WA Police are scanning faces in Perth. The PRIS Act lesson for your business

By Moe Chizari / Aug 1, 2026 / Epic IT News

In late June, a marked police van at Mirrabooka bus station scanned the faces of everyone who walked past and checked them against a watchlist in real time. One woman was flagged for failing to appear in court and arrested on the spot. Western Australia is the first jurisdiction in the country to run live facial recognition on public crowds, and it is happening here in Perth, with further deployments in the CBD and Joondalup through July.

The trial’s early numbers are striking. But the detail that matters most for Perth business owners is one of timing: the cameras switched on nine days before the Privacy and Responsible Information Sharing Act 2024, the PRIS Act, took effect on 1 July. WA’s new privacy law is now in force, it reaches further into the private sector than most businesses realise, and the facial recognition trial is a live demonstration of what happens when powerful technology arrives before governance does. Both halves of that story affect you.

What the WA Police facial recognition trial involves

The WA Police live facial recognition trial runs cameras from a marked van in designated public spaces, comparing passing faces against a watchlist. Commissioner Col Blanch has said the list holds around 4,000 people with outstanding arrest warrants, plus registered child sex offenders and missing persons. Faces that do not match are pixelated on the operator’s screen and the biometric data is deleted immediately. Each deployment requires sign-off from a superintendent or above, and an alert alone is not grounds for arrest; an officer reviews every match before approaching anyone.

In its opening weeks the system scanned more than 130,000 faces, generated 33 alerts and contributed to 19 arrests, along with two welfare checks. Two of those alerts were false matches, caught by the human review step. Whatever your view on the technology, the safeguards are specific and documented: a defined watchlist, a conservative match threshold, human review before action, immediate deletion of non-matches, and senior authorisation for every deployment. Hold that list in your head, because we are coming back to it.

The sequence problem: capability first, governance second

Here is the part of the story that did not make the police media releases. The trial began on 22 June 2026. The PRIS Act’s main privacy provisions commenced on 1 July 2026. And WA’s Office of the Information Commissioner confirmed in July that it was not consulted on the design of the trial. The state’s independent privacy regulator found out about Australia’s first live biometric surveillance program roughly the way the public did.

We are not here to prosecute WA Police. The trial is overt, signposted, and by the published numbers it is catching people with outstanding warrants. But the sequence is the lesson: a genuinely powerful capability went operational before the governance framework designed to oversee it was in force, and without the regulator in the room. If that pattern sounds familiar, it should. It is exactly how AI is being adopted inside most Australian businesses right now. Our audits consistently find 40% to 60% of knowledge workers using AI tools no one approved, and the governance conversation happens after deployment, if it happens at all. When a police force with lawyers, standard operating procedures and a commissioner fronting the media still ends up ahead of its own oversight, an SMB with no AI governance framework has no chance of getting the sequence right by accident.

The PRIS Act is now in force, and it does not stop at government

Most Perth business owners have filed WA’s new privacy law under “government problem”. That is a mistake. The PRIS Act binds WA public entities, but it also binds contracted service providers: businesses that deliver services to or on behalf of a WA public entity under a State services contract, where that contract includes a clause applying the Act’s privacy provisions. Subcontractors under those arrangements are captured too. The Office of the Information Commissioner has published guidance on exactly how the Act applies to contracted service providers.

Three details deserve your attention. First, there is no small business exemption for contracted service providers: sole traders and small firms signing State services contracts with a PRIS compliance clause carry the same obligations as a government department. Second, expect those clauses to become standard, because where a contract lacks one, the public entity wears liability for its provider’s conduct, so agencies have every incentive to include them. Third, the Act’s notifiable information breach scheme commences on 1 January 2027, adding a state-level breach reporting obligation on top of the federal scheme.

If your business supplies WA government, local government, public schools or universities, in any capacity from consulting to construction to cleaning, the compliance clause in your next contract renewal quietly changes your privacy obligations. This sits alongside the federal Privacy Act, which already applies to most businesses turning over more than $3 million. Between the two, the era of Perth SMBs treating privacy as someone else’s problem ended on 1 July.

Your business is closer to biometrics than you think

It is tempting to read the facial recognition story as something only police do. Look around your own operation first. Fingerprint time and attendance clocks. Facial recognition door access. AI-enabled CCTV that counts, tracks or identifies people in your store or on your site. Voice identification in phone systems. All of these collect biometric information, which the federal Privacy Act treats as sensitive information, the category with the strictest handling rules and, in general, a consent requirement.

