Biometric Data Privacy Rights: Walmart Keeps 512 Face Numbers

Biometric data privacy gets complicated when a store says, "We don't keep your photo." A store, an app, an airport kiosk can say that and mean it completely. And it can still be sitting on something far more permanent than your photo ever was, a string of roughly 512 numbers that describe the exact geometry of your face. That number gets created the instant a camera "sees" you, and depending on the policy, it can outlive the photo by years.
Biometric data privacy comes down to one distinction almost nobody checks: a face photo and a biometric template (the mathematical pattern made from your face) are two separate things, and a company can delete one while keeping the other indefinitely.
That's the idea sitting underneath Walmart's biometric privacy notice, which shoppers rarely read past the first paragraph, and honestly, who would? But buried in there is a distinction that matters more than almost anything else in the document: what gets deleted, and what gets kept. According to Cybernews, Walmart's policy allows biometric data to be retained until "the initial purpose for collecting or obtaining such biometric data has been satisfied," within three years of your last interaction, or as required by law, whichever comes first. Notice what's missing from that sentence. It never says anything about the photo. Because the photo and the "biometric identifier" it creates are governed by two completely different clocks. This retention gap is exactly why privacy laws matter here: without clear disclosure rules, shoppers have no way to know which clock applies to which piece of their information.
What biometric data privacy rights actually protect, and what they don't
Biometric data privacy is supposed to protect the things about you that can't be changed: your face, your fingerprint, your voice. But here's where it gets slippery. Most people think "protecting my face" means protecting the photo. It doesn't. It means protecting the mathematical fingerprint made from that photo, something that can exist and get shared, matched, and stored long after the picture itself is gone. A privacy policy that only talks about deleting images is answering the wrong question, or at least, only half of it. Your rights under most disclosure frameworks hinge on this exact distinction, which is why reading past the first paragraph actually matters.
Biometric data privacy laws, security gaps, and the photo versus template gap
Biometric data privacy laws generally require companies to disclose what they collect and how long they keep it, but the wording often lets a company be truthful about photos while staying silent on templates. That's not necessarily deceptive. It's just incomplete unless you know to ask the second question. This is also where security information tends to thin out fastest, since most public notices describe collection but stay vague about how templates are protected once they're stored.
How a face becomes a string of numbers through biometric data collection
Let's slow down and actually walk through what happens when a camera "reads" your face, because once you see the steps, the whole photo-versus-template thing stops being abstract.
A facial recognition system doesn't "look" at your face the way a person does. It measures it. It finds the distance between your eyes, the width of your nose, the angle of your jawline, dozens of tiny relationships between points on your face that, together, are about as unique as a fingerprint. A well-built system does this in real time: the camera captures the image, the software extracts those measurements, and then, ideally, the original photo gets tossed. What's left behind is the biometric template, the actual mathematical output of that measuring process. This article is part of a series, start with Biometric Based Authentication A Face Is Just 512 Numbers.
Around 512 numbers. That's it. No pixels, no photo, just a list of values that a computer can compare against other lists of values. When you walk past a facial recognition camera a second time, the system isn't pulling up your old photo and squinting at it next to your face. It's doing math. It creates a new template from the current camera feed and calculates what's called Euclidean distance, basically, how far apart two sets of numbers are when you plot them like points on a map. Close enough, and it's a match. Too far apart, and it's not you. This is described in research summarized in an arXiv paper on privacy-preserving biometric matching, which explains the same comparison method used across most modern facial recognition systems.
Here's why that detail changes everything about how you should read a privacy policy. If a company says "we delete photos after 30 days," that sentence is talking about the raw image, the actual picture. It says nothing about the 512 numbers derived from that picture, which might be stored under a completely separate retention rule, sometimes for years, sometimes without a clear end date at all. This is also the point where identity verification and long-term data storage quietly split into two different questions with two different answers.
The misconception that trips up almost every shopper
Most people assume that because the photo and the template come from the same moment, the same camera flash, they must live in the same database and get deleted on the same schedule. It's a completely reasonable assumption. Nobody teaches you otherwise. Privacy notices are written in legal language that uses phrases like "we don't retain images," which sounds like a full stop, an assurance that the whole biometric episode is over. It isn't a lie. It's just answering a narrower question than the one you actually care about, and it rarely includes the security information you'd actually need to judge the risk.
