Australians could have their faces scanned and compared against watchlists while doing something as ordinary as buying groceries, raising fresh concerns about how far supermarket surveillance may reach.
Privacy campaigners warn that customers and workers could be identified, assessed and tracked inside stores without fully understanding what information is being collected or how long it will be kept.
Coles and Woolworths have presented facial recognition as a safety measure aimed at identifying people linked to violence, threats or repeated offending.
Protecting supermarket workers is a legitimate concern, but the system may still need to scan every person entering a participating store to locate the relatively small number of people it is designed to detect.
That means ordinary shoppers could be subjected to biometric screening simply because they need food, medication or household essentials.
Walking away may not be a realistic option when the major supermarkets dominate much of Australia’s grocery market and alternative stores are not always nearby.
Facial data is particularly sensitive because it cannot be cancelled or replaced in the way a compromised password, bank card or account number can.
If the information is leaked, misused or incorrectly attached to someone’s identity, the consequences could follow that person each time they enter another store using the same technology.
The reliability of facial recognition is also under scrutiny, particularly when a match can lead to someone being watched, questioned or approached by security staff.
An innocent customer wrongly identified as a known offender may have no immediate way to understand why they have been stopped, let alone challenge the information behind the decision.
Research into facial recognition has raised further concerns about differing accuracy rates across racial and demographic groups.
Privacy advocates fear customers from minority backgrounds could face a greater risk of false matches, exposing some people to repeated suspicion while they are simply trying to shop.
Tom Sulston, head of policy at Digital Rights Watch says the problems with facial recognition could not be separated from the public places in which it was being introduced.
“There are very few responsible uses of facial recognition, and none that involve its use in public places. The technology is privacy-invasive, unreliable, and fundamentally racist.” said Sulston
The effects may extend well beyond customers because supermarket employees spend entire shifts inside the same monitored environment.
Technology installed to identify threatening customers could also be adapted to record where workers go, how long they remain in certain parts of a store and how quickly they complete tasks.
Sulston also warned that without firm restrictions, facial recognition could become another layer of workplace monitoring and performance management.
“Facial recognition could easily be repurposed to monitor employee activity and behaviour, and used to manage their performance – including tracking toilet breaks or the speed at which employees work.”
Supermarkets may argue that employee monitoring and customer profiling sit outside the purpose of a safety trial, but installing facial recognition cameras creates an identification system capable of much wider use.
Once the infrastructure exists and biometric information is being collected, commercial pressure could encourage retailers to use it for purposes that go well beyond the original justification.
Coles’ relationship with defence technology company Palantir has added to those concerns because Palantir develops systems that connect and analyse large datasets.
There is no evidence that Coles is currently linking facial recognition records with loyalty programme information, but the technical possibility has prompted questions that deserve answers before the technology is expanded.
If those datasets were connected in the future, a retailer could potentially examine how identifiable customers move through a store, which products attract their attention and how those movements relate to their previous purchases.
Information gathered under the banner of staff safety could then become part of a much larger customer profiling and marketing operation.
The issue comes after findings by the Privacy Commissioner concerning Bunnings’ use of facial recognition technology.
Privacy advocates say the case exposed weaknesses in Australia’s privacy protections and showed how corporations can deploy powerful biometric systems before the law has properly addressed their effect on personal privacy and dignity.
Consent remains one of the hardest questions because a sign placed at a supermarket entrance does not necessarily amount to a meaningful choice.
A person buying dinner, collecting medicine or shopping for their family may feel they have little option other than entering the store and accepting whatever scanning takes place inside.
There are also unanswered questions about who is placed on a watchlist, what evidence is required and how long facial records remain in the system.
Customers need to know whether a mistaken identification can be challenged, who reviews those complaints and whether biometric information is shared with outside companies or law enforcement agencies.
Without clear rules and independent oversight, the harm caused by an incorrect match may fall almost entirely on the person who was wrongly identified.
The supermarket retains the technology and its records, while the customer may leave without even knowing why security staff treated them with suspicion.
Sulston questioned why Australians should be expected to accept this level of monitoring in supermarkets and workplaces.
“Why are Coles and Woolworths treating their customers and staff like criminals? Why should we accept that in our public spaces and workplaces?”
Coles and Woolworths have tested facial recognition technology, but neither has confirmed whether it will be introduced across its stores.
The Australian Financial Review reported both retailers had “conducted early testing” as part of efforts to combat retail crime.
The trials follow the Bunnings privacy dispute, which ended with the hardware retailer winning a legal battle in February over its use of AI-powered facial recognition.
In 2024, the Privacy Commissioner found Bunnings had breached privacy laws by scanning hundreds of thousands of customers’ faces without proper consent.
The Administrative Review Tribunal later ruled the technology could be used in limited circumstances to address retail crime and protect staff and customers from violence and abuse.
That decision may give supermarkets a legal pathway forward, but serious questions about consent, accuracy and biometric privacy remain unanswered.
Digital rights campaigners are calling for a moratorium on supermarket facial recognition until legislation places strict limits on where it can be used, which data can be kept and whether information can later be repurposed.
Once facial surveillance becomes a routine part of buying groceries, pulling it back may prove far harder than stopping it before the cameras become part of everyday shopping.

