CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
facial-recognitionBy Cara Candelario

Does Walmart Have Facial Recognition? 2026 Policy & Retail Tech Facts

Your Face Is Being Scanned at the Grocery Store — and a Tiny Sign Is All They Owe You
A grocery store camera above the entrance illustrates the debate over does walmart have facial recognition in its stores.

Quick answer

Does Walmart use facial recognition in its stores?

Walmart has publicly said it does not use facial recognition for security in its stores. Its privacy policy covers video surveillance and biometric data in broad terms, and it has said any change would be disclosed. That is a statement about current practice, not a permanent guarantee, so shoppers can reread the policy.

Picture this: You walk into a grocery store, grab a cart, head for the produce section. Somewhere above the door, a camera captures your face, runs it against a database of people flagged for shoplifting, and either clears you silently or sends an alert to a loss-prevention officer, all before you've touched a single apple. You never see a sign. You never agreed to anything. You have no idea this happened.

That's not a future scenario. It's a present-day practice. And in April 2026, a Québec privacy authority called the CAI, the Commission d'accès à l'information (that's the provincial watchdog in charge of protecting Quebecers' personal information), issued a ruling that exposed just how complicated the question of consent really is when a store wants to scan your face.

TL;DR

Québec's privacy watchdog conditionally approved a grocery chain's facial recognition pilot, but the consent question is still unresolved, and the gap between "we posted a sign" and "we actually asked you" is exactly where shoppers' rights live or die.

Quebec's Facial Recognition Ruling

The case centered on Metro Inc., a large Canadian grocery chain. Metro had been running a facial recognition pilot across ten stores, matching camera footage against a database of people previously caught shoplifting. The goal: reduce theft losses. The problem: this is biometric data, your face, captured and converted into a unique digital template, the same way a fingerprint gets stored, and under Québec's privacy law, collecting that kind of data requires serious justification.

CaraComp DailyEP.74
3 stories · 3:34
Starts at 01:12 — this story
3:34

Watch this story, in under a minute

Plays right here · jumps to 01:12
In this episode

A new briefing every weekday — three stories, three minutes.

Subscribe on YouTube

Biometric Data: What It Actually Means for Shoppers

Biometric data is any measurement of your body that's unique to you, your face shape, your fingerprint, your voice pattern. When a store converts a camera image of your face into a mathematical template, that template becomes biometric data the same way a fingerprint card would. This matters because biometric data can't be changed the way a password can; once it's collected, you're stuck with the consequences of how it's stored, shared, or lost.

Walmart and the Facial Recognition Question

Does Walmart have facial recognition in its stores? Walmart has publicly stated that it does not use facial recognition technology for security purposes in its stores, a position it has reiterated after past reporting raised questions about the practice. Walmart's privacy policy addresses video surveillance and biometric data broadly, and the company has said any change to that stance would be disclosed. That distinguishes Walmart from Metro Inc., where the pilot program described in the Québec ruling was confirmed and scrutinized directly by regulators.

Here's the twist. The CAI's February 2025 ruling had actually blocked Metro's program on consent grounds. That ruling is still under appeal. The April 2026 follow-up ruling said Metro could potentially continue, if the earlier consent prohibition gets overturned on appeal. So the "yes" is conditional. It's a legal holding pattern, not a green light. The store can argue its case while the legal fight plays out, but it cannot simply ignore the underlying question of whether shoppers ever agreed to this in the first place.

What makes this ruling worth paying attention to, even if you don't live in Québec, is what the CAI required Metro to show before it even considered approving the program. This article is part of a series, start with Face Match Not Proof Biometric Assurance Deepfakes.

10
The number of stores Metro was permitted to run its facial recognition pilot in, capped there specifically to limit the scale of data collection
Source: CAI ruling, as reported by Ogletree Deakins

Facial Recognition in Retail: Proving Business Necessity

Emotional Recognition Versus Identity Matching

It's worth separating two things people often lump together: identity matching (is this the same face as the one in a database?) and emotional recognition (what mood or intent does this face suggest?). Metro's pilot was about identity matching against a shoplifter database, not emotional recognition. Some retail technology vendors have pitched emotional recognition tools for reading customer mood, but that's a separate and less-regulated frontier that raises its own accuracy concerns.