Think about it like a cashier checking your ID to confirm you're old enough to buy something. The cashier looks at your birthdate, does the math in their head, and hands the ID back. They don't need to keep a photocopy of your license to have verified your age, the verification already happened. But now imagine that instead of just checking and forgetting, the cashier wrote down a permanent, unchangeable summary of your face on an index card and filed it away for later use, even after handing your ID back. That's roughly the situation with biometric templates: the "photocopy" (the photo) can vanish, while the "index card" (the template) stays in a drawer somewhere, sometimes for three years, sometimes longer.
What You Just Learned About Biometric Data Privacy
- 🧠 Photos and templates are separate data objectsa policy can delete one and keep the other under a completely different timeline
- 🔬 A face template is just numbersaround 512 values describing distances between facial features, not an actual picture
- 💡 Matching happens between number setsusing Euclidean distance, not by comparing two photos side by side
- ⚠️ Templates can't be reset like a passwordif one leaks, you can't just issue yourself a new face
Why biometric data privacy protections need to cover both objects, not just one
This is the part that should genuinely change how you read any biometric disclosure form, whether it's at a retailer, a gym with fingerprint check-in, or an airport kiosk. Biometric data privacy protections that only address image retention are protecting half the problem. The template is the part that actually gets used for identity verification again in the future. It's also the part that's basically permanent, and irreplaceable if it's ever exposed.
Compare that to a stolen password. Annoying, sure, but you change it and move on. A stolen biometric template is a different animal entirely, because your face isn't something you can rotate out like a login credential. According to researchers whose work was covered by Biometric Update, a team from South Korea and Singapore developed a method in 2024 that reconstructs recognizable facial images from stolen templates thousands of times faster than previously thought possible, with success rates ranging from about 67% up to nearly 96% depending on the underlying model. Templates that were once assumed to be a one-way street, impossible to reverse back into a face, turned out to be reversible after all, under the right conditions. That finding is part of why data breaches involving stored templates carry more long-term risk than breaches involving ordinary photos.
Once verification is complete, the raw face image should be deleted. Some services keep it for days, others for years, and some forever. Shorter is better. Previously in this series: What Is Biometric Information One Clause Decides Who Pays Po.
summary of biometric verification best practices, Realeyes
That's the quiet part biometric privacy notices tend to leave out. Deleting the photo is the easy, cheap, feel-good move. Deleting or limiting the template is the part that actually protects you, and it's the part most people never think to ask about, mostly because they don't know templates exist as their own separate thing.
How does a company's biometric privacy policy handle photos versus templates
Read the retention section twice, once for the word "image" or "photo" and once for the word "template," "biometric identifier," or "facial geometry." If a policy only addresses one of those categories, that's not necessarily a red flag, but it is a gap you should ask about directly before agreeing to anything involving a camera. Personal data handled this way deserves the same scrutiny you'd give any written consent form before you sign it.
| What's collected | Typical retention behavior | What it's used for | Security status |
|---|---|---|---|
| Raw camera photo | Often deleted within days to a few months | Temporary verification at the moment of capture | Lower long-term security exposure once deleted |
| Biometric template (facial geometry, numeric map) | Can be retained for years, sometimes until a stated business purpose ends | Ongoing matching against future visits or transactions | Higher security stakes due to permanence |
| Match result or verification outcome | Varies widely by company and stated purpose | Fraud prevention, loss prevention, age or identity confirmation | Depends on stated retention purpose |
This is where a company like CaraComp spends most of its time, honestly, sitting inside exactly this gap between what a system captures and what it actually keeps, because that gap is where most consumer confusion (and most real risk) lives. It's not a flashy corner of facial recognition technology. It's the paperwork corner. But it's the corner that determines whether your face data outlives your last shopping trip by three years or three days.
Biometric data privacy laws, disclosure of all biometric data, and the four questions worth asking
Before agreeing to any biometric collection, whether it's a loyalty app, a store camera, or a workplace fingerprint clock, ask four things: What exactly is collected, the image, the template, or both? Why is it being used, verification, loss prevention, something else? Who else receives or has access to it? And how long is each piece kept, separately, not as one combined answer? A policy that dodges the "how long" question for templates specifically is telling you something, even if it never says it outright. Full disclosure all biometric data collection practices should answer all four questions plainly, without making you dig through legal boilerplate to find them.
