17/1/25 | Read time: 2 min
The Office of the Australian Information Commissioner (OAIC) recently decided that Bunnings breached Australian privacy laws by using facial recognition technology (FRT) to identify people causing problems in their stores.[1]
While the OAIC provided important guidance on several privacy principles and concepts,[2] the focus of its determination was about whether privacy laws permitted the use of FRT in such circumstances.
We consider this aspect of the case in further detail, including its implications for businesses who use (or plan to use) FRT in the same way.
The case addressed situations where an individual previously created trouble at a Bunnings store, sometimes amounting to a crime eg theft or assault.
Bunnings used FRT to create an internal record of such individuals and identify them when they revisited Bunnings stores. Bunnings staff were then able to take action to pre-empt the individual in case they created trouble or misbehaved again.
The central assumption in this: an individual who previously created trouble or misbehaved was likely to repeat their behavior. In other words, sensitive personal information (facial images) were collected and used to prevent something that may or may not take place, based on past conduct.
Do our privacy laws permit this (or, depending on your perspective of what laws are, should they be interpreted to permit the use of personal information for such situations)?
Privacy laws essentially provide 2 routes toward collecting and using personal information: with individual consent, or without, via an applicable legal exception.
In this context, the only viable route was perhaps through an applicable legal exception (because it is unrealistic to presume that a misbehaving individual would consent to have their personal information collected and used to be reidentified for future misbehaviour).
Bunnings tried to justify its collection and use of personal information within 2 legal exceptions – that it reasonably believed the personal information was necessary to either prevent a serious threat to its staff and customers or act against unlawful activity or misconduct.
The OAIC disagreed.
It was apparent from the following points that it felt the privacy of an individual should not be easily displaced for a business to take pre-emptive security actions based on its assumptions about past conduct:
It throws into serious doubt whether businesses can continue to use FRT for similar pre-emptive action-based situations, especially in respect of individuals who have not been proven to have engaged in unlawful conduct.
Based on the above points, to stand a (probably remote) chance for consideration under either of the 2 exceptions argued, an FRT would need to:
This is in addition to all the other requirements such as the need for effective notification under Australian Privacy Principles.
The question for businesses is whether it is operationally feasible to have an FRT which meets all these requirements and that it still makes commercial sense (at what cost?) to do so.
Perhaps not, but was that the outcome the OAIC was driving for?
The Bunnings case addressed the use of FRT in a retail setting. All eyes will now be on the latest use of FRT, albeit in a different setting – at the Australian Open (AO).
Notably, AO’s ticket conditions of sale and entry state that FRT may be used for pre-emptive security actions to ‘identify and deny entry to, or eject, persons who have been removed or denied entry to the AO’ if the organiser ‘reasonably believe it is in the best interests of the safety, security or integrity of the AO to do so’. At face value, this does not appear to meet the Privacy Commissioner’s requirement for a ‘rational basis’.[5]
It is difficult to rationally reconcile how the use of FRT at the AO in that manner is consistent with the Privacy Commissioner’s determination in the Bunnings case, and questions will undoubtedly arise in that regard.
From an enforcement perspective, Australians will be watching closely whether the Privacy Commissioner takes a consistent approach in the exercise of its investigative powers or provides guidance on why FRT use in a sporting event for pre-emptive action is permitted, but not in a retail setting.[6]