Your Face Is the New Match Ticket: Facial Recognition, Privacy and the Law of Sport

Facial recognition technology (‘FRT’) is increasingly attractive to sporting organisations seeking to strengthen stadium security, identify banned spectators and streamline entry.  However, the recent controversy at Rome’s Olympic Stadium demonstrates that technological capability does not necessarily equal legal permission.  

Between 2021 and 2025, the stadium reportedly operated an FRT system that captured seven photographs of each spectator entering the venue and retained them for seven days alongside ticket-holder information. Following an incident, the system could compare a person of interest against images collected from spectators. Italy’s data protection authority, the Garante, ultimately intervened over the absence of a sufficient legal basis,  and the Interior Ministry suspended the technology.[1]  

For Australian sport, the controversy raises a similar question: how far can sporting organisations monitor their own fans in the name of security?  

Is Your Face Part of the Ticket? 

Under Australian privacy law, facial recognition involves substantially more than ordinary CCTV. The Privacy Act 1988 (Cth) treats biometric information used for automated biometric identification or verification as “sensitive information.”[2] Consequently, Australian Privacy Principle (‘APP’) 3  generally requires an organisation collecting such information to establish that the collection is reasonably necessary for its functions or activities and obtain the individual’s consent, unless an exception applies.[3]  

The requirement is particularly difficult in sport. The Office of the Australian Information Commissioner (‘OAIC’) considers valid consent to require that an individual is adequately informed and that consent is voluntary, current and specific. Its facial-recognition guidance also stresses transparency about collection and the serious privacy impacts involved.[4]  

Imagine a supporter who has already purchased a Grand Final ticket and travelled to the stadium, only to discover that facial scanning is required for entry. If refusing biometric collection effectively means missing the match, whether consent is genuinely voluntary becomes questionable. Sport therefore creates an unusual privacy problem: stadium operators deal with tens of thousands of people simultaneously, while the technology designed to efficiently manage those crowds can require collection of particularly sensitive information.  

Does Stadium Security Justify Scanning Everyone? 

Security provides the strongest argument for FRT. Sporting venues may need to prevent violence, identify banned spectators and respond rapidly to serious incidents. However,  Australian privacy law does not equate a legitimate objective with unlimited means.  

The OAIC’s APP 3 guidance treats “reasonably necessary” as an objective standard and emphasises the circumstances surrounding collection. Its current FRT guidance asks whether the technology is a suitable response, whether less privacy-intrusive security measures are available, and whether the benefits outweigh the serious privacy impacts.[5]  

This issue became particularly important following Bunnings Group Limited and Privacy Commissioner (Guidance and Appeals Panel) [2026] ARTA 130. The Tribunal held that  Bunnings did not breach APP 3.3 because a permitted general situation applied to its collection through FRT. Still, it otherwise affirmed findings concerning failures in privacy governance and notification.[6] Although Bunnings concerned retail rather than sport, it provides a useful Australian framework for high-volume public environments. 

Applied to sport, this creates an important distinction. Using FRT narrowly to address serious security threats may be easier to justify than systematically processing the biometric information of every supporter entering a 50,000-seat stadium. The legal question is therefore not simply whether FRT makes sport safer, but whether mass biometric surveillance is necessary and proportionate to the particular sporting risk it seeks to prevent.  

Does Watching Sport Mean Giving Up Privacy? 

Australian sports law already demonstrates that the public and commercial nature of professional sport does not automatically eliminate confidentiality interests.  

In Australian Football League v The Age Company Ltd (2006) 15 VR 419, the Supreme  Court of Victoria considered confidential information identifying AFL players who had tested positive under the AFL’s Illicit Drugs Policy. The Court granted protection against publication, and its treatment of public-interest arguments illustrates that information does not lose legal protection merely because it concerns matters attracting substantial public interest.[7] The case also shows that rumours and online discussion do not necessarily place otherwise confidential sporting information into the public domain.[8]  

FRT transfers that tension from players to fans. Spectators voluntarily enter a highly monitored commercial environment, and sporting organisations have legitimate interests in regulating access and protecting participants. But purchasing a ticket does not necessarily amount to accepting every subsequent collection or use of personal information. The OAIC’s FRT guidance additionally directs organisations to address transparency, accuracy and bias, data security, and deletion or de-identification.[9]  

The Rome controversy therefore represents more than a European privacy dispute. As  Australian stadiums become increasingly “smart”, sports law must determine where legitimate venue management ends, and disproportionate surveillance begins. The question for the future is simple but difficult: should watching your team play require allowing your team to watch you?  

References 

[1] Pinsent Masons, ‘Sports venues face growing scrutiny over use of facial recognition  technology’ (18 September 2026).  

[2] Privacy Act 1988 (Cth) s 6(1) (definition of ‘sensitive information’).  [3] Privacy Act 1988 (Cth) sch 1, APP 3.2–3.4.  

[4] Office of the Australian Information Commissioner, ‘Facial Recognition Technology: A  Guide to Assessing the Privacy Risks’ (updated 2026).  

[5] Office of the Australian Information Commissioner, Australian Privacy Principles  Guidelines, ch 3; Office of the Australian Information Commissioner, ‘Facial  Recognition Technology: A Guide to Assessing the Privacy Risks’.  

[6] Bunnings Group Limited and Privacy Commissioner (Guidance and Appeals Panel)  [2026] ARTA 130.  

[7] Australian Football League v The Age Company Ltd (2006) 15 VR 419, [72]–[94].  [8] Australian Football League v The Age Company Ltd (2006) 15 VR 419, 431.  [9] Office of the Australian Information Commissioner, ‘Facial Recognition Technology: A  Guide to Assessing the Privacy Risks’ (updated 2026).

Photo by Arthur Mazi on Unsplash

Next
Next

The Costliest Free Agency Signing in Sporting History? A Snapshot of NBA Salary Caps and the LA Clippers Scandal