

Australian retailer Kmart has been found to have violated privacy laws through its use of facial recognition technology, the Privacy Commissioner has ruled.

Privacy Commissioner Carly Kind determined that Kmart collected personal and sensitive information from customers over a two-year period under the pretext of identifying individuals committing refund fraud. The technology was deployed in 28 stores nationwide.
However, Kmart failed to adequately inform shoppers about the use of facial recognition or obtain their consent, constituting a breach of the Privacy Act. Kmart had argued that consent was not required due to an exemption for tackling unlawful activity, but Commissioner Kind rejected this claim.
Kind noted that the system collected sensitive biometric data indiscriminately, including from thousands of customers not suspected of retail fraud, making it a disproportionate interference with privacy. She added that less intrusive methods were available to address refund fraud and that the privacy impact outweighed any potential benefits of the technology.
The ruling concludes a three-year investigation, with Kmart cooperating throughout the process.
Kmart expressed disappointment at the finding, stating that the trial of facial recognition was limited in scope, aimed at preventing theft and anti-social behavior, and that customer privacy measures were implemented. A spokesperson said only images matching persons of interest were retained, with all other data deleted, and no information was used for marketing.

