Skip to content

Facial recognition, ANPR and smart surveillance in strata buildings

Only if your managing-agent business is a covered APP entity, and a managing agent turning over A$3 million or less that is not part of a larger covered group may not be. But where you are covered, facial recognition and number-plate cameras are the highest-risk technology in the building. The OAIC's Bunnings determination treated facial images as sensitive biometric information that needs clear notice and a compliant privacy policy, and the 2026 tribunal appeal affirmed those transparency and notification breaches. State surveillance law applies to the cameras either way.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

First, work out who is actually on the hook

Smart surveillance does not change the coverage question, it just raises the stakes of getting it wrong. So start where every strata privacy question starts.

Here is the honest catch, though: state surveillance-devices law binds the cameras regardless of any of this. The exemption that shelters a small manager from the APPs does nothing to shelter the surveillance hardware. So even a manager who is outside the Privacy Act cannot install whatever cameras it likes.

Why facial recognition is the highest-risk camera in the building

An ordinary CCTV camera captures images of people. A facial recognition camera does something legally different: it converts a face into a biometric template and matches it against a database. Under the Privacy Act, biometric information used for automated identification is sensitive information, a special category that attracts a higher level of protection than ordinary personal information.

That distinction is what makes a "smart" entry system in an apartment lobby a different problem from a plain camera over the bins. If your managing-agent business is covered, you are no longer just holding footage. You are collecting and holding sensitive information, the category the Act protects most strictly,, about every resident, visitor, contractor and delivery driver who walks through the door, including people who have never dealt with your office and were never asked.

What the Bunnings case actually decided

The clearest Australian guidance comes from the OAIC's Bunnings determination (29 October 2024), which examined a retailer using facial recognition on shoppers. It is not a strata case, but it sets the benchmark for how the regulator treats facial recognition, and the reasoning transfers directly to a covered strata manager running the same technology in a building.

The original determination found breaches of APP 1 (failing to manage information openly, including through a compliant and up-to-date privacy policy), APP 3 (collecting sensitive information without consent) and APP 5 (failing to notify people that the collection was happening).

On appeal, the Administrative Review Tribunal (4 February 2026) affirmed the APP 1 and APP 5 findings, the transparency and notification failures, but set aside the APP 3 finding on collection without consent. So be precise about the durable lesson, because it is easy to overstate: the affirmed, settled obligations are transparency and notice, not a blanket rule that you always need express consent to collect. If you are a covered manager, you must have a privacy policy that openly discloses the facial recognition, and you must clearly tell people, before or at the point of entry, that their face is being captured and matched. The narrower consent-to-collect question is more contested after the appeal, so treat it as unsettled rather than as a fixed rule .

ANPR and number-plate cameras at the boom gate

Automatic number-plate recognition (ANPR) sits at the car-park boom gate and video intercom, reading plates to open a gate, log entries or flag visitors. Managers often assume a number plate is not personal information, so ANPR feels lower-risk than facial recognition. Be careful with that assumption.

Whether a bare plate is personal information turns on the statutory test in s 6(1): information about an identified individual, or an individual who is reasonably identifiable. Registration details sit with the state road authority rather than with you, so a plate on its own will often not make the driver reasonably identifiable to a strata manager. But a strata manager rarely holds it on its own. The moment you match a plate to a resident, an allocated car space, an owner on the roll or an access log, the plate becomes information about an identifiable individual, which is personal information for a covered manager. A log of who came and went, and when, is a movement record, and it inherits the same APP obligations as any other personal information you hold: collect only what is reasonably necessary (APP 3), tell people it is happening (APP 5), keep it secure and destroy it when it is no longer needed (APP 11). Whether a plate alone is personal information depends on what else you hold alongside it, not on which state you are in: the s 6(1) test is federal and asks whether the individual is reasonably identifiable.

ANPR is generally lower-risk than facial recognition because a plate is not biometric sensitive information, but it is not no-risk, and a manager who treats the entry log as disposable exhaust is the one who gets caught out when it leaks.

