Australian Privacy Commissioner Revises Retail Facial Recognition Guidance
Key Takeaways
- Guidance Updated After Bunnings Ruling: The Office of the Australian Information Commissioner revised its facial recognition guidance to incorporate the Administrative Review Tribunal's March 2026 decision in the Bunnings case.
- High Bar for Facial Recognition: The updated guidance reinforces that organizations face a high legal threshold when deploying facial recognition technology in publicly accessible retail environments under Australia's Privacy Act.
- Case-By-Case Assessments Remain Essential: The OAIC emphasized that retailers must assess every proposed deployment individually, including whether an exception to the requirement for consent to collect sensitive biometric information applies.
- Privacy Concerns Continue to Grow: The Privacy Commissioner cited the 2026 Australian Community Attitudes to Privacy Survey, which found that 45% of Australians now view facial recognition technology as one of the country's biggest privacy risks, up from 27% in 2023.
Deep Dive
The legal fight over Bunnings may be over, but the Office of the Australian Information Commissioner is making sure its lessons are not left behind in a tribunal ruling. The regulator on Tuesday published updated guidance for organizations covered by the Australian Privacy Principles that are considering deploying facial recognition technology in busy, publicly accessible spaces such as retail storefronts. The revisions are not a change in the law. They are a statement of how the Office of the Australian Information Commissioner (OAIC) intends to apply it after the Administrative Review Tribunal's March 2026 decision in the long-running Bunnings case.
That decision examined Bunnings Group Limited's use of facial recognition technology across 62 stores between 2018 and 2021. The tribunal affirmed aspects of the Privacy Commissioner's November 2024 determination against the retailer and confirmed what had already become increasingly apparent throughout the case. Using facial recognition technology in Australia carries a high legal threshold, particularly when it involves collecting biometric information from members of the public.
The updated guidance folds those findings into the regulator's existing framework and offers more detailed direction for businesses weighing whether they can rely on exceptions to the Privacy Act's requirement to obtain consent before collecting sensitive information. Just as importantly, it makes clear that there is no formula that automatically makes facial recognition lawful in a retail setting.
No Blanket Approval
Retailers hoping the Bunnings decision would produce a clearer path to deployment will not find one here. Instead, the OAIC emphasizes that organizations must assess each proposed use of facial recognition technology on its own facts. Whether an exception to the consent requirement applies depends on the particular circumstances of the deployment rather than the technology itself.
"The Bunnings decision by the ART provided important clarification on certain aspects of the Privacy Act, and this updated guidance incorporates those points of clarification," Privacy Commissioner Carly Kind said. "The guidance remains clear, however, that each proposed deployment of FRT will need to be assessed against the requirements of the Act."
That emphasis runs throughout the revised guidance. Rather than relaxing expectations following the tribunal's decision, the OAIC has used the ruling to sharpen how those expectations should be interpreted.
Public Opinion Is Moving in the Same Direction
The regulator also pointed to a shift outside the courtroom. According to the 2026 Australian Community Attitudes to Privacy Survey, 45% of Australians now regard facial recognition technology as one of the country's biggest privacy risks. Three years earlier, that figure stood at 27%.
For Kind, those numbers reinforce why organizations should approach the technology cautiously.
"A precautionary approach to the deployment of FRT is required under Australian law," she said. "This is consistent with the expectations of the Australian community, a significant and growing proportion of whom think facial recognition technology is one of the biggest privacy risks they face today."
The reference is notable because it links the regulator's interpretation of the Privacy Act with changing public expectations. While community opinion does not determine the law, the OAIC is making clear that the two are moving in the same direction.
The Bunnings litigation may have concluded, but Australia's legal debate over facial recognition in retail has not. The Privacy Commissioner's separate August 2025 determination against Kmart over its use of facial recognition technology remains before the Administrative Review Tribunal. Hearings in that matter are scheduled for early 2027.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

