commissioner's original 2024 finding against Bunnings and delivered a split outcome. It agreed Bunnings' collection of biometric information fell within a "permitted general situation", meaning it didn't need individual consent from every customer whose face was scanned. But it also upheld the Commissioner's finding that Bunnings breached APP 1 and APP 5, because it hadn't properly notified customers or documented a formal risk assessment before deploying the system. Bunnings keeps its system running; it still has compliance work to do.
- The Kmart determination remains contested. A separate 2025 finding against Kmart over its own FRT use, deployed across 28 stores to catch refund fraud, is still under review by the Tribunal. Kmart has filed for review, but no hearing date has been set beyond an expectation it will be heard in early 2027. There's no result to report yet, and won't be for some time.
The headline point the OAIC wants understood: the Privacy Act doesn't ban or bless FRT. It's technology-neutral. Whether a deployment is lawful comes down to a fact-specific test that the Bunnings decision has now made concrete instead of hypothetical.
A narrow scope, and still not simple
It's worth being precise about what this guidance actually covers. The OAIC states upfront that it applies to FRT used for facial identification in a physical commercial or retail setting: a shopfront, a store, a venue people walk into. It doesn't extend to FRT built for other purposes, such as age assurance, which the OAIC treats separately. Public space surveillance by government agencies, workplace access systems, and law enforcement use each sit under their own frameworks.
Even within that narrow slice, the primary guidance document runs to 25 pages, and the OAIC felt it necessary to supplement it with a dedicated flowchart, a factsheet, and a separate checklist just to make the collection pathway navigable. That's not a criticism of the guidance. The underlying law genuinely is fact-specific, and the Bunnings and Kmart cases show why a general rule would fail most retailers most of the time. But it's a useful data point on its own: if getting FRT right in one clearly bounded use case takes this much documentation, it is not a decision to make on the strength of a vendor's sales pitch.
The starting point: this is sensitive information, always
Facial recognition works by extracting a biometric template from an image and comparing it against a reference database. Under the Privacy Act, that biometric template is sensitive information: the highest protection tier the Act offers.
The detail that surprises a lot of operators: there's no minimum time threshold for "collection." Even if a system captures a face, checks it against a database in milliseconds, finds no match, and discards it, that momentary presence in a computer's memory still counts as a collection event under the Act. It doesn't matter that nothing was written to a hard drive. This means every person who walks past an FRT camera has had their sensitive information collected, whether or not they were ever "recognised."
Why consent mostly doesn't work here
The Act's default position is that sensitive information needs consent to collect. But valid consent has to be informed, voluntary, specific, and given by someone with the capacity to understand what they're agreeing to. A sign at the door doesn't meet that bar. Signage alone was explicitly called out in the guidance as insufficient for sensitive information. In a space anyone can walk into off the street, there's usually no practical way to get real consent from every person captured.
That leaves two other pathways:
- Authorised by law β a very narrow lane. It only applies where a law explicitly requires or authorises FRT, not just where nothing prohibits it. South Australian gaming venues are the clearest example currently in force.
- Permitted general situations β the pathway both Bunnings and Kmart relied on, covering a serious threat to safety or suspected unlawful activity or serious misconduct.
For most retail and commercial operators, the permitted general situation pathway is the only realistic option, and it comes with a high bar.
The three-part test that decided the collection question
Worth being precise here: this test decided whether Bunnings had a lawful basis to collect biometric information in the first place. It's a separate question from whether Bunnings handled that collection properly once it started, and on that second question, the Tribunal found against Bunnings. Both parts matter, and getting the first right doesn't excuse getting the second wrong.
On the collection question, the Tribunal's reasoning gives operators something they didn't have before: a working test for "reasonably necessary." It has three parts.
Suitability β does FRT actually work for the problem you're pointing it at? Bunnings could show that proactively identifying known repeat offenders before an incident reduced violent incidents, compared with confronting people only after they'd already offended.
Alternatives β could a less intrusive method achieve a similar outcome? This is not a test of whether an alternative would be equally effective. It's whether a genuinely less intrusive option was practical. Bunnings' security experts assessed that no other control (more guards, better training, banning orders) could reliably identify repeat offenders across stores with multiple entry points and in-store vehicle access, the way FRT could.
Proportionality β do the benefits outweigh the privacy cost? This is where the specific design of Bunnings' system mattered as much as the policy behind it. Faces that didn't match were deleted within milliseconds. The system wasn't capable of reconstructing an image from the stored template. The risk of the data being breached or on-sold was assessed as low. Those technical choices, not just the business justification, are what tipped the scale.
The point regulators and the Tribunal both stress: Bunnings' circumstances were unusual. Large format stores, multiple entrances, vehicles driving inside, and shelves stocked with items that double as weapons. A retailer with a single-entry shopfront and a much lower incident rate is not automatically covered by the same reasoning just because Bunnings passed this test.
And passing it wasn't the end of the story. The Tribunal separately upheld the finding that Bunnings hadn't taken reasonable steps to notify customers what it was doing, or documented a formal privacy impact assessment before it started. A lawful basis to collect doesn't substitute for the transparency and governance obligations that sit alongside it . Bunnings is the clearest illustration available of that distinction, having satisfied one and fallen short on the other in the same case.
What this means if you're weighing FRT in a retail setting
A privacy impact assessment isn't optional in practice, even where it isn't legally mandated. The guidance is blunt that FRT is "highly intrusive" and that a PIA is the expected first step before any deployment decision. For government agencies it's mandatory for high-risk projects; for everyone else, it's treated as the reasonable step under the Act's accountability principle.
Generic CCTV signage won't cover you. Notification for FRT specifically needs to say what's happening and why. "Cameras in use" doesn't tell someone their face is being biometrically matched against a database.
Retention has to be near-immediate for anyone who isn't a match. The OAIC's own recommended practice is transient processing by design: process, compare, delete, with no persistent copy for non-matches.
Third-party FRT vendors don't reduce your liability. If you're engaging someone else's system, the guidance is explicit that responsibility for Privacy Act compliance stays with the entity deploying it, particularly where the vendor is offshore.
Accuracy and bias testing needs a paper trail. Regulators expect documented testing, not a vendor's marketing claim about accuracy rates.
The bigger pattern
What the Bunnings and Kmart cases really demonstrate is that the law was never asking "is FRT good or bad." It was asking the same three questions it asks of every surveillance decision: is this the right tool for a specific, articulable problem, is there a less intrusive way to solve it, and does the benefit actually outweigh what it costs the people being watched. FRT just makes the stakes of getting that assessment wrong higher, because the information collected is sensitive by definition and the tolerance for error is lower.
That's a useful discipline regardless of whether the surveillance in question uses biometric identification or not. The same proportionality logic sits underneath any decision to point a camera at a public space and turn on AI-based analysis. The technology changes; the test for whether it's justified doesn't.
This isn't settled law yet
Everything above reflects the position as it stands today, with Kmart's own Tribunal review still to come. Whatever that decision says, it's worth treating this area as unsettled for a while yet. Not because the Tribunal is unpredictable, but because FRT (and AI-driven surveillance more broadly) is moving faster than the legislation built to govern it. The Privacy Act's core provisions predate the technology now being tested against them, which is exactly why cases like Bunnings and Kmart have had to do so much interpretive work to apply decades-old principles to biometric matching at scale. That gap between what the law was written for and what it's now being asked to cover doesn't close with one Tribunal decision. Expect this guidance to keep being revised as more cases are decided and as the technology itself keeps changing.