We sell people counting for a living, so take this post for what it is: one vendor's working understanding of the Australian legal landscape, written for the facilities managers, legal teams and privacy officers who keep asking us the same question. It is general information, not legal advice; your counsel gets the final word. The short version: counting is regulated by what your system collects and keeps, not by what the brochure calls it. The same "occupancy sensor" line item can be trivially compliant or a live legal risk depending on architecture.
01 · THE PRIVACY ACT QUESTION: IS A COUNT PERSONAL INFORMATION?The Privacy Act question: is a count personal information?
The Privacy Act 1988 and its Australian Privacy Principles regulate personal information: information about an identified individual, or one who is reasonably identifiable. The number 14, as in "14 people are in the library right now", is not about any identifiable individual. A pure count, with no image, no biometric template, no device identifier attached, sits outside the personal information regime because there is no individual in the data at all.
The trap is that most counting systems do not produce a pure count. They produce a video recording, and then derive a count from it. The moment footage of recognisable people is recorded or transmitted, that footage is personal information, and the full APP framework applies to it: collection notices, storage security, access rights, retention limits, the lot. The count was never the compliance problem. The footage was.
02 · THE NEW PRESSURE: A STATUTORY TORT WITH TEETHThe new pressure: a statutory tort with teeth
Since 10 June 2025, Australia has a statutory tort for serious invasions of privacy. Any individual can now sue over an intentional or reckless intrusion upon their seclusion, recording private activities is the canonical example, where they had a reasonable expectation of privacy and the invasion was serious.
For building operators this changes the risk calculus around stored footage in two ways. First, the claimant no longer needs a regulator to act; employees, patients and visitors can bring the action themselves. Second, in workplaces the tort operates alongside the Privacy Act's employee-records exemption, which means "the Privacy Act doesn't cover staff records" is no longer the end of the analysis for workplace monitoring. A camera network hoarding footage of staff and visitors is a standing inventory of exactly the material the tort is about. A system that never records anyone has nothing in the inventory.
03 · THE STATE LAYER: SURVEILLANCE DEVICES AND WORKPLACE NOTICEThe state layer: surveillance devices and workplace notice
Two more bodies of law sit underneath the federal regime, and they are where camera-adjacent projects usually stall:
- Surveillance devices legislation. Every state and territory regulates optical surveillance devices, with rules that mostly bite on recording private activities without consent. Sensors in genuinely public or common spaces counting anonymously sit at the low-risk end, but the statutes are drafted around devices, not data, so the review still happens.
- Workplace surveillance rules. New South Wales and the ACT require notified, visible workplace surveillance (or covert-surveillance authorisation), and Victoria's consultation obligations under occupational health and safety law point the same direction. If a sensor watches a space where people work, tell them, in writing, before it goes in. That obligation applies to an anonymous counter too, and meeting it is dramatically easier when the honest answer to "what does it record about me" is "nothing, it cannot identify you".
Our position: transparency is not a compliance tax to minimise, it is the deployment strategy. Signage and a one-page staff notice cost nothing when the architecture has nothing to hide, and they pre-empt the workplace-relations conversation that kills stored-footage projects. The same logic is why anonymous systems survive procurement review that camera systems fail.
04 · TWO EDGE CASES WORTH KNOWINGTwo edge cases worth knowing
Wi-Fi and Bluetooth counting is not automatically anonymous. MAC addresses, even hashed, can be persistent device identifiers, which drags "passive" Wi-Fi counting back toward personal-information territory while also delivering poor accuracy. We covered both failures in why MAC counting breaks.
Automated decision-making disclosure arrives in December 2026. The first tranche of Privacy Act reforms requires privacy policies to disclose automated decisions made using personal information from 10 December 2026. A system making decisions from anonymous counts (dim the lights, open the second entrance) is not making them with personal information, but if your stack mixes counts with badge data or booking identities, that mixture belongs in the disclosure review.
05 · THE CHECKLIST WE HAND TO LEGAL TEAMSThe checklist we hand to legal teams
Counting people is legal everywhere in Australia. Recording people, in order to count them, is where every legal question on the list comes from.
When a review lands on your desk, these five questions resolve most of it:
- Is any image or biometric of a person recorded, stored or transmitted? If no, the personal-information analysis largely ends here. If yes, run the full APP program.
- Can any output identify or single out an individual, directly or by combination with other data you hold? Counts and densities cannot; trajectories, device IDs and face templates can. Our answer is architectural: no biometrics, no demographics, no exceptions.
- Have the people in the space been told? Workplace notice rules, and plain decency, want visible signage and staff notification regardless of how anonymous the system is.
- What would a tort claimant point to? If there is no recording of anyone, there is no intrusion-by-recording claim to construct.
- What does the vendor contract say leaves the site? Verify it against the network traffic, not the brochure. We document ours and invite the audit.
The pattern across all five: the legal exposure tracks the data, and the data tracks the architecture. Choose the architecture where the sensitive record never exists, and "is this legal" becomes one of the shortest conversations in the project. If your legal team wants the deeper version, our privacy-by-design documentation is written for exactly that review, and we will walk them through it.
