Lander & Rogers logo
1 Insights

Facial recognition technology: OAIC updates privacy guidance for retail and public settings

Facial recognition technology: OAIC updates privacy guidance for retail and public settings

The Office of the Australian Information Commissioner (OAIC) has published updated guidance for organisations considering using facial recognition technology (FRT) in retail and other public settings. The guidance makes clear that:

  • FRT involves the collection of biometric information, which is "sensitive information" under the Privacy Act 1998 (Cth) (Privacy Act) and therefore attracts a higher level of privacy protection;
  • Organisations should only use FRT in limited circumstances and each proposed deployment must be assessed on its own facts against the requirements of the Australian Privacy Principles (APPs); and
  • Where FRT is used, organisations must satisfy a range of specific obligations relating to governance, lawful collection, transparency, accuracy and data security.

Key takeaways

The OAIC's updated guidance sends a clear signal - FRT should only be deployed in limited, carefully justified circumstances. Organisations considering its use should not assume that convenience or a generalised security rationale will be sufficient. The guidance also reinforces that the question of whether use of FRT is appropriate and permitted by the Privacy Act should be considered closely on a case-by-case basis (including, in retail settings, on a store-by-store basis).

Where an organisation uses FRT, it must be able to demonstrate, through a documented Privacy Impact Assessment (PIA), a clear lawful basis, specific and timely notification, and robust accuracy and security controls. It must be also able to demonstrate that FRT is necessary, proportionate and compliant with the APPs at every stage.

APP 1: Privacy by design - conducting a Privacy Impact Assessment

Before implementing FRT, organisations should conduct a PIA to identify and address potential privacy impacts, consistent with their accountability obligations under APP 1. The OAIC has identified 10 steps that should be considered when undertaking a PIA, set out in its PIA guide. It strongly recommends that organisations publish their PIA report to demonstrate that the deployment has undergone genuine privacy scrutiny.

Where FRT is proposed to be used across multiple premises, a single risk assessment may be appropriate, but only where the premises are genuinely comparable. Organisations should document how the relevant set of sites were chosen and consider whether any location has distinguishing features (such as differing threat profiles or physical layouts) that warrant separate consideration.

APP 3: Lawful basis for collection

Collecting sensitive information via FRT will require the individual's consent, unless an exception applies. Consent must be informed, voluntary, current, specific and given by an individual who has capacity. Given the practical difficulty of obtaining meaningful, informed consent from every person entering a publicly accessible space (including, for example, children and individuals from non-English speaking backgrounds), the consent pathway is likely to only be available where an organisation can engage with all individuals before they attend the relevant premises (for example, via a booking or membership system). Use of signage which advises that FRT is in use will rarely be sufficient to establish valid consent to the collection of sensitive information, and the OAIC considers that implied consent (including opt-out models) should generally not be relied on.

Where consent cannot be obtained, organisations must only collect sensitive information if an exception applies. The most relevant exceptions for a retail or commercial setting are:

The authorised by law pathway, which applies only where the law explicitly requires or authorises the specific collection involved in FRT (for example, in South Australia, legislation requires certain gaming venues to use FRT for exclusion purposes); and

The permitted general situation pathway, most commonly where either:

  1. serious threat: it is unreasonable or impracticable to obtain an individual's consent, and the organisation reasonably considers the collection of FRT data is necessary to lessen or prevent a serious threat to the life, health or safety of any individual, or to public health or safety; or
  2. unlawful activity: there is reason for the organisation to suspect that unlawful activity, or misconduct of a serious nature that relates to the organisation's activities has been, is being or may be engaged in, and the organisation reasonably believes the collection of FRT data is necessary for it to take appropriate action in relation to the matter.

To rely on the permitted general situations, an organisation must reasonably believe that collection via FRT is necessary, having regard to:

  • Suitability - whether the specific FRT system will actually be effective in addressing the relevant threat or conduct;
  • Alternatives - whether there are less privacy-intrusive methods (such as CCTV, security personnel or workplace protection orders) that could practically and effectively achieve the same outcome; and
  • Proportionality - whether the privacy impact on individuals is outweighed by the benefit gained, having regard to the severity of the threat or conduct being addressed.

Organisations should have processes in place to assess the suitability, alternatives and proportionality on an ongoing basis. For example, if better alternative methods become available over time, or data shows that the system is not effective in addressing the underlying threat or unlawful activity, it may no longer be necessary to use FRT.

APP 5: Transparency and notification

Organisations must take reasonable steps to notify or otherwise ensure the awareness of every individual whose face is captured by an FRT system, including non-matches, of the matters referred to in APP 5. The OAIC states that a general reference to "video surveillance" or CCTV is not sufficient, and notices must specifically and positively identify that FRT is in use and for what purpose. Notification should occur at or before the point of collection, and organisations should consider how this can be achieved having regard to the layout of the relevant premises (for example, signage at each entry point).

APP 10 & 11: Accuracy, bias and security

Organisations must take reasonable steps to ensure the biometric information used in FRT is accurate, including through pre and post deployment testing and human verification of matches, and must actively manage the risk that the system produces biased or discriminatory outcomes across demographic groups. This will require ongoing testing and assessment, rather than a "one-off" testing process at the time of deployment.

Organisations must also take reasonable steps to secure any personal information collected and must delete or de-identify it once it is no longer needed. In practice, this generally means immediate deletion of biometric information and templates when no match is made.

Further guidance

For specific guidance on your organisation's obligations when considering or using FRT, please contact our Digital Economy team.

All information on this site is of a general nature only and is not intended to be relied upon as, nor to be a substitute for, specific legal professional advice. No responsibility for the loss occasioned to any person acting on or refraining from action as a result of any material published can be accepted.