OAIC Finds Bunnings Breached Privacy Act Using Facial Recognition on Customers
Bunnings Group
What happened
The OAIC found that Bunnings Group used facial recognition technology in its stores to collect and match the biometric information of millions of customers without adequate consent or lawful basis. The system was operated from November 2018 to November 2021.
Root cause
Biometric data collection deployed without privacy impact assessment, without establishing a lawful basis under APP 3, and without any consent mechanism.
Architectural failure
No privacy-by-design review before deploying biometric collection system; no data minimisation; no consent architecture; no retention limits.
Outcome
OAIC determination: Bunnings breached Australian Privacy Act. Required to destroy all collected biometric templates. Landmark ruling on facial recognition in retail.
Architectural Failure Patterns
These pattern categories on aipatterns.com.au describe the systemic failure modes this incident exhibited.
Cite this incident
https://corporateai.com.au/incidents/bunnings-facial-recognition-oaic-2024Quick facts
- Date
- 1 November 2022
- Organisation
- Bunnings Group
- Sector
- Retail
- Severity
- Medium
- Regulatory bodies
- Privacy ActAustralian Privacy Principles
- Tags
- facial-recognitionbiometricsretailoaicprivacy-actconsentaustralia
Explore failure patterns
aipatterns.com.au