Key Takeaway
Biometric data privacy isn't really about whether a store keeps your photo. It's about whether it keeps the 512 numbers pulled from that photo, the biometric identifier that can outlast the picture by years and, unlike a password, can never truly be reset once it's exposed.
So here's the reframe worth carrying with you the next time a store, an app, or an airport line asks you to look at a camera. Don't ask "did they keep my picture." Ask "did they keep my measurements." A photo is just a snapshot, forgettable, deletable, harmless once it's gone. A template is a permanent numeric shadow of your face, quietly outliving the moment it was made. The picture fades. The math doesn't. Up next: Biometric Based Authentication A Face Is Just 512 Numbers Po.
biometric data privacy: Frequently Asked Questions
What is the difference between a face photo and a biometric template?
A face photo is the actual picture captured by a camera, the kind of image you'd recognize as a face. A biometric template is different: it's a set of roughly 512 numerical values that describe measurements like the distance between your eyes or the shape of your jawline. The template is what gets stored and compared during future matches, not the photo itself. It is not ordinarily stored as a viewable image, though research shows that under some conditions stolen templates can be used to reconstruct recognizable facial images. This distinction is exactly the kind of information most shoppers never get, since policies rarely spell it out in plain language.
Can a biometric template be deleted the same way a photo can?
Technically yes, but policies rarely treat them the same way. A photo is often deleted quickly because it has no ongoing use once verification happens. A template, on the other hand, may be kept for years because it serves an ongoing purpose, like collecting biometric data for recognizing a returning customer. Biometric data privacy laws generally require disclosure of retention periods, but companies often set separate, longer timelines for templates than for raw images. Asking for this information directly, in writing, is often the only way to get a straight answer.
Why can't a stolen biometric template just be replaced like a password?
Because it's built from something permanent, your face. A password can be reset in seconds. A biometric template is sourced from static human features that don't change on demand. If a template is exposed or stolen, researchers have shown it's increasingly possible to reconstruct a recognizable face from it, meaning the exposure isn't a one-time inconvenience, it can be a lasting identity and security risk with no simple undo button.
Does a facial recognition system ever make skin appear too smooth in a stored image?
When companies store the raw photo (rather than just the template), image processing steps like noise reduction can sometimes make skin appear too smooth, which is more of an image quality artifact than a privacy issue on its own. The bigger privacy question isn't image quality, though, it's whether that photo is deleted quickly and whether the separate biometric template derived from it is retained far longer than the picture itself.
What should I look for in a store's biometric data privacy policy?
Look for four specific answers: what exactly is collected (image, template, or both), why it's used, who it's shared with, and how long each piece is retained, listed separately, alongside clear biometric data protection commitments. A policy that only discusses photo deletion without mentioning template retention is leaving out the part of biometric data privacy that matters most for your long-term exposure. If those details aren't clear, it's reasonable to ask the retailer directly before participating, and you have every right to expect a straight answer.
How does facial recognition matching actually work behind the scenes?
The system converts your face into a template made of numeric values, then compares that template to previously stored templates using a calculation called Euclidean distance, essentially measuring how far apart two sets of numbers are. A small distance suggests a strong match; a large distance suggests it's not the same person. This comparison happens between numbers, not by visually comparing two photographs, and it provides methods for verifying identity without ever storing a viewable image at all.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
What Is Biometric Information: One Clause Decides Who Pays
An insurance fight over face-scan data reveals a myth a lot of businesses believe: that having insurance means you're covered no matter what. Here's the fine-print detail that decides who actually pays.
biometricsBiometric based authentication: a face is just 512 numbers
You'll learn why modern face matching turns your face into 512 numbers instead of comparing photos, and why a high similarity score is a clue for investigators, not a verdict.
privacyIdentity Fraud: 170M Leaked IDs Can't Be Reset Like Passwords
A password breach is a two-minute fix. A leaked driver's license photo can fuel identity fraud for years. Here's how identity verification actually works, and why stolen documents break the whole system.
