
Self-service Devices
Retail kiosks and self-service devices
Plan a retail kiosk around a shopper task, then check access, store data, payments, assistance and ongoing operation.
A retail kiosk works best when it helps a shopper finish a defined task, understand the outcome and get help if something goes wrong. Define that task before choosing a screen, scanner or payment device. Product lookup, ordering and payment carry different data, staffing and security needs.
Define the task and its finish point
Write the shopper’s question in plain language: Where is this item, can I order it, and has my payment gone through? Specify what a useful answer looks like.
A product lookup might end with an aisle and a qualified stock indication. An order needs a reference the store can retrieve. A payment task needs a clear transaction outcome for the shopper and the store.
Include every staff handoff in the service design. A screen cannot make an uncertain stock record accurate or complete an action with no assigned owner.
Choose components around the task
A kiosk may include a display, enclosure, scanner, printer, network connection and software linked to store systems. Specify each component only where the task needs it.
A lookup device may need a scanner but no printer. A payment kiosk also needs a payment terminal, plus arrangements for its security and support.
The PCI Security Standards Council’s point-of-interaction standard includes unattended payment terminals. Identify the system that supplies each answer. Decide what the screen should show when stock is unavailable, a price changes or a connection fails.
Check payment-device assurance
The PCI Security Standards Council’s PTS Point of Interaction (POI) Standard covers device characteristics and management intended to protect payment-card PINs, account data and other sensitive payment-card data. Its categories include unattended payment terminals, PIN entry devices, non-PIN acceptance devices evaluated for account-data protection and secure card readers.
For device selection, the Council encourages merchants and their acquirers to use its listing of approved PTS POI devices. Independent PCI-recognised laboratories evaluate devices against the standard’s security requirements; the Council then reviews the reports and approves devices for its listing. Questions about which entities must validate compliance, or whether a listed product is required, should go to the payment brands.
Assess access in the store
The Australian Human Rights Commission has published Guidelines on equal access to digital goods and services. Assess the interface and its physical setting: approach space, reach, viewing angle, glare, readable instructions and a usable way to request help. Test with people who have relevant access needs.
Where a session includes personal details, check what remains visible to the next shopper and how the session ends. If the kiosk collects personal information, assess applicable Australian Privacy Principles, including collection notice and security obligations. Their application depends on the organisation and the information involved.
For a kiosk that collects personal information, APP 5 notification matters include the collecting organisation’s identity and contact details, why and in what circumstances information is collected, and whether collection is required or authorised by law. They also include consequences of not collecting it, usual disclosures, information about the organisation’s privacy policy and, where practicable, overseas recipients and their countries.
An APP entity must take reasonable steps to notify people of these matters before or when collection occurs, or ensure they are aware of them. If that is not practicable, it must do so as soon as practicable afterwards. The requirement applies to personal information collected directly from a person or from a third party.
The notice approach depends on the circumstances. The OAIC identifies the information’s sensitivity, possible adverse consequences for the person and any special needs as relevant considerations; more rigorous steps may be needed where sensitivity or risk is greater, or a person may not readily understand the notice.
APP 11 requires an APP entity holding personal information to take reasonable steps to protect it from misuse, interference, loss, and unauthorised access, modification or disclosure. Reasonable steps include technical and organisational measures, so planning needs to account for how the kiosk and the organisation handle the information.
When personal information is no longer needed for a purpose permitted under the APPs, reasonable steps must be taken to destroy it or ensure it is de-identified. This does not apply where it is part of a Commonwealth record or must be retained under Australian law or a court or tribunal order.
Key Compliance and Operational Metrics for Retail Kiosks
- PCI-PTS Approved DevicesRequired for unattended payment terminals to protect card data
- Accessibility GuidelinesAustralian Human Rights Commission’s Guidelines on Equal Access to Digital Goods and Services
- ACCC OversightRegulatory scrutiny of major retailers like Woolies and Coles on self-service technology use
Plan operation and trial
Give staff a clear way to recognise a failed session, help a shopper, stop use of a faulty device and request repair. Assign responsibility for updates, cleaning, consumables, payment-terminal inspection and fault reporting.
Trial the task in the intended store with ordinary cases and exceptions, including unavailable stock, mistaken input, interrupted service and requests for assistance. Record completion, abandonment, help requests and failure reasons. Expand only after the store can support the service shown to shoppers.
In this guide
- Choosing a kiosk task shoppers can complete independentlySelect a kiosk task by checking its answer, dependencies, accessibility, exceptions and the shopper’s finish point.
- Testing kiosk usability before installationTest realistic kiosk tasks, access needs, errors and the proposed shop-floor setting before fixing the device in place.
- Planning assistance when a kiosk failsGive shoppers a clear next step and staff a safe handoff for kiosk faults, uncertain results and payment interruptions.
- Reviewing kiosk access and maintenance controlsCheck the public session, staff access, payment terminal and upkeep responsibilities for a retail kiosk.