Now revisit the safeguards WA Police published for their trial: a defined purpose, a limited watchlist, a match threshold, human review before any action, immediate deletion of non-matches, and named senior accountability for every deployment. That is, honestly, a better governance checklist than most private biometric deployments we encounter. If a fingerprint clock vendor installed your system, ask yourself who in your business can answer the questions the police had to answer publicly: what exactly is collected, where is it stored, when is it deleted, who reviews errors, and who signed off. If nobody can, the technology got ahead of the governance, and you are running the same experiment the regulator was locked out of, just without the media scrutiny.

What the PRIS Act and the trial mean for Perth businesses

Put the two stories together and the direction for Western Australia is clear. Surveillance-grade AI is now operationally normal, a state privacy regulator with real enforcement powers now exists, and the compliance perimeter has expanded to include private businesses connected to government work. The gap between what technology can do and what your governance covers is now a commercial risk with a regulator attached, not a philosophical debate. For businesses in legal, health, education and anyone in the WA government supply chain, that gap needs closing this financial year, not next.

What you should do now

Pull out your State services contracts and look for the privacy clause. If your business services WA government at any tier, including as a subcontractor, check whether your contracts reference the PRIS Act or its Information Privacy Principles. If they do, you became an IPP entity on 1 July and your handling of personal information under those contracts is now regulated by the state.

Inventory every system that collects biometric or personal information. Time clocks, door access, cameras, call recording, AI tools. For each one, document what is collected, where it lives, how long it is kept, and who approved it. This is a lightweight version of the privacy impact assessment the PRIS Act now mandates for public sector projects, and it is the foundation your cyber security programme and privacy obligations both stand on.

Get the governance in place before the next deployment, not after. The lesson from the trial is sequence. Whether the next capability in your business is an AI tool, a biometric system or a new data flow to a vendor, the vetting comes first. Our AI governance onboarding builds the register, the policy and the approval process so you never have to explain why the technology went live before anyone was watching. Contact us on 1300 EPIC IT to get started.

Frequently asked questions

Is WA Police using facial recognition?

Yes. WA Police began a live facial recognition trial on 22 June 2026, the first of its kind in Australia. Cameras on a marked van scan faces in public spaces and compare them against a watchlist of people with outstanding warrants, registered sex offenders and missing persons. Deployments have run in Perth, Mirrabooka and Joondalup, with non-matching faces pixelated and deleted immediately.

What is the PRIS Act?

The Privacy and Responsible Information Sharing Act 2024 (WA) is Western Australia’s first comprehensive privacy law. Its main privacy provisions, including Information Privacy Principles and mandatory privacy impact assessments, commenced on 1 July 2026, with a notifiable breach scheme starting 1 January 2027. The PRIS Act is overseen by WA’s Office of the Information Commissioner.

Does the PRIS Act apply to private businesses?

It can. The PRIS Act applies to contracted service providers: businesses (and their subcontractors) delivering services to or on behalf of WA public entities under State services contracts that include a privacy compliance clause. There is no small business exemption, so sole traders and small firms with these clauses in their government contracts carry full obligations.

Is facial recognition legal in Australia?

There is no single national law governing facial recognition. Police use is decided jurisdiction by jurisdiction, which is why the WA trial is an Australian first. For businesses, biometric information is classified as sensitive information under the federal Privacy Act, which imposes the strictest handling requirements and generally requires consent to collect.

Do WA businesses need to worry about privacy compliance now?

Yes, on two fronts. The federal Privacy Act already covers most businesses turning over more than $3 million, and the PRIS Act now adds state-level obligations for businesses in the WA government supply chain. Any business collecting biometric data through time clocks, door access or AI cameras should document what is collected, where it is stored and who approved it.

Is your governance ahead of your technology?

Our Perth-based team maps every AI tool and data collection point in your business and builds the governance to match. Book a free AI readiness review today.

Book a Free Assessment

About the Author
Written by Moe Chizari, Chief Executive Officer of Epic IT, a managed IT, cyber security and AI partner for Australian mid-market businesses, with offices in Perth, Sydney and Brisbane. Moe brings 17 years across financial markets, treasury and technology, including five years at Bravura Solutions running enterprise software delivery and five years inside Group Treasury at Westpac and Macquarie leading APRA-regulated programmes (APS-117 IRRBB, APS-210 LCR & Capital Transformation). He holds a Bachelor of International Business from RMIT University, is a certified Project Management Professional (PMP), and an AFMA Diploma of Financial Markets graduate.

Further Reading

Previous

Lifeline data breach: five things every Australian charity should check this week

Return to News
Back to News
Next

Why a Microsoft Partner likes what it sees in Microsoft Foundry and open weight models