The privacy risks of facial recognition in apartment building entry systems
The convenience of walking up to your apartment building and having the door unlock as it recognises your face feels like something out of a tech brochure. In cities like Sydney and Melbourne, where high-density living is booming, body corporates and strata managers are increasingly installing biometric entry systems to replace fobs, keys, and intercoms. Yet beneath the polished marketing lies a web of data collection, storage, and sharing that most residents never consent to in any meaningful sense. Readers who want a broader view of how these trade-offs tend to unfold can browse the main archive for related essays.
Australian apartment dwellers are accustomed to strata meetings, levies, and the occasional saga over a new rubbish chute. Adding a camera that logs your face every time you come home is a different kind of upgrade. It turns the lobby into a surveillance point, your face into a credential, and your daily movements into a dataset. The trade-off feels less like progress and more like a quiet erosion of the privacy Australians still assume they have at home.
This piece walks through how these systems actually function, what happens to the images and templates they generate, and where the legal lines currently sit under Australian law. It also looks at the practical steps residents can take when their building committee proposes the technology, and why the choice between convenience and control is rarely as simple as a lobby kiosk suggests.
How facial recognition entry systems work
Most facial recognition entry setups rely on a camera mounted near the front door, paired with software that maps the geometry of a face and converts it into a mathematical template. When you approach, the system compares the live capture against stored templates and grants access if there is a match. From a user perspective, the experience is seamless. Behind the scenes, however, the system is constantly deciding what counts as a face, what counts as a match, and what to do with the images it rejects.
Templates, not photographs, are often what gets stored, but that distinction is less comforting than it sounds. A template can be reverse-engineered, and any image submitted during enrolment is usually retained alongside it. Vendors frequently store enrolment photos on cloud servers, sometimes overseas, and access logs often record timestamps, entry directions, and confidence scores. A resident leaving for work at 8:47 am on a Tuesday generates a data point that, aggregated over months, paints a picture of their routine.
Many systems also retain footage of every person who passes by, even those who are not residents. Visitors, couriers, cleaners, and tradies get logged too. In an inner-city Melbourne building near Fitzroy, a courier delivering a flat white and a parcel would be captured, timed, and possibly matched against databases the resident never agreed to share with.
What happens to your face once it is scanned
The enrolment process usually asks residents to submit a clear photo or stand in front of a camera while the system registers them. Once that is done, the face template becomes the key. The question of who owns that template, where it is backed up, and whether it is shared with third parties is where most privacy concerns begin. Vendors often retain the right to use aggregated data for product improvement, and some contracts allow law enforcement access without a warrant.
In strata buildings, the arrangement is layered. The owners corporation enters a contract with the technology provider, the strata manager oversees day-to-day operations, and residents are looped in only at a meeting that few attend. When a body corporate manager in Brisbane signed a deal with a biometric vendor, residents discovered the fine print only after the cameras were already in the lobby.
Data breaches remain a real risk. Facial templates are immutable in a way passwords are not. If a database is compromised, you cannot rotate your face. A 2023 incident involving a biometric security provider exposed millions of face hashes, and similar breaches have occurred since. Australians who assumed their face was safe with a single provider learned that exposure is permanent.
The legal landscape in Australia
Australia does not yet have a dedicated biometric privacy law. Instead, facial recognition entry systems fall under the Privacy Act 1988 and the Australian Privacy Principles, which were strengthened by amendments in late 2024. The APPs require organisations to notify individuals about the collection of personal information, limit its use to the stated purpose, and take reasonable steps to protect it. Facial templates, in most interpretations, count as personal information.
The Office of the Australian Information Commissioner has signalled that biometric data attracts a higher standard. Yet enforcement against a body corporate or its technology vendor is rare, and the penalties, even after the recent reforms, are modest relative to the scale of data being collected. The federal government has floated a statutory tort for serious invasions of privacy, but the proposal remains on the drawing board.
State-level laws add another layer. In NSW, the Surveillance Devices Act 2007 restricts the use of listening devices and optical surveillance in residential contexts, but the line between building security and individual privacy is blurry. Victorian bodies corporate operate under the Owners Corporations Act 2006, which gives committees wide latitude to install security measures, with limited resident veto. Residents who object often find the legal avenues narrow and slow.
