When the Bunnings proceedings came to a close, I recognised a pattern I’ve been seeing across my entire career in privacy: the decision didn’t change at all.
Bunnings wanted to use facial recognition in its stores to combat serious retail crime and violence, and it did, across more than 60 of them between 2018 and 2021. CHOICE reported the use. The Privacy Commissioner investigated and found breaches of the Privacy Act. Bunnings sought review and the Administrative Review Tribunal held that the collection was justified for the purpose Bunnings had identified. What Bunnings had failed to do was the paperwork: a privacy impact assessment and a notice.1
Bunnings is now preparing to reintroduce the technology with a PIA, improved signage, community consultation and operating safeguards in place before it starts.2 The governance around it is better. But Bunnings wanted to use facial recognition, and nothing in the years of complaint, investigation, determination and review that followed was able to change that.
The missing PIA would have said yes
I think a PIA completed beforehand would still have said yes. Not because the instrument is incapable of asking (the OAIC’s own guide says a PIA should go beyond compliance, test necessity and proportionality, consider less intrusive alternatives and happen early enough that the organisation can still decide not to proceed3) but because a PIA can be an inquiry into whether a proposal should go ahead, or the work required to make a proposal that’s already been chosen defensible. From the outside, the two produce the same document.
After the Australian decision, Bunnings rolled facial recognition out to its New Zealand stores with a full PIA, independent research with 1,000 New Zealanders, engagement with a Māori digital sovereignty expert and a detailed set of safeguards.4 The assessment was extensive. The answer was still yes.
What this shows is what the formal privacy system is built to see and correct. Once a use can be legally justified, the visible problems become the missing assessment, the inadequate notice, the safeguards and the process, and an organisation can fix every one of them without reopening the purpose it set out to pursue. This is what I call the privacy compliance loop.
The loop isn’t the existence of the evidence. Records are the only reason accountability is more than assertion; without them an organisation could claim careful judgement that nobody could ever test. The loop is what happens when evidence that the work was done is allowed to stand in for evidence that the decision was any good.
Three levers keep the loop turning
Being a participant in this loop makes it hard to recognise. Over the years I realised that the forces I was up against, when the job was preventing harm to a person, had three distinct but coupled dimensions. I call them Structural, Capability and Operating Model, and each one builds the next.
proof that privacy happened
Bunnings illustrates the Structural lever and nothing beyond it. The public record can’t tell us what happened inside its privacy function, who challenged the proposal, or how far they got, and I’m not going to infer any of it. The other two levers come from years spent inside compliance environments, watching how organisations build privacy functions in response to what the outside system asks of them.
Structural is that outside system: the law, regulatory guidance and enforcement, tribunal and court decisions, audit expectations, and whatever the field has agreed counts as evidence of a working privacy program. Australian privacy law is principles-based, which gives organisations flexibility, but flexibility means somebody inside the organisation has to exercise judgement about reasonableness, necessity and proportionality in the circumstances.5 Many privacy functions sit inside legal and compliance, which tells you what organisations understand the job to be: meeting the letter of the law rather than its substance, which is protecting the individual.
The system still has to decide whether you complied with the privacy principles. Regulators need evidence they can inspect and boards and auditors need records they can oversee, so organisations produce the evidence: PIAs, policies, notices, training records, breach reports, governance papers. Then we measure it, by how many PIAs were completed, whether annual training was finished, how many breaches were reported, and whether the privacy policy was reviewed on schedule. A flurry of activity and documentation, all of it countable, none of it answering whether the organisation is becoming any less likely to harm someone.
That demand shapes Capability. If the system is geared towards demonstrating compliance, the people hired to run it will be people who think in the letter of the law. Rule followers and rule repeaters, and nothing more, because the external environment doesn’t reward anything else. Organisations then build their capability around producing documentation rather than exercising judgement.
The judgement that never gets built is the one that starts with the person. Risk gets created upstream in every discipline, but privacy is different because its law is principles-based and its judgement starts with the individual the organisation is making a decision about, not the organisation’s own legal, financial or reputational exposure. The organisation pursues the aim and usually collects the benefit; the person whose information, behaviour or identity is being used may not know the decision is being made at all, and they carry the consequences either way. Keeping that person in the decision means asking whether the intrusion is justified, what harm could follow, whether something less harmful would achieve the same aim, and what the organisation is prepared to do about consequences it can’t remove. Build the capability mainly around explaining the rules and documenting compliance, and the person disappears while the privacy work is being completed properly.
