The sequence matters, because it explains why guidance is being updated rather than
written. The Privacy Commissioner made a determination against Bunnings in
November 2024. Bunnings sought review. In February 2026 the
Administrative Review Tribunal affirmed aspects of that determination and, in the OAIC’s
words, confirmed that there is a high bar for using facial recognition technology in
Australia
. The regulator now says the matter concluded with an ART decision in
March 2026.
Those two dates appear in the same release and we have not reconciled them from published material; the likeliest reading is a substantive decision followed by a final one, but that is inference and we are flagging it rather than asserting it.
What actually changed in the guidance
One thing, and it is the thing retailers were arguing about. The update provides
greater clarity on how exceptions to the obligation to obtain consent when collecting
sensitive information, including biometric information, should be applied in retail
settings
.
Faces are sensitive information under the Privacy Act, and collecting sensitive information generally requires consent. A shopper walking through a door does not give it. So every retail FRT deployment has depended on whether an exception applies, and the exceptions are where the argument has been. The Tribunal ruled on that ground and the guidance now reflects what it said.
What has not changed is the requirement to think for yourself. The Commissioner is explicit:
The guidance remains clear, however, that each proposed deployment of FRT will need to
be assessed against the requirements of the Act.
The OAIC frames the update as
supporting retailers in making those contextual assessments, not replacing them.
The regulator is citing public opinion as a legal input
The Commissioner links the standard directly to community expectation: A
precautionary approach to the deployment of FRT is required under Australian law. This is
consistent with the expectations of the Australian community, a significant and growing
proportion of whom think facial recognition technology is one of the biggest privacy risks
they face today.
The number attached to that is 27 per cent in 2023 rising to 45 per cent in 2026, from the Australian Community Attitudes to Privacy Survey, the same survey we read in full three days ago. Nearly half the country now rates facial recognition among the biggest privacy risks it faces, and that figure has risen by two-thirds in three years.
Our view, labelled as such: quoting an attitudes survey inside a statement about what the law requires is worth noticing. Community expectation is not a section of the Privacy Act, and the Commissioner is not claiming it is. But “reasonable” and “proportionate” do a great deal of work in privacy law, and what a reasonable person expects is exactly the kind of thing a survey can evidence. A regulator putting that number in the same paragraph as the legal standard is signalling how it intends to read those words.
The second case is still running
Bunnings is finished. The other one is not. A separate determination issued in August 2025 against Kmart, concerning its use of FRT, remains under review in the Administrative Review Tribunal, with hearings scheduled for early 2027.
So the guidance published on 29 July reflects settled law on one matter while a second is still before the Tribunal. Anyone treating the update as the final word should hold that lightly for another year and a bit.
What the guidance actually requires, read in full
We have read the updated guidance rather than the announcement of it. It is organised against five Australian Privacy Principles, which is the useful part: it turns a general anxiety about facial recognition into five specific obligations a business either meets or does not.
- APP 1, governance and ongoing assurance: clear governance arrangements and privacy risk management practices.
- APP 3, lawful basis for collection: the pathway question, below.
- APP 5, transparency and notification: reasonable steps to notify or ensure people are aware, regardless of whether the collection is by consent or under an exception.
- APP 10, accuracy, bias and discrimination: the biometric information must be accurate, and steps must be taken to address any risk of bias.
- APP 11, security and deletion: protect the information even if it is held only briefly, and destroy or de-identify it once it is no longer needed for a valid purpose.
The sentence that carries the whole thing, from the checklist published
alongside the guidance: FRT systems collect the sensitive information of
every person whose face is captured, even if they are not a ‘match’.
That is why the obligations attach to everyone who walks past a camera rather than to the
small number of people a system flags, and it is the practical meaning of the Bunnings
finding.
The two pathways, and the three-limb test
Under APP 3 there are two ways to be lawful. The consent pathway requires valid consent from each individual, and even then the collection must be reasonably necessary and proportionate in the circumstances. The exception pathways are narrow: where collection is specifically authorised or required by law or a legal order, or where a Permitted General Situation relating to serious threats and unlawful misconduct exists.
