Most organisations deploying AI-powered technology assume the hard part is the technology. The Bunnings case shows the hard part is the governance.
Between November 2018 and November 2021, Bunnings installed facial recognition technology (FRT) in a number of its Australian and New Zealand stores. The system captured the face of every person who walked through the door, compared it against a database of individuals previously involved in criminal conduct or incidents involving staff, and alerted store employees when it found a match. The facial data itself was deleted in milliseconds. Nobody was told it was happening.
That decision triggered a regulatory investigation that took six years to resolve, a determination by the Privacy Commissioner, an appeal to the Administrative Review Tribunal, and a still-open question about whether the matter ends there. The legal outcome was mixed, but the compliance lessons are not.
The Regulator Found Bunnings Collected Biometric Data, Whether It Knew It or Not
On 29 October 2024, Privacy Commissioner Carly Kind found that Bunnings had breached several Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). The breaches related to transparency, collection, and notification. In the Commissioner’s view, FRT was a highly privacy-invasive tool that interfered disproportionately with the privacy of all store entrants, not just the small number of people it was designed to identify.
Bunnings appealed and on 4 February 2026, the Administrative Review Tribunal (ART) partially set aside the determination and upheld the findings that Bunnings breached APP 1 (transparent management of personal information) and APP 5 (notification of collection). It overturned the finding on APP 3 (collection of sensitive information without consent).
The APP 3 decision turned on a specific provision. Under section 16A of the Privacy Act, an organisation can collect sensitive information without consent when obtaining that consent would be unreasonable or impracticable, and when the collection is reasonably necessary to prevent a serious threat to the life, health, or safety of any individual or to public health or safety. The Tribunal accepted that Bunnings faced genuine and serious threats, noting the scale of retail crime, the nature of incidents involving staff and customers, and the fact that many products in a Bunnings store can be used as a weapon. On those facts, the Tribunal found FRT to be a reasonable and proportionate response.
The Privacy Commissioner subsequently confirmed she would not appeal the Tribunal’s decision.
The Tribunal was explicit on that this outcome is not a green light for biometric deployment, but is a fact-specific finding about a specific organisation facing specific threats, with specific controls in place. Other organisations attempting to rely on the same reasoning without equivalent circumstances will likely find the exception does not apply to them.
The Breaches Upheld Tell the More Useful Story
Bunnings succeeded on the consent question but did not succeed on governance, and that distinction matters more for most organisations thinking about where their own exposure sits.
“Milliseconds” Is Not a Defence Against Collection
Bunnings argued that because the facial matching process occurred in RAM and the data was deleted in milliseconds, it had not technically “collected” personal information. The Tribunal rejected this.
The Tribunal found that Bunnings collected facial images captured by CCTV cameras, that those images constituted biometric information, and that biometric information is sensitive information under the Privacy Act, regardless of how briefly it was held. The legal threshold for collection is low. If your system processes personal information, even in real time, even transiently, you have collected it, and privacy obligations follow.
This matters beyond FRT. Any organisation using automated systems that touch personal information, including AI tools processing voice, images, location, or behavioural data, should assume collection is occurring and govern accordingly.
A Sign on the Door Is Not Enough When You Are Taking Someone’s Face
Bunnings had posted privacy notices at store entry points. The Tribunal found this insufficient.
The Tribunal’s reasoning was that given the sensitive nature of biometric data, the size of Bunnings as an organisation, and the resources available to it, more was required. Customers needed to know the specific type of information being collected, the technology being used, the purposes behind collection, and what happened if they chose not to provide it.
Generic privacy policies are written to cover everything. Biometric collection requires notices written to cover that specific thing. When the information being collected is sensitive, specificity is required.
The Absence of a Documented Risk Assessment is Treated as a Governance Failure
This is the finding with the broadest application.
APP 1.2 requires organisations to take reasonable steps to implement practices, procedures, and systems that ensure compliance with the APPs. The Tribunal found that Bunnings failed to meet this standard. The steps taken prior to deployment were described as “random enquiries and actions”. No formal, structured, and documented privacy risk assessment had been conducted before the FRT system went live.
