rulesmate.com.au — Compliance reference
https://rulesmate.com.au/insights/biometric-information-privacy-act-frt-guide
Printed 31 August 2026
Biometric information under the Privacy Act — facial recognition and the OAIC's 2024 determination
How the Privacy Act treats biometric information including facial recognition, and the OAIC's 2024 Bunnings determination on FRT in retail.
Biometric information as sensitive information
Biometric information falls under the definition of 'sensitive information' as outlined in section 6 of the Privacy Act 1988 (Cth). This classification applies specifically to biometric information used for automated biometric verification or identification. Furthermore, biometric templates that are derived from this information are also considered sensitive information.
The designation as sensitive information means that biometric data receives a higher level of protection compared to ordinary personal information. This heightened protection reflects the increased potential for harm that can arise from misuse or compromise of this type of data.
Generally, Australian Privacy Principle 3.3 requires organisations to obtain consent before collecting sensitive information. However, this requirement is subject to exceptions, meaning consent is not always mandatory.
The Bunnings FRT determination
The Australian Information Commissioner made a determination on 19 November 2024 concerning Bunnings Group Limited’s use of facial recognition technology. The determination found that Bunnings had breached the Privacy Act between November 2018 and November 2021.
The Commissioner’s assessment identified specific breaches of the Act. Bunnings was found to have collected sensitive information without consent, contravening Australian Privacy Principle 3.3. Additionally, the organisation failed to take reasonable steps to notify individuals about the collection of their personal information (APP 5) and had inadequate content in its privacy policy (APP 1.3 / 1.4).
As a result of the determination, Bunnings is required to destroy personal information that is no longer needed and to publish a statement regarding the breaches.
When FRT can lawfully be used
Facial recognition technology (FRT) involving the collection of biometric information generally requires express, informed consent from individuals. This consent is typically needed when the FRT is used for verification or identification purposes.
However, there are limited exceptions to this requirement. These exceptions allow for the use of FRT without consent in circumstances involving serious threats to life, health or safety, and when undertaken by enforcement bodies for law-enforcement-related activities.
Regardless of whether consent is obtained or an exception applies, organisations deploying FRT should conduct Privacy Impact Assessments. Furthermore, all entities must adhere to the security requirements outlined in Australian Privacy Principle 11 when handling biometric templates.
What's coming next
The Privacy and Other Legislation Amendment Act 2024 introduces significant changes to privacy protections in Australia. Most notably, a statutory tort of serious invasions of privacy will commence on 10 June 2025. This provides individuals with a new avenue for redress if their privacy has been seriously interfered with.
Misuse of biometric data is likely to be considered a potential basis for a claim under this new tort, meaning individuals may be able to seek compensation independently of any determination made by the Office of the Australian Information Commissioner (OAIC). This expands the avenues for accountability beyond existing privacy legislation.
The Government has indicated further reforms to the Privacy Act are planned, referred to as Tranche 2. These reforms may include specific requirements around consent and transparency, particularly concerning high-risk personal information like biometric data.
Frequently asked
Does CCTV that records faces collect biometric information?
Not automatically. CCTV that simply records video is collection of personal information. Biometric information specifically arises where biometric processing — such as facial recognition matching — is applied to those images.
Is consent required for staff time-and-attendance FRT?
In most cases yes, and consent must be freely given. The Fair Work Commission has held that requiring biometric scanning as a condition of employment can be unreasonable in the absence of consultation and adequate alternatives.
Related
Related reading
ISO 27701 privacy information management and the Australian Privacy Act
ISO/IEC 27701:2025 is now a standalone privacy management standard. How a PIMS maps to the Australian Privacy Principles, and what it does and does not satisfy.
Privacy Act 2026: what Australian SMBs need to do before 10 December
On 10 December 2026, ADM transparency and the Children's Online Privacy Code commence. The proposed small business exemption removal — which would bring ~2 million SMBs into APP scope — is not yet law. Here's what you need in place.
The marketing consent stack: how the Spam Act, the Australian Privacy Principles and the Do Not Call Register interact
Three separate regimes govern Australian direct marketing. Which one applies to which channel, how APP 7.8 carves them apart, and the consent record that satisfies all three.
Privacy impact assessments: when an Australian business should run one and what it must cover
Where a PIA is legally mandatory in Australia, the high privacy risk threshold test, the OAIC's ten-step process, and how PIA findings become auditable commitments.
Free tools
© Rules Mate · Source citations at the end · Information current as at 1 June 2026
Printed from https://rulesmate.com.au/insights/biometric-information-privacy-act-frt-guide