Three years after its investigation commenced, the Office of the Australian Information Commissioner (OAIC) has found that retail giant Kmart Australia Limited (Kmart) breached the Privacy Act 1988 (Cth) (Privacy Act) through its use of facial recognition technology (FRT) in 28 retail stores between June 2020 and July 2022.
This determination marks the OAIC’s second major ruling on the use of FRT in retail settings, following the October 2024 decision against Bunnings (summarised in a previous post here).
Kmart deployed FRT for the purpose of detecting and preventing fraudulent refunds. Images of every customer presenting at in-store returns counters were matched against a historical database of individuals who had previously engaged in refund fraud or theft. If a match was identified, staff members could refuse refunds to those customers.
Kmart’s position
Kmart’s primary defence was its processing of personal information via the FRT system was justified under one of the “permitted general situations” in section 16 of the Privacy Act – namely that it:
- had reason to suspect that unlawful activity or misconduct of a serious nature relating to its functions or activities (in the form of refund fraud) was taking place; and
- reasonably believed that its collection, use and disclosure of personal information in connection with the FRT system was “necessary” to take appropriate action in relation to the refund fraud.
Where this exemption applies, the default position under the Privacy Act does not apply and consent is not required for the collection of biometric information.
OAIC’s Key Findings
The Commissioner concluded that Kmart breached the Australian Privacy Principles in the Privacy Act by unlawfully interfering with the privacy of individuals whose personal and sensitive information was collected through the FRT system. In particular:
- Lack of consent: Kmart incorrectly applied the “permitted general situation” exemption upon which it relied. Accordingly, consent was required for collection of sensitive biometric information and Kmart failed to obtain such consent. Whilst acknowledging the conveniences and benefits associated with using an FRT system, the Commissioner found that the FRT system’s utility to prevent fraud was limited (given the comparatively low value of fraudulent returns in comparison to the size of Kmart’s operations and profits), and that less privacy-intrusive alternatives were available (such as the relocating the Returns Counter so that customers would not need to enter the store to obtain a refund, or using radio frequency identification tags).
- Failure to notify: Kmart did not adequately notify individuals about the collection and use of their personal information via the FRT system. Kmart displayed a “Conditions of Entry Notice” stating that FRT was used as part of its 24-hour CCTV coverage, as well as a “Privacy Poster” at certain entry points, and made a privacy policy available on its website. However, the Commissioner did not consider these measures adequately notified individuals of certain required information -namely the facts and circumstances of the collection, the purposes of the collection, the consequences for the individual if their personal information was not collected, and information about how requests for access and correction may be submitted.
- Incomplete privacy policy: Three iterations of Kmart’s privacy policy were in force during the FRT system’s period of operation. None of them were found to be sufficiently transparent about Kmart’s use of the FRT system to collect personal information, including sensitive biometric information. According to the Commissioner, the policies failed to articulate, “even in generic terms”, that collection of facial images via the FRT system involved the generation of additional metadata.
What’s Next for Kmart?
The OAIC has made declarations that Kmart must:
- Not repeat or continue the acts and practices that led to the interference with individuals’ privacy (noting that Kmart ceased operating the FRT system in July 2022, at the start of the OAIC investigation);
- Within 30 days of the determination (by 18 October 2025), publish:
- an apology on the Kmart website and in relevant stores; and
- a detailed public statement on the Kmart website explaining its use of FRT, the breach and how individuals may seek further information or lodge complaints, which must remain available for at least 12 months after publication; and
- Retain all personal and sensitive information obtained or generated through the FRT system for 12 months following publication of the statement. All such information must be destroyed after 12 months and one day.
Final Thoughts
In an accompanying blog post on the use of FRT, Privacy Commissioner Carly Kind has stated that the OAIC’s successive determinations do not amount to an effective ban on the use of FRT in Australia, as the Privacy Act is technology neutral.
Instead, her hope is that the Bunnings and Kmart cases clarify the threshold for reliance on exemptions under the Privacy Act, and emphasise the need for greater transparency and improved consent processes regarding the use of FRT – such measures being “a high bar that must be cleared, and for good reason“.