Burhan Doğuş Ayparlar

← All decisions

Australia · 4 February 2026

Retail facial recognition fell within a “permitted general situation”, but notice breaches were upheld

The tribunal held that Bunnings could rely on a consent exception for its facial recognition system but upheld findings on notice and governance.

Court / authority
Administrative Review Tribunal (Guidance and Appeals Panel)
Date
4 February 2026
Case / decision no.
Bunnings Group Limited and Privacy Commissioner, [2026] ARTA 130
Status
Final

Facts

Between November 2018 and November 2021, the hardware retailer Bunnings used facial recognition technology on CCTV footage in stores in Victoria and New South Wales. The system captured the face of every person who entered and compared it against a database of individuals Bunnings regarded as high-risk because of violence, organised retail crime or other inappropriate conduct. In October 2024 the Privacy Commissioner determined ([2024] AICmr 230) that Bunnings had breached the Australian Privacy Principles by collecting sensitive information without consent, failing to notify customers and lacking adequate policies. Bunnings sought review before the Administrative Review Tribunal.

Question

The Tribunal had to decide whether the collection of facial images and facial vectors, which are sensitive biometric information, breached APP 3.3 or was permitted by a “permitted general situation” under section 16A of the Privacy Act 1988 (Cth). In this case the situation relied on was the purpose of preventing retail crime by repeat offenders. It also had to decide whether the findings under APP 1 and APP 5 should stand.

Decision

The Guidance and Appeals Panel set aside the finding that Bunnings breached APP 3.3. Given evidence of repeated violence, threats and serious theft, it accepted that Bunnings could rely on the permitted general situation for the limited purpose of combating retail crime and protecting staff and customers from violence, abuse and intimidation, and it found the use reasonable and proportionate despite the significant intrusion on privacy. The Tribunal affirmed that Bunnings breached APP 1 and APP 5 by failing to notify individuals and to carry out a formal, documented privacy risk assessment. It also confirmed that even momentary collection by digital tools is a collection under the Privacy Act.

Why it matters

The decision shows that a permitted general situation under section 16A can cover biometric surveillance when a retailer can document a real problem of repeat retail crime, while transparency and governance duties remain fully enforceable. The Privacy Commissioner has said that the decision sets a high bar and does not give retailers general permission to deploy the technology. It underlines the need for a specific, documented risk assessment before any business adopts facial recognition.

Related stages

In a statement on March 5, 2026 the Privacy Commissioner said she had not filed an appeal against the decision. The original determination of the Office of the Australian Information Commissioner (OAIC) against Bunnings was dated October 29, 2024.