Skip to main content
Rules Mate

CCTV and camera surveillance of customers and staff: the state-by-state rules

Rules Mate Editorial8 min read

Camera surveillance in Australia sits under two bodies of law at once. What each jurisdiction requires before a camera goes up, and what the Privacy Act adds on top.

Two bodies of law apply at once

Any camera an Australian business points at a person sits under two legal regimes simultaneously, and satisfying one does not satisfy the other.

The first is state and territory surveillance legislation, which regulates the act of recording. These statutes are criminal in character. They prohibit installing or using a surveillance device to record certain activities without consent, and in some jurisdictions impose notice and consultation requirements before an employer may watch its own workers.

The second is the Privacy Act 1988 (Cth), which regulates what happens to the recording afterwards. Footage of an identifiable individual is personal information, so its collection engages APP 3, its notification APP 5, its use and disclosure APP 6, its security and destruction APP 11, and access requests APP 12.

Businesses reliably get the first regime approximately right — signage goes up, change rooms are avoided — and the second substantially wrong, because it is invisible at installation and surfaces only when someone asks for footage, a system is breached, or a regulator asks how long recordings are kept.

The state and territory surveillance layer

Each jurisdiction has its own instrument and the coverage is uneven. Some Acts regulate optical, listening, tracking and data surveillance devices; two regulate listening devices only.

JurisdictionPrincipal surveillance statuteRegulates optical surveillanceWorkplace-specific rules
NSWSurveillance Devices Act 2007YesWorkplace Surveillance Act 2005
VicSurveillance Devices Act 1999YesPart 2A of the same Act
QldInvasion of Privacy Act 1971No — listening devices onlyNone
WASurveillance Devices Act 1998YesNone
SASurveillance Devices Act 2016YesNone
TasListening Devices Act 1991No — listening devices onlyNone
NTSurveillance Devices Act 2007YesNone
ACTListening Devices Act 1992NoWorkplace Privacy Act 2011

These statutes are cited by name only, and they are amended more often than most compliance registers are updated — confirm the current instrument in your jurisdiction before relying on this table. The workplace surveillance Acts explainer covers the employment-side patchwork.

Two structural points matter. First, the optical-surveillance test is not the same everywhere. In New South Wales the prohibition turns on whether installing or using the device involved entry onto premises, or interference with a vehicle or object, without consent. In Victoria, Western Australia, South Australia and the Northern Territory it turns on recording a private activity without the consent of the participants, with Western Australia extending that to a private activity the person is themselves party to. Queensland and Tasmania regulate listening devices only. Second, only New South Wales and the ACT run a full notice-and-consultation workplace regime.

Cameras pointed at customers

For customer-facing camera surveillance in an ordinary retail, hospitality or service environment, the surveillance-device statutes are usually not the binding constraint. The Privacy Act is, and the OAIC says so in its guidance on security cameras.

Four obligations do the work. Under APP 3, the business must only collect personal information reasonably necessary for one or more of its functions — so it must be able to articulate the function the camera serves, not merely assert that cameras are normal. Under APP 5, it must take reasonable steps to notify individuals at or before collection: signage visible before a person enters the recorded area, plus a description in the privacy policy. Under APP 6, footage collected for security cannot be repurposed for staff performance monitoring or marketing analytics without a fresh basis. Under APP 11, it must be secured, and destroyed or de-identified once no longer needed.

APP 11.2 is the sleeper. A retention period is a legal requirement, not a storage decision. A system holding 90 days of footage because that is what the hard drive fits, with no documented purpose for 90 days, is not compliant — and it is 90 days of sensitive material exposed in a breach. The collection notice obligation under APP 5 is the one most often discharged with a sticker reading "smile, you're on camera"; a compliant notice identifies the operator, states the purpose, and points to the privacy policy.

Cameras pointed at staff

Where the camera watches employees, two additional layers apply.

In New South Wales, the Workplace Surveillance Act 2005 requires written notice at least 14 days before camera surveillance of an employee begins (an employee may agree to less; new employees must be notified before they start work), requires cameras or their casings to be clearly visible with signs at each entrance, and prohibits surveillance of an employee in any change room, toilet facility or shower or other bathing facility. Covert surveillance is lawful only under an authority granted on application to a Judge of the Local Court — the office of magistrate was replaced in NSW in March 2026, so older guidance referring to a magistrate is out of date. The NSW workplace surveillance obligation and the covert surveillance authority walkthrough set out the mechanics.

In the Australian Capital Territory, the Workplace Privacy Act 2011 requires notice at least 14 days before surveillance starts and, distinctively, requires the employer to consult the worker in good faith for at least that period — a genuine opportunity to influence how the surveillance is conducted. Its prohibited-area list runs wider than the NSW one, extending to parent or nursing rooms, prayer rooms, sick bays and first-aid rooms. See the ACT workplace privacy obligation. In Victoria, Part 2A of the Surveillance Devices Act 1999 prohibits an employer from knowingly using an optical or listening device to monitor a worker in a toilet, washroom, change room or lactation room — a targeted prohibition, not a notice-and-consultation scheme.

Elsewhere there is no workplace surveillance statute, which is not the same as no obligation: the general surveillance-device Act still applies, WHS consultation duties still bite on changes affecting worker health or safety, and the Privacy Act still applies to the footage.

The employee records exemption in section 7B(3) is often invoked here and is narrower than assumed. The OAIC's position is that where an employer keeps a record of its monitoring the Australian Privacy Principles may apply, giving as an example a CCTV recording that does not directly relate to the person's employment. Whether particular footage is an employee record is not settled by OAIC guidance, and the exemption does nothing about the state surveillance statutes, which are criminal provisions the Privacy Act cannot switch off. The employee records exemption explainer sets out the boundaries.