The Tribunal’s language is deliberate. When an organisation collects sensitive information, it faces a serious intrusion of privacy. Serious intrusions require formal responses, not ad hoc ones. A Privacy Impact Assessment (PIA) conducted before deployment, documented, and retained, is what reasonable steps look like in this context.
The compliance lesson here goes beyond privacy. Regulators across multiple domains, including privacy, cybersecurity, and financial services, are increasingly focused on whether organisations can demonstrate that their governance preceded their deployment decisions, not followed them. If the PIA exists only after a complaint is made, it does not count.
The Regulatory Environment Around This Decision Has Changed
The Bunnings case was decided under the existing Privacy Act 1988 framework. That framework is now amended.
The Privacy and Other Legislation Amendment Act 2024 (Cth), which received royal assent in December 2024, introduced changes that take effect progressively through 2026. Three are particularly relevant to organisations using AI or data-intensive technologies.
The definition of personal information now explicitly covers inferred or generated data, such as the outputs of machine learning models. AI generating risk scores, predicted preferences, and behavioural classifications are now personal information for the purposes of the APPs. Organisations that assumed model outputs sat outside the Act’s reach need to revisit that assumption.
From December 2026, organisations must disclose in their privacy policies when personal information is used in substantially automated decision-making that has significant effects on individuals. This requires organisations to audit existing systems now, identify where automated decisions are being made, what professional function they perform, and build disclosure workflows before the obligation takes effect.
A Children’s Online Privacy Code is being developed, with registration expected by December 2026. Organisations whose services are likely to be accessed by minors face heightened obligations and need to begin preparing ahead of the code’s commencement.
A further reform expected in the second tranche of amendments is a general “fair and reasonable” test for the collection, use, and disclosure of personal information. If introduced, this would shift the compliance question from whether a notice is given to whether the underlying practice can withstand objective scrutiny. An AI system that targets individuals based on inferred sensitive characteristics, or that generates unexpected outcomes from opaque models, may fail that test regardless of what the privacy policy says.
What Organisations Should Do Now
The Bunnings case illustrates a familiar pattern. The organisation deployed the technology first and worked out the governance as concerns arose. That sequence creates risk, and the regulatory direction of travel is toward holding organisations accountable for the order in which they do things.
The following steps address the specific failure modes the Tribunal identified.
Conduct a Privacy Impact Assessment before deployment, not after. For any system that collects sensitive information, a formal, structured, and documented PIA is what APP 1.2 compliance looks like. This assessment should identify the risks, document the controls, and record who made the decisions and why, and should exist before the system goes live.
Write specific notices for specific technologies. If your organisation uses FRT, AI-powered monitoring, or any other tool that collects biometric, health, or other sensitive information, the privacy notice for that collection needs to name the technology, describe what is collected, state the purpose, and explain the consequences of not providing the information. Generic notices covering all data collection are not adequate for high-risk processing.
Audit your systems for the amended definition of personal information. AI model outputs, including risk scores, classifications, and generated assessments, now sit within the Act’s scope. Organisations using AI tools that generate outputs about individuals should review how those outputs are managed, retained, disclosed, and corrected.
Map automated decisions and prepare for disclosure. Identify where your organisation uses personal information in automated or substantially automated decision-making with significant effects. Build the workflows and policy language needed to disclose this before December 2026.
Maintain records of AI-assisted decisions. Accountability under the APPs requires being able to demonstrate what decisions were made, on what basis, and with what human oversight. If that record does not exist, accountability cannot be demonstrated.
The Bunnings outcome is sometimes framed as a partial win for business. In a narrow legal sense, that is accurate. On the question of governance, Bunnings did not win and was found to have deployed an invasive technology without adequate transparency, without specific notification, and without a documented risk assessment. Those findings were not overturned.
The compliance clock started the moment the technology was deployed. For organisations considering similar decisions, it starts now.