New guidance explains consent requirements, statutory exceptions and governance expectations The Office of the Australian Information Commissioner (OAIC) has published updated guidance for organisations covered by the Australian Privacy Principles (APPs) that are considering using facial recognition technology (FRT) in high-volume, publicly accessible physical spaces such as retail shopfronts. The revised guidance implements the findings of the Administrative Review Tribunal (ART) in the Bunnings Group Limited matter, which concerned the retailer’s use of facial recognition technology in 62 of its stores between 2018 and 2021. The ART’s findings confirmed that there is a high bar for using facial recognition technology in Australia. In a media release, the OAIC explained that the new guidance makes clear that the Privacy Act neither prohibits nor expressly permits facial recognition technology. Instead, entities must demonstrate that any use complies with the APPs. It confirms that biometric templates and facial images used for automated identification are considered sensitive information and generally attract stronger privacy protections. The OAIC states that entities should adopt a "privacy by design" approach before introducing facial recognition technology. It recommends conducting a privacy impact assessment at the outset of any project to identify, manage and minimise privacy risks, and encourages entities to publish the assessment where possible. Businesses operating facial recognition systems across multiple premises should assess whether each location presents different privacy or security considerations rather than relying on a single blanket assessment. The updated guidance also provides more detailed direction on the lawful collection of biometric information. It says entities must generally obtain an individual's valid consent unless a narrow statutory exception applies. The OAIC emphasises that prominent signage alone will not normally constitute consent, while implied or opt-out consent should rarely be relied upon for the collection of sensitive information. Where businesses seek to rely on an exception