Privacy & Data · Australia · Biometrics

Facial Recognition and ID Scanners in Australian Venues: What the APPs Actually Require

A venue can sometimes require identity verification, but that does not mean it can automatically collect and retain biometric data however it wants. The Privacy Act sets a much higher bar for sensitive information.

Biometric Information Is Sensitive Information

Under the Privacy Act, biometric information used for automated biometric verification or identification is sensitive information. APP 3 generally requires consent for collection of sensitive information unless a specific exception applies.

The OAIC's July 2026 facial-recognition guidance says businesses using facial recognition in physical commercial spaces must be able to establish a lawful pathway and consider necessity, proportionality, transparency, security and alternatives.

ID Scanning Is Different From Facial Recognition

Scanning a driver's licence creates a digital copy of an identity document. Facial recognition creates biometric information. The legal analysis overlaps in places but is not identical.

The OAIC says an organisation should only scan an ID where doing so is reasonably necessary. If simply sighting the ID is enough, copying it may be excessive. State or territory laws can also impose additional requirements.

Can a Pub or Club Refuse Entry if You Will Not Scan?

There is no universal national rule guaranteeing entry to every venue without complying with a lawful identity or age-verification process. Licensing, gambling, anti-money-laundering and other sector-specific rules can require identity checks.

But a venue cannot use that as a blanket answer to every biometric collection. If the Privacy Act applies and biometric information is being collected, the business must still satisfy APP 3 or a relevant exception.

The Bunnings and Kmart Decisions Changed the Practical Privacy Conversation

The OAIC's updated 2026 guidance reflects the Administrative Review Tribunal's consideration of Bunnings' facial-recognition practices and the Privacy Commissioner's 2025 determination concerning Kmart, which remains under review. These decisions do not create a blanket ban on facial recognition; they reinforce the need for a strong lawful basis, necessity, proportionality and transparency.

What to Ask the Venue

  1. Who is the APP entity and controller?
  2. What exact data is collected?
  3. Is facial recognition being used for identification or verification?
  4. What is the legal basis under APP 3?
  5. How long is the information retained?
  6. Who receives it?
  7. Is there a less intrusive alternative?
  8. How can you make a privacy complaint?

How to Challenge the Use

Keep photographs of signage where appropriate, the privacy policy, booking or entry terms, the venue's response and any evidence showing what the scanner actually collected. Make a complaint to the venue first and then consider an OAIC complaint if the organisation is covered by the Privacy Act and the issue remains unresolved.

What This Means Practically

Sources