
Protecting Customer Privacy: What the Kmart Ruling Means for All Businesses
When the Office of the Australian Information Commissioner (OAIC) rules that one of the nation’s most beloved retailers has breached its privacy obligations, it’s a warning to businesses across Australia. If a business like Kmart can get privacy compliance wrong, no brand is beyond scrutiny.
Kmart, a trusted name with vast resources and in-house compliance capability, was found to have unlawfully deployed facial recognition technology across 28 stores between 2020 and 2022. The system captured biometric data (which is sensitive information under the Privacy Act 1988 (Cth) (Privacy Act)) from every customer entering the store, as well as some customers at return counters.
The OAIC called it an “indiscriminate” collection of personal information and a “disproportionate interference of privacy”. The orders were blunt: stop the practice, destroy the data, and issue a public apology with an explanation within 30 days.
Kmart has signaled its intention to appeal. However, even if the ruling is overturned, the court of public opinion can be much harder to convince.
A broader trend
Kmart is not the first large, Australian retailer to fall into the crosshairs of the regulator. The OAIC has previously investigated Bunnings and The Good Guys for similar facial recognition practices. Each case adds to a pattern of emerging technologies being tested against existing privacy law, and, so far, the law is holding firm.
For businesses, it’s an indication that regulators are paying close attention to how customer data is collected and used, especially when sensitive information like biometrics is involved.
More than retail
To call this a “retail problem” would not be looking at the full picture. The issues extend far wider and apply to a wide range of industries and sectors. For example:
- Hospitality: Loyalty programs and age-verification tools trialing face scans.
- Financial services: Fraud detection systems processing voiceprints.
- Healthcare and fitness: Wearables capturing continuous biometric data.
- Workplaces: Fingerprint scanners and facial recognition used for security or timekeeping.
The lesson is, if you use technology to capture sensitive information, the same risks apply. Sector or size doesn’t matter.
Due diligence is non-negotiable
Under the Privacy Act, the onus sits squarely with businesses to get it right. Protecting sensitive and personal information isn’t something that can be addressed with a template privacy policy or the assumption that new technology somehow falls outside the law. Regulators expect businesses to be proactive, able to demonstrate, with evidence, that they have carefully assessed risks, implemented safeguards, and are actively monitoring compliance.
This means businesses must go beyond good intentions and take practical, measurable steps. Compliance requires a structured approach that shows you’ve thought through the risks, documented your decisions, and built systems that will stand up to scrutiny.
What does that look like in practice and what actions should you take?
- Assess before you act
Conduct Privacy Impact Assessments before introducing new technology or data processes.
- Minimise collection
Gather only what’s strictly necessary for a defined purpose.
- Stay transparent
Ensure privacy policies are written clearly, are readily available and represent your operation.
- Obtain consent properly
Where the law requires consent, make it explicit, informed, and up-to-date.
- Audit and review
Compliance is ongoing, and regular reviews and updates are essential.
The business implications
While the law sets the minimum standard, customers often expect more. Even where practices technically comply with the minimum requirements of the privacy framework, your clients may lose their trust in your business if your business practices feel invasive or opaque, trust erodes. People increasingly expect to be asked for explicit consent, to be given clear choices, and for businesses to be transparent in how they handle their customer’s personal information.
A breach of your customer’s trust can undo years of brand-building and goodwill overnight and the effects of a breach are long lasting and far reaching.
Reputational damage – Once confidence is lost, it’s extremely difficult to win back. Customers will quickly take their business elsewhere if they feel their personal information isn’t respected.
Partnerships – Beyond customers, suppliers, investors, and insurers now expect clear evidence of robust privacy and compliance practices. Falling short can weaken valuable commercial relationships.
Future-proofing – With privacy law reforms on the horizon, businesses that delay action risk higher compliance costs later, along with greater scrutiny from regulators and the public.
The takeaway
No matter if you’re a national retailer or a growing SME, the same rules apply, and carrying out a due diligence of your privacy framework is the best strategy to protect your business. It promotes brand equity, commercial relationships, and long-term resilience.
At Quest Legal, we help businesses embed privacy compliance into their operations. From stress-testing policies to guiding the roll-out of new technologies, we’ll help you ensure your business is privacy compliant.


