Regulator sharpens the warning on facial recognition

This is not administrative tidying. The Office of the Australian Information Commissioner (OAIC) has used the Bunnings case to sharpen its practical message on facial recognition technology: if an organisation wants to use biometric surveillance in a public-facing environment, the legal and governance bar is high, and the assessment has to be done properly for each deployment.

Published on 29 July 2026, the updated guidance applies to Australian Privacy Principles (APP) entities considering facial recognition technology in high-volume, publicly accessible physical spaces such as retail shopfronts.

It reflects the Administrative Review Tribunal’s (ART) March 2026 findings in the Bunnings matter and is designed to give clearer direction on how the Privacy Act applies in practice.

Board-Level Take

The immediate signal for boards and executives is straightforward: facial recognition is no longer something that can be treated as a generic security upgrade.

The Regulator is saying the assessment must be contextual, evidence-based and aligned to the requirements of the Act.

That matters because the guidance does more than restate the law. It reinforces the need to test whether any exception to consent can genuinely be relied on when biometric information is being collected, and whether the proposed use is defensible in the circumstances.

What Is Actually Changing — and Why It Matters

Bunnings decision has become the reference point

The updated guidance incorporates the ART’s clarification in the Bunnings matter, which the OAIC says provides important guidance on how the Privacy Act should be applied.

That means the regulator is not speaking in the abstract. It is translating a contested enforcement outcome into a clearer supervisory position.

In practice, any organisation using or trialling facial recognition should assume its privacy reasoning will need to be articulated clearly and supported by records.

A “we thought it was justified” approach will not be enough.

The guidance specifically addresses exceptions to the obligation to obtain consent when collecting sensitive information, including biometric information. That is the pressure point. The issue is not simply whether the technology is useful, but whether the legal pathway for collecting that data has been properly tested.

Boards should be asking whether the business has an up-to-date view of when consent is required, when it is not, and what evidence exists to support that position.

Retailers cannot rely on one-size-fits-all answers

The OAIC makes clear that retailers will continue to need contextual assessments on a case-by-case basis. That means no blanket approval model and no assumption that a tool approved in one store format, use case or risk environment will automatically be acceptable elsewhere.

For business leaders, that raises a familiar but important issue: where is the decision documented, who signed off the privacy and conduct risks, and what controls exist to ensure the deployment does not drift beyond the original case?

The Commissioner’s remarks make clear that regulatory expectations are being shaped alongside public concern. The updated guidance cites the growing share of the community that sees facial recognition as one of the biggest privacy risks they face today.

That matters because reputational risk is now part of the compliance picture. Even where a deployment is arguably lawful, organisations should still be asking whether they can explain it, defend it and sustain it under public scrutiny.

Questions Risk and Governance Teams Should Ask Now

  • Do we use, trial or plan to use facial recognition in any retail, venue or other public-facing setting?
  • What is our documented basis for relying on any exception to consent for biometric collection?
  • Have privacy, legal, risk and operational teams all signed off the same use case, or are there gaps between them?
  • What evidence would we produce if asked to show how we assessed necessity, proportionality and alternatives?
  • Do our contracts, notices and internal policies align with the updated OAIC guidance?
  • If the deployment is challenged, who owns the response and who can explain the decision in plain English?

Why This Needs Attention Now

The timing is important because the OAIC has already turned a contested enforcement matter into updated guidance, and the Kmart matter remains under review in the ART.

That means the practical rulebook may continue to evolve. Waiting for more certainty is itself a risk, especially for organisations already using or piloting facial recognition.

The sensible response is to treat this as a readiness exercise now: map current use, test the legal basis, tighten documentation and make sure the board can see where the real risk sits.

Turning Regulatory Signal Into Board-Ready Action

The Innovation of Risk Reading Room tracks APRA, ASIC, the OAIC and other regulatory developments as they move from consultation to enforcement.

If your board or risk team wants a structured way to monitor obligations, test maturity and identify evidence gaps before they become governance issues, that is the place to start.

More from the Reading Room

When National Alerts Miss Local Needs: Queensland’s Opt-Out from AusAlert

Queensland opted out of AusAlert this bushfire season despite a 94% national test success rate. This isn't about whether that call was right — it's about the resilience discipline it illustrates: weighing your own specific variables today and making a definitive decision ahead of the event that will test it.

Risk Maturity in Action: Turning Customer Promises into Reliable Outcomes

Two recent ASIC matters provide a useful opportunity to think differently about risk management. They can be read as stories about compensation, penalties and compliance...

APRA’s Level 3 conglomerate standard reset is a governance issue

APRA has published its response to consultation on remaking the Level 3 conglomerate standards. This is a substantive prudential and governance update for groups with complex conglomerate structures, especially where superannuation, insurance and banking interests…

Business continuity is needed everywhere

Organisations that value the customer and evaluate themselves on their effective response to events will prepare incident response plans prior to events through analysis of their business processes and identification of potential failure points.


Click the title to read more.