You can win the argument and still breach the Act.
On 29 July 2026 the Privacy Commissioner published an update to the OAIC's facial recognition guidance, first published in 2024, incorporating the Administrative Review Tribunal's decision in the Bunnings appeal. Most coverage of that appeal recorded that the retailer succeeded. The more useful reading is what the retailer succeeded at, and what it did not, because the two halves come apart cleanly and the half that survived is the half every assurance function should be looking at.
What did the Tribunal actually decide?
The Commissioner's November 2024 determination concerned the use of facial recognition across more than 60 stores in Victoria and New South Wales between November 2018 and November 2021. It found contraventions on four fronts: collection of sensitive information, notice, the practices and procedures an entity must have in place, and the contents of the privacy policy itself.
The Tribunal moved one of those. The OAIC's own statement on the decision records that the Tribunal found the entity entitled to rely on exemptions in relation to Australian Privacy Principle 3.3, reversing the Commissioner's conclusion on collection. On the other three it went the other way, finding that the entity had failed to provide appropriate notice and should have completed what the OAIC describes as a "formal, structured and documented" risk assessment of its system. The Tribunal's decision states the affirmed set precisely: it decides that the entity was in breach of Australian Privacy Principles 5.1, 1.2 and 1.3.
The Privacy Commissioner's later statement is careful about the scope of the win. The entity was "entitled to use FRT for the limited purpose of combatting very significant retail crime", and the Tribunal "did not disturb the original findings" that the use "was not properly notified" and lacked "appropriate policies and procedures".
Read that as a compliance rule rather than a news item. The system was permitted. The file was not adequate. Those are separate obligations, and the second one stood on its own.

Why does a lawful system still breach the Act?
Because three of the Australian Privacy Principles in issue are about the organisation, not the data.
Australian Privacy Principle 1.2 requires an APP entity to take such steps as are reasonable in the circumstances to implement practices, procedures and systems that will ensure compliance with the principles and enable the entity to deal with inquiries and complaints. Nothing in that obligation depends on whether a particular collection turned out to be permitted. It is a standing requirement about how the entity is organised.
Australian Privacy Principle 1.3 requires the entity to have a clearly expressed and up to date policy about the management of personal information, and Australian Privacy Principle 1.4 sets out what that policy has to contain. The Tribunal found that the entity's privacy policies did not say what kinds of personal information it collected and held, or how it collected and held them, as Australian Privacy Principles 1.4(a) and 1.4(b) require, and that this put it in breach. The OAIC's guidance makes the distinction that matters here: the notice obligation is "separate to the requirement to provide information in a privacy policy under APP 1.3". Satisfying one does not satisfy the other.
Australian Privacy Principle 5.1 requires the entity to take such steps, if any, as are reasonable in the circumstances to notify individuals of such of the matters in Australian Privacy Principle 5.2 as are reasonable in the circumstances, or otherwise ensure they are aware of them, at or before collection or, if that is not practicable, as soon as practicable after. The qualifier "if any" is genuinely there in the text and is routinely dropped in summaries, which matters because it signals a proportionate standard rather than an absolute one. So is the second reasonableness filter sitting inside paragraph (a). A proportionate standard is still a standard, and a sign at an entrance is a weak answer where the collection is biometric and continuous.
The practical consequence for a GRC function is that the AI risk assessment and the AI system approval are not the same control. An organisation can run a rigorous vendor evaluation, conclude correctly that a deployment is defensible, deploy it, and hold no artefact that demonstrates the reasoning. The Act asks for both.
What counts as sensitive information here?
This is where a lot of internal analysis goes wrong, and it is worth getting exactly right because it determines whether the higher collection threshold applies at all.
The Privacy Act definition of sensitive information treats biometric information as sensitive where it is to be used for the purpose of automated biometric verification or biometric identification. It treats biometric templates as sensitive without any such qualifier. Those are two different tests sitting in adjacent paragraphs, and almost every secondary summary flattens them into a single claim that biometric data is sensitive information.
