On December 19, 2023, the Federal Trade Commission alleged that Rite Aid had failed to implement reasonable procedures to prevent harm from its facial recognition system. The agency’s announcement described shoppers falsely identified as people previously associated with shoplifting or other problematic conduct. A match against a surveillance photograph or another database image could lead employees to follow someone, order them out, or call police.
The record supports a precise distinction. Rite Aid assigned employees a checking role. The FTC alleged that the company failed to give that role adequate testing, training, and correction procedures. These are allegations in a complaint resolved through a proposed settlement, not findings after a contested trial.
What did a match establish?
The FTC’s complaint, matter number 2023190, describes Rite Aid’s use of facial recognition from 2012 to 2020. The company maintained a database of people it considered to have engaged in criminal or otherwise problematic behavior. The system compared shoppers’ faces against that collection and sent employees alerts about possible matches.
That process contained 2 separate judgments. Someone first decided that a person belonged in the database. Software then suggested that a shopper was that person. Neither judgment established that the shopper was stealing during the present visit.
The distinction matters because the complaint describes employees acting against shoppers after false matches. The agency alleged that employees searched people, accused them of shoplifting, and contacted police. Some accusations occurred in front of friends or family. The alleged injury was not simply an inaccurate entry in a computer system.
What supported the original suspicion?
According to the complaint, Rite Aid’s enrollment images came from sources including security cameras, employees’ mobile phones, and news stories. The agency alleged that the company failed to enforce reasonable image-quality standards. Poor-quality photographs entered the database and could increase the likelihood of false matches.
The gallery therefore carried its own evidentiary problem before any live comparison occurred. It was a collection of people associated with suspected or problematic behavior, not a register limited to judicial findings of theft.
The FTC’s 2012 report, Facing facts, had already identified accuracy, privacy, and data-security considerations for commercial facial recognition. It recommended assessing risks when designing and implementing these systems. Rite Aid’s alleged image-quality failures concerned the material against which every subsequent shopper would be compared.
Was the technology tested for this job?
The complaint alleged that Rite Aid failed to test, assess, measure, document, or adequately inquire into the system’s accuracy before deployment. That is a different failure from purchasing software that occasionally makes mistakes. It concerns whether the purchaser established what mistakes to expect in its own operation.
The National Institute of Standards and Technology’s 2018 report on one-to-many face recognition, NISTIR 8238, evaluates searches against galleries of faces. That is the relevant task distinction here. Searching a database for a possible identity is not the same exercise as checking a claimed identity against a single reference photograph.
NIST’s tests do not measure Rite Aid’s deployment. They show why performance must be tied to the task, image collection, and operating conditions being evaluated. The FTC alleged that Rite Aid lacked the corresponding assessment of the system it put in stores.
Could employees supply the missing check?
Rite Aid’s process expected employees to review alerts and determine whether the shopper matched the enrolled person. That was a human review step. It was not, by itself, evidence that the step worked.
The complaint alleged inadequate employee training, including inadequate instruction about the technology’s limitations and the risk of false positives. Employees were being asked to resolve an identification problem produced by a system whose accuracy the company had not adequately established.
The agency also alleged that Rite Aid failed to monitor whether employees followed its procedures. Written instructions and reliable execution are different records. The complaint describes thousands of false-positive matches and employees taking action against people incorrectly identified by the system.
Those allegations do not support describing the employee as an effective safeguard merely because the employee had the last decision.
Who bore the identification errors?
The FTC alleged that Rite Aid’s failures disproportionately harmed people of color. Its complaint described a higher incidence of false-positive matches in stores serving plurality-Black and Asian communities than in stores serving plurality-white communities.
NISTIR 8280, published in December 2019, separately documents demographic differences in the performance of many face recognition algorithms. Results varied by algorithm and application. That study supplies evidence that demographic performance requires examination, rather than an assumption that one aggregate accuracy figure settles the issue.
The Rite Aid allegation remains grounded in the agency’s account of the company’s deployment. Its significance is operational: an identification procedure can impose different error burdens on different groups of shoppers. The FTC alleged that Rite Aid failed to assess and address that risk.
What happened after a bad match?
The complaint alleged that Rite Aid failed to adequately track false positives and act on that information. Without a dependable correction process, an employee’s discovery that an alert was wrong did not become a reliable system-wide control.
The FTC’s May 2023 biometric policy statement identifies foreseeable harms, inadequate assessment, employee training, and ongoing monitoring as relevant to its enforcement analysis. Section 5(n) of the FTC Act supplies the underlying unfairness test: substantial injury that consumers cannot reasonably avoid and that countervailing benefits do not outweigh.
The agency’s case was therefore not that every mistaken identification automatically violates federal law. It was that Rite Aid failed to take reasonable precautions against foreseeable injuries from its particular use of the technology. Accusations and police involvement were the alleged consequences.
Who owned the vendor’s risk?
The FTC also alleged violations of a separate 2010 order requiring Rite Aid to maintain a comprehensive information-security program. That earlier settlement concerned failures to protect customers’ sensitive information, including disposal practices.
In the facial recognition case, the agency alleged that Rite Aid failed to adequately assess and oversee service providers. Buying the identification service did not remove the purchaser’s obligations under its existing order.
The FTC’s Start with security business guidance likewise treats service-provider selection, contractual safeguards, and verification as distinct responsibilities. A vendor’s involvement is not evidence that the customer has checked the vendor’s work. Here, the alleged failures extended from procurement through employees’ responses to alerts.
What would the order require?
The proposed order announced in December 2023 would prohibit Rite Aid from using facial recognition for surveillance or security for 5 years. It would also require deletion of covered images and specified products developed from them, subject to its exceptions.
For covered future biometric uses, the order would require a monitoring program addressing consumer risks, testing, employee training, and responses to complaints. It also includes notice requirements and an obligation to discontinue uses when identified risks cannot be controlled.
Those provisions address different points in the same chain: collecting a face, assessing a match, acting against a shopper, and correcting a mistake. They are remedial requirements, not evidence that comparable protections operated during the period described in the complaint.
What is the verdict?
The FTC’s record does not establish a meaningful, consistently enforced evidence threshold between a Rite Aid face match and a theft accusation. It establishes an assigned human review step surrounded by alleged failures in testing, image quality, training, oversight, and correction. The problem was not simply that software could be wrong. Rite Aid had not adequately established how its employees would know that before acting against a shopper.



