A venue can sometimes require identity verification, but that does not mean it can automatically collect and retain biometric data however it wants. The Privacy Act sets a much higher bar for sensitive information.
Biometric Information Is Sensitive Information
Under the Privacy Act, biometric information used for automated biometric verification or identification is sensitive information. APP 3 generally requires consent for collection of sensitive information unless a specific exception applies.
The OAIC's July 2026 facial-recognition guidance says businesses using facial recognition in physical commercial spaces must be able to establish a lawful pathway and consider necessity, proportionality, transparency, security and alternatives.
ID Scanning Is Different From Facial Recognition
Scanning a driver's licence creates a digital copy of an identity document. Facial recognition creates biometric information. The legal analysis overlaps in places but is not identical.
The OAIC says an organisation should only scan an ID where doing so is reasonably necessary. If simply sighting the ID is enough, copying it may be excessive. State or territory laws can also impose additional requirements.
Can a Pub or Club Refuse Entry if You Will Not Scan?
There is no universal national rule guaranteeing entry to every venue without complying with a lawful identity or age-verification process. Licensing, gambling, anti-money-laundering and other sector-specific rules can require identity checks.
But a venue cannot use that as a blanket answer to every biometric collection. If the Privacy Act applies and biometric information is being collected, the business must still satisfy APP 3 or a relevant exception.
The Bunnings and Kmart Decisions Changed the Practical Privacy Conversation
The OAIC's updated 2026 guidance reflects the Administrative Review Tribunal's consideration of Bunnings' facial-recognition practices and the Privacy Commissioner's 2025 determination concerning Kmart, which remains under review. These decisions do not create a blanket ban on facial recognition; they reinforce the need for a strong lawful basis, necessity, proportionality and transparency.
What to Ask the Venue
- Who is the APP entity and controller?
- What exact data is collected?
- Is facial recognition being used for identification or verification?
- What is the legal basis under APP 3?
- How long is the information retained?
- Who receives it?
- Is there a less intrusive alternative?
- How can you make a privacy complaint?
How to Challenge the Use
Keep photographs of signage where appropriate, the privacy policy, booking or entry terms, the venue's response and any evidence showing what the scanner actually collected. Make a complaint to the venue first and then consider an OAIC complaint if the organisation is covered by the Privacy Act and the issue remains unresolved.
What This Means Practically
- Biometric identification is sensitive information.
- Consent is generally required unless a defined exception applies.
- ID scanning is not identical to facial recognition.
- There is no universal right to enter every venue without any ID check.
- Ask for necessity, retention, security and alternative-process information.
Sources
- OAIC — Facial recognition technology: guide to assessing privacy risks, updated 29 July 2026. oaic.gov.au
- OAIC — ID scanning guidance. oaic.gov.au
- OAIC — Biometric scanning. oaic.gov.au
- OAIC — APP 3 guidance, updated 13 May 2026. oaic.gov.au