Illinois passed the Biometric Information Privacy Act in 2008, and it remains the strongest such law in the country. It requires written notice and a signed release before a company captures a face template, mandates a published retention and destruction schedule, and gives individuals a private right to sue.
Texas and Washington have narrower statutes. New York City requires disclosure signs. A few localities, including Portland, have banned private use in places of public accommodation outright.
In the large majority of states, none of this applies. A retailer may scan every face entering a store, match it against a watchlist, and retain the templates indefinitely without notifying anyone.
The distinction that matters legally is not whether a camera recorded you but whether a system converted your face into a measurement. Security cameras have been ordinary for decades and are governed by general privacy law. A face template is a biometric identifier, and where a statute exists it attaches to that conversion rather than to the recording. The label a vendor uses does not control the question; the function does.
In December 2023 the Federal Trade Commission banned Rite Aid from using facial recognition for security purposes for five years. The FTC found the company had deployed the technology across hundreds of stores without reasonable safeguards.
The system generated thousands of false matches. Employees acting on them accused, searched, detained and called police on customers who had done nothing. The FTC found the errors fell disproportionately on shoppers in predominantly Black and Asian neighbourhoods.
The action was brought under Section 5 of the FTC Act, which prohibits unfair or deceptive practices. That is a general consumer protection statute, not a biometric one, which is itself the point: absent a specific law, enforcement depends on a regulator stretching a broad authority to fit.
The settlement also required Rite Aid to delete the images and templates it had collected, and to build a safeguards programme before deploying any comparable system in future. Notably, the FTC did not find that the technology was inherently unlawful. It found that deploying it without procedures to catch errors was unfair to customers, which is a narrower holding than the headlines suggested and leaves the underlying practice open to anyone who does implement safeguards.
Federal testing by the National Institute of Standards and Technology has repeatedly documented higher error rates for darker skinned faces, for women, and for the very old and very young. Those findings drove much of the early opposition.
The same testing has documented substantial improvement over the past decade, and the demographic gaps have narrowed considerably in the best performing systems. Defenders argue that rules written around 2018 error rates may not fit 2026 technology, and that the appropriate response is to require measured performance rather than to ban the category.
Supporters of regulation answer that the systems deployed in shops are not always the best performing ones, and that a customer misidentified has no way to know which system was used.
There is a further complication that both sides tend to skip. Accuracy in a laboratory evaluation is measured under controlled conditions, while a store camera deals with movement, poor lighting, masks and angles. Even a system that performs well in testing can perform considerably worse in deployment, which means published accuracy figures are an upper bound rather than a description of what happens in practice.
BIPA has generated litigation on a scale that surprised nearly everyone. Illinois courts have held that a person may sue on a statutory violation alone, without showing any consequential harm, and that a five year limitations period applies.
Combined with statutory damages calculated per violation, this means ordinary compliance failures can produce very large exposure. Class actions have been filed against major retailers over self-checkout cameras and against employers over fingerprint time clocks.
Critics argue this rewards litigation rather than protecting customers. Supporters argue that a private right of action is the only enforcement mechanism that has produced any behavioural change, and that companies complaining about technical violations could avoid them by providing notice.
The practical effect has been to make Illinois a distinct compliance jurisdiction. Several national retailers and technology vendors have simply disabled biometric features for Illinois users rather than build a consent flow, which is a form of protection but not the one the statute was aiming at. Whether that counts as the law working depends on whether the goal was consent or absence.
Both sides accept that retail theft is a real cost and that a shop has some legitimate interest in identifying someone who has previously stolen from it. Store detectives and staff recognition have never required consent.
Both also accept that the Rite Aid outcome was bad, and that a system generating thousands of false accusations is not defensible regardless of how one weighs privacy against loss prevention.
What separates them is whether the answer is a purpose limitation with strict accuracy and retention requirements, or a prohibition. And underneath that sits a question neither side has answered well: whether consent means anything at a shop entrance, where the only alternative to being scanned is not going in.
Want the core arguments from both sides, side by side?
See both sides of the Facial Recognition in Stores debate →