The distinction has real consequences. A system that generates and retains templates is collecting sensitive information regardless of what it is used for. A system capturing biometric information for some other purpose sits differently, and the purpose limb has to be reasoned through rather than assumed.
Where the higher threshold does apply, Australian Privacy Principle 3.3 is not the consent test people take it for. For an organisation, the individual must consent and the information must also be reasonably necessary for one or more of the entity's functions or activities, unless a separate exemption applies. Both limbs, not either.
The exemptions that carried the day in this matter sit in section 16A of the Act, in the table of permitted general situations. The Tribunal decided the collection point on item 2, and then found that the permitted general situation in item 1 existed as well, although it had already recorded that it did not need to reach that question. The two items do not test the same thing. Item 2 has two cumulative limbs: the entity must have reason to suspect that unlawful activity or misconduct of a serious nature relating to its functions or activities has been, is being or may be engaged in, and it must reasonably believe the collection is necessary in order to take appropriate action in relation to the matter. Item 1's two limbs are different: it must be unreasonable or impracticable to obtain the individual's consent to the collection, and the entity must reasonably believe the collection is necessary to lessen or prevent a serious threat to the life, health or safety of any individual, or to public health or safety. Having a suspicion is not enough on its own, and neither is the impracticability of consent. In both items the belief about necessity has to be reasonable, and reasonableness is evidenced in a document or not at all.
What does the assessment have to contain?
The updated guidance sets the bar plainly: entities "should conduct a formal, structured and documented risk assessment prior to implementing FRT in any form".
Where the deployment relies on a permitted general situation, the guidance also supplies the test the necessity judgement has to work through. It asks entities to consider three factors: the suitability of collecting the information captured by the particular system under consideration, the alternatives to collecting the personal information that are available to the entity, and whether collecting by that means is proportionate to the impact on individuals' privacy.
The second factor is the one most likely to be skipped, and the guidance does not leave it abstract. It names candidates directly, including quality CCTV coverage, deployment of security guards, training employees to deal with safety and security issues, and taking legal action to restrict known repeat offenders. An assessment that never mentions the alternatives has not performed the test, and an assessment written after deployment is evidence of a conclusion rather than of a process.
It is worth being concrete about what "formal, structured and documented" implies as an artefact, because those three adjectives are doing distinct work. Formal means it is a recognised step in a process rather than a conversation someone remembers having. Structured means it follows a defined method, so a reviewer can tell whether a required question was answered or skipped. Documented means it has a date, an author and an approver, and the date is the one that matters most, because an assessment produced after a regulator asks for it is not evidence of a decision, it is evidence of a response.
On privacy impact assessments the guidance draws a line worth reproducing accurately in internal policy. For agencies, conducting one is mandatory for all high privacy risk projects. For APP entities generally, agencies included, the OAIC frames a privacy impact assessment as a reasonable step to take under Australian Privacy Principle 1.2, and strongly recommends entities publish the report. So a private sector entity that skips the assessment has not automatically breached a mandatory rule, but it has declined a step the regulator has publicly identified as reasonable, which is a difficult position to hold in an investigation.

Where does this reach beyond retail?
Everywhere an AI system's defence depends on judgement rather than on a bright line.
Facial recognition happens to be the most legible case because the technology is visible and the community reaction is strong. The Commissioner reports the share of Australians who think facial recognition is one of the biggest privacy risks they face today rising from 27 percent in 2023 to 45 percent in 2026, drawing on the 2026 Australian Community Attitudes to Privacy Survey, and states that a precautionary approach to deployment is required under Australian law.
