
Loss Prevention
Part of In-store customer analytics
Reviewing privacy implications of store sensors in Australia
Trace what store sensors capture, retain and share. Check Australian privacy coverage, notice, de-identification and facial-recognition risks.
Before deploying or expanding an in-store sensor, trace its data flow, assess whether people could be identified, check applicable Australian privacy obligations, then document the decision. The Office of the Australian Information Commissioner (OAIC) is Australia’s independent national privacy regulator and publishes guidance on the Australian Privacy Principles. A door count, a persistent path and facial identification each present different identification risks.
Start with purpose and data flow
State the store question and why each field is needed to answer it. For each device and connected system, trace what is captured, processed, transmitted, accessed, used, disclosed and retained, including which parties hold or control each record.
- raw inputs, including any images, audio, device identifiers or location traces;
- temporary or persistent identifiers created from those inputs;
- data sent to the supplier, other processors and the retailer;
- access to raw and derived records, including support access;
- retention and deletion for each copy.
Ask for the proposed configuration. Processing an image on a device and exporting only counts may reduce exposure, but capture, temporary storage and support access still need checking. An aggregate dashboard does not establish that underlying records are de-identified.
Check Australian obligations
The Privacy Act 1988 (Cth) covers Australian Government agencies, organisations with an annual turnover of more than $3 million, and some other organisations. Most small businesses fall outside the Act, but check whether the retailer is covered rather than relying on turnover alone. The OAIC publishes guidance for organisations subject to the Act.
For an APP-covered retailer, APP 3 permits collection of personal information only where it is reasonably necessary for the organisation’s functions or activities. Collection must be by lawful and fair means and from the individual, unless an exception applies; collecting sensitive information also requires consent unless an exception applies.
Under APP 5, take reasonable steps to notify people of the collecting entity’s identity and contact details, the circumstances and purposes of collection, and whether collection is required or authorised by law. Notice must also cover consequences of not collecting the information, usual disclosures, the APP Privacy Policy and, where practicable, overseas recipients and their countries; provide it at or before collection, or as soon as practicable afterwards if earlier notice is not practicable.
APP 11 requires reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. When information is no longer needed for a purpose permitted under the APPs, take reasonable steps to destroy or de-identify it, unless an Australian law or court or tribunal order requires retention, or it is part of a Commonwealth record.
State and territory surveillance and monitoring laws also cover surveillance devices. The OAIC advises contacting the Attorney-General’s Department in the relevant state or territory for more information; check the requirements for the store’s location.
If sensor-derived personal information is accessed or disclosed in a way likely to result in serious harm, assess promptly whether it is an eligible data breach. If it is, notify the OAIC and affected individuals under the Notifiable Data Breaches scheme.
Australian Privacy Principle (APP) requirements for sensor use
- APP 3: Collection necessityPersonal information must be reasonably necessary for the organisation’s functions.
- APP 5: Notification obligationMust inform individuals about the purpose, identity of the collector, and disclosure practices at or before collection.
- APP 11: Security requirementMust protect personal information from misuse, interference, loss, and unauthorised access.
Assess facial identification separately
Removing a name is not necessarily enough to de-identify information. Assess whether someone is reasonably identifiable in the relevant access environment, including from information available to the retailer and supplier; an aggregate dashboard alone does not settle that question. The OAIC’s De-identification and the Privacy Act guidance can inform this assessment.
A camera used to count people is not automatically a facial-recognition system. If a feature creates or compares biometric information, such as a template, to identify people, treat it as sensitive information: APP 3 requires consent for its collection unless an exception applies.
Use the OAIC’s Facial recognition technology: a guide to assessing the privacy risks when reviewing a proposed feature. Assess necessity, lawful collection, notification, accuracy and security on the facts of the proposed use; do not assume ordinary camera-surveillance awareness is consent to collect sensitive information.
Record the decision
Document the purpose, data flow, fields, alternatives, applicable obligations, notice, access, supplier responsibilities, retention rationale and safeguards. The OAIC’s Guide to undertaking privacy impact assessments can help structure the review.
Revisit the assessment after an integration, software change or layout change alters collection or linking. If the data flow or legal basis for an identity-linking feature is unclear, hold that feature while it is resolved and assess a narrower count on its own terms.


