
On 29 July 2026, the Office of the Australian Information Commissioner updated its guide to assessing the privacy risks of facial recognition technology.
The update matters because it now draws on the Administrative Review Tribunal's decision about Bunnings' use of facial recognition, giving operators a clearer view of how the privacy principles apply in practice.
The guidance is aimed at organisations using or considering facial recognition in physical commercial and retail spaces. It is not legally binding on its own, but the Australian Privacy Principles it explains are.
For operators, the message is clear: if you use facial recognition, you need to be able to explain why, document the decision, notify people properly and show that the system is being managed responsibly.
APP 1 requires organisations to have real practices, procedures and systems in place to support compliance.
The OAIC recommends completing a privacy impact assessment before deploying facial recognition. If you operate across multiple sites, one assessment may not cover every location, particularly where purposes, layouts and risk profiles differ.
Using a third-party technology provider does not shift that responsibility. Due diligence, contracts, privacy processes and deletion requirements still sit with the organisation using the technology.
From 10 December 2026, privacy policies will also need to address automated decision-making where computer programs make decisions that could significantly affect a person's rights or interests.
Facial images and biometric templates used for automated identification are sensitive information under the Privacy Act.
Collection happens as soon as the image is processed, even where it is deleted almost immediately.Organisations generally need to rely on consent, explicit legal authorisation or a permitted general situation under section 16A.
Where a permitted general situation is relied on, the OAIC focuses on three key questions.
Does facial recognition actually address the problem you are trying to solve?
That means looking at accuracy, camera placement, lighting, real-world performance and whether people can easily work around the system.
This is an important question for security teams.
Less intrusive options might include improved CCTV monitoring, anomaly detection, additional guards, staff training, police engagement or other operational controls.
For icetana AI customers, this distinction matters. Our core anomaly detection technology does not identify individuals. It detects unusual activity and brings it to an operator's attention, while facial recognition is a separate capability.
So before enabling facial recognition, ask a simple question:
Do you actually need to know who someone is to achieve the security outcome?
If detecting and responding to unusual behaviour is enough, facial recognition may not be necessary.
The benefit of facial recognition needs to justify the privacy impact.
Serious, repeated and documented incidents make a stronger case than occasional low-level behaviour.
For existing facial recognition customers, this means being able to show why the technology is needed, why less intrusive measures were not enough and why identifying individuals is proportionate to the risk.
icetana AI's Safety & Security solution can also help teams document the frequency and severity of security events over time, helping build a clearer evidence base for that assessment.
The Bunnings decision is important because the Tribunal accepted that there was a legitimate security problem and that facial recognition could help address it.
However, Bunnings still breached the Privacy Act.
The issues included inadequate documented privacy practices, a privacy policy that did not properly address facial recognition and insufficient notification to customers.
That is the key lesson for operators.
Having a strong reason to use facial recognition is not enough. You also need to document it and tell people clearly that the technology is being used.
APP 5 applies to everyone whose face is captured, including people who never match a watchlist.
A general CCTV or surveillance notice is not enough. People need to be told that facial recognition is being used and why.
The OAIC accepts that signage cannot contain every detail, so a short notice can direct people to a website, factsheet or staff member for further information.
APP 10 requires organisations to take reasonable steps to ensure information is accurate.
For facial recognition, that means keeping reference databases current, testing the system in the environment where it will operate, reviewing performance regularly and using human verification for positive matches.
Operators should also understand how the system performs across different demographic groups.
A vendor's headline accuracy figure is not enough. You need to understand how the technology performs in your own environment.
APP 11 requires biometric information to be deleted or de-identified once it is no longer required.
For non-matches, the expectation is immediate deletion.
For matches, organisations should define a retention period linked to the purpose and consider whether the biometric data itself needs to be retained at all.
Automatic deletion, restricted access, secure storage and clear vendor obligations should all be part of the deployment.
If you already use facial recognition, the OAIC update does not necessarily mean you need to stop.
It means you need to be able to answer a few important questions:
For icetana AI customers, facial recognition remains a separate capability from our core anomaly detection technology.
The practical approach is to start with the security problem, understand what can be achieved without identifying people, and only introduce facial recognition where there is a clear and defensible need.
Read the OAIC guidance: Facial recognition technology: a guide to assessing the privacy risks