But the structure of the finding generalises. Fraud detection models, behavioural analytics, voice authentication, automated identity verification and any system relying on a permitted general situation all sit on the same footing: lawful if necessary and proportionate, and provably so only if somebody wrote down what was considered and rejected. The same reasoning is now tested outside the regulator too, because the statutory tort of serious invasion of privacy lets an individual sue directly on necessity and proportionality without an OAIC complaint. The Commissioner's announcement of the update is explicit that each proposed deployment "will need to be assessed against the requirements of the Act", which forecloses the reading that one favourable outcome settles the question for a class of technology. The same announcement records that a separate determination issued against another retailer in August 2025 remains under review in the Tribunal, with hearings scheduled for early 2027.

Note also what is coming. From 10 December 2026 the automated decision making transparency requirements attach to privacy policies, which means the population of AI systems an entity has to be able to describe grows again. An organisation that cannot produce a proportionality assessment for the systems it runs today will find that gap harder to close once it also has to publish a description of them.
Bottom line
The entity won the point everyone reported and lost the points that actually generalise. Substantive lawfulness and demonstrated governance are separate obligations under the Privacy Act, and the second one does not follow from the first. If your AI system's legal position rests on necessity, proportionality and the absence of a less intrusive alternative, then the document recording that reasoning is not paperwork about the control. It is the control.
Do this Monday
- List every deployed system that captures biometric information or generates biometric templates, and record for each which limb of the sensitive information definition applies
- For each, locate the assessment that predates deployment and note whether it addresses suitability, alternatives and proportionality by name
- Where a permitted general situation is being relied on, identify which item in the section 16A table applies, then write down that item's limbs and the evidence for each, particularly the reasonable belief about necessity
- Check the notice actually given at the point of collection against what Australian Privacy Principle 5.2 lists, rather than against the privacy policy
- Separately, check the privacy policy itself says what kinds of personal information the system collects and holds and how, which Australian Privacy Principle 1.3 requires whether or not the notice at collection was adequate
- Add a standing gate to the AI approval workflow requiring the documented assessment before implementation, not before go-live sign-off
Content disclaimer: This article is for general educational and informational purposes only. It does not constitute legal advice, regulatory guidance, or a substitute for professional compliance judgement. Privacy obligations vary by entity type, circumstance and the nature of the information involved. Statements about what the Administrative Review Tribunal decided are drawn from the OAIC's published statements and guidance and from the Tribunal's published decision. Always refer to primary source guidance from the OAIC or the relevant regulatory authority.
Primary sources
- OAIC, Privacy Commissioner publishes updated guidance on facial recognition in retail spaces, media release, 29 July 2026. https://www.oaic.gov.au/news/media-centre/privacy-commissioner-publishes-updated-guidance-on-facial-recognition-in-retail-spaces
- OAIC, Facial recognition technology: a guide to assessing the privacy risks, published 19 November 2024, last updated 29 July 2026. https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/facial-recognition-technology-a-guide-to-assessing-the-privacy-risks
- OAIC, OAIC statement on Administrative Review Tribunal's Bunnings decision, 4 February 2026. https://www.oaic.gov.au/news/media-centre/oaic-statement-on-administrative-review-tribunals-bunnings-decision
- OAIC, Privacy Commissioner statement on Administrative Review Tribunal's Bunnings decision, 5 March 2026. https://www.oaic.gov.au/news/media-centre/privacy-commissioner-statement-on-administrative-review-tribunals-bunnings-decision
- OAIC, Bunnings breached Australians' privacy with facial recognition tool, media release, 19 November 2024. https://www.oaic.gov.au/news/media-centre/bunnings-breached-australians-privacy-with-facial-recognition-tool
- Bunnings Group Limited and Privacy Commissioner (Guidance and Appeals Panel) [2026] ARTA 130, 4 February 2026. https://www.austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/ARTA/2026/130.html
- Privacy Act 1988 (Cth), Compilation No. 104, C2026C00227, in force 4 June 2026, sections 6(1) and 16A and Australian Privacy Principles 1.2, 1.3, 3.3 and 5.1. https://www.legislation.gov.au/C2004A03712/latest/text
TheAICommand. Intelligence, At Your Command.


