Part of the AI Regulation News hub.
The OAIC has updated its facial recognition guidance to fold in the Administrative Review Tribunal's Bunnings decision and clarify when a retailer can collect biometrics without consent
The update is not a loosening. Bunnings carried the necessity and proportionality factors on facts the OAIC now spells out as unusually strong, which makes the guidance a harder benchmark for any retailer without them.
Bottom line: Updated regulatory guidance, not a rule change. The Privacy Act 1988 is unchanged. The guidance describes the OAIC's regulatory application of the law and now incorporates the Administrative Review Tribunal's findings in the Bunnings matter.
Who this affects: Privacy officers, general counsel and loss prevention leads at Australian retailers and other APP entities operating facial recognition in high volume, publicly accessible physical spaces; privacy consultants writing PIAs; security system vendors selling FRT into Australian retail.
Issue date: Guidance updated 29 July 2026; originally published 19 November 2024. The OAIC media release is dated 29 July 2026. No compliance deadline is set.
What changed: Greater clarity on how the APP 3.4 exceptions to consent apply in retail settings, and a new Bunnings case study working through suitability, alternatives and proportionality on the Tribunal's findings.
Analysis: Read the case study as a specification of difficulty, not permission. The OAIC records that Bunnings' security environment was significantly different from that of most other retailers, that no alternative control could identify repeat offenders, and that staff faced threatening or abusive behaviour at least every two to three days. A retailer without that evidentiary record is not inside the case study.
Primary sources: OAIC media release, 29 July 2026 · Facial recognition technology: a guide to assessing the privacy risks
- Instrument (EN)
- Facial recognition technology: a guide to assessing the privacy risks
- Authority
- Office of the Australian Information Commissioner (OAIC)
- Jurisdiction
- Australia (Commonwealth)
- Status
- Published guidance, updated
- Bindingness
- Guidance, not law. Binding obligations sit in the Privacy Act 1988 (Cth) and the Australian Privacy Principles. The guidance states the OAIC's regulatory application of those obligations.
- Issue date / next deadline
- Updated 29 July 2026; first published 19 November 2024; no deadline
- Trigger
- Administrative Review Tribunal decision in the Bunnings Group Limited matter
- Still open
- The Privacy Commissioner's August 2025 determination against Kmart remains under review in the ART, with hearings scheduled for early 2027
- Primary source
- https://www.oaic.gov.au/news/media-centre/privacy-commissioner-publishes-updated-guidance-on-facial-recognition-in-retail-spaces
What the update does and does not do
The Privacy Act is technology-neutral. The guidance repeats that it does not specifically ban or permit FRT, and that entities can use it in accordance with the Act in certain circumstances provided they comply with the Australian Privacy Principles. That was true before the update and it is true after.
What is new is the incorporation of the Tribunal's findings. The media release says the update implements the findings of the ART in the Bunnings matter, which concerned the retailer's use of FRT in 62 of its stores between 2018 and 2021, and that the Tribunal confirmed there is a high bar for using facial recognition technology in Australia.
The Privacy Commissioner is quoted saying the decision provided important clarification on certain aspects of the Privacy Act, and that the guidance remains clear that each proposed deployment of FRT will need to be assessed against the requirements of the Act.
Collection happens earlier than most deployers assume
The guidance is direct on a point that defeats a common design argument. Even where a system captures and discards biometric information at a rapid pace, that amounts to a collection of personal information that must be consistent with the Privacy Act, and there is no minimum temporal threshold for collection.
It goes further: images are collected for inclusion in a record even where they are stored only in the random access memory of a computer possessed or controlled by an entity, and not in persistent memory. Building a system that never writes to disk does not put it outside the Act.
Biometric templates and biometric information, including facial images used for automated verification or identification, are sensitive information under the Act and attract the higher level of protection.
The two pathways, and why consent rarely works in a shopfront
The consent pathway requires both that collection be reasonably necessary for one or more of the entity's functions or activities and that the individual consent. The guidance notes the practical difficulty: in spaces open to the public it is not often practical to obtain valid consent from everyone whose biometric information might be captured.
It says the consent pathway is most likely to work where the entity can make contact with each individual before they physically attend, giving membership and advance-booking models as the example. A walk-in shopfront generally is not that.
Where consent is unavailable, the entity must not use FRT unless an APP 3.4 exception applies. The two the guidance treats as most relevant are collection required or authorised by or under an Australian law or court or tribunal order, and the permitted general situations under section 16A.
Of the seven permitted general situations, the guidance treats the first two as most likely relevant: serious threat to life, health or safety where it is unreasonable or impracticable to obtain consent, and reason to suspect unlawful activity or serious misconduct where collection is reasonably believed necessary to take appropriate action.
