Legal Insights

Different face, familiar story – Kmart’s use of facial recognition technology and what Commonwealth agencies can learn

By
• 24 September 2025 • 7 min read

On 26 August 2025, Australian Privacy Commissioner Carly Kind (Commissioner) determined that Kmart had breached the Privacy Act 1988 (Privacy Act) by using Facial Recognition Technology (FRT) in relation to its customers between June 2020 and July 2022. This decision is similar to the Commissioner’s decision in October 2024 which found that Bunnings’ use of FRT was similarly in breach of the Privacy Act (the Bunnings decision). 

How did Kmart use FRT? 

Kmart used FRT systems at entry points and at the returns service desks in 28 stores, which it explained was for the purpose of preventing refund fraud. 

The face of every person entering the store or attending the returns service desk was captured by CCTV. The FRT systems then used the CCTV images to identify customers in databases that contained the facial images and metadata of individuals who were considered ‘persons of interest’ (being individuals who had attempted, or were suspected of having attempted, to make fraudulent returns at a Kmart store). 

A generated alert then informed Kmart staff members of a match, allowing staff members to review CCTV footage of the individual and decide whether to continue with the refund process.

Was Kmart’s collection of sensitive information via FRT permitted?

This use of FRT constituted a collection and use of sensitive information for the purposes of the Privacy Act and Australian Privacy Principles (APPs), as the resulting images and maps of ‘facial vectors’ were biometric information. The key question was therefore whether the collection was compliant with Kmart’s obligations under APPs 1, 3 and 5. 

Kmart did not contest that it had not obtained consent for the collection of the sensitive information. It instead sought to rely on the exception in APP 3.4, which allows for the collection of sensitive information without consent if a ‘permitted general situation’ (PGS) under s 16A of the Privacy Act exists. Kmart argued that a PGS did exist because: 

  • Kmart had reason to suspect that unlawful activity or misconduct of a serious nature relating to Kmart’s functions or activities had been, was being, or may be engaged in; and
  • Kmart reasonably believed that the collection, use or disclosure was necessary in order for Kmart to take appropriate action. 

The Commissioner was satisfied that Kmart had established the first element, but found that Kmart has failed to satisfy the second element. 

While the Commissioner accepted that it was appropriate for Kmart to take action to detect and prevent refund fraud, she considered that FRT was merely one tool by which Kmart could have implemented appropriate action in relation to the unlawful activity, and it was necessary to also consider the suitability of the collection, having particular regard to: 

  • the alternatives, if any, that were available to Kmart; and
  • whether the collection was proportionate, balancing the benefits of FRT against the broader privacy impacts. 

In summary, the Commissioner found that less intrusive alternatives were available and that the use of FRT was disproportionate to the accompanying interference with privacy of the thousands of individuals who entered a Kmart store. 

This is similar to the reasoning the Commissioner adopted in the Bunnings decision, in which the Commissioner also rejected Bunnings’ arguments that this PGS applied to justify the collection of sensitive information about all customers. 

The Commissioner did not impose a financial penalty on Kmart, but has, among other things, ordered Kmart to make an apology and to destroy all personal information it still holds which was obtained or generated through its use of FRT. 

Did Kmart give proper notification to customers?

In most circumstances, APP 5 requires individuals to be notified about the collection of their personal information, including sensitive information. The Commissioner found that Kmart should have taken additional steps to notify individuals about its use of FRT. 

In coming to this view, the Commissioner found that the notices provided by Kmart in its Conditions of Entry notice, a privacy poster, and its privacy policy, were not sufficient and should have contained more detailed information about the FRT system in line with APP 5.2. They were also not all uniformly deployed in all stores. 

What can Commonwealth agencies learn from this case? 

Both the Kmart and Bunnings decisions now provide a solid framework for analysing any implementation or continued use of FRT. Agencies should take heart that the decisions indicate that the identified faults lie not with the use of FRT itself, but with its proper implementation. The Commissioner has emphasised that her decisions do not constitute a ban on FRT – in a blog post on 18 September 2025, she stated ‘It may be tempting to suggest that my successive determinations amount to an effective ban on the use of this technology. However, that is incorrect; the Privacy Act is technology-neutral.’ 

FRT is part of the technological future we are all facing (pun intended). It is already being deployed by several Commonwealth agencies, including in airports and other high security risk areas. It is also being actively considered by governments for use in other settings (e.g. the NSW Government is currently considering consultation comments on a Code of Practice it has developed for the use of FRT in hotels and clubs). 

Without any legislative intervention from Parliament, it is essential that Commonwealth agencies have carefully and thoroughly examined privacy compliance under the Privacy Act, as well as privacy impacts and best practice, before implementing or continuing use of any FRT technology. Undertaking a comprehensive PIA process will allow agencies to consider:

  • the expectations of privacy that will apply in the places in which the FRT will be deployed (e.g. are they public spaces, or places in which an essential service is provided; can individuals access alternative places which do not use the FRT technology);
  • what will individuals be told about the handling of their personal information via FRT (and how will they be told);
  • whether a meaningful and valid consent process will be implemented, or are there defensible grounds for concluding that an exception in APP 3 will apply; and
  • if alternative and less intrusive means might be deployed to achieve the same purpose (e.g. is the FRT technology merely convenient, or can the use of FRT be defensibly justified?)

It will also be important to consider:

  • the size, nature and resources of the relevant agency;
  • the number of individuals that will be affected by the FRT;
  • the amount, type, and quality of the personal information and other data that will be collected and used, and
  • how the relevant data will be stored, used and accessed (including whether any artificial intelligence tools will be used for analysis); and
  • the proposed arrangements for retention of the collected personal information (noting the requirements of the Archives Act 1983 (Cth)). 

These are, of course, a non-exhaustive list of issues, and new or changed questions will need to be asked as our expectations of privacy and FRT evolve at pace. 

Need assistance?

Make sure you reach out to our Maddocks privacy and data experts if your agency is using or considering implementing FRT, to ensure you can reach the high bar that is currently being set for privacy compliance.

Sign up to receive our latest legal insights

Katherine Armytage

Katherine has a highly regarded and dynamic practice in information law, with a particular focus on privacy and data protection.

View profile
By

Keep up to date with our legal insights and events

Sign up

Online Access