Skip to main content
Cavefish
Compliance9 min readSeptember 2026

Is Emotion Recognition Legal in Australia?

Yes — no Australian statute prohibits it, and there is no Australian AI Act. But Australia sits closer to Europe than to America, because the Privacy Act 1988 treats biometric information as sensitive information, and sensitive information generally cannot be collected without consent. That is a real gateway, not paperwork. Australia also has something no other common-law jurisdiction has: a contested tribunal decision on biometric collection. The Bunnings matter shows exactly how the regulator reasons — and it shows that the deployment failed on transparency and notification, not on the technology.

Jonathan Prescott
Jonathan Prescott
Founder & CEO, Cavefish — MBA Bayes Business School · B.Eng Computer Systems · Former Director of Digital, The Royal Mint
About Jonathan →LinkedIn ↗

This is not legal advice. It is a buyer's orientation written by a vendor in the category. Australian privacy law is mid-reform, the employee records exemption is under review, and whether emotion classification falls inside the sensitive information definition is genuinely arguable. Take specific advice before deployment, and treat any vendor claim — including ours — as something to verify rather than accept.

No AI Act — what actually governs

Australia has not enacted an AI statute. The government has published a voluntary AI Safety Standard and consulted on mandatory guardrails for high-risk AI, but nothing binding has followed. Emotion recognition is therefore governed by the Privacy Act 1988 and the Australian Privacy Principles, by state surveillance and workplace surveillance legislation, and by federal and state anti-discrimination law including the Disability Discrimination Act 1992.

The Privacy Act carries most of the weight, and it does so through one structural feature: the distinction between personal information and sensitive information.

Biometric information is sensitive information

Section 6 of the Privacy Act defines sensitive information to include biometric information that is to be used for the purpose of automated biometric verification or biometric identification, and biometric templates. Sensitive information attracts the Act's highest protection: under APP 3.3, an organisation must not collect it unless the individual consents and the collection is reasonably necessary for one or more of the organisation's functions, subject to limited exceptions.

This is a genuine gateway. Unlike Singapore, where biometric data is ordinary personal data, and unlike the US, where the question is consent paperwork and damages exposure, an Australian deployment has to clear a consent threshold before collection happens at all.

There is an argument that emotion classification which identifies nobody sits outside the definition, since the definition is framed around verification and identification rather than analysis. It is a serious argument and it has not been tested. Given the OAIC's demonstrated approach to facial analysis, it is not one to rely on without advice, and it is certainly not one to accept from a vendor.

What Bunnings actually teaches

Between 2018 and 2021 Bunnings deployed facial recognition across 62 stores in Victoria and New South Wales. It produced the only contested tribunal ruling on biometric collection anywhere in the common-law world, and it is worth understanding properly rather than by headline.

In October 2024 the Privacy Commissioner determined that Bunnings had breached APPs 1.2, 1.3, 3.3 and 5.1 — transparency, collection, and notification — and stressed that the sensitivity of biometric data demanded rigorous compliance systems and, in particular, a privacy impact assessment. On 4 February 2026 the Administrative Review Tribunal affirmed the APP 1 and APP 5 findings but set aside the APP 3 finding on collection without consent. In July 2026 the OAIC published updated guidance on facial recognition in high-volume publicly accessible retail spaces.

The lesson for buyers is not that biometric analysis is unlawful in Australia. It is that Bunnings improved its position on the hard question — consent — and still lost on the easy ones. Transparency, a compliant privacy policy, a collection notice and a documented impact assessment are where Australian deployments actually fail. Those are entirely within your control, and they are cheap compared with the alternative.

The employee records exemption trap

Australian employers reliably reach for the employee records exemption, and reliably over-read it. The Privacy Act does exempt acts and practices relating to employee records of current and former employees. Two limits make it close to useless here.

First, it attaches to records the employer already holds, not to the act of collection. Lee v Superior Wood established that personal information must be collected lawfully and in accordance with the Act before the exemption can attach — so where what is being collected is sensitive information such as biometric data, APP 3.3 consent is required at the point of collection regardless. Second, the exemption does not cover job applicants at all, including unsuccessful ones, because an applicant is not an employee. Recruitment is entirely outside it.

