CCTV/Plate recognition data collection

See also Trespass page.

Preface, Key OAIC sections (Australian Privacy Principles, APP):

  • APP 3.3 (Sensitive information — consent required): An APP entity must not collect sensitive information about an individual unless the individual consents and the collection is reasonably necessary for the entity’s functions/activities, subject to limited exceptions. OAIC
    Biometrics used for identification is generally treated as sensitive information in Australian privacy law (OAIC guidance consistently treats facial recognition/biometric templates as sensitive/high-risk and emphasises consent). OAIC+1

  • APP 3.1 (Reasonably necessary limitation): Even for non-sensitive personal information, an organisation may only collect personal information if it is reasonably necessary for its functions/activities (and agencies have a similar “reasonably necessary / directly related” test). OAIC
    This is a constraint you can point to when challenging “collect everything” practices.

  • APP 3 (Lawful and fair collection; covert collection concerns): OAIC materials stress that collection must be by lawful and fair means, and that collecting personal information covertly without an individual’s knowledge is likely to be unfair. OAIC+1

  • APP 5 (Collection notice / awareness): Requires reasonable steps to notify you (or ensure you’re aware) of key matters at/before collection (or as soon as practicable), including whether collection is required/authorised by law, purposes, disclosures, etc. OAIC+1
    This is the “you must be told what’s happening” lever.

In plain terms, you can refuse consent. If the information is sensitive information, APP 3.3 generally means the organisation can’t collect it without your consent, unless a specific exception applies.

Option 1

 

NOTICE TO CCTV / ANPR OPERATORS
No Collection/use/disclosure/photography (trespass)
Trespass damages 32oz gold per trespass

CCTVTrespass (docx of the above message on an A4 page)
CCTVTrespass1 (pdf of above message on an A4 landscape)

Print, laminate and slide down your windscreen, message displays on the top section, lower section is blank.

Option 2

Or make your own message on an A4 page. Stick it on your dashboard or write it on a teeshirt.

Option 3

Another alternative, stickers on your bonnet and/boot, see photos below.

Option 4

Or wear a No trespass teeshirts (and hoodies) available from Teespring

Front:
NO-TRESPASS
Tort of Trespass actionable
No authority to detain without lawful warrant for execution of the King’s process.
The occupier of this property has the right not to be unlawfully invaded.
Trespass penalties apply of $100,000 per tort, of each offender.
Plenty v Dillon [1991] 171 CLR 635 | Romani v State of New South Wales [2023] NSWSC 49
GARDINER v DOERR [2022] QSC 188 | WILDEN v JENNINGS (no 1) [2021] NSWDC 705
Front:
Biometric Collection Denied
– Release Available upon 32 oz Gold ExchangeBack:
Biometric Collection Denied
– Release Available upon 32 oz Gold Exchange
Front:
Legal Notice
NO-TRESPASS
Implied right of access revoked
No Consent Is Granted
for Photography, Recording
or Facial Recognition
Back:
No Photo. No Recording. No Facial ID.
Consent Not Granted.
Trespass penalties apply of 32 oz gold per trespass.

 

Option 5

Do nothing, comply, have your biometric data collected, be tracked, traced, monitored, be a marketing target and pay the penalties.

Allowing unsolicited biometric collection (like faceprints, fingerprints, voice templates) or ANPR/number-plate capture can permanently increase your exposure to tracking and misuse: once captured, these identifiers can be linked to you (or your vehicle), combined with other datasets, used for profiling and monitoring over time, shared cross-border, or leaked in a breach—and unlike a password, you can’t meaningfully “change” your face, fingerprints, voice, or historical movement trail. Under Australian privacy law, biometric data is treated as high-risk “sensitive information” and generally requires consent to collect unless a specific exception applies, and organisations must notify and handle personal information transparently, securely, and within limits on use and disclosure.

Last Updated 8 months ago

Views: 609

Posted by Jillian