The CAI didn't just ask Metro whether the technology worked. It asked something harder: Did you actually need to use face scanning specifically? Under Québec's privacy framework, collecting sensitive personal data, and yes, a digital map of your face absolutely counts, has to pass what's called a necessity test. The CAI required that the objectives be real and legitimate, that the data collection be proportionate to the problem, and that there be no less invasive option that would work just as well.

Metro had to show it had already tried other approaches. It had to commit to not keeping facial templates when no match was foundmeaning if the system scanned your face and you weren't in the database, your data would be deleted, not stored "just in case." It agreed to cap retention of any flagged data at 18 months. And critically, the pilot stayed limited to ten stores, not a chain-wide rollout.

The CAI also flagged something retailers almost never talk about publicly: accuracy risks, demographic bias, and false positives. In plain terms: these systems make mistakes, and they make more mistakes on certain groups of people, particularly people of color. Being wrongly flagged as a shoplifter in a grocery store is not an abstract harm. It's embarrassing, potentially humiliating, and in some cases has led to wrongful detentions.

"The important question is no longer just whether face-based technology works. It is whether regular people get clear notice, real choice, and limits on what happens to their face data after they walk through the door." Ogletree Deakins, analyzing the CAI's April 2026 ruling

Why Facial Recognition Needs More Than Signage

What Information a Store Actually Collects

When people ask what information a facial recognition system collects, the honest answer is more than most shoppers assume. It's not just a photo, it's a template that can be matched instantly against a database, timestamps of when you entered and left, and sometimes which parts of a store you walked through. That information can sit in company servers for months, depending on the retailer's own retention rules.

Here's where it gets interesting for shoppers across North America, not just in Québec.

The American patchwork on this is a mess, and that's being generous. According to Recording Law, only three U.S. states, Illinois, Texas, and Washington, have laws that specifically protect biometric data (your face scan, fingerprint, voiceprint, the body-based stuff that's uniquely yours). About 20 more states treat it as "sensitive" under broader privacy laws. The rest of the country? Mostly covered only if there's a data breach. Meaning: a retailer in most U.S. states can scan your face without asking, post a small sign near the entrance as a legal fig leaf, and call it a day.

Illinois is the notable exception. Its Biometric Information Privacy Act, known as BIPA, requires written consent before any company collects your biometric data, and it allows individuals to sue directly if their rights are violated. The lawsuits have been significant. WSHB Law notes that the regulatory pressure has shifted away from whether a company posted a notice, toward whether the system was accurate, proportionate, and actually constrained by real deletion rules. The FTC's enforcement action and settlement with Rite Aid, following its use of facial recognition that disproportionately misidentified people of color as shoplifters, made clear that "we had a sign" is not a defense when the underlying system is producing false accusations. Previously in this series: That 99 Face Match Unlocking Your Bank Fraudsters Just Found.

Why This Matters for You

  • ⚡ It's already in stores near youRetail facial recognition is not experimental. It's operational in chains across the U.S. and Canada right now, mostly without your knowledge.
  • 📊 A small sign is not the same as asking youMost current retail deployments rely on entrance notices rather than explicit consent. Québec's ruling challenges whether that's good enough.
  • 🔮 False positives have real consequencesBeing wrongly matched to a shoplifting database doesn't just disappear. It affects how store staff interact with you, and in documented cases, it's led to wrongful confrontations.
  • 🛡️ The "delete it after no match" rule is the bar to watchMetro's agreement not to retain your facial template if you're not flagged is actually a meaningful protection. That standard isn't universal yet.
Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

The One Thing You Can Actually Do Right Now

Look, nobody expects you to audit every store before you walk in. But if you've ever had the nagging feeling that something about a store interaction felt off, that a security guard materialized a little too quickly, or that you were followed through a store despite doing nothing unusual, you're now aware of one possible explanation.

The useful thing you can do: pay attention to entrance signage. Some retailers that use facial recognition are required by state law or company policy to disclose it. In Illinois, that disclosure must be explicit and must come with a consent mechanism. In other states, a small print notice somewhere near the door may be all that's legally required. If you see language about "biometric security systems" or "loss prevention technology" near a store entrance, that's likely what it's referring to.

If you care about this, and it's completely reasonable if you do, you can also check whether a retailer has a publicly posted biometric data policy on its website. CSIS has documented that responsible-use frameworks across jurisdictions increasingly require this kind of transparency. A company that refuses to publish one while claiming it takes privacy seriously is telling you something important.

