Bunnings Won. That Is Not the Same as a Green Light.
Coles and Woolworths are testing facial recognition technology in Australian stores. The Guardian reported this week that both confirmed the pilots and are considering broader rollout. The stated justification is protecting staff from aggression, and the timing is not an accident. In February the Administrative Review Tribunal handed Bunnings a win that the retail sector read as clearance.
Retail workers face real violence, and the problem has worsened. No serious person disputes that. What deserves dispute is whether the executives approving these pilots have read the Bunnings decision or only the headline about it, because the decision is considerably narrower than the coverage suggested — and the parts Bunnings lost are the parts most pilots will fail.
What Bunnings Actually Won
On 4 February 2026 the Tribunal set aside the central finding in the Privacy Commissioner’s 2024 determination. It held that Bunnings was entitled to rely on an exemption to the consent requirement for the limited purpose of combating retail crime and protecting staff and customers from violence, abuse and intimidation. That is a real loss for the regulator, and the Commissioner has not appealed it.
Two things about that ruling matter more than the result.
First, Bunnings still lost on transparency. The Tribunal affirmed the Commissioner’s findings that Bunnings contravened APP 1 and APP 5 — open and transparent management of personal information, and notification of collection. Signage, customer notification, the explanation of how deletion works, the privacy policy itself: all found wanting. The company that won the proportionality argument still failed the disclosure obligations, and those obligations are the cheapest part of the whole exercise to get right.
Second, the reasoning was welded to how the system was actually built. Faces that produced no match were deleted in roughly four milliseconds. The enrolled watchlist numbered in the hundreds, not the millions. The deployment covered 62 stores in New South Wales and Victoria between 2019 and 2021, with a correspondingly limited breach surface. The Tribunal was not asked to bless facial recognition in retail. It was asked whether this configuration, for this purpose, cleared the bar. The Commissioner’s guidance since has been explicit that the outcome turns on the specific facts and circumstances of Bunnings’ use.
Proportionality Attaches to the Deployment
This is where boards are most likely to go wrong. Nobody decided that it is lawful for a retailer to use facial recognition. What was decided is that a system with a narrow purpose, a bounded watchlist and near-instant deletion of non-matches can satisfy the test. Change any of those variables and you have left the facts that produced the result.
So the question for management is whether your deployment carries the properties the Tribunal relied on, and whether you can evidence them.
What is the retention period for a non-match, measured rather than quoted from the vendor’s datasheet? Is deletion happening at the edge, or after the image has travelled to a central store? How large is the enrolled list, who approves an addition, and against what evidentiary standard? Is the stated purpose still confined to serious offending, or has it widened to take in low-value theft, loitering, and customers who have made complaints? Purpose creep is what turns a defensible system indefensible, and it almost never arrives as a decision. It arrives as a request from operations that nobody thought needed governance.
Australian privacy law still requires that collection be reasonably necessary, and biometric data still sits in its own category of sensitivity. A password can be changed and a card cancelled. Facial geometry cannot, which makes a biometric database breach permanent in a way that almost no other breach is. None of that changed in February. What changed is that the sector now has one worked example of a configuration that survived scrutiny, and a strong commercial incentive to claim a resemblance to it.
What the Vendor Didn’t Put in the Pitch Deck
We have seen this sales cycle, and the deck has a new slide on it now. The vendor will cite Bunnings. The correct response is to ask them to demonstrate, in writing, that the system they are selling has the same properties as the system that was assessed.
What still does not appear in the deck is the retention schedule, the access control model, the breach notification obligation for biometric data, or the class action scenario. These are the questions a CISO with board access should be putting on the table before the pilot is approved — not after the infrastructure is embedded in 200 stores.
The custody question deserves particular attention. Is the data held centrally or by the vendor? What contractual rights does the retailer retain if the vendor relationship ends or the vendor is acquired? Vendor acquisitions in the security technology space happen regularly, and data processed on behalf of a client frequently becomes an asset in those transactions.
The access control question is equally pointed. Who inside the organisation can query the system? Is there an audit log, and does anyone read it? What prevents an employee checking whether a former partner visits a particular store? Biometric surveillance infrastructure creates insider threat vectors that most retail IT environments were never designed to manage.
‘Pilot’ Is Not a Governance Category
The normalisation dynamic is predictable. A pilot is approved below board visibility. It runs without reported incident. It becomes operationally embedded. The cost of removing it grows. By the time it reaches the board, it is presented as existing infrastructure rather than a live decision, and the governance question becomes retrospective.
Treat pilots as permanent deployments from day one, because that is what they statistically become. The privacy obligations and the reputational exposure attach from the moment the first face is processed.
The regulatory floor is also still moving. The first tranche of Privacy Act reform passed in December 2024 and is commencing progressively. The second tranche — which carries the proposals that would matter most here, including a fair and reasonable test and revised definitions of consent and personal information — remains a government commitment rather than law. The Attorney-General confirmed in February that it is being progressed; there is no bill and no commencement date. A system designed to the current floor may be assessed against a higher one, and facial recognition in retail is on the Commissioner’s stated list of regulatory priorities. The February decision resolved a dispute about 2019 to 2021. It did not settle the law for 2028.
What Boards Should Do
“Is this technology effective?” was the old question and “is this lawful?” is no longer the interesting one. The question worth putting to management is narrower: which parts of the Bunnings configuration do we replicate, which do we not, and where is that written down?
If nobody can answer on the spot, the pilot waits. The staff safety objective is legitimate and the technology may well advance it, and a tribunal has now accepted that it can be deployed lawfully. None of that amounts to having done the work — and the Commissioner’s own research puts public tolerance for biometric collection in retail in the single digits, which is the number your brand team should probably see before the pilot does.
Bunnings won the argument it was best placed to win and lost on the obligations it could most cheaply have met. Copy that second part.