← the record
AIAAIC-1839

Bunnings' facial recognition ruled to breach Australians' privacy

Australian retailer Bunnings breached the privacy of hundreds of thousands of Australians by using facial recognition in 62 stores without consent, thereby infringing customer privacy. What happened Bunnings deployed facial recognition technology via CCTV cameras in 62 stores across Victoria and New South Wales between November 2018 and November 2021. The system captured facial images of all individuals entering these stores, processing them to create biometric profiles. Bunnings claimed this was to identify "known and repeat offenders" and reduce theft and violence. Why it happened Australia's O ffice of the Australian Information Commissioner ( OAIC ) ruled that Bunnings' use of facial recognition was disproportionate and unnecessarily intrusive. The regulator also said that the company had failed to adequately notify customers about the use of facial recognition , obtain consent for collecting sensitive biometric data, and implement proper privacy compliance practices. What it means The ruling is seen as a landmark in Australia and likely to set a precedent for the use of facial recognition technology in Australian retail environments. Bunnings was ordered to cease using FRT in breach of privacy laws, destroy collected data, and publish a statement about the ruling. The company said it would appeal the decision. System 🤖 Unknown Developer: Country: Australia Sector: Retail Purpose: I mprove safety; Reduce theft; Str engthen security Technology: Facial reco gnition Issue: Accountability; Consent; Privacy/surveillance; Prop ortionality; Transparency Timeline ⏰ November 2018. Bunnings begins rolling out the facial recognition system across selected stores in New South Wales and Victoria. November 2021. Bunnings pauses the use of the facial recognition technology in its stores. June 2022. Consumer group Choice flags concerns about in-store facial recognition practices to the OAIC. October 2024. The Privacy Commissioner issues a determination stating that Bunnings breached the Australian Privacy Principles (APPs). February 2026. The Administrative Review Tribunal (ART) rules on appeal, affirming breaches of transparency and notification but setting aside the finding that the collection was unlawful without consent. Legal, regulatory 👩🏼‍⚖️ O ffice of the Australian Information Commissioner. Bunnings breached Australians’ privacy with facial recognition tool

Date it happened
2018-01-01
Organisation involved
Bunnings
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from AIAAIC and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.