"The OAIC's new facial recognition guidance: what changed on 29 July 2026"
If you walked into a Bunnings warehouse between 2018 and 2021, there was a reasonable chance a camera at the door was turning your face into a biometric template and checking it against a watchlist. The Privacy Commissioner's November 2024 determination said that was an interference with the privacy of "likely hundreds of thousands" of people. The Administrative Review Tribunal's February 2026 appeal decision — [2026] ARTA 130 — agreed with most of that determination but set aside its centrepiece: the finding that Bunnings collected sensitive information without consent. On 29 July 2026 the OAIC republished its facial recognition guidance to absorb both outcomes. Here's what the decision found, what the guidance now demands, and what it doesn't settle.
What the Bunnings litigation actually established
Start with the original determination. Bunnings ran FRT across 62 stores in Victoria and New South Wales — a two-month pilot in November 2018, then a rollout from January 2019 to November 2021. Cameras integrated with the store CCTV captured every face at entry, extracted facial features into templates, and matched them against a database built from imagery of people banned for threatening staff or committing retail crime. The Commissioner found five failures: no valid consent from customers; signage that was unclear and in some stores absent; no meaningful staff training; no clear policy governing the collected data; and a volume of collection well beyond the "minimum, reasonably required" to mitigate organised retail crime and threats — the disproportionality limb of APP 3. Even the Commissioner conceded the technology's potential value against violence and theft; the problem was scale, not purpose.
The appeal turned on one question. The Tribunal affirmed the Commissioner's findings on notice failures, governance, staff training, and proportionality, but held that Bunnings could rely on the "permitted general situation" exception in s 16A of the Privacy Act — collection reasonably believed necessary to lessen or prevent a serious threat to life, health or safety. Evidence from Bunnings workers about weapon-carrying offenders, assaults, and death threats supported a reasonable belief that some form of watchlist technology was needed. So the consent finding fell — Biometric Update's reporting captures the same caution in the sector's initial read — but the case is not the free pass retailers hoped for. The OAIC's own summary of the outcome is that the Tribunal "confirmed that there is a high bar for using facial recognition technology in Australia" (Privacy Commissioner publishes updated guidance on facial recognition in retail spaces), and the Tribunal left intact the parts of the determination dealing with sloppy implementation: bad signage, no documented policies, no training, no structured assessment before rollout. Those findings stand and they are now embedded in the regulator's guidance.
A limitation worth conceding: the reasoning rests on reasonableness of belief, which is contextual. The Conversation's analysis argues the exception could become a consent-optional loophole for any retailer with a risk-management narrative. That risk is real, but the 29 July guidance is partly the regulator's answer to it — tightening what "reasonable belief" and due diligence have to look like on paper.
What the updated guidance now requires
The guidance was first published on 19 November 2024, three weeks before the original determination. The 29 July 2026 revision (facial recognition technology: a guide to assessing the privacy risks) reorganises it around five parts — accountability (APP 1), lawful collection (APP 3), transparency (APP 5), accuracy (APP 10), and security/deletion (APP 11) — with a flowchart mapping the two lawful pathways for collecting sensitive biometric information in a retail space. The substantive changes:
PIAs as a compliance step, not a suggestion. The guidance now states plainly that a formal, structured, documented privacy impact assessment is a reasonable step an entity should take under APP 1.2 to demonstrate compliance. It cross-references the OAIC's 10-step PIA process, and for government agencies a PIA is mandatory for high-privacy-risk projects — a bar FRT projects will almost always meet. The OAIC strongly recommends publishing the PIA report. This matters because the Tribunal's decision preserved the finding that Bunnings' rollout lacked proper assessment and documentation. A PIA you can't produce is now evidence of non-compliance, and "we looked at it once, informally" doesn't qualify.
Premise-by-premise assessment. A new section tackles the exact mistake Bunnings made: treating 62 stores as one problem. A single risk assessment can cover multiple sites only if they're substantially similar, and the entity must record how the site set was chosen and why the sites are comparable. Differences that can force separate assessments include the threat profile of each store, the purpose (serious-threat mitigation versus retail fraud), physical characteristics — mall tenant versus freestanding, one entrance versus several, vehicle access — and what's sold there. Purpose changes the obligations: keeping staff safe in one location versus across a national chain changes what goes in collection notices and how data is secured and destroyed.
