Bunnings, Biometrics and the APPs – Use of Facial Recognition Technology in Retail Spaces
The Administrative Review Tribunal's decision regarding Bunnings' use of facial recognition technology provides important guidance for Australian businesses using, or considering using, facial recognition technology (FRT) in retail and other publicly accessible spaces.
We examine the decision, the privacy obligations that continue to apply and the OAIC's updated guidance for businesses using FRT.
- FRT involving biometric identification generally involves collection of sensitive information under the Privacy Act.
- Consent may not always be required where an applicable Privacy Act exception can be established.
- Businesses still need to meet transparency, notification, governance and privacy policy obligations.
- Businesses considering FRT should undertake appropriate privacy risk assessment and governance before implementation.
On this page:
- Bunnings' use of facial recognition technology
- The OAIC's determination on Bunnings' use of FRT
- Bunnings' appeal to the Administrative Review Tribunal
- What does the Bunnings FRT decision mean for businesses?
- Updated OAIC guidance on facial recognition technology in retail spaces
- What should businesses using facial recognition technology do now?
- Our cyber and information security experts
Bunnings' use of facial recognition technology
Between 2018 and 2021, Bunnings Group Limited (Bunnings) deployed a facial recognition technology (FRT) system in stores across Victoria and New South Wales. The system used CCTV cameras to capture real-time facial images of customers and compare them against a database of known offenders. Although intended to protect staff and customers and reduce retail crime, the system raised questions about compliance with the Privacy Act 1988 (Cth) (Privacy Act).
The Privacy Act is technology-neutral – it neither prohibits nor authorises FRT. However, where biometric information (such as facial imagery) is used for automated verification or identification, it constitutes sensitive information and attracts a higher level of privacy protection.
The OAIC's determination on Bunnings' use of FRT
In 2022, the OAIC commenced an investigation of whether Bunnings had interfered with the privacy of individuals whose information was collected through its FRT system.
In 2024, the OAIC handed down its determination, finding that Bunnings had breached the APPs by:
- collecting sensitive information without customers’ consent or an applicable exception (APP 3.3);
- failing to take reasonable steps to notify customers about the collection and use of their personal information, as well as the consequences for them if the information was not collected (APP 5.1);
- failing to implement adequate practices, procedures and systems to ensure compliance with the APPs (APP 1.2); and
- failing to maintain an up-to-date privacy policy about the kinds of personal information collected and held, and how such information was collected and held (APP 1.3).
The Privacy Commissioner declared that Bunnings must cease the infringing conduct and issue a public statement about the determination, its use of FRT, and how individuals may contact Bunnings to make a complaint.
Central to the OAIC’s reasoning was its assessment of the ‘permitted general situation’ exception in section 16A of the Privacy Act – specifically, Item 2 (‘unlawful activity or misconduct’ exemption). Under this exception, an entity may collect sensitive information if the entity: (a) has reason to suspect that unlawful activity or serious misconduct in relation to the entity’s functions or activities has been, is being or may be engaged in; and (b) reasonably believes that the collection is necessary in order to take appropriate action (Privacy Act, section 16A, Item 2).
The Commissioner accepted that Bunnings had reason to suspect unlawful activity in its stores (satisfying condition (a)), but was not satisfied that Bunnings met condition (b) – that it reasonably believed the collection was necessary to take appropriate action.
The Commissioner assessed this by reference to three factors: (i) the suitability and effectiveness of the FRT system; (ii) available alternatives; and (iii) proportionality, balancing privacy impacts against benefits.
- On suitability, the Commissioner noted that the FRT system was only effective against recidivist offenders already enrolled in the database and could not address first-time unlawful activity.
- On alternatives, she noted Bunnings had already adopted various tools including in-store security guards, staff training, CCTV, prohibition notices and engagement with law enforcement.
- On proportionality, the Commissioner found that the FRT system involved the ‘wholesale and indiscriminate collection’ of sensitive information from hundreds of thousands of individuals to take action in respect of a relatively small number of enrolled persons, and that individuals were not adequately notified the system was in operation.
The Commissioner concluded that Bunnings could not have reasonably believed the collection was necessary, and therefore no permitted general situation existed.
Bunnings' appeal to the Administrative Review Tribunal
On appeal, the Administrative Review Tribunal (ART) overturned the OAIC’s findings regarding APP 3.3. The ART held that Bunnings could rely on the ‘unlawful activity or misconduct’ exemption to collect sensitive information without consent. Critically, the ART adopted a different analytical framework: rather than asking whether the collection was objectively necessary, the ART held that condition (b) required only that Bunnings ‘reasonably believed’ the collection was necessary – importing objectivity into the assessment of belief, but not requiring proof that collection was essential or indispensable.
- On suitability, the ART accepted that FRT, used in conjunction with other security controls, was effective and suitable to identify known offenders and reduce the likelihood of further theft or violence. Unchallenged evidence from store managers indicated that FRT had a ‘dramatic’ effect on the identification and management of persons of interest.
- On alternatives, the ART found that no comparable alternative existed for efficiently identifying known offenders, given the size of Bunnings’ stores, their multiple entry and exit points, and that customers could drive vehicles inside. Many products sold at Bunnings (such as axes and screwdrivers) can be used as weapons. Alternative controls – including live CCTV monitoring, covert security guards and staff‑memorised photographs – could not consistently achieve the same outcome.
- On proportionality, the ART found that the FRT system limited the privacy intrusion because collected sensitive information was only momentarily held (approximately 4 milliseconds) before being permanently deleted. The risk of misuse was negligible and the system was not susceptible to cyber-attack.