The Capability lever supplies the judgement, but that alone does not make privacy a decision capability. The judgement still has to reach a consequential choice while credible alternatives exist and be capable of changing what the business owner decides, which depends on the Operating Model.
Operating Model is where the organisation puts that capability and what it permits the capability to do. It decides when privacy gets involved, what question privacy is asked, who has to respond to the answer, and whether the answer has any consequence for the proposal. An organisation can employ genuinely capable practitioners and still use them as a review service that arrives once the purpose, the technology, the supplier and the timetable have been settled, and at that point the only work left is to document, condition and defend the decision, because nobody has left room to make a different one. Privacy by design is the guiding principle of every privacy program, and the operating models organisations actually build don’t allow it.
The business owner should still own the decision. Privacy doesn’t need a veto for its judgement to matter, and a decision can change by degrees: the purpose narrows, less information gets used, the design changes, conditions are attached, or the thing stops. What the operating model has to do is require the owner to engage with the privacy judgement while any of those are still available.
The three levers keep handing work to each other. The Structural environment tells organisations what good privacy performance looks like, organisations build the Capability to produce that performance and an Operating Model to house the work, and the documents and activity that result get reported back as evidence that privacy is functioning, which confirms the original definition of good performance. Everyone can be doing the job they were given and the loop keeps turning.
Nowhere in it does anyone have to ask whether we’re protecting the individual, because nothing in the loop demands that question. The privacy risk was created long before the data breach or the regulator. It was created in the decision, and the loop never touched the decision.
You can’t see the loop by counting what it produces
You can’t diagnose any of this by counting more outputs. A completed PIA tells you a PIA was completed, and a training completion rate tells you people attended the training. None of it tells you what somebody in your organisation will do when a proposed use is profitable, operationally attractive, already supported by people more senior than them, and harmful to somebody who isn’t in the room.
Ordinary work doesn’t make it visible either. Every real decision arrives with its own history, personalities, deadlines and commercial pressure, so a strong practitioner compensates for a weak process, a senior sponsor intervenes, or a project changes for reasons that had nothing to do with privacy at all. The organisation sees the result without ever learning which part of its own system produced it.
The only way I know to test whether the Capability and Operating Model levers can move a decision is to rehearse one.
By rehearse I mean putting a decision the organisation could plausibly face in front of the people who would really make it, with the authority and the processes they really have, and watching what happens to it. What comes out is the material no record can hold: whether anyone names the consequence for the person without being prompted, whether privacy is asked before or after the answer becomes inconvenient, whether an alternative gets built or only mentioned, who can say the uncomfortable thing to the person running the project, and what happens to them when they do.
That’s how you separate a Capability problem from an Operating Model problem. If the process leaves room for judgement and the people in it can only recite the rules, the gap is Capability. If they can see the harm and put up credible alternatives but they arrive too late, have no route to the person who owns the decision, or can be heard and then ignored without consequence, the gap is Operating Model. Often it’s both, and the two are almost impossible to tell apart from the outside, because a capable practitioner in a late process and a weak practitioner in a good one produce exactly the same unchanged decision.
Rehearsal doesn’t touch the external environment. What it shows you is how completely the organisation has reproduced that environment inside itself, and whether its own two levers can move without waiting for the first one.
What it looks like when the levers move
All three levers can move. Organisations just don’t control them equally.
Structural moves through law reform, a more interventionist regulator, court and tribunal decisions, advocacy, lobbying, and shifts in what the industry treats as ordinary practice. That’s slow, collective work, and no single organisation moves it on the timetable of its own product roadmap. What would be different is the thing being rewarded, which would be evidence that harm was avoided rather than evidence that paperwork was finished. Waiting for it is how another decade of compliant harm gets approved.
Capability and Operating Model are already yours. On Capability, the shift is from a practitioner who can tell you what the law permits to one who can recognise the consequential choice inside a messy commercial proposal, say what it will do to a person in terms the business can act on, put up an alternative that’s genuinely viable, and know when the unresolved question belongs to somebody more senior. Knowing the rules stays necessary; it stops being the whole of the job.
On Operating Model, the shift is in when privacy arrives and what happens to what it says. Privacy meets the choice while alternatives still exist, before the supplier, the budget and the purpose have stopped being negotiable. Somebody owns the decision and has to respond to the privacy judgement rather than simply receive it. A material disagreement has somewhere to go that ends with a person who can accept it, constrain it or refuse it. None of that puts privacy in charge, because the business keeps the decision and its consequences. It stops the consequences for people being the part that’s easiest to leave out.
