Switching analytics on is not an IT decision. In Australia it is a privacy decision, and since February 2026 it is a decision with published regulatory reasoning behind it. Most Melbourne businesses running AI enabled cameras have never written down why they collect what they collect, and that document is now the first thing a regulator asks for.
What changed in 2026
Following the Bunnings decision handed down by the Guidance and Appeals Panel on 4 February 2026, the Office of the Australian Information Commissioner updated its guidance for businesses using facial recognition technology in physical commercial and retail settings. The guidance confirms that facial recognition can be used where its use complies with the Privacy Act 1988 and the Australian Privacy Principles, and it sets out five areas the OAIC expects businesses to consider and document before deployment.
- Accountability and ongoing assurance, including a privacy impact assessment and internal procedures
- A lawful basis for collection
- Transparency and notification
- Accuracy, bias and discrimination
- Data deletion and security, including deletion of records generated by non matches
There is also a dated obligation attached. Businesses are expected to update privacy policies and notices to reference the technology and the information it collects, and to address any automated decision making, by 10 December 2026.
Biometric information sits in a higher category
Biometric templates and biometric information collected by facial recognition are treated as sensitive information under the Privacy Act. Sensitive information attracts heightened requirements: individuals must consent to its collection unless an exception applies, the collection must be reasonably necessary for the organisation’s functions or activities, and it may only be used for the purpose for which it was collected.
That is a materially different standard from ordinary CCTV footage, which may still be personal information if a person is identifiable from it, but does not attract the consent requirement in the same way.
Your CCTV sign is not a facial recognition notice
The OAIC has been explicit that a general reference to video surveillance or CCTV is not sufficient. Notices must specifically and positively identify that facial recognition is in use and state the purpose. Notification also has to be given before collection, tailored to the premises and timed so that a person can actually see it before they walk through the door.
This is the failure we find most often during commercial assessments. The technology has moved on and the sign at the entrance has not been touched since the system was installed.
The compliance sweep raises the stakes
In early 2026 the OAIC opened a compliance sweep reviewing the privacy policies of around sixty businesses across sectors where personal information is commonly collected in person, focused on whether policies contain what Australian Privacy Principle 1.4 requires. The regulator has pointed to enforcement options including infringement notices with penalties up to $66,000 for certain breaches.
Being outside the sample is not much comfort. The sweep signals that documentation and practice are being compared against each other, which is a very different exercise from checking whether a policy exists.
Victoria adds a second layer for staff
The Surveillance Devices Act 1999 applies on top of the federal framework. In Victoria it is an offence to install or use a surveillance device to monitor the private activity of an employee without consent, and surveillance in private areas of a workplace such as bathrooms and change rooms is prohibited outright. Employee monitoring involving biometric identifiers pushes the data into sensitive information territory and brings consent and heightened safeguards with it.
Where the line actually sits for most sites
The important distinction is between detection and identification. Analytics that classify a person, a vehicle, a loitering event or a line crossing do not identify anyone. Facial recognition that matches a face against a stored template does. The overwhelming majority of Melbourne commercial and industrial sites get everything they need from the first category and take on none of the obligations of the second.
If a provider is selling you facial recognition for a warehouse yard or a loading dock, ask what operational question it answers that person detection does not. Usually there is not one.
A pre-deployment checklist
- Write down the specific purpose each analytic serves and the incident it is meant to prevent
- Complete a privacy impact assessment where identification technology is involved
- Rewrite entrance and staff signage to name the technology in use, not just CCTV
- Confirm retention periods and set automatic deletion, including for non matches
- Document who can access footage, how access is logged, and how requests are handled
- Update the privacy policy for automated decision making ahead of 10 December 2026
- Check any staff facing coverage against the Victorian restrictions before it goes live
Frequently asked questions
Do I need consent to run CCTV in my Melbourne business?
Ordinary CCTV generally requires a reasonable purpose, appropriate notice and secure handling rather than express consent. Facial recognition is different because biometric information is sensitive information, which brings a consent requirement unless an exception applies.
How long should we keep footage?
Long enough to serve the purpose you documented and no longer. For most retail and hospitality sites that is a matter of weeks rather than days, because incidents are frequently reported late.
Is this legal advice?
No. This is a practical summary for property and facility managers. Where facial recognition or staff monitoring is involved, get advice on your specific deployment before it goes live.
Get your system assessed against current obligations
Forever Secure runs security assessments that cover coverage, retention and documentation together. Call 1300 232 152. Licence 969-120-00S.
Not sure what your property actually needs?
A licensed member of our team will walk the site, map the real risk points and give you a right-sized recommendation. Free, and no obligation.