§72 · Lane 7 — Australian Regulatory Primary Instruments
OAIC Facial Recognition Privacy Guide the biometric limb of the Australian privacy regulator's AI guidance
OAIC (2024, updated 2026) · OAIC FRT Guidance
Bibliographic data
- Title
- OAIC Guidance — Facial recognition technology: a guide to assessing the privacy risks (2024; updated 30 July 2026)
- Authors / Issuing body
- Office of the Australian Information Commissioner (OAIC)
- Venue / Publisher
- Office of the Australian Information Commissioner
- Year
- 2024
- Designation
- Guidance
- Licence
- Stable URL — refer to publisher for full licence terms.
How to cite
OAIC (2024, updated 2026). OAIC Guidance — Facial recognition technology: a guide to assessing the privacy risks (2024; updated 30 July 2026). Office of the Australian Information Commissioner. https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/facial-recognition-technology-a-guide-to-assessing-the-privacy-risks.
The Australian privacy regulator's guide to assessing the privacy risks of facial recognition technology. First published November 2024 and substantially updated on 30 July 2026 with a retail-sector focus, it sets out the OAIC's position on how the Privacy Act 1988 (Cth) and the Australian Privacy Principles apply to biometric collection and matching.
Why it matters for NETEVO
Facial recognition is the case where an AI system collects sensitive information by default, and the Australian privacy regulator has now written to it twice. This guidance is the OAIC's stated position on how the Privacy Act 1988 (Cth) and the Australian Privacy Principles apply when an organisation deploys facial recognition.
It closes the biometric gap in the regulator's AI guidance. The OAIC's October 2024 guidance addresses privacy in the procurement and use of commercially available AI products, and its companion addresses privacy in developing and training generative models. Neither reaches biometric collection specifically — and biometric information is sensitive information under the Privacy Act 1988 (Cth), which carries a materially higher collection threshold than ordinary personal information. This guidance is what an organisation reads before deploying facial recognition, rather than reasoning by analogy from the general AI guidance.
The July 2026 update is current regulatory attention, not a legacy document. The OAIC republished the guidance on 30 July 2026 with a retail-spaces framing — the deployment context in which Australian enforcement attention has concentrated. For any organisation operating physical premises alongside digital services, it is the most directly applicable Australian privacy guidance issued in 2026.
Two regimes at once for the public sector. A NSW Government agency deploying facial recognition sits under this guidance on the privacy side and under the NSW AI Operational Policy on the AI-governance side, with the NSW AI Assessment Framework as the assessment process and mandatory AI Review Committee referral if the use case rates high or critical. A single well-constructed impact-assessment template built on ISO/IEC 42005 can serve both — the same one-template-many-hooks argument, extended into biometrics.
NETEVO encodes obligations identified by counsel or compliance into executable controls. It states what an instrument requires; it does not interpret the Privacy Act 1988 (Cth) against any particular deployment.
Where NETEVO applies this
- AI Governance in ANZ Whitepaper — privacy section — completes the regulator posture across procurement, development and biometric collection
- Listed Leaders ICP — boards accountable for biometric deployments in physical premises
Who acts on this
Reading this usually means something has forced the question — a listing, an audit finding, a procurement questionnaire, a regulator's letter. The role pages below set out what NETEVO does about it, including where we would tell you not to engage.