If you've ever looked at a profile online and wondered whether the person is really who they claim to be, or wondered whether a photo has been altered to mislead you, that same instinct applies here. The question of "is this really the right person?" is exactly what facial recognition systems are trying to answer. The problem is that when they get it wrong, you are the collateral damage, not the algorithm.

Key Takeaway

Québec's ruling didn't settle whether retailers can use facial recognition, it set the bar for what they have to prove before doing so. That bar includes showing the technology was necessary, that alternatives were tried and failed, and that your face data gets deleted when it's not needed. Most retailers in North America aren't meeting that bar yet. Now at least one regulator is asking why not. Up next: That 99 Face Match Unlocking Your Bank Fraudsters Just Found.


The Question Nobody Wants to Answer

The retailers will tell you this is about stopping organized theft rings that cost the industry billions. That's real. Retail shrink, inventory lost to theft, is a genuine and expensive problem, and stores aren't wrong that repeat offenders account for a disproportionate share of it.

But here's the thing the Québec ruling quietly exposed: the moment a store decides that loss prevention justifies scanning every single customer's face, it has made a choice that the overwhelming majority of those customers, the law-abiding ones, which is essentially everyone, never consented to and may never even know about. The math of that trade-off isn't purely a business decision. It's a decision about who the store thinks its customers are before they've done a single thing.

Metro agreed not to keep your facial template if you don't match anyone in their database. That sounds like a reasonable minimum. But think about what it implies: without that rule, a grocery chain could theoretically build a record of every face that walked through its doors, your shopping frequency, your patterns, your presence, without ever telling you. The protection isn't baked into the technology. Someone had to negotiate for it.

So here's the question the CAI left on the table, still unanswered: if a store has to go to that much trouble to minimize the harm of scanning your face, maybe the more honest question is whether the scan should happen at all, and whether the person who should be deciding that is you, not the loss-prevention manager.

If a retailer told you it used facial recognition to prevent fraud, what would actually make you comfortable, a sign at the door, a real opt-in, a strict deletion rule, or none of it at all? Drop your answer in the comments. This one's worth talking about.

For shoppers wondering does Walmart have facial recognition specifically, it helps to compare Walmart's public position against how Metro's pilot program was actually confirmed and regulated. Walmart's stated position is a denial of current use for facial recognition, while Metro's program was openly acknowledged, described in filings, and reviewed by a government privacy authority. Those are two very different levels of transparency, and shoppers are right to notice the difference.

Walmart's privacy policy, like most large retailers, covers store security broadly, mentioning video surveillance, loss prevention practices, and how personal information collected in stores may be used. A privacy policy that mentions video surveillance in general terms is not the same as a specific disclosure that facial recognition, biometric templates, or a shoplifter identification system are in active use. That gap between broad language and a specific technology is exactly the kind of ambiguity Québec's ruling was trying to close.

Store security teams at large retailers generally rely on a layered approach: visible video surveillance cameras, human loss-prevention staff walking the floor, electronic article surveillance tags on merchandise, and in some documented cases, database-matching software tied to cameras at entrances. Facial recognition, when it is used, is typically one layer among several rather than the only tool a store relies on. Knowing which layer applies to a specific store often depends on what that store's own signage and policy disclosures actually say.

It's worth noting that wal-mart has abandoned certain surveillance pilots in the past after public pushback, according to past reporting cited in industry coverage of retail biometrics. That history matters here: a retailer's current stance can shift, and a policy that says "we do not use facial recognition" today is a statement about current practice, not a permanent guarantee. Shoppers who care about this should check back periodically, since privacy policies get updated as technology and public pressure change.

The ACLU and similar civil liberties organizations have long pushed for clearer rules around face recognition in commercial spaces, arguing that consent should be explicit rather than buried in a general privacy policy. Their position lines up with what the CAI required of Metro: real notice, a genuine choice, and enforceable deletion rules, not just a small sign near the door. Whether a specific store meets that standard is still, in most of North America, left up to the retailer to decide on its own.

For a shopper trying to figure out whether a specific business uses this kind of technology, the most reliable approach is to read that business's actual privacy policy rather than relying on rumor or a single news report. Search the policy for terms like "biometric," "facial recognition," or "video surveillance," and look for language about how long any personal information collected in stores is retained. If a policy is silent on the topic entirely, that silence is itself useful information about how the company is choosing to handle the question.

