Your Face Gets Scanned the Second You Walk In. Australia Just Said No.
Picture this: you walk into a hardware store to grab a box of screws. Before you even touch a cart, a camera above the door has already scanned your face, compared it to a database, and logged that you were there. You didn't sign anything. You didn't press "agree." You just... walked in.
That's not a dystopian movie plot. That's what two major Australian retailers — Kmart and Bunnings, the kind of stores you'd find in any suburb — were doing. And last week, Australia's privacy watchdog finally drew a hard line in the sand.
Australia just ruled that stores can't silently scan every shopper's face "just in case" — and that precedent is headed your way, whether U.S. lawmakers are ready or not.
The Office of the Australian Information Commissioner — the government body that enforces privacy rules there — published fresh, specific guidance for retailers who want to use facial recognition in their stores. The short version: you can't just point a camera at everyone and call it security. You have to prove you actually need it. You have to tell people. And you have to have real protections in place so the wrong person doesn't get flagged as a shoplifter.
This might sound like far-away news. It isn't. Because the same technology is quietly showing up in stores near you, right now, with far fewer rules attached.
How Did We Get Here?
Retail facial recognition — cameras that scan your face when you walk in and compare it against a list of known shoplifters or banned individuals — has been creeping into stores for years. For a long time, it lived in a legal gray zone. Stores treated it like a security camera with extra features. Privacy advocates treated it like a surveillance dragnet. Regulators mostly looked the other way.
Then Kmart and Bunnings got caught. Both retailers had been scanning the faces of every single customer who walked through their doors — not just people they suspected of anything. Every shopper. Every day. A retired teacher picking up a lamp. A dad buying a garden hose. All of them scanned, matched, logged. The Australian privacy authorities investigated and found both companies had broken the law.
Those cases set the legal ground rules. Now the regulator has turned that case-by-case enforcement into written guidance — a playbook that tells every retailer exactly where the line is. This article is part of a series — start with Face Detection Before Identification How Facial Analysis Act.
That jump — from 27% to 45% — is not small. That's almost half the population moving from "meh, it's fine" to "actually, this worries me." And public opinion tends to drag regulation behind it, which is exactly what happened here.
What the New Rules Actually Say (In Human English)
The guidance from the Office of the Australian Information Commissioner boils down to four tests that any retailer must pass before they can legally run a facial recognition system on shoppers.
The Four Tests Every Store Must Pass
- ⚡ Necessity — Is facial recognition actually the only way to solve the problem? Could a regular security guard or a standard camera do the job? If yes, the face scan isn't allowed.
- 📋 Transparency — Does the store tell you, clearly, that it's scanning faces? A tiny sign by the fire exit doesn't count.
- ✋ Consent — In some cases, they need your actual permission. Not implied permission. Not "you walked in, so you agreed." Real consent.
- 🛡️ Safeguards — What happens when the system gets it wrong and flags an innocent person? (It will. These systems have documented error rates, especially for women and people with darker skin tones.) There must be a real human review process.
The piece that matters most for regular shoppers is the necessity test. It kills the lazy approach. Stores can't just say "facial recognition helps our security" and call it done. They have to prove no simpler option would work. That's a high bar — and deliberately so.
As SC Media reported, the guidance makes clear that regulators acknowledge how hard it is to get consent from every single customer walking through a door. But that friction — the inconvenience of asking — cannot be used as a reason to skip asking entirely. Retailers must either find a narrow legal reason they don't need consent, or they need to actually get it.
"Retailers cannot collect broad watchlists of all faces for fraud prevention; they must prove the system is proportionate and that less intrusive alternatives don't exist." — Analysis of OAIC guidance, GRC Report
Now Here's the Part That Affects You Directly
Australia has rules now. Most of the United States does not.
According to data tracked by State of Surveillance, most U.S. states have no specific laws covering how retailers can use facial recognition on shoppers. A handful of states have moved toward banning it or restricting it. Most have done nothing. That means retailers in those states are largely operating on their own judgment — and their own business interests.