Two pathways, honestly named. Sensitive biometric information can only be collected via the consent pathway — reasonably necessary for your functions, plus valid consent — or an APP 3.4 exception: authorised by law, or a permitted general situation. The guidance is blunt about the consent pathway's reach in retail. Signage alone is not consent. Implied consent should not be relied on for sensitive information; opt-out mechanisms only count in very limited circumstances. The realistic consent route is pre-contact — bookings, memberships — where you can seek informed consent before someone walks in. On the permitted general situation pathway, a law authorises collection only where it's explicit about it; the fact that no law prohibits FRT doesn't authorise anything. The guidance's example is South Australia's licensed-venue rules for gambling-machine exclusion, which do explicitly mandate FRT.
No memory-size loophole. Biometric capture into RAM only, discarded moments later, is still collection under APP 3. There's no minimum temporal threshold. That forecloses the "we never store faces" argument that some FRT vendors lean on.
Transparency regardless of pathway. APP 5 notification obligations apply whether you collect by consent or under an exception. Bunnings' signage failures were affirmed by the Tribunal, so this is where retailers should expect enforcement attention first: collection notices and privacy policies that name FRT, what's extracted, who it's matched against, and how long templates live.
Accuracy and bias (APP 10). Entities must ensure biometric templates are accurate and take steps to address bias risk — a genuine engineering burden, since false-positive matching across skin tones and lighting conditions remains a documented weakness of commercial systems.
Deletion (APP 11). Non-matching data — which at a hardware store entrance is most shoppers — must be destroyed or de-identified when no longer needed, and secured in transit across multi-site systems.
One honest gap: the guidance is principles-based, not prescriptive. It tells you a PIA must exist and be documented but doesn't set an acceptable false-match rate, a retention window, or a signage standard. Retailers will still need contextual legal advice, which is the point the Privacy Commissioner made in the release: "each proposed deployment of FRT will need to be assessed against the requirements of the Act."
What's next
The Bunnings matter closed with the Tribunal's March 2026 decision, but the Kmart determination — issued by the Commissioner in August 2025 over its own FRT use — is under ART review, with hearings scheduled for early 2027. Kmart's deployment targets suspected offenders' faces rather than screening every entrant, so its outcome will test how the permitted general situation exception scales to narrower, more targeted systems. If the Bunnings appeal reaches the Federal Court, we could get a binding answer on whether "serious threat" is a safety exception or a consent bypass.
The wider frame is the Privacy Act reform process. Tranche 1 passed in December 2024, bringing a statutory tort for serious privacy invasions and expanded transparency rights; FRT has been a recurring candidate for explicit regulation in later tranches, with the government having run consultations on biometric-specific rules since 2023. Community pressure is real: the 2026 Australian Community Attitudes to Privacy Survey found the share of Australians who rank facial recognition among their biggest privacy risks rose from 27% in 2023 to 45% in 2026. Statutory FRT rules would replace the current ask-forgiveness-later posture with defined thresholds, and any such reform would land in the ART's Kmart review and any Federal Court appeal alike.
What shoppers can do
Until the law changes, your levers are limited but real. Read the collection notice at the door — under APP 5 it must tell you FRT is in use; if it doesn't, that's a complaint to the OAIC, and the signage failures in the Bunnings determination are the precedent. You can ask the retailer for a copy of, or at least details from, their privacy impact assessment; the OAIC now expects those to exist and, ideally, to be published. Complaints to the OAIC are free and the Kmart review shows the regulator is still active in this space.
And while the cameras are fixed infrastructure, most of the digital profiling that follows you from aisle to website is not. The device you carry is the other half: a degoogled Pixel 8a running GrapheneOS stops the ad-sdk side of retail profiling at the OS layer, and a faraday phone pouch goes further for anyone who wants their phone dark while shopping. Between the OS-level control and a self-hosted DNS filter that kills ad and analytics calls from retail apps and sites before they leave your house — we cover the practical setup on stealthoz.tech if you want to cut the network-level half of the tracking problem while the biometric half is being fought out in tribunals.
The pattern from the last two years is consistent: Australian privacy law will tolerate facial recognition in retail only where the threat is serious, the implementation is disciplined, and the paperwork exists. Bunnings kept its system by a majority of one pathway; its governance failures were never reversed. The 29 July guidance turns that lesson into a checklist every retailer will be measured against — and the Kmart hearings in early 2027 will show how strictly.