Footage is personal information

Once recorded, footage of an identifiable person is personal information and inherits every downstream obligation. An individual can make an access request for footage of themselves under APP 12, so the business needs a process — including how to redact others in the frame. A breach of the recording system can be an eligible data breach requiring assessment, and offshore hosting engages APP 8. The security of the system is an APP 11 obligation in its own right, which is why default credentials on network video recorders and unrestricted remote viewing apps are a compliance problem, not just an IT one. The APP 11 reasonable steps guidance sets the standard.

Facial recognition changes the analysis

Applying facial recognition to a camera feed converts an ordinary collection into a collection of sensitive information, because biometric information used for automated identification or verification, and biometric templates, are sensitive information under the Privacy Act. Sensitive information generally requires consent, and the biometric information guide covers the analysis. Two determinations define the current position (checked August 2026).

On 19 November 2024 the Privacy Commissioner determined that Bunnings Group Limited breached Australians' privacy through a facial recognition system running over CCTV in 63 stores in Victoria and New South Wales between November 2018 and November 2021 — collecting sensitive information without consent, failing to take reasonable steps to notify, and falling short on governance and privacy policy content.

Bunnings sought review, and the outcome matters. On 4 February 2026 the Administrative Review Tribunal affirmed the APP 1 and APP 5 findings — inadequate notice, and no formal, structured, documented risk assessment — but set aside the collection finding under APP 3.3, holding that Bunnings was entitled to rely on an exception to the consent requirement, having accepted the deployment as a proportionate response to retail crime and violence against staff. The OAIC's statement on the decision records that the Privacy Act's safeguards nonetheless apply to biometric technologies even where data is retained only briefly.

The Kmart matter runs the other way on the facts. In a determination made on 26 August 2025, the Commissioner found Kmart Australia Limited's use of facial recognition to address refund fraud unlawful — deployed across 28 stores between June 2020 and July 2022 without notification or consent — concluding that the benefits in addressing refund fraud did not proportionately outweigh the impact on individuals' privacy. That determination is under review, with Tribunal hearings listed for early 2027.

The operational reading is clear. Notification and transparency failures were affirmed and are not curable by a good purpose. The collection limb turns on proportionality between the harm addressed and the privacy impact, and violent retail crime and refund fraud are not treated alike. Conduct a privacy impact assessment before deployment, evidence that less intrusive alternatives were considered, and document the risk assessment — the OAIC's guide "Facial recognition technology: a guide to assessing the privacy risks", updated in July 2026, is the framework, alongside the PIA process.

The CCTV compliance file

A defensible deployment produces a small evidence set, worth assembling before installation rather than after a complaint: a stated purpose for each camera zone tied to a function of the business; a camera plan confirming no camera covers a prohibited area; photographs of the signage in position; the privacy policy section describing the surveillance; the retention period with its reasoning and evidence that automatic deletion works; an access control list with the viewing audit log; a disclosure log recording every release to police, insurers or third parties and its legal basis; for employee-facing cameras, the jurisdiction-specific notice and consultation records; and, where facial recognition is used, a completed privacy impact assessment with its recommendations tracked.

Run the obligation finder to confirm which of these attach to your entity, and the Privacy Act 2026 readiness check to see how the reform program affects the footage you hold.

Frequently asked

Do we need signage before recording customers on CCTV?

Yes, in substance. APP 5 requires an entity to take reasonable steps to notify an individual of the collection of their personal information at or before the time of collection, and footage of an identifiable person is personal information. For camera surveillance that means signage visible before a person enters the recorded area, identifying the operator and the purpose of the recording, supported by a description of the practice in the privacy policy. A sign that says only that cameras are in use does not discharge the obligation.

Which states have a dedicated workplace surveillance law?

New South Wales, through the Workplace Surveillance Act 2005, and the Australian Capital Territory, through the Workplace Privacy Act 2011. Both impose advance notice requirements before surveillance of workers begins and restrict surveillance in areas such as change rooms and toilets; NSW also requires an authority from a Judge of the Local Court for covert surveillance of employees (the office of magistrate was replaced in March 2026, so older guidance saying "magistrate" is out of date). Every other jurisdiction relies on its general surveillance devices legislation plus the Privacy Act, which is an obligation, not an absence of one.

How long can we keep CCTV footage?

For as long as it is needed for a purpose for which it may be used or disclosed under the Australian Privacy Principles, and no longer. APP 11.2 requires an entity to take reasonable steps to destroy or de-identify personal information once it is no longer needed. That makes the retention period a documented decision tied to purpose, not a consequence of storage capacity. A system retaining months of footage with no articulated reason holds sensitive material it cannot justify and would have to assess in a breach.

Does the employee records exemption mean the Privacy Act does not apply to staff CCTV?

Do not assume so. The section 7B(3) exemption applies to acts and practices directly related to a current or former employment relationship and an employee record, and its application to surveillance footage is contested rather than settled. It also has no effect on state and territory surveillance legislation, which is criminal in character and cannot be displaced by a Commonwealth privacy exemption, or on work health and safety consultation duties triggered by introducing a monitoring regime.

Can a retailer use facial recognition in its stores?

Only on a demonstrably proportionate basis and with proper notification. In the Bunnings matter the Administrative Review Tribunal upheld the Privacy Commissioner's findings that the retailer failed to notify customers properly and lacked appropriate policies, while accepting that the technology could be used for the limited purpose of combatting very significant retail crime. In the Kmart determination the Commissioner found the use unlawful, concluding the benefits in addressing refund fraud did not proportionately outweigh the privacy impact; that matter is under Tribunal review with hearings listed for early 2027. Conduct a privacy impact assessment first, evidence that less intrusive alternatives were considered, and be transparent about the deployment.

Related

Related reading