Here's the scale of what we're talking about: according to National Retail Federation data reported by The Spokesman-Review, 18% of retailers were already piloting or had implemented facial recognition by 2025 — up from 12% just three years earlier. That's not fringe tech anymore. That's one in five retailers, growing fast, in an environment where most consumers have no idea it's happening. Previously in this series: Your Kids Id Photo Just Became Someone Elses Database.
The retailers have a real argument, by the way. This isn't made up. Shoplifting has gotten genuinely worse and genuinely more dangerous — Biometric Update noted that 73% of retailers reported shoplifters becoming more violent in 2024, and by 2025 that number had climbed to 83% saying violence was as bad or worse than before. Loss prevention is a real problem. Nobody's pretending otherwise.
But here's the thing. Scanning every single person who walks into a store — innocent parents, confused retirees, bored teenagers, all of them — is a different thing than having a system that checks known offenders against a specific watchlist. The Australian ruling actually protects the second approach while banning the first. Targeted and purposeful: fine. Dragnet on everyone with a pulse: not fine.
(The difference matters a lot if you've ever been incorrectly flagged for anything. These systems make mistakes. The question is who bears the cost of those mistakes.)
What You Can Actually Do Right Now
If you've ever squinted at a sign in a store and thought "wait, are they doing something with cameras?"— that instinct is worth trusting. Your face is biometric data. That means it's in the same category as your fingerprints or your medical records: the body stuff that's uniquely yours, that can't be changed if it's stolen or misused.
Treat a store asking for your face more like handing over your driver's license than tapping a loyalty card. Ask yourself three questions before you walk in anywhere that posts notices about "advanced security technology" or "image capture for safety purposes":
What are they actually capturing? A camera that records footage is not the same as a system that runs facial matching — comparing your face against a database in real time. The sign should say which one.
Why do they need it? "Safety" is a reason. "Safety that requires scanning every single customer's face rather than using any other method" is a much harder thing to justify. Up next: Before Facial Recognition Names You It Has To Find You And T.
Can you say no without consequence? The Australian rules explicitly say you can't be punished for opting out. If a store tells you the face scan is "required" to enter, that's worth questioning — and worth reporting to your state's consumer protection agency.
At CaraComp, the question we keep coming back to is the same one regulators in Australia just turned into law: if you've ever wondered whether an image, a profile, or a scan is being used in ways you didn't agree to — that's not paranoia. That's the exact question that privacy law is slowly, finally, catching up to answer. Knowing what questions to ask is the first real protection you have, long before any rule gets written.
Your face is now a regulated data point in Australia. In most of the U.S., it isn't yet. That gap is where retailers are quietly making decisions about your biometric data right now — and the only person asking questions on your behalf, today, is you.
Australia's watchdog just answered a question that most countries haven't gotten around to asking yet: does walking into a store mean you've agreed to give a corporation your face? The answer, finally, is no. Not automatically. Not by default. Not just because it's convenient for them.
So here's the question worth sitting with: the next time you see a small sign near a store entrance mentioning "security imaging" or "loss prevention technology" — will you know what it means? Or will you tap your rewards card, grab your cart, and walk right past it?
Because that sign? It might mean more than you think.
Would you shop somewhere that required a face scan if the store said it was for safety or fraud prevention? Drop your answer in the comments — we read every one.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore News
Your Family Could Be Stuck 8 Hours in 95° Heat at Europe's New Border Lines
The EU's new facial-scan border system caused eight-hour queues in scorching summer heat. If you're flying internationally this year, here's what you need to know before you go.
biometricsYour Boss Wants to Scan Your Face to Log You In. Ask These 3 Questions First.
Philips just launched office monitors with built-in facial recognition login. Before your employer rolls them out, there's one question every employee should ask first.
ai-regulationThat Voice on the Phone Sounds Exactly Like Your Mom. It Isn't Her.
Europe's deepfake labeling law just went live. The problem? Scammers cloning your boss's voice or faking a family emergency video aren't going to follow the rules. Here's what the label you DON'T see should tell you.
