Case note: Facial recognition technology and privacy

In Commissioner Initiated Investigation into Bunnings Group Ltd (Privacy) [2024] AICmr 230 Privacy Commissioner Carly Kind has found Bunnings Group Limited breached Australians’ privacy by collecting their personal and sensitive information through a facial recognition technology system (FRT).

Bunnings has announced it will seek a review of OAIC’s Determination before the Administrative Review Tribunal.

Previous cases.

The system, via Closed Circuit Television, captured the faces of every person – likely hundreds of thousands of individuals – who entered 63 Bunnings stores in Victoria and New South Wales between November 2018 and November 2021.

Commissioner Kind found Bunnings collected individuals’ sensitive information without consent, failed to take reasonable steps to notify individuals that their personal information was being collected, and did not include required information in its privacy policy.

The Commissioner also found that Bunnings breached APP 1.2 by failing to take such steps as were reasonable in the circumstances to implement practices, procedures and systems relating to its functions or activities to ensure that it complied with the APPs, as required by APP 1.2(a).

The FRT system operated at the entry points of relevant stores by capturing the facial image of every person who entered the store during the relevant period, regardless of their age or other characteristics. This included customers, staff, visitors and contractors. The FRT system analysed the individuals’ facial images on the live CCTV footage to create a ‘real-time facial image’.

Bunnings used the facial image of each individual, through an algorithm, to create ‘searchable data’ about that individual’s facial image which had the potential to adversely impact the safety and security of individuals in the stores, together with its stock and facilities.

If you found this article helpful, then subscribe to our news emails to keep up to date and look at our video courses for in-depth training. Use the search box at the top right of this page or the categories list on the right hand side of this page to check for other articles on the same or related matters.

David Jacobson

Author: David Jacobson
Principal, Bright Corporate Law
Email:
About David Jacobson
The information contained in this article is not legal advice. It is not to be relied upon as a full statement of the law. You should seek professional advice for your specific needs and circumstances before acting or relying on any of the content.

 

Your Compliance Support Plan

We understand you need a cost-effective way to keep up to date with regulatory changes. Talk to us about our fixed price plans.