AUD 0Privacy Act 1988 (Australia)APAC
Australia OAIC v. Kmart: Facial Recognition AI Privacy Breach
Summary
The Privacy Commissioner found Kmart violated the Privacy Act by deploying facial recognition technology in its stores. The Commissioner found Kmart failed to obtain adequate consent and lacked a lawful basis for collecting biometric data from shoppers via AI surveillance.
Details
- Violation: Privacy Act breach — unlawful biometric data collection via AI
- Penalty: No monetary penalty (Act did not provide for fines at the time)
- Framework: Australian Privacy Act 1988
- Status: Enforcement determination
Injunctive Relief
Kmart was ordered to cease using facial recognition technology and to ensure adequate safeguards for any future biometric AI deployment.
Key Takeaways
- Retail AI surveillance requires explicit consent and lawful basis
- Biometric data collection without clear notice is a Privacy Act violation
- Australian regulators are actively pursuing AI surveillance cases
- Cease-and-desist orders apply even without monetary penalties