An organisation that has moved those two levers has something a compliance-mode program can’t produce: decisions that went differently because privacy was there. A purpose that got narrower, a data source that was declined, a design that changed, a proposal that went ahead on conditions with real force, or one that didn’t go ahead. That’s what I mean by privacy as a decision capability: the capacity to bring privacy judgement into a consequential choice while credible alternatives still exist, so that the effect on people can change what gets decided, how it’s designed, who owns it, or the terms it proceeds on.
Overcompliance is only a risk if compliance is the point
Preventing a harm the law doesn’t expressly prohibit looks like overcompliance, and that’s the objection I get. If the law permits it and the regulator hasn’t moved, why spend money on a problem you don’t have yet.
It only works as an objection if compliance is the target. Legal permission is a floor, the level below which you can be penalised, and treating the floor as the goal means deciding that anything not yet prohibited is acceptable to do to your customers. Once the aim is not harming them, overcompliance stops being a category that means very much.
Customers don’t experience a company’s conduct as a technical answer to an APP. They experience what it decided to do with information about them, what followed from that, and whether it held itself back when it had the power not to. A legally available use can still cost an organisation the trust of the people it depends on, if those people experience it as intrusive, unfair or indifferent to them.
Bunnings won, and it’s worth looking at what winning involved: a consumer group complaint, a Commissioner-initiated investigation, a determination, an appeal, and years of public argument, all over a use the law turned out to permit. The legal answer arrived a long time after the public one did. The version now being prepared for Australian stores comes with the assessment, the improved signage and the community consultation that weren’t there in 2018.
An organisation that can move a decision has something better available than asking to be trusted, and it’s the one thing nobody can fake: it can say what it decided not to do. The inference it declined to draw, the data it turned down, the vendor request it refused. That’s the only kind of privacy claim that costs the organisation something to make, which is exactly why it’s the only kind worth believing. Trust us, we completed an assessment asks customers to take comfort from a document they will never see.
The loop doesn’t break, it rewires
The loop isn’t going anywhere, because organisations will always have to show that obligations were met. What changes is what it reinforces. It will keep reinforcing something, and the only question is whether that’s proof privacy happened, or decisions that stopped harm before it reached anyone.
decisions that stopped harm before it reached anyone
Structural change is slow and collective, and it isn’t the lever you have, whereas the other two are already yours. When the capability is built for judgement rather than recall, and the operating model puts that judgement in front of a choice while it can still go either way, the loop turns on the same machinery and produces something different, because there is finally something to report other than that the work was done.
That is all privacy as a decision capability means. It doesn’t put privacy in charge of anything, and it doesn’t require a longer assessment. It produces an organisation with decisions it can account for, and an organisation in that position can say something about its own conduct that a completed assessment will never be able to say for it.
It also gives oversight something it can test. A board that is told the assessment was completed has learned that the loop is working, and nothing else, so it should treat that as the first question answered and not the one that matters. Did the decision change because privacy was there? The purpose may have narrowed, the scope may have shrunk, the design may have changed, conditions may have been attached, or the proposal may have stopped. If the only answer available is that the assessment exists, the loop is still turning.
Notes
- The Commissioner found breaches of Australian Privacy Principles 1, 3 and 5. The Tribunal set aside the APP 3 finding and upheld the findings on APPs 1 and 5. See: Office of the Australian Information Commissioner, “OAIC opens investigations into Bunnings and Kmart”, 12 July 2022; Administrative Review Tribunal, “Guidance and Appeals Panel decisions: Bunnings Group Limited and Privacy Commissioner”, decision published 5 February 2026; Office of the Australian Information Commissioner, “OAIC statement on Administrative Review Tribunal’s Bunnings decision”, 4 February 2026.↩
- Bunnings Australia, “Facial Recognition Technology”, accessed 10 August 2026.↩
- Office of the Australian Information Commissioner, “Guide to undertaking privacy impact assessments”, accessed 10 August 2026.↩
- Bunnings New Zealand, “How we are using Facial Recognition Technology (FRT) to help keep our team and customers safe”, updated 7 July 2026.↩
- Office of the Australian Information Commissioner, “Australian Privacy Principles”, accessed 10 August 2026.↩