If a business is relying on a Permitted General Situation, the guidance sets out what “reasonably necessary” means as three questions, and they are the ones worth putting to any retailer that installs this: is collecting sensitive information suitable in your situation, what alternatives are available, and is the privacy impact proportionate to the benefit? An organisation that cannot answer the middle one has not done the work.
There is a checklist, and it is short
The OAIC published an eight-question privacy essentials checklist alongside the guidance, plus a factsheet and a flowchart on collection pathways. The questions run from whether a detailed risk assessment and privacy impact assessment have been done, through the APP 3 lawful basis, an up-to-date privacy policy, protection of the information even if you only intend to hold it briefly, processes to destroy or de-identify it when no longer needed, and governance arrangements.
Our view, labelled as such: the checklist is the most useful thing in the 29 July update, and it got one line in the announcement. A business deciding whether to install facial recognition can answer eight questions in an afternoon, and a business that cannot answer them has its answer.
How we sourced this
The publication of the updated guidance on 29 July 2026, its scope (APP entities
considering FRT in high volume and publicly accessible physical spaces such as retail
shopfronts), the Bunnings matter covering 62 stores between 2018 and 2021, the November 2024
determination, the February 2026 ART affirmation and the March 2026 conclusion, the specific
change regarding exceptions to the consent obligation for sensitive and biometric
information, all quotations from the Privacy Commissioner, the ACAPS figures of 27 per cent
in 2023 and 45 per cent in 2026, and the status of the August 2025 Kmart determination with
hearings in early 2027 are from the OAIC media release Privacy Commissioner publishes
updated guidance on facial recognition in retail spaces
, read on 31 July 2026.
We have not read the updated guidance document itself, only the regulator’s description of what changed in it, nor the Tribunal’s decision. The February and March 2026 dates both appear in the release and we have not reconciled them. Nothing here is a claim about the conduct of any retailer beyond what the regulator and the Tribunal have published; the Kmart matter is under review and no finding about it is final. The paragraph beginning “Our view” is opinion, built on the sourced facts above it.
Sources
- Office of the Australian Information Commissioner, Facial recognition technology: a guide to assessing the privacy risks (updated 29 July 2026, read in full 1 August 2026): the scope covering facial identification in physical commercial or retail settings, the statement that it was updated to reflect the Administrative Review Tribunal decision concerning Bunnings Group, the five-part structure against APP 1, 3, 5, 10 and 11, the consent and exception pathways under APP 3, the requirement that notification obligations apply regardless of the pathway used, and the security and destruction obligations covering information held only briefly.
- Office of the Australian Information Commissioner, Privacy essentials checklist for considering facial recognition in physical settings (such as retail) (downloaded and read 1 August 2026): the eight questions, the statement that FRT systems collect the sensitive information of every person whose face is captured even if they are not a match, the exception pathways including a Permitted General Situation relating to serious threats and unlawful misconduct, and the three-limb reasonable necessity test of suitability, available alternatives and proportionality of privacy impact to benefit.
- Office of the Australian Information Commissioner, Privacy Commissioner publishes updated guidance on facial recognition in retail spaces (media release, published 29 July 2026, read 31 July 2026): the guidance update and its scope, the Bunnings matter and its 62 stores between 2018 and 2021, the November 2024 determination and the February and March 2026 Tribunal decisions, the clarification on consent exceptions for sensitive and biometric information, the Privacy Commissioner's quotations including the precautionary-approach standard, the ACAPS 27 per cent to 45 per cent figures, and the status of the Kmart determination.
- AI Geek, Four per cent of Australians trust AI companies: our reading of the 2026 Australian Community Attitudes to Privacy Survey the Commissioner cites.
Updated 1 August 2026. The original was written from the OAIC's announcement. We have since read the guidance itself and the checklist published with it, and added the five Australian Privacy Principles the guidance is structured against, the two lawful-basis pathways and the three-limb necessity test, the point that the obligations attach to every face captured and not only to matches, and the eight-question checklist. Nothing in the original was wrong.
Spotted an error? Tell us and we will check it against the sources and log the outcome here.