Balancing Security and Privacy: Lessons from Facial Recognition Tests

Facial recognition technology presents boards and executives with exactly the kind of decision modern organisations will increasingly face: a technology may solve a genuine problem and still create significant new risk.

The question is therefore not simply whether facial recognition works.

It is whether the problem is serious enough to justify its use, whether less intrusive options could achieve the same outcome, whether the organisation can control the technology properly, and whether the decision would remain defensible if it appeared on the front page tomorrow.

Recent testing by Coles and Woolworths provides a useful prompt for boards well beyond the retail sector.


The 30-second take

Coles and Woolworths have both explored facial recognition technology as retailers continue to confront aggression, violence and retail crime.

Importantly, neither has announced an Australian customer deployment.

Coles told the ABC that it had undertaken a small, one-off controlled proof of concept that did not use customer or team-member information. Woolworths confirmed testing at a New Zealand office. Neither retailer had made a final decision about deployment.

That distinction matters.

But from a governance perspective, the important point is that the decision-making process starts before live biometric data is collected—not afterwards.

A proof of concept is the point at which an organisation should establish why the technology is being considered, the conditions under which it could proceed, and what evidence would cause it to stop.


A legitimate problem does not automatically justify the technology

Retail worker safety is a serious issue.

The ABC reported industry concerns about continuing aggression, threats and violence in stores, with facial recognition being considered as one potential way of identifying known high-harm repeat offenders.

Boards should not minimise that problem. Nor, however, should the existence of a genuine safety problem automatically validate the proposed solution.

That is where necessity and proportionality become critical governance concepts.

The questions should be:

  • What specific harm are we trying to prevent?
  • How effective is the proposed technology likely to be in preventing it?
  • What alternatives have we considered?
  • What new risks do we introduce by solving the original problem this way?

This is much more useful than a binary discussion about whether facial recognition is “good” or “bad”.

The Bunnings decision is more nuanced than a win or loss

The February 2026 Administrative Review Tribunal decision involving Bunnings is particularly instructive.

The Tribunal accepted that, in Bunnings’ particular circumstances, facial recognition could be used for the limited purpose of addressing very significant retail crime and protecting staff and customers from violence, abuse and intimidation. But that did not mean Bunnings’ governance was entirely adequate.

The Tribunal upheld findings relating to deficiencies in notification and privacy policies, and the OAIC highlighted that Bunnings should have undertaken a formal, structured and documented risk assessment dealing with the privacy implications of the system.

The Privacy Commissioner subsequently made the message even clearer: organisations should treat Bunnings as a useful case study, not as a general approval for facial recognition technology.

That is an important distinction for boards.

The lesson is not:

Bunnings could use facial recognition, therefore we can.

The lesson is:

Under particular circumstances, a highly privacy-intrusive technology may be justified—but the organisation needs evidence capable of demonstrating why.

The board should be interested in the alternatives

One of the most useful elements of the OAIC’s updated guidance is its focus on alternatives.

The Privacy Act does not specifically ban or approve facial recognition technology. Instead, organisations must consider whether their proposed use complies with existing privacy obligations.

The OAIC asks organisations to consider whether facial recognition is a suitable and effective response, whether other safety or security measures could achieve the objective without collecting sensitive biometric information, and whether the benefits outweigh the privacy impacts.

This turns the conversation into something boards already understand: options analysis.

If facial recognition is proposed to reduce violence, theft or another risk, management should be able to show the board what alternatives were considered.

That might include security personnel, physical redesign, incident intelligence, restricted-access arrangements, conventional CCTV, improved staff response procedures or other technologies.

The purpose is not to force management to choose the least technologically advanced option.

It is to demonstrate that the organisation has not jumped from “we have a problem” directly to “we need facial recognition.”

A proof of concept needs governance too

Organisations sometimes treat a proof of concept as being outside normal governance because “we are only testing”.

That is dangerous.

A well-controlled test using synthetic or non-customer information may significantly reduce privacy risk, as Coles says occurred in its proof of concept.

But executives should still understand:

  • what data the technology receives;
  • what the vendor can access;
  • where information is processed and stored;
  • what information is retained;
  • whether data can be used to improve the vendor’s models;
  • what happens to test information when the exercise finishes;
  • how accuracy, false positives and false negatives are assessed;
  • what security controls surround biometric templates and related information; and
  • what would be required before the technology could move from a laboratory or controlled environment into production.

