Skip to main content
AUD 0Privacy Act 1988 (Australia)APAC

Australia OAIC v. Bunnings: Facial Recognition AI Breached Privacy Act

Entity
Bunnings Group
Penalty
AUD 0
Status
enforced
Date
Nov 15, 2023

Summary

Australia's Privacy Commissioner found Bunnings unlawfully deployed facial recognition technology across 63 of its hardware stores (November 2018 – November 2021), capturing biometric data of hundreds of thousands of shoppers without consent, without clear notice, and without a lawful basis under the Privacy Act.

Details

  • Violation: Unlawful biometric data collection via facial recognition AI
  • Penalty: No monetary penalty (Act did not provide for fines at the time)
  • Framework: Australian Privacy Act 1988
  • Status: Enforcement determination; partially overturned on appeal in 2026 but core breach finding upheld

Key Takeaways

  1. Retail facial recognition AI requires consent and lawful basis
  2. Biometric data collection at scale triggers privacy enforcement
  3. Companies must provide clear notice when deploying AI surveillance
  4. Core Privacy Act breach finding was upheld even on appeal

Related Enforcement Actions