Compliance13 July 2026 · 4 min read

A venue operator's compliance checklist for the NSW facial recognition Code

The Code reads clearly enough; turning it into actions on the ground is another job. Eight practical steps to work through with your team and your provider, from the Privacy Impact Assessment to staff training records.

The NSW Code of Practice for facial recognition reads clearly enough, but turning it into actions on the ground is another job. It took effect on 18 March 2026 and is voluntary for now. If your venue already uses facial recognition for self-exclusion, or you are about to, here is a practical checklist that translates the Code into steps you can work through with your team and your provider.

1. Start with a Privacy Impact Assessment

Before the system goes live, document a Privacy Impact Assessment (PIA). It should explain why facial recognition is necessary, why it is proportionate to the problem of gambling harm and whether any less intrusive option would do the job. This isn't box-ticking. It is the foundation the rest of your compliance rests on. It is also one of the first things a regulator will look for. Ottica assists its clients in navigating the complexities of a PIA, so venues aren't left working through it alone.

2. Get your privacy policy right

Your venue's privacy policy must specifically address biometric information: what you collect, why, how it is stored, who can access it and when it is destroyed. A generic policy that doesn't mention biometrics won't cut it. The OAIC publishes guidance on building an Australian Privacy Principles policy that's worth following. We give Ottica clients ready-made biometric wording to fold into their existing policy.

3. Put up clear signage

Patrons need to know facial recognition is in use before they're scanned. That means prominent, easy-to-read signage at the points where the technology operates, typically venue and gaming-area entrances. Passive or hidden notice isn't enough; the Code expects transparency that a reasonable patron would actually notice.

4. Lock down your data

The Code expects patron information to be stored securely, with controlled access so only authorised staff can reach it and clear rules on how it may be used. Just as important is deletion: once data is no longer needed, it should be removed. A good system makes both the easy default, keeping data on-site or in-country then discarding non-matches automatically rather than hoarding them. Onshore storage is not spelled out as a requirement, but it takes a whole category of questions out of your privacy assessment.

5. Monitor accuracy and keep records

The Code expects ongoing monitoring of how the system performs, including false positives (wrongly flagging someone) and false negatives (missing a real match). Keep records of accuracy and of any incidents. This is what lets you show the system is working as intended, then fix it if it isn't.

6. Train your staff, then prove it

Authorised staff should be trained before they access the system, covering how it works, their privacy obligations and exactly how to respond to a match. Retain training records for at least five years. Practical drills matter more than a slideshow: responding to an alert, verifying identity, escalating an issue.

7. Define the staff response to a match

A match is the start of a human process, not the end.

Decide in advance what happens when the system flags someone: who is alerted, how identity is confirmed, how the patron is approached with discretion and how it is all logged. Clear, consistent responses protect both the patron and your venue.

8. Lean on your provider for the technical parts

Much of the Code's technical detail is meant to be answered by your facial-recognition provider, through a technical checklist covering how the system is installed, maintained and secured. Use that. A good provider will help with your PIA, confirm where and how data is handled then take the technical compliance load off your floor staff. At Ottica the checklist sits in our dashboard: we handle most of the items as your provider, then guide you through the ones that sit with your venue. Our facial-recognition platform is built in-house in Australia and already runs across hundreds of venues, so we can speak directly to how each requirement is met. Accountability for the system still rests with the venue, which is why the assistance matters more than the paperwork.

Where this is heading

The Code is voluntary today. The NSW Government has committed to mandating facial recognition in hotels and clubs with gaming machines once the statewide exclusion register is operating. Working through this checklist now means you're not starting from scratch when the rules tighten. If you'd like this mapped to your specific setup, we're glad to walk through it with you.

Current as at July 2026. This article is general information, not legal advice. Check the current version of the Code before acting on it.

Sources

Liquor & Gaming NSW — Code of Practice: Facial Recognition Technology in Hotels & Clubs. Lander & Rogers — NSW takes a governance-first approach to facial recognition technology. NSW Government — ministerial release on the facial recognition code.

See it on your own footage
A private, on-premise demo — tuned to your venue.
Request a quote
Let's build it

See it run on your own footage.

Book a private demo and we will show you Ottica AI working on real venue scenarios — entirely on-premise, with nothing leaving your site.