Australia Privacy Update - Facial recognition technology

Alert
|
6 min read

The OAIC releases new guidance on the use of facial recognition technology

Following the Bunnings' decision (Bunnings Group Limited and Privacy Commissioner (Guidance and Appeals Panel) [2026] ARTA 130 (4 February 2026)), the Office of the Australian Information Commissioner (the OAIC) has updated its guidance for businesses using facial recognition technology (FRT) in physical commercial or retail settings in Australia.

The guidance clarifies that businesses may use FRT where this complies with the Privacy Act 1988 (Cth) (the Privacy Act) and the Australian Privacy Principles (APPs). It covers five areas that the OAIC expects businesses will consider and document before implementing FRT: (a) accountability and ongoing assurance; (b) lawful basis for collection; (c) transparency and notification; (d) accuracy, bias and discrimination; and (e) data deletion and security.

Accountability and ongoing assurance

APP 1.2 requires businesses to take proactive steps to establish and maintain internal practices, procedures and systems that ensure compliance with the APPs, including undertaking privacy impact assessments for new projects handling personal information or changes to information handling practices.

The OAIC considers FRT highly intrusive to individuals' privacy and expects businesses to undertake privacy impact assessments as part of APP 1.2 compliance, using a structured, documented process for identifying and mitigating privacy risks. Businesses should document mitigation steps and ensure practices, procedures and systems are regularly reviewed and updated.

Privacy impact assessments should also be undertaken where third party providers install or operate FRT systems on a business' behalf. The guidance recommends conducting due diligence on providers and their services, and entering into contractual arrangements that impose reviewable or auditable privacy obligations on providers.

Lawful basis for collection 

APP 3 requires that businesses only collect personal information that is reasonably necessary for one or more of its functions or activities, and where the information is sensitive information, that information must only be collected where the individual consents unless an exception applies.

The guidance considers the pathways that businesses may seek to rely on in deploying FRT and collecting personal information, including:

  • Consent pathway: Collection must be reasonably necessary for the business' functions or activities, and the business must obtain valid consent. As obtaining consent before FRT collection can be difficult in practice, this pathway works best where the business can contact individuals before they attend a location (e.g., membership or booking access). 
  • Authorised by law pathway: Consent is not required where collection is required or authorised by law or a court/tribunal order,  although this is limited to information reasonably necessary to fulfil that obligation. FRT should only be used where the law explicitly addresses the collection or a practice that directly involves using FRT. 
  • Permitted general situation pathway: The Privacy Act's seven permitted general situations are exceptions to certain APP requirements, including APP 3. Businesses should consider whether reliance on a permitted general situation is suitable, whether less intrusive alternatives exist, and whether the collection is proportionate to the privacy impact. 
  • The guidance considers that there are two permitted general situations that may apply to the use of FRT: 
    • Serious threat: This situation will apply where:
      1. it is unreasonable or impracticable to obtain consent to the collection; and
      2. the entity reasonably believes it is necessary to lessen or prevent a serious threat to the life, health or safety of any individual, or to public health or safety.
    • The threat must be carefully assessed (e.g., in a retail setting, serious violent or aggressive behaviour involving weapons or threats).
    • Unlawful activity or serious misconduct: This situation will apply where:
      1. there is reason for the business to suspect that unlawful activity, or misconduct of a serious nature, that relates to the business' functions or activities has been, is being or may be engaged in; and
      2. the business reasonably believes that the collection is necessary in order for it to take appropriate action in relation to the matter.
    • Businesses should be able to demonstrate a reasonable basis for their suspicion, and reliance on this permitted general situation should be proportionate to the severity of the suspected unlawful activity.

Transparency and notification

APP 5 requires entities to take reasonable steps before, or at the time of collection, to notify individuals of certain matters, such as the purpose of collection and any usual disclosures of personal information. All individuals whose sensitive information may be collected must be notified, even where a captured face is a non-match or only briefly stored.

The guidance notes that more rigorous notification steps may be needed given the sensitive nature of information FRT collects. At a minimum, businesses should publicise that an FRT system is in use and its purpose, for example via signage that directs individuals to further information, such as a fact sheet. A general notification that surveillance is being used on the premises is not sufficient. Businesses should consider how to notify individuals and provide sufficient information to comply with APP 5, tailoring the notice to the premises and timing it appropriately.

Accuracy, bias and discrimination 

Personal information must be accurate, up-to-date and complete under APP 10.1. As FRT systems carry inherent accuracy risks, including bias and discrimination, the OAIC expects businesses to validate FRT accuracy to prevent false positives or negatives, including through testing, due diligence on data quality practices, and human verification of positive matches.

Data deletion and security

APP 11 requires businesses to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. The reasonable steps required depend on the circumstances, including the sensitivity of the information held and the possible consequences for individuals of a breach. Businesses using FRT should in particular consider how long information is stored, the steps a threat actor would need to take to compromise the system, and who has access to the system and any associated databases.

Businesses must also take reasonable steps to delete or de-identify personal information once it is no longer needed. The OAIC expects biometric information and templates for non-matches are deleted immediately, and information on matches will be held only as long as needed for the purpose of collection.

Next steps

Businesses seeking to deploy and use FRT systems, should ensure that they: 

  • Undertake privacy impact assessments considering all FRT privacy risks and mitigations, and confirm the collection is necessary for the business' functions and activities and otherwise meets APP 3.
  • Document privacy impact assessments and mitigation steps, updating them whenever the FRT system or data handling methods change.
  • Only engage third party service providers to install or operate FRT systems after appropriate due diligence, and on terms addressing privacy, cyber security, audit/review and risk allocation. Where providers are located outside Australia, also consider the additional risks of transferring personal information overseas and whether privacy policies or notices need updating to reflect this.
  • Update privacy policies and notices to reference FRT and the information it collects, addressing any automated decision-making by 10 December 2026.
  • Limit FRT collection to what is necessary and delete information that is no longer required, including for non-matches. 
  • Provide appropriate notification before FRT collection and consider whether valid consent is required beforehand. 

If you would like to read the guidance from the OAIC in full, please visit the OAIC’s website. Please contact a member of our team if you would like to discuss further.

White & Case means the international legal practice comprising White & Case LLP, a New York State registered limited liability partnership, White & Case LLP, a limited liability partnership incorporated under English law and all other affiliated partnerships, companies and entities.

This article is prepared for the general information of interested persons. It is not, and does not attempt to be, comprehensive in nature. Due to the general nature of its content, it should not be regarded as legal advice.

© 2026 White & Case LLP

Top