Kmart Australia: two years of unlawful face scanning
Facial recognition ran for refund-fraud prevention in 28 Australian stores for about two years before a consumer group's investigation triggered the privacy regulator. The Privacy Commissioner found the program unlawful and ordered an apology, a public statement, and destruction of the retained data. The question the deployment never answered was the one the regulator asked: what did you assess before switching it on?
What the verified record says.
- Organizations
- Kmart Australia; Office of the Australian Information Commissioner
- When
- June 2020Resolved September 18, 2025
- Failure class
- Unlawful data use unlawful-data-use
- Discovered by
- An advocate or consumer group advocate Not caught by the organization running the AI
- Missing control
- Accuracy monitoring in production. Measuring what the system actually does after launch: error rates, bias, drift against outcomes. Full definition and the other incidents in this group → Watch this kind of control catch a planted failure →
- What would have caught it
- A privacy impact assessment and customer notice before biometric collection starts, reviewed by someone outside the team that wants the system.
- Sources
- Verification
- Adjusted: the incident is real, and details were corrected against the primary source before publication. Earlier reporting dated this to November 2024, conflating it with the separate Bunnings determination. The Kmart determination is dated September 18, 2025, and covers June 2020 to July 2022 in 28 stores. Verified against the primary source on August 12, 2026. Published on this site August 13, 2026, updated September 1, 2026.
This record is one of 26 in The receipts, each checked against a primary source before it is published. How the list is built →