Most importantly, there should be no accidental path from experiment to implementation.

Moving into live use should require a deliberate new decision.

Establish the “go, change or stop” criteria before the test begins

This is where boards and executives can substantially improve technology governance. Before a significant technology trial begins, management should establish the criteria that will determine the outcome.

For facial recognition, those criteria might include effectiveness, accuracy, privacy impact, customer impact, security, cost, regulatory requirements and the performance of less intrusive alternatives.

Then the organisation has three genuine choices:

Go — the evidence supports deployment and the risks can be controlled.

Change — the concept has merit, but the design, controls, scope or operating model needs to change.

Stop — the benefit is insufficient, the intrusion is disproportionate or the risks cannot be reduced to an acceptable level.

Without those criteria, pilots have a tendency to develop momentum simply because money, time and organisational reputation have already been invested.

Good governance gives management permission to stop.

Privacy is only one part of the board conversation

Although privacy is central to facial recognition, the board discussion should be wider.

There are questions of:

  • Cyber security. Biometric information requires particularly careful protection because, unlike a password, someone’s face cannot simply be reset following a breach.
  • Technology performance. What are the consequences of a false match? Who reviews an alert before action is taken?
  • Bias and fairness. Does performance vary between populations, environments or demographic groups?
  • Third-party risk. How dependent is the organisation on the technology provider, its algorithms, infrastructure and future product changes?
  • Operational risk. What happens when the technology fails, becomes unavailable or produces an unexpected volume of alerts?
  • Conduct and reputation. Even something that can legally be done may damage customer trust if people believe it is unnecessary or disproportionate.
  • Human decision-making. Technology should support rather than obscure accountability. Someone remains responsible for decisions made because of what the system identifies.

These are not questions for the privacy team alone.

They require input from operations, technology, cyber security, legal, risk, customer, people and potentially the board itself.

Five questions boards should ask

For directors overseeing facial recognition—or any similarly intrusive technology—the discussion can start with five questions:

  1. What specific problem are we trying to solve, and how significant is it?
  2. What less intrusive alternatives have been tested and why are they inadequate?
  3. What evidence demonstrates that the proposed technology is effective and proportionate?
  4. How are privacy, security, accuracy, third-party, operational and reputational risks being controlled?
  5. Who has authority to move from testing into live deployment, and what evidence must they see first?

If management cannot answer those questions clearly, the organisation probably isn’t ready to deploy.

Govern the decision, not just the technology

The broader lesson from facial recognition is relevant to AI and emerging technology generally.

Boards do not need to become experts in facial-recognition algorithms.

They do need to ensure that significant technology decisions are supported by a clear purpose, evidence, alternatives, defined risk appetite, appropriate controls and accountable decision-making.

Technology will continue to create opportunities to solve difficult business problems.

Good governance should not prevent organisations from taking those opportunities.

It should help them determine when using the technology is justified, what safeguards are necessary, and when the right answer is to walk away.

That is the balance boards increasingly need to get right.

Want to test whether your organisation’s assessment could support a defensible go, change or stop decision?

Visit the Innovation of Risk and explore practical tools for turning emerging technology risks into structured executive and board decisions.

More from the Reading Room

AI Agent Security: What the RubyGems and Hugging Face Incidents Reveal

Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.

When Fraud Syndicates Exploit Loan Processes: What Australia’s $600 Million Scam Reveals About Control Failures

NSW police allege a criminal syndicate defrauded banks of up to $600 million using false loan applications and insider help from accountants and money mules. This case uncovers how multi-party collusion exploits gaps in loan processes, demanding tighter fraud controls and cross-agency scrutiny.

APRA and ASIC put frontier AI, cyber and resilience on the board agenda

APRA and ASIC’s September 2026 superannuation roundtable summary shows why AI, cyber and supplier disruption should be tested as one compound event. Businesses need rehearsed authority to contain harm, operate through disruption and approve recovery.

APRA’s ING action is a blunt reminder: liquidity breaches are not just an internal issue

APRA’s 3 September 2026 action against ING Australia showed how a reported liquidity ratio near 160 per cent could conceal a materially lower position. Every business should govern critical metrics as controlled products with reproducible calculations, named ownership and escalation for uncertainty.