AUD 0Privacy Act 1988 (Australia)APAC
Australia OAIC v. Bunnings: Facial Recognition AI Breached Privacy Act
Summary
Australia's Privacy Commissioner found Bunnings unlawfully deployed facial recognition technology across 63 of its hardware stores (November 2018 – November 2021), capturing biometric data of hundreds of thousands of shoppers without consent, without clear notice, and without a lawful basis under the Privacy Act.
Details
- Violation: Unlawful biometric data collection via facial recognition AI
- Penalty: No monetary penalty (Act did not provide for fines at the time)
- Framework: Australian Privacy Act 1988
- Status: Enforcement determination; partially overturned on appeal in 2026 but core breach finding upheld
Key Takeaways
- Retail facial recognition AI requires consent and lawful basis
- Biometric data collection at scale triggers privacy enforcement
- Companies must provide clear notice when deploying AI surveillance
- Core Privacy Act breach finding was upheld even on appeal