The headline was a five-year ban on facial recognition. The more consequential terms are the ones after it: an obligation to destroy the models built from unlawfully collected images, and a safeguards programme that governs Rite Aid’s use of automated biometric systems for two decades.
What was filed, where, and under what theory
On 19 December 2023 the Federal Trade Commission announced an action against Rite Aid Corporation and Rite Aid Headquarters Corporation in the United States District Court for the Eastern District of Pennsylvania, filed with a proposed stipulated order attached. The FTC matter number is 2023190, and the Commission’s case page collects the complaint and the order.
The core count was unfairness under Section 5 of the FTC Act. The complaint alleged that between 2012 and 2020 Rite Aid deployed facial recognition in hundreds of stores to identify people it believed had shoplifted or behaved badly, without reasonable procedures to prevent harm: low-quality enrolment images, no meaningful accuracy testing before or during deployment, no thresholds tuned for the population it was used on, matches acted on by employees without verification, and no monitoring of the false positive rate. The alleged consequence was consumers being followed, searched, publicly accused and removed from stores on the strength of a wrong match, with the complaint alleging the burden fell disproportionately on Black, Asian and Latino consumers and on women.
Two features of that theory are worth pulling out. It is an unfairness case rather than a deception case, so it does not depend on Rite Aid having said anything false — the wrong is the deployment itself causing substantial injury consumers could not reasonably avoid. And the FTC brought it under general consumer protection law: there is no federal statute regulating retail facial recognition, and Section 5 was the instrument available. The FTC’s announcement is explicit about the reasoning.
A summary of a public court filing, not legal advice. A consent settlement binds only its parties, and whether any of it constrains your deployment depends on your facts and your jurisdiction — take advice rather than treating the order as a rulebook.
The five-year ban and its edges
The order prohibits Rite Aid from using facial recognition or analysis technology for security or surveillance purposes for five years. The scope is defined by purpose, which is the interesting part: it is not a prohibition on biometrics generally, and it does not touch uses outside the security and surveillance context.
Because the case was brought in federal court, the proposed order was not effective on announcement. It required entry by the district court, and Rite Aid was in Chapter 11 at the time, which added a bankruptcy approval step. The stipulated order for permanent injunction was entered on 26 February 2024 by Judge Kelley B. Hodge in the Eastern District of Pennsylvania, and that is the date the five-year clock is properly measured from rather than the December announcement.
Deletion reaches the models, not just the images
This is the term that made the case notable, and it is routinely summarised too weakly. The order requires Rite Aid, within 45 days, to destroy all photos and videos of consumers it collected in connection with the operation of any facial recognition or analysis system, and — the operative words — any data, models or algorithms derived from them, and to certify compliance in writing to the Commission. Within 60 days it must identify every third party that received such images or derived data, models or algorithms, and instruct them to destroy them too.
Deleting the training data is easy to comply with and cheap. Deleting what was learned from it is neither, and it is the remedy that gives the case its weight: it treats the model as fruit of the improperly collected data rather than as a separate asset. The FTC had used this shape of remedy before — in matters involving photo data and health data — and Rite Aid is the clearest application of it to a deployment case.
The third-party instruction is the operationally hardest part. It presupposes you know which vendors and partners received the images and the derived artefacts, which for a system running across hundreds of stores for eight years is a records question, not a technical one. Any organisation that could not answer “who has copies of this and what did they build from it?” within 60 days would find this term difficult regardless of goodwill.
The safeguards programme is the durable part
The ban expires; the programme does not. The order requires Rite Aid to implement a comprehensive automated biometric security or surveillance system monitoring programme before deploying any such system again, and the components read like a compliance specification written by someone who had studied the failure:
- Assess and document the risks to consumers of the technology, before deployment and on an ongoing basis, including the risk of misuse and the risk that error rates differ across groups.
- Test accuracy in the conditions of actual use, not in the vendor’s conditions, and monitor performance after deployment rather than at procurement time only.
- Train the employees who act on outputs, and stop them acting on a match without the checks the programme specifies.
- Discontinue use where risks to consumers cannot be controlled — an obligation to stop, which is unusual and is the one most likely to bind in practice.
- Notify consumers when their biometric information is enrolled, and when the system is a basis for action against them, and provide a way to complain and have the outcome reviewed.
- Obtain independent third-party assessments of the programme, and report to the Commission, with the order running for twenty years.
If you want to know what the FTC thinks reasonable deployment of a consequential automated system looks like, this list is the closest thing to an answer it has published in an operative document rather than in guidance.
The 2010 order in the background
The 2023 action also alleged that Rite Aid had violated a 2010 FTC data security order, Docket C-4308, by failing to maintain the information security programme that order required, including with respect to vendors. The Commission separately reopened and modified that older order. This is a second lesson sitting quietly underneath the first: an existing consent order is a live obligation that a later, unrelated technology deployment can breach, and the exposure compounds.
What the order does not establish
It is a stipulated settlement. Rite Aid did not admit the allegations, no court found the facts, and nothing here is precedent binding on anyone else. What it establishes is what the FTC is prepared to demand, which is a different and still useful thing.
It does not hold that facial recognition in retail is unlawful. The complaint’s theory is about deployment without reasonable procedures — untested accuracy, unverified matches, no monitoring — and a deployment with those procedures is not what was challenged. It does not create a federal biometric notice rule; the notice obligations here bind Rite Aid because it agreed to them, while a general statutory duty of that kind exists in the US only at state level, most stringently under the Illinois Biometric Information Privacy Act. And it does not settle the FTC’s authority over algorithmic discrimination as a general matter: the unfairness theory here was litigated to a settlement rather than to a judgment, which leaves the question of how far Section 5 reaches into automated decisions unresolved. That question runs alongside the Commission’s other AI work, including its deception cases about AI capability claims.
Top comments (0)