Security and accuracy concerns
Facial recognition software is not infallible. Studies consistently show higher error rates for women, people of colour, and older Australians. An algorithm that struggles to recognise a retiree in a Surry Hills apartment may lock them out at the worst possible moment, while a stranger who happens to match a stored template can be waved through. False acceptance rates may be tiny in vendor brochures, but the consequences of a single false match at a front door are not.
Spoofing is another concern. Photographs, videos on phones, and even printed masks can fool poorly configured systems. Some vendors offer liveness detection, requiring a blink or a turn of the head, but these features vary in reliability. A building that prides itself on security may be running a system that accepts a printed image held in front of the camera.
Beyond accuracy, there is the question of network security. Cameras connected to building management systems have been hacked, exposing live feeds and stored footage. When that feed includes the faces of every resident and visitor, the breach extends far beyond the building. In a country where apartment living is the norm for many young professionals and downsizers, the blast radius is significant.
The social cost of always being watched
The chilling effect of surveillance is well documented, even when the surveillance is mundane. Residents who know their face is logged at every entry may think twice before having a friend stay over, ordering a late-night food delivery, or returning home after a breakup. The lobby becomes a checkpoint that records the rhythm of private life. For renters in particular, who often have less say in building decisions, the surveillance is imposed rather than chosen.
There is also a fairness issue. Body corporate committees tend to skew older and owner-occupied, while renters, students, and shift workers form a large portion of residents in many Australian suburbs. A system optimised for the convenience of daytime residents can inconvenience night-shift workers coming home at dawn, and create a permanent record of their comings and goings that they never agreed to.
Trust between neighbours can erode as well. When facial data is collected for security, it is tempting for building managers to ask whether a particular resident was home on a certain night. The answer, drawn from access logs, is now a query away. The presumption of privacy that once shielded residents from each other begins to dissolve.
Privacy-preserving alternatives
None of this means buildings must abandon modern access control. PIN codes, encrypted fobs, mobile credentials, and QR passes can offer security without biometric harvesting. Token-based systems can be issued, revoked, and rotated, and they leave behind only a log of the token, not the person. For many buildings, the upgrade that delivers genuine security is a move away from easily copied keys, not a move toward face scanning.
Where biometrics are already in place, privacy-by-design principles can reduce the risk. On-device processing, where the template never leaves the camera, eliminates cloud storage. Local-only matching, short retention windows, and clear deletion policies can align the system with Australian Privacy Principles. Some vendors now offer opt-in modes where residents choose between biometric and token access.
The technology is not inherently the problem. The contracts, defaults, and consent processes are. A building that asks residents to opt in, explains what is stored, and offers a clear alternative creates a different kind of environment than one that installs cameras and expects acceptance. The same biometric verification that screens patrons at gaming venues, as discussed in this review of payout-focused casinos, is now being pitched to your building committee, often with the same vague assurances about data being safe.
What residents can do
If your building is considering facial recognition, ask for the privacy impact assessment before any vote. Read the contract the body corporate intends to sign, paying attention to data retention, third-party sharing, and overseas storage. Ask whether on-device matching is available, and whether the vendor has suffered any breaches. The model rules for NSW and Victorian strata schemes allow residents to requisition general meetings, which can be a useful tool.
Request an alternative. Token-based or PIN access is rarely controversial, and most vendors offer it alongside biometrics. If the building has already installed the system, you may still be able to opt out, although this varies. Document your concerns in writing to the strata manager and the owners corporation, as paper trails matter if a privacy complaint is later made to the regulator.
For a deeper look at the broader pattern behind these choices, this essay on giving up privacy traces how the erosion tends to happen gradually, not all at once, and why each small concession feels harmless in isolation.
The pitch for facial recognition in apartment buildings is that it is safer, faster, and more modern. The reality is that it turns the threshold of your home into a data pipeline, and asks you to trade a face you cannot change for a convenience that is easy to replicate without one. Before the next AGM rolls around and a shiny new system is waved through, ask the hard questions, demand the alternatives, and remember that the most private place in a dense city is still meant to be your own front door.