The three-factor necessity test
For either permitted general situation the entity must hold a reasonable belief, not merely a genuine or subjective one, and must be able to justify how it was formed against objective facts. The guidance restates the APP Guidelines position that necessary requires something more than helpful, desirable or convenient.
Three factors structure the assessment. Suitability, meaning not only whether the system accurately identifies matched individuals without error but whether it is more broadly effective against the threat or conduct in question. Alternatives, including alternatives that still involve collecting personal information but are less intrusive or more proportionate. And proportionality against the privacy impact on individuals.
There is also a scoping instruction for chains. Where an entity wants to run FRT across multiple premises, it should consider whether individual locations have features warranting separate assessment, and if it assesses a set of premises together it should record how the set was chosen and why the locations are considered sufficiently similar.
The Bunnings case study, read carefully
On suitability, the guidance records that Bunnings proved its FRT was effective because identifying known offenders let staff be alerted and remove them proactively, reducing violent incidents relative to confronting people after the fact, and that human verification of matches adequately mitigated the risk of acting on a false positive.
On alternatives, the guidance records the Tribunal's finding in quoted terms: the reason FRT was effective was because it could survey the facial features of nearly every person who entered a Bunnings store, less privacy-intrusive alternatives could not achieve the same outcome for repeat offenders, and no other security control could identify repeat offenders in the way FRT did.
On proportionality, three system design features mattered: information was stored only for a few milliseconds before permanent deletion when there was no match; the design and security arrangements made cyber attack or on-selling improbable; and it was not possible to reconstruct a facial image from the generated biometric template.
Those three features are the transferable part. The store environment is not. The guidance describes Bunnings' setting as significantly different from most other retailers, with large stores, multiple entry and exit points, vehicles driven inside, and readily accessible products such as an axe, screwdriver or drill usable as a weapon.
What we did not verify
We opened the OAIC media release and the full updated guidance page and took every fact and quotation from them. The guidance page states it was first published 19 November 2024 and updated 29 July 2026, and carries a modified timestamp of 30 July 2026.
We did not open the ART decision, the Privacy Commissioner's November 2024 Bunnings determination, the August 2025 Kmart determination, the downloadable PDFs, the flowchart, the factsheet, the checklist, or the 2026 Australian Community Attitudes to Privacy Survey from which the 27% to 45% figures are quoted. All are reported as the OAIC states them.
One inconsistency we did not resolve: the media release says the ART affirmed aspects of the Commissioner's determination in February 2026, and later in the same release refers to the matter concluding with the ART's March 2026 decision. We have not opened the decision to establish which date is correct, so we do not assert either.
We take no view on whether any particular retailer's FRT deployment is lawful. The OAIC states that each proposed deployment must be assessed against the requirements of the Act, and that is not an assessment an article can perform.
The guidance leaves consent as a narrow route and the permitted general situations as a documented, evidence-heavy one. If you are running or scoping FRT in an Australian retail space, the file that matters is the privacy impact assessment: it needs a specific articulated threat, evidence of severity, an assessment of alternatives that were genuinely considered and found inadequate, and system design features limiting retention and reconstruction. The OAIC also warns that a design which holds images only in RAM is still a collection.
Source File
Open the OAIC media release dated 29 July 2026 and confirm the reference to implementing the ART's findings in the Bunnings matter and the 62 stores figure. Then open the guidance page and confirm the Updated: 29 July 2026 line, the Part B statement that there is no minimum temporal threshold for collection, and the Bunnings case study under Part B.
A precautionary approach to the deployment of FRT is required under Australian law. This is consistent with the expectations of the Australian community, a significant and growing proportion of whom think facial recognition technology is one of the biggest privacy risks they face today. ยท Australian Privacy Commissioner, OAIC media release, 29 July 2026
FAQ
Did the Bunnings decision make facial recognition easier to deploy in Australian retail?
The OAIC does not present it that way. Its media release says the Tribunal confirmed there is a high bar for using FRT in Australia, that a precautionary approach is required, and that each proposed deployment will still need to be assessed against the requirements of the Act.
Does a system that deletes images in milliseconds avoid the Privacy Act?
No. The guidance states there is no minimum temporal threshold for collection, and that images are collected for inclusion in a record even where they are held only in random access memory rather than persistent memory.
Can a retailer rely on consent for FRT at a shopfront?
Rarely. The guidance says the nature of FRT means it is often not practical to obtain valid consent from everyone whose biometrics might be captured, and that the consent pathway is most likely applicable where the entity can contact each individual before attendance, such as booking or membership models.
Is the Kmart matter resolved?
No. The OAIC states that the separate determination issued in August 2025 by the Privacy Commissioner against Kmart, concerning its use of FRT, remains under review in the Administrative Review Tribunal, with hearings scheduled for early 2027.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.