The ART concluded that Bunnings’ belief in the necessity of FRT was reasonable, noting that retail crime in the nature of violence and theft was a ‘very serious issue’ and Bunnings was entitled to take action in response.
The ART otherwise upheld the OAIC’s findings that Bunnings had breached:
- APP 5.1, as signage stating “video surveillance, which may include facial recognition, is utilised” at store entrances was insufficient to notify customers: (i) that Bunnings was in fact collecting customers’ sensitive information through an FRT system; (ii) the purpose for which that collection occurred; or (iii) the main consequences of not collecting the information;
- APP 1.2, as Bunnings had failed to implement practices, procedures and systems to ensure compliance with the APPs; and
- APP 1.3, as Bunnings failed to include information in its privacy policy about its collection of sensitive information through a FRT system for the purpose of dealing with threatening and violent situations and retail crime.
For businesses using or considering FRT, the decision provides several important practical lessons.
What does the Bunnings FRT decision mean for businesses?
While the ART’s decision turns on the specific facts of Bunnings’ operations, it carries broader implications for any business operating CCTV or surveillance technology in retail or publicly accessible spaces.
- Consent. The decision confirms that even a momentary or automated holding of personal information through CCTV or FRT constitutes a ‘collection’ under the Privacy Act. Businesses deploying CCTV systems enhanced with facial recognition, analytics or biometric identification capabilities will be collecting sensitive information and must either obtain consent or satisfy an applicable exception.
- Signage and notification. A key lesson is that generalised notification of ‘video surveillance’ is insufficient where FRT or biometric identification technology is in operation. Businesses must use specific, clear and prominent signage at or immediately before entry points expressly stating that FRT is in use, the purpose of collection, and the main consequences for individuals if the information is not collected. Vague or hedged language such as ‘may be used’ should be avoided where FRT is in fact deployed. The privacy policy must also specifically reference FRT and the handling of biometric information.
- Standard CCTV versus enhanced analytics. Businesses operating standard CCTV (without facial recognition or biometric identification) are not necessarily collecting ‘sensitive information’ and the heightened consent requirements may not apply in the same way. However, where CCTV footage is used in conjunction with facial recognition algorithms or biometric matching, the information will cross the threshold into ‘biometric information’ and therefore ‘sensitive information’ under the Privacy Act.
Updated OAIC guidance on facial recognition technology in retail spaces
Following the Bunnings decision, in July 2026 the OAIC published updated guidance for businesses considering FRT in high-volume, publicly accessible physical spaces, providing greater clarity on how the exceptions to consent apply in a retail context.
Consistent with a privacy-by-design approach, the OAIC expects businesses to consider the following principles before implementing FRT:
- Clear and lawful basis for collection
(APP 3)
Businesses must have a clear and lawful basis for collecting and using biometric information, either by obtaining consent or relying on an exception under the Privacy Act. - Transparency and notification (APP 5)
Businesses must be transparent about their use of FRT and take reasonable steps to notify, or otherwise ensure customers are aware of, the collection of their biometric information. This may require reviewing existing in-store signage to clearly communicate that FRT is being used, explain its purpose, and ensure notices are prominently displayed at each entrance or area where FRT operates. - Accuracy, bias and discrimination (APP 10)
Businesses should ensure the accuracy of biometric information used by FRT systems and implement appropriate measures to reduce risk of bias or discriminatory outcomes. - Security of personal information (APP 11)
Businesses that store biometric information, even for a short period, should implement appropriate safeguards to protect it from misuse, interference, loss, and unauthorised access and disclosure. Biometric information must also be destroyed or de-identified once it is no longer required. - Governance and ongoing assurance (APP 1)
Businesses implementing FRT should establish effective governance arrangements, including documented privacy risk management practices and policies that are regularly reviewed. The OAIC strongly recommends undertaking a Privacy Impact Assessment (PIA) before deploying FRT to identify potential privacy impacts and implement strategies to manage, minimise, or eliminate those risks. The Bunnings decision demonstrates that failing to undertake a documented assessment may contribute to a breach finding.
What should businesses using facial recognition technology do now?
Businesses using or considering FRT should review whether they have a lawful basis for collecting biometric information, ensure appropriate signage and privacy notices are in place, assess the security and accuracy of their systems, and establish appropriate privacy governance. Undertaking a Privacy Impact Assessment before implementation can also help identify and manage privacy risks. FRT remains one of the most significant privacy concerns identified by the Australian community. As FRT and other emerging technologies become more widespread, businesses must carefully balance legitimate security objectives with individuals’ privacy rights and ensure ongoing compliance with the APPs.
If your business uses or is considering facial recognition technology, CCTV analytics or other biometric technologies, our team can assist you to understand your privacy obligations and manage associated legal and regulatory risks.
This article provides general comments only. It does not purport to be legal advice. Before acting on the basis of any material contained in this article, we recommend that you seek professional advice.
The author would like to thank Ava Czuchwicki for contributing to this article.
Our cyber and information security experts
Related Insights
OAIC’s privacy compliance sweep – lessons from the Optus privacy proceedings

OAIC Privacy Act action: Federal Court orders Australian Clinical Labs to pay $5.8 million for 2022 Medlab data breach

Privacy law in practice: Lessons from the OAIC’s latest data breach report

Cyber risks in the supply chain – Legal, IT & AI strategies for protection – Association of Corporate Counsel event
