Back to the archive

The encyclopedia · Legal & Compliance · Legal decision · 2012–2020

Rite Aid ran facial recognition for 8 years, never checked accuracy — FTC banned it for 5

Rite Aid's facial-recognition system flagged shoppers as shoplifters on bad matches, worse in Black and Asian areas. The FTC banned it for five years.

Rite Aid Corporation · 2023-12-19

What happened

Rite Aid ran facial-recognition surveillance in hundreds of stores from 2012 to 2020, matching customers' faces against internal watchlists of people the chain suspected of shoplifting or other misconduct. The FTC's complaint found the company never tested the system for accuracy before deploying it, never asked its vendors how accurate it was, and never checked afterward whether it was generating false matches.

It was. The system produced thousands of false-positive alerts, and employees acted on them: following flagged customers, searching them, ordering them to leave, and calling police over matches that were wrong. In one case cited by the FTC, a Black woman was accused of matching the alert profile of "a white lady with blonde hair." About 60 percent of the stores running the technology were in plurality-Black or -Asian neighborhoods, and the false-positive rate ran higher there than elsewhere.

The FTC's order, issued 19 December 2023, bars Rite Aid from using facial recognition for surveillance purposes for five years and requires it to delete any images and data collected through the program. The order carries no separate monetary fine, but Rite Aid had already filed for Chapter 11 bankruptcy earlier that year under the weight of opioid litigation and other liabilities, and the facial-recognition ban became one more mark on the record as it restructured.

Why it happened

  • Rite Aid deployed a biometric identification system into live retail operations without validating its accuracy against real shoppers before or after rollout.
  • It relied on vendor claims about the technology's performance rather than independently testing false-positive rates.
  • Store staff were not trained on the system's limitations, so they treated a probabilistic match as a confirmed identification and escalated accordingly — searches, expulsions, police calls.
  • The deployment pattern concentrated the highest-error version of the system in plurality-Black and -Asian neighborhoods, compounding an accuracy problem into a discriminatory one.
What it cost5-year FTC ban on facial recognitioncostly

The lesson

Deploying a probabilistic identification system as if it were a confirmed one turns every false positive into a real-world accusation — test the error rate before anyone acts on the output.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →