
Self-service Devices
Part of Retail kiosks and self-service devices
Reviewing kiosk access and maintenance controls
Check the public session, staff access, payment terminal and upkeep responsibilities for a retail kiosk.
Treat a retail kiosk as a public device with private administration. Shoppers should reach the intended task; authorised staff need controlled access to inspect, update and restore it. Before installation, identify the owner of the kiosk, its software, any payment terminal and every route into its settings.
Check the public session boundary
Try to leave the intended task through home controls, browser menus, downloads, print dialogue boxes, error screens, keyboard shortcuts and restart. Check whether one shopper can see the previous shopper’s information, including printed output. An idle timer alone does not prove that every application record is cleared.
If the kiosk collects personal information, assess collection notice, security and retention under the Australian Privacy Principles where they apply to the organisation.
Microsoft documents Assigned Access for a restricted kiosk experience and recommends a low-privilege account on public devices. Microsoft Edge kiosk mode lists 'Reset on inactivity' as a supported feature.
Key Compliance and Security Metrics
- APPLY - Public Session Boundary Check
- Test for escape via keyboard shortcuts, browser menus, print dialogs, error screens
- APPLY - Data Clearing on Inactivity
- Idle timer alone is insufficient; verify application data is cleared
- APPLY - Personal Information Collection Notice
- Required under Australian Privacy Principle 1 (APP 1)
- APPLY - Security of Personal Information
- Required under APP 11 (Security of Personal Information)
- APPLY - Payment Terminal Compliance
- Must meet PCI PTS POI standard for unattended terminals
Pros and Cons of Assigned Access vs. Full Admin Access
- Pros of Assigned Access (Low-Privilege Account)Reduces risk of accidental or malicious changes; aligns with Microsoft recommendations for kiosk devices
- Cons of Assigned AccessMay limit diagnostic capabilities for staff; requires careful configuration to avoid lockout
- Pros of Full Admin AccessAllows full system control for troubleshooting and updates
- Cons of Full Admin AccessIncreases risk of data exposure, misconfiguration and unauthorised changes
Control service access
List staff and suppliers who may unlock the enclosure, change settings, install software or provide remote support. Define how access is granted, recorded and removed. Keep public and maintenance access separate, and check whether servicing the device could expose customer records in the shop.
If the kiosk accepts cards, review the payment terminal separately. The PCI Security Standards Council includes unattended payment terminals in its Point of Interaction standard. Its merchant guidance recommends keeping a list of payment terminals, checking them for tampering and allowing repairs only by authorised repair personnel. According to the standards body, questions about which entities need to validate compliance should be referred to the payment brands.
Make upkeep visible
Assign an owner and schedule for screen and scanner checks, consumables, software updates, payment-terminal inspection and recovery after an outage. Microsoft recommends configuring kiosk devices so they are always up to date without disrupting the user experience; for other platforms, ask the supplier to show how updates and restarts are managed.
A maintenance record can identify the device, software version, last check, fault, action, owner and outcome. Retain access logs and customer information under the retailer's approved policy.