Recognition technology in retail settings is not a single piece of software; it's a category that covers cameras, matching algorithms, and the databases they check against. When people ask whether a store uses recognition technology, they are usually really asking three separate things: does the store have cameras capable of it, does the store run matching software on that footage, and does the store keep the results. Walmart's public answer addresses the middle question directly, it says it does not run that kind of matching software for security purposes, but a full picture still requires looking at devices, sensors, and data retention rules together.

Facial recognition in retail is often discussed as if it were one uniform technology, but the systems, sensors, and devices involved vary a lot between chains and even between individual stores in the same chain. Some in-store cameras are simple video recorders with no matching capability at all. Others feed directly into recognition technology that compares faces against a watchlist in real time, which is the setup the CAI examined in the Metro case.

Privacy is the concept underneath almost everything in this debate, and it is worth being precise about what privacy means here. It is not just about whether a camera exists, nearly every store already has those. It is about whether the data those cameras generate gets converted into something that can identify you personally, how long that data sits in a company's systems, and who besides store security can see it.

Facewatch is one example of a commercial recognition technology provider that other retailers, mostly outside the Walmart or Metro cases described above, have used to power in-store facial matching systems. Naming a specific vendor matters because it shows this is an industry of third-party systems and devices, not something every retailer builds in-house. A store's privacy policy may not name its vendor directly, which is one more reason reading the fine print on data handling matters more than trusting a general assurance.

Retailers justify using facial recognition primarily on loss-prevention grounds, arguing that repeat shoplifters account for a large share of retail shrink and that recognition technology lets security staff intervene before a theft happens rather than after. That justification is not baseless, shrink is a real cost, but the CAI's ruling shows that a business justification alone does not automatically satisfy a legal necessity test. A store has to show the technology, the data it collects, and the systems that store that data are proportionate to the actual problem.

Facial recognition can increase security in narrow, well-documented ways, such as flagging someone already known to have caused harm in a specific store. But "can increase security" is different from "is necessary," and different again from "was consented to." The CAI's decision separated those three questions carefully, and that separation is exactly what most store privacy policies, including generic statements about data and systems, tend to blur together.

Retail facial recognition cameras can identify known criminals only when a store already has that person's face in its own database, the technology cannot identify someone it has never seen before, no matter how sophisticated the sensors or intelligence behind the matching software are. This limitation matters because it means recognition technology is fundamentally reactive: a person has to already be flagged somewhere before the system can act on their presence. That is very different from broad, general surveillance of every customer's face regardless of history.

Face recognition is highly controversial precisely because the trade-offs are so uneven: the store gains a security tool, while ordinary shoppers absorb the privacy cost, the risk of false positives, and the uncertainty about how their data and biometric templates are handled by unfamiliar systems. That imbalance is why regulators, civil liberties groups, and privacy advocates keep returning to consent as the central issue rather than accuracy alone.

Some industry voices argue that facial recognition will facilitate retail evolution by tying loss prevention, customer experience, and inventory systems together into one smarter security and service model. Whether that vision arrives responsibly depends entirely on the same questions the CAI raised: real necessity, proportional data collection, and a genuine, informed choice for the shopper walking through the door, not just a sign and a sensor overhead.

Frequently asked questions

Does Walmart have facial recognition in its stores?

The article does not report Walmart using facial recognition; it focuses on Metro Inc., a Canadian grocery chain that ran a facial recognition pilot across ten stores to match shoppers against a database of people previously caught shoplifting. Quebec's privacy watchdog, the CAI, conditionally approved that pilot, but no findings about Walmart specifically are presented.

How does grocery store facial recognition work, based on the Metro case?

According to the ruling described, cameras capture a shopper's face and convert it into a biometric template, then match it against a database of people flagged for prior shoplifting. A match can trigger a silent clearance or an alert to loss-prevention staff, often without a visible sign or the shopper's knowledge or consent.

Is signage enough for a store to legally use facial recognition?

No. The article explains that Quebec's CAI treated a posted sign as insufficient on its own, since biometric data collection requires serious justification and real consent, not just notice. The gap between posting a sign and actually asking shoppers is described as the point where their rights are decided, and the consent question remains unresolved even after the pilot's conditional approval.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search