ARTICLE
13 August 2026

OAIC Publishes Updated Guidance On Facial Recognition Technology For Australia

KG
K&L Gates LLP

Contributor

At K&L Gates, we foster an inclusive and collaborative environment across our fully integrated global platform that enables us to diligently combine the knowledge and expertise of our lawyers and policy professionals to create teams that provide exceptional client solutions. With offices worldwide, we represent leading global corporations in every major industry, capital markets participants, and ambitious middle-market and emerging growth companies. Our lawyers also serve public sector entities, educational institutions, philanthropic organizations, and individuals. We are leaders in legal issues related to industries critical to the economies of both the developed and developing worlds—including technology, manufacturing, financial services, healthcare, energy, and more.
The Office of the Australian Information Commissioner (OAIC) has published updated guidance for entities considering using facial recognition technology (FRT) in high-volume, publicly accessible physical spaces, like retail shopfronts.
Australia Technology
Cameron Abbott’s articles from K&L Gates LLP are most popular:
  • within Technology topic(s)
  • with Senior Company Executives, HR and Finance and Tax Executives
  • with readers working within the Business & Consumer Services, Media & Information and Metals & Mining industries

The Office of the Australian Information Commissioner (OAIC) has published updated guidance for entities considering using facial recognition technology (FRT) in high-volume, publicly accessible physical spaces, like retail shopfronts.

The updated guidance incorporates the findings of the Administrative Review Tribunal regarding Bunnings’ use of FRT in its stores (see our earlier blog), and clarifies exceptions to the consent requirement to collecting sensitive biometric information.

The OAIC noted that the Bunnings decision “confirmed that there is a high bar for using facial recognition technology in Australia”, with the regulator signaling that its appetite in this space has not decreased. The timing of this guidance is particularly notable, given recent announcements of FRT being deployed in Australia instead of digital or paper tickets for live events, as well as the impending glut of AI “smart glasses”.

The guidance emphases 5 key principles for ensuring your organisation’s FRT deployment is compliant:

  1. Governance and Ongoing Assurance (APP 1): Clear governance arrangements in place, including privacy risk management practices and policies (including privacy impact assessments) that are documented and regularly reviewed.
  2. Lawful Basis for Collection (APP 3): Only collecting biometric information with valid consent, and only where collection is reasonably necessary and proportionate. Where consent is not relied upon, carefully consider whether a narrow exception applies.
  3. Transparency and Notification (APP 5): Regardless of the collection pathway, taking reasonable steps to notify individuals about the collection of their personal information.
  4. Accuracy, Bias and Discrimination (APP 10): Ensuring biometric information used in FRT is accurate and actively addressing any risk of bias or discriminatory outcomes.
  5. Security of Personal Information (APP 11): Even where personal information is held only briefly, taking reasonable steps to protect it from misuse, interference, loss, and unauthorised access, and destroying or de-identifying it once no longer needed.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More