Australian EnterpriseAI Index
Back to incident database
MediumRetail1 November 2022

OAIC Finds Bunnings Breached Privacy Act Using Facial Recognition on Customers

Bunnings Group

What happened

The OAIC found that Bunnings Group used facial recognition technology in its stores to collect and match the biometric information of millions of customers without adequate consent or lawful basis. The system was operated from November 2018 to November 2021.

Root cause

Biometric data collection deployed without privacy impact assessment, without establishing a lawful basis under APP 3, and without any consent mechanism.

Architectural failure

No privacy-by-design review before deploying biometric collection system; no data minimisation; no consent architecture; no retention limits.

Outcome

OAIC determination: Bunnings breached Australian Privacy Act. Required to destroy all collected biometric templates. Landmark ruling on facial recognition in retail.

Architectural Failure Patterns

These pattern categories on aipatterns.com.au describe the systemic failure modes this incident exhibited.

Cite this incident

https://corporateai.com.au/incidents/bunnings-facial-recognition-oaic-2024

Quick facts

Date
1 November 2022
Organisation
Bunnings Group
Sector
Retail
Severity
Medium
Regulatory bodies
Privacy ActAustralian Privacy Principles
Tags
facial-recognitionbiometricsretailoaicprivacy-actconsentaustralia

Explore failure patterns

aipatterns.com.au