The surveillance-law layer that binds even if you are exempt

Whatever the Privacy Act does or does not do, state Surveillance Devices Acts apply to the cameras themselves, independently, and they bind a manager who is inside the small-business exemption just as much as one who is outside it. Facial recognition and ANPR are still optical surveillance devices, so the state rules on common-property cameras apply on top of everything above: cameras should be video-only, because using a listening device to record a private conversation you are not a party to is an offence in every state we have checked at source (Surveillance Devices Act 2007 (NSW) s 7(1), Surveillance Devices Act 1999 (Vic) s 6(1), Surveillance Devices Act 1998 (WA) s 5(1), Invasion of Privacy Act 1971 (Qld) s 43); they should not be aimed into private lots or windows; and the scheme still needs whatever resolution or approval its own state's strata legislation requires, which differs in every jurisdiction. Signage is not itself a surveillance-devices requirement. It is how a covered manager meets APP 5, and in New South Wales it is what the Workplace Surveillance Act 2005 s 11 requires for camera surveillance of employees, so it is worth doing either way. Read: CCTV and surveillance on strata common property

Those rules are not uniform. Victoria and Western Australia each make it an offence to use an optical surveillance device to record or observe a private activity you are not a party to, without the consent of the parties: Surveillance Devices Act 1999 (Vic) s 7(1) and Surveillance Devices Act 1998 (WA) s 6(1)(a). New South Wales is narrower. Its optical offence, Surveillance Devices Act 2007 (NSW) s 8(1), bites only where installing, using or maintaining the device involves entering premises or a vehicle without the owner's or occupier's consent, or interfering with a vehicle or object without consent, and it speaks of recording an activity rather than a private activity. Queensland has no equivalent general optical-surveillance offence at all: the Invasion of Privacy Act 1971 (Qld) regulates listening devices, and the words optical, visual and camera do not appear anywhere in it (checked at source, August 2026). Other states and territories were not checked here. So the same smart-camera install can be lawful in one state and an offence in another. Confirm your own state before relying on any of this. Read: strata CCTV rules by state

There is also a newer lever worth noting: a statutory tort of serious invasion of privacy, inserted as Schedule 2 to the Privacy Act 1988 (Cth) by the Privacy and Other Legislation Amendment Act 2024, commenced on 10 June 2025. It gives an individual a direct right to sue, but only where all five conditions in cl 7(1) are met: the defendant intruded on the plaintiff's seclusion or misused information relating to them; a person in the plaintiff's position would have had a reasonable expectation of privacy; the invasion was intentional or reckless; it was serious; and the public interest in the plaintiff's privacy outweighed any countervailing public interest. It is narrow, and no case under it has yet dealt with building surveillance. What is clear is that it does not depend on you being an APP entity: the only exemptions in Schedule 2 cover journalists (cl 15), agencies and State and Territory authorities (cl 16), intelligence agencies (cl 17) and people under 18 (cl 18), and none of them turns on turnover.

What a covered manager should actually do before switching it on

If your managing-agent business is a covered APP entity and a scheme wants facial recognition or ANPR, the honest baseline is to treat the technology as a decision to justify, not a default to install.

Common questions

Usually, yes. APP 3.3 requires the individual's consent, plus reasonable necessity, before a covered organisation collects sensitive information, unless one of the APP 3.4 exceptions applies. In the 2026 Bunnings appeal the Tribunal set the consent finding aside because it accepted that a permitted general situation under s 16A applied to a retailer dealing with theft, fraud and violence in its stores. That is a fact-specific exception, not a general permission, and routine building access is unlikely to reach it. What the appeal affirmed, and what applies either way, is the transparency and notice duty: disclose the technology in your privacy policy and tell people at the point of entry.

Is a car number plate personal information?

A bare plate may not identify a person on its own . But once a covered manager matches it to a resident, a car space, the owners roll or an access log, it becomes information about an identifiable individual, which is personal information carrying APP obligations. Treat your ANPR entry log as personal data unless you have confirmed otherwise for your setup.

We are a small manager under $3 million. Can we install facial recognition freely?

No. Even if your business falls within the small-business exemption and the APPs largely do not bind you, state surveillance-devices law still governs the cameras, the scheme still needs the right by-law and approval, and the statutory tort of serious invasion of privacy does not depend on you being an APP entity. The exemption shelters your business from the APPs, not the hardware from the law.

Is facial recognition riskier than ANPR?

Generally yes. Facial recognition creates biometric information and biometric templates, which s 6(1) makes sensitive information, so a covered manager collecting it has to satisfy APP 3.3. A number plate is not biometric. ANPR is lower-risk but not no-risk, because a plate matched to a resident is still personal information and a movement log is still a security and privacy liability if it leaks.

Keep reading


General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether the Privacy Act 1988 (Cth) applies to your managing-agent business depends on your turnover and structure; state Surveillance Devices Acts and strata legislation apply separately and vary by jurisdiction. The Bunnings determination and its 2026 tribunal appeal are cited as general guidance, not as advice about your building. The law changes over time, so check you are working from a current version and confirm your own state's requirements. For advice on your specific circumstances, consult a qualified Australian legal practitioner.