The government has in any case agreed in principle to narrow or remove the exemption, so any architecture that depends on it is building on ground that is scheduled to move.

Automated decisions from 10 December 2026

The Privacy and Other Legislation Amendment Act 2024 introduced automated decision-making transparency obligations that take effect on 10 December 2026. A new APP 1.7 requires entities to set out in their privacy policies the kinds of decisions made by computer programs that make — or do something substantially and directly related to making — decisions that could reasonably be expected to significantly affect an individual's rights or interests, along with the kinds of personal information used.

Decisions affecting employment opportunities clear that threshold comfortably. If emotion analysis contributes anywhere in a hiring, promotion or performance process, the public privacy policy needs to say so before that date. This is a disclosure obligation rather than a restriction, but it has a second-order effect worth anticipating: it makes the deployment visible to candidates, journalists and unions in a way it previously was not.

Use case by use case

The table grades how hard each deployment is to defend rather than whether it is allowed, because none of them is prohibited. Note that security and public space screening ranks harder here than in any other jurisdiction we cover — that is the Bunnings effect.

Use caseHow hard to defendWhat carries the risk
Contact centre — customer emotionLow frictionNo employment relationship. Consent at the point of collection, a clear collection notice under APP 5, and a privacy policy that describes it under APP 1.
Investor and earnings communicationLow frictionYour own executives, for their own preparation. Consent is meaningful because the subject is the beneficiary.
Market research and message testingLow frictionConsenting participants, properly notified. The most straightforward case under the APPs.
Vulnerability detection (financial services)High scrutinyCustomer-facing, but inference touching health engages sensitive information on a second basis, and ASIC and the Banking Code add expectations on top of the Privacy Act.
Security and public space screeningHard to defendThis is the Bunnings fact pattern. The OAIC has published specific guidance, and transparency and notification failures sank that deployment even where consent was arguable.
Recruitment and interview assessmentHard to defendApplicants are outside the employee records exemption entirely. APP 3.3 consent from a candidate is rarely genuinely voluntary, and ADM transparency obligations bite from 10 December 2026.
Employee monitoring or engagement scoringHard to defendThe employee records exemption does not reach collection — Lee v Superior Wood. Consent is still needed for sensitive information, and employee consent is the weakest kind.
Education — student attention or engagementHard to defendChildren's data, state-based school regulation and the highest level of OAIC scrutiny of any case on this list.

Five questions to put to any vendor in writing

  1. Does your system infer emotional state or report observable signals — and how would you evidence that to the OAIC?
  2. What is your written position on whether your outputs are sensitive information under section 6, and does it depend on the identification argument?
  3. What do you provide for a privacy impact assessment, an APP 5 collection notice, and the APP 1.7 disclosure due on 10 December 2026?
  4. What adverse impact testing have you done across disability and ethnicity, for Disability Discrimination Act exposure?
  5. Which of our intended deployments would you decline to support — in Australia, and separately in the EU, UK and US?

The third question is the Bunnings question. A vendor who cannot help you produce those three documents is selling you the part of the deployment that was never the problem.

Where EchoDepth sits

EchoDepth reports observable delivery signals using the Facial Action Coding System — 44 Action Units calibrated across 14 cultural cohorts in 6 countries — together with vocal and language measures. It reports what the signals did and leaves interpretation to context-aware human review, rather than returning an emotion label. Cavefish provides privacy impact assessment support documentation for every enterprise deployment.

We scope Australian deployments on the same lines as our EU, UK, US and Singapore ones. Contact centre, investor and executive communication, market research and message testing are supported. We do not scope candidate-facing recruitment assessment or employee monitoring deployments, and we will say so at the first conversation rather than the last. Where a security or public-space application is proposed, the Bunnings guidance makes specific legal advice a precondition rather than a formality.

