Skip to main content
AUD 0Privacy Act 1988 (Australia)APAC

Australia OAIC v. Kmart: Facial Recognition AI Privacy Breach

Entity
Kmart
Penalty
AUD 0
Status
enforced
Date
Jun 15, 2024

Summary

The Privacy Commissioner found Kmart violated the Privacy Act by deploying facial recognition technology in its stores. The Commissioner found Kmart failed to obtain adequate consent and lacked a lawful basis for collecting biometric data from shoppers via AI surveillance.

Details

  • Violation: Privacy Act breach — unlawful biometric data collection via AI
  • Penalty: No monetary penalty (Act did not provide for fines at the time)
  • Framework: Australian Privacy Act 1988
  • Status: Enforcement determination

Injunctive Relief

Kmart was ordered to cease using facial recognition technology and to ensure adequate safeguards for any future biometric AI deployment.

Key Takeaways

  1. Retail AI surveillance requires explicit consent and lawful basis
  2. Biometric data collection without clear notice is a Privacy Act violation
  3. Australian regulators are actively pursuing AI surveillance cases
  4. Cease-and-desist orders apply even without monetary penalties

Related Enforcement Actions