Three years after its investigation commenced, the Office of the Australian Information Commissioner (OAIC) has found that retail giant Kmart Australia Limited (Kmart) breached the Privacy Act 1988 (Cth) (Privacy Act) through its use of facial recognition technology (FRT) in 28 retail stores between June 2020 and July 2022.

This determination marks the OAIC’s second major ruling on the use of FRT in retail settings, following the October 2024 decision against Bunnings (summarised in a previous post here).

Kmart deployed FRT for the purpose of detecting and preventing fraudulent refunds. Images of every customer presenting at in-store returns counters were matched against a historical database of individuals who had previously engaged in refund fraud or theft. If a match was identified, staff members could refuse refunds to those customers.

Kmart’s position

Kmart’s primary defence was its processing of personal information via the FRT system was justified under one of the “permitted general situations” in section 16 of the Privacy Act – namely that it:

  • had reason to suspect that unlawful activity or misconduct of a serious nature relating to its functions or activities (in the form of refund fraud) was taking place; and
  • reasonably believed that its collection, use and disclosure of personal information in connection with the FRT system was “necessary” to take appropriate action in relation to the refund fraud.

Where this exemption applies, the default position under the Privacy Act does not apply and consent is not required for the collection of biometric information.

OAIC’s Key Findings

The Commissioner concluded that Kmart breached the Australian Privacy Principles in the Privacy Act by unlawfully interfering with the privacy of individuals whose personal and sensitive information was collected through the FRT system. In particular:

What’s Next for Kmart?

The OAIC has made declarations that Kmart must:

  • Not repeat or continue the acts and practices that led to the interference with individuals’ privacy (noting that Kmart ceased operating the FRT system in July 2022, at the start of the OAIC investigation);
  • Within 30 days of the determination (by 18 October 2025), publish:
    • an apology on the Kmart website and in relevant stores; and
    • a detailed public statement on the Kmart website explaining its use of FRT, the breach and how individuals may seek further information or lodge complaints, which must remain available for at least 12 months after publication; and
  • Retain all personal and sensitive information obtained or generated through the FRT system for 12 months following publication of the statement. All such information must be destroyed after 12 months and one day.

Final Thoughts

In an accompanying blog post on the use of FRT, Privacy Commissioner Carly Kind has stated that the OAIC’s successive determinations do not amount to an effective ban on the use of FRT in Australia, as the Privacy Act is technology neutral.

Instead, her hope is that the Bunnings and Kmart cases clarify the threshold for reliance on exemptions under the Privacy Act, and emphasise the need for greater transparency and improved consent processes regarding the use of FRT – such measures being “a high bar that must be cleared, and for good reason“.