Primary sources

Read the instruments rather than summaries of them. The Privacy Act 1988 — section 6 for sensitive information, Schedule 1 for the Australian Privacy Principles — and the Privacy and Other Legislation Amendment Act 2024 are on legislation.gov.au. The OAIC publishes the Bunnings determination, its guide to assessing the privacy risks of facial recognition technology, its updated retail FRT guidance, and its employee records exemption guidance. Lee v Superior Wood [2019] FWCFB 2946 is the authority on the exemption and collection. Where this page and a primary source disagree, the primary source is right.

Frequently Asked Questions

Is emotion recognition legal in Australia?

Yes. No Australian statute prohibits it, there is no Australian AI Act, and there is no equivalent of EU AI Act Article 5(1)(f). But Australia sits closer to the European end of the spectrum than to the American one, because the Privacy Act 1988 classifies biometric information as sensitive information, and sensitive information generally cannot be collected without consent under Australian Privacy Principle 3.3. That is a genuine gateway rather than a documentation exercise. Australia also has something no other common-law jurisdiction has: a contested tribunal decision on biometric collection, in the Bunnings matter, which tells you how the regulator and the Tribunal actually reason about this technology rather than how they say they would.

Is biometric data sensitive information under the Australian Privacy Act?

Yes. Section 6 of the Privacy Act defines sensitive information to include biometric information that is to be used for the purpose of automated biometric verification or biometric identification, and biometric templates. Sensitive information attracts the highest level of protection in the Act: under APP 3.3 an organisation must not collect it unless the individual consents and the collection is reasonably necessary for its functions, subject to limited exceptions. Whether emotion classification that does not identify anyone falls inside the definition is genuinely arguable, since the definition is framed around verification and identification. That argument has not been settled, and the OAIC's approach to facial analysis suggests it should not be relied on without advice.

What did the Bunnings decision decide?

Bunnings deployed facial recognition across 62 stores in Victoria and New South Wales between 2018 and 2021. In October 2024 the Privacy Commissioner determined that it had breached Australian Privacy Principles 1.2, 1.3, 3.3 and 5.1, covering transparency, collection and notification, and emphasised that the sensitivity of biometric data required rigorous compliance systems and a privacy impact assessment. On 4 February 2026 the Administrative Review Tribunal affirmed the findings on APP 1 and APP 5 but set aside the APP 3 finding on collection without consent. The OAIC published updated guidance on facial recognition in retail spaces in July 2026. The practical lesson for buyers is that Bunnings lost decisively on transparency and notification even where it improved its position on consent — governance paperwork was the failure, not the technology.

Does the employee records exemption cover workplace emotion recognition?

Not in the way employers usually assume, and this is the most common Australian misunderstanding. The Privacy Act exempts acts and practices relating to employee records of current and former employees. But the exemption applies to records the employer already holds, not to the act of collection. Lee v Superior Wood established that personal information must be collected lawfully and in accordance with the Act before the exemption can attach — so where the information collected is sensitive information such as biometric data, consent is required at the point of collection regardless of the exemption. The exemption also does not cover job applicants at all, including unsuccessful ones, because they are not employees. The government has agreed in principle to narrow or remove the exemption in any case.

What changes for automated decisions on 10 December 2026?

From 10 December 2026, transparency obligations for automated decision-making introduced by the Privacy and Other Legislation Amendment Act 2024 take effect. A new APP 1.7 requires APP entities to disclose in their privacy policies the kinds of decisions made by computer programs that make, or do something substantially and directly related to making, decisions that could reasonably be expected to significantly affect an individual's rights or interests, together with the kinds of personal information used. Decisions affecting employment opportunities fall within that threshold, so an employer using emotion analysis anywhere in a hiring or promotion process needs its public privacy policy updated before that date.

Scope your use case before you procure

Tell us the deployment you have in mind. We will tell you what it has to survive under the Privacy Act — including if the answer is that we cannot support it.

Talk to us about scoping →
Other Jurisdictions
European Union →United Kingdom →United States →Singapore →Proof & Methodology →