Artificial intelligence and biometric technologies are rapidly becoming part of everyday business operations. From customer analytics to theft prevention, retailers are increasingly looking at facial recognition technology (FRT) as a tool to improve security and reduce losses. However, Australia’s Privacy Commissioner has recently updated guidance that makes it clear businesses must tread carefully before implementing these systems.
The updated guidance from the Office of the Australian Information Commissioner (OAIC) follows several high-profile investigations into retailers’ use of facial recognition technology and provides valuable insight into how Australian privacy laws apply in practice. For businesses considering AI-powered surveillance technologies, the message is simple: just because technology is available does not mean it can be used lawfully.
Why facial recognition is different
Unlike ordinary CCTV, facial recognition technology does more than record images. It analyses an individual’s facial features and converts them into biometric information capable of identifying a person. Under the Privacy Act 1988 (Cth), biometric information used for identification purposes is generally regarded as sensitive information, attracting a much higher level of legal protection.
As a result, organisations cannot simply install facial recognition cameras in the same way they install ordinary security cameras.
The updated OAIC guidance
The OAIC’s revised guidance focuses on retailers using facial recognition to identify known offenders, prevent shoplifting and enhance store security. While recognising that these may be legitimate business objectives, the Privacy Commissioner emphasises that businesses must carefully assess whether facial recognition is necessary, proportionate and reasonable before deploying it.
Importantly, the guidance clarifies when an organisation may rely on limited exceptions to the usual requirement to obtain an individual’s consent before collecting sensitive information. Those exceptions are interpreted narrowly and will not automatically justify the widespread use of facial recognition across retail premises.
Lessons from recent enforcement action
The updated guidance has been shaped by several significant privacy decisions involving major Australian retailers.
In recent years, the Privacy Commissioner determined that facial recognition systems used by large retailers breached the Australian Privacy Principles because they collected sensitive biometric information from every customer entering certain stores, regardless of whether those customers presented any security risk.
The Commissioner concluded that collecting facial images of thousands of ordinary shoppers in order to identify a relatively small number of suspected offenders was disproportionate and inconsistent with Australian privacy law. Those decisions have become an important benchmark for organisations considering similar technology.
Privacy by design
Businesses considering facial recognition should not treat privacy compliance as an afterthought. Instead, privacy should be incorporated into system design from the outset.
The OAIC encourages organisations to undertake a comprehensive Privacy Impact Assessment before implementing facial recognition technology. Businesses should consider:
- whether facial recognition is genuinely necessary;
- whether less intrusive alternatives could achieve the same outcome;
- the scale of information being collected;
- how long biometric data will be retained;
- who will have access to the data;
- how customers will be informed; and
- whether the collection is fair, lawful and transparent.
These questions are becoming increasingly important as AI technologies become more sophisticated and affordable.
More than a retail issue
Although the latest guidance is directed primarily at retailers, its implications extend much further.
Businesses operating gyms, entertainment venues, residential developments, aged care facilities, hospitality venues and even workplaces may also consider using facial recognition for access control, attendance monitoring or security purposes.
The same privacy principles are likely to apply whenever biometric information is collected for identification purposes.
Any organisation using facial recognition should therefore review whether its current practices comply with the Australian Privacy Principles and ensure appropriate governance processes are in place.
What this means for your business
Artificial intelligence offers significant opportunities to improve efficiency and reduce risk. However, regulators are making it increasingly clear that innovation must be balanced against individuals’ privacy rights.
Businesses should avoid assuming that because facial recognition technology is commercially available it is legally compliant. Regulatory scrutiny in this area is increasing, and privacy enforcement is expected to remain a priority for the OAIC. Organisations that fail to comply risk regulatory investigations, reputational damage and potentially significant legal consequences.
Practical steps
If your business is considering implementing facial recognition technology, now is the time to seek advice. In particular, businesses should:
- conduct a Privacy Impact Assessment before deployment;
- review compliance with the Australian Privacy Principles;
- assess whether less privacy-invasive alternatives exist;
- implement robust governance and data security measures; and
- obtain legal advice before collecting or processing biometric information.
As AI and surveillance technologies continue to evolve, privacy compliance will become an increasingly important part of corporate governance. Businesses that proactively address these issues will be better positioned to embrace innovation while maintaining customer trust and meeting their legal obligations.
If you would like to book a time to speak with one of lawyers for confidential advice, contact us by calling 08 9375 3411.
About the Author: This article was authored by Steven Brown, Steven Brown’s legal career covers working with multinational corporations and Australian listed companies to family-owned businesses. This range of experience has equipped Steven with the unique ability to offer tailored legal services that make a significant difference to businesses of all sizes.
Steven enjoys working with entrepreneurs and family enterprises to both protect them and allow them to forward develop their businesses as well as ensure it can flow to the future generations.

















