Your Face Is Being Scanned at the Grocery Store — and Washington Doesn't Make Them Tell You
You grab your grocery list. You drive to the store. You walk through the door. And somewhere between the parking lot and the produce section, a camera reads the distance between your eyes, maps the width of your mouth, traces the arc of your brow — and converts all of it into a unique numeric code that gets checked against a database. You didn't sign anything. Nobody told you. And in Washington state, they're not legally required to.
This isn't coming. It's already happening. A Grocery Outlet in downtown Spokane is doing exactly this, right now, according to The Spokesman-Review. The only thing alerting shoppers? A relatively small sticker next to the front door — which, to be clear, is more than state law actually requires.
Stores in Washington can scan and analyze your face for security purposes with almost no legal obligation to tell you — and the gap between what technology can do and what the law demands is growing fast.
The Law That Forgot About Stores
Here's the thing that should make you do a double-take. Washington state actually passed a law in 2020 dealing with face-scanning technology — but it was almost entirely aimed at police. Cops face serious restrictions on using this stuff. Accountability rules, documentation requirements, the works. But private businesses? The lobbying pressure to include them was apparently no match for industry pushback, and the retail exemption slipped through.
"The lobbying against [extending rules to private use] was just too intense, and that got abandoned fairly early on." — A tech activist who lobbied for Washington's 2020 facial recognition bill, as reported by The Spokesman-Review
So we ended up with this strange inversion: a detective trying to identify a suspect with face-scanning technology faces a stack of legal requirements. A grocery store scanning every single person who walks in to buy milk faces almost none. That's not an accident. That's a choice — just not one most shoppers got a vote on.
Washington does have a general rule that companies can't capture biometric data (that's the technical term for your face measurements, fingerprints, voice pattern — the body stuff that's uniquely yours) for commercial targeting without notice and consent. But "commercial targeting" is a specific, narrow thing. Running faces through a security watch list? That's private security. Different category. Much lighter rules.
What's Actually Happening to Your Face
The Spokane store's system doesn't just take a picture. It measures. Eye distance. Face shape. Mouth width. Brow position. All of that gets compressed into a unique numeric code — think of it like a password that only your face can generate. That code gets run against a list of people the store has flagged as previous theft risks. The company behind it claims 99.8% accuracy, a figure they say is verified by the National Institute of Standards and Technology (a federal agency that tests this kind of tech).
Look, nobody's saying retail theft isn't real. It is. And the violence angle is genuinely alarming — by 2025, 83% of retailers reported that the violence was as bad or getting worse. Store employees getting hurt is a real problem that deserves real solutions. The retailers deploying this technology aren't villains. They're scared.
But here's where accuracy claims get complicated. In 2023, the Federal Trade Commission — the government agency that polices unfair business practices — ordered Rite Aid to stop using covert face-scanning technology entirely after an investigation found it was flagging innocent people as suspects at an alarming rate, with the errors falling disproportionately on people of color. Rite Aid's vendor almost certainly had impressive accuracy numbers too. "99.8% accurate" sounds bulletproof until you do the math: in a store that serves a thousand people a day, that's two wrong faces flagged daily. Over a year, that's hundreds of innocent people treated as suspects.
The retailers using this technology argue it's tightly controlled. One company says clients must file detailed reports before adding anyone to a watch list and must sign a statement affirming the information is accurate under penalty of perjury. That's a real safeguard — if it holds. But critics point out that history with similar tools (license plate readers come to mind) shows that when humans have access to powerful surveillance data, some of them eventually misuse it for personal reasons. These things get used to track people who aren't criminals. It happens.
The States That Didn't Wait
Washington isn't alone in having a gap here — Recording Law's 2026 state biometric privacy comparison shows that most US states have no laws specifically targeting face-scanning in retail settings at all. General privacy rules offer some protection, but nothing with teeth aimed specifically at the store-security use case.
Connecticut, though, didn't wait. In January 2026, they introduced legislation to ban retail facial recognition outright — pushed into action after Wegmans, a major grocery chain, admitted it had been running the technology in stores it identified as having "elevated risk." The Wegmans disclosure triggered the kind of public reaction that tends to move legislatures fast. One announcement. Suddenly it's a bill. Continue reading: Your Face Is Being Scanned At The Grocery Store And Washingt.
That's the pattern worth watching. One high-profile story. Public outcry. Emergency legislative scramble. Gaps that took years to open get closed in weeks — but not before a lot of shoppers got scanned without knowing it. State of Surveillance documented Connecticut's response as part of a broader nationwide shift that's still very much in progress.
Why This Matters for You
- 🏪 It's not hypothetical — A real store in Spokane is scanning faces today, and Washington's law requires them to tell you almost nothing about it
- ⚖️ Accuracy ≠ fairness — Even "99.8% accurate" systems have a documented history of errors that fall hardest on people of color, as the Rite Aid FTC case showed
- 📋 The rules are coming, unevenly — Connecticut moved fast after one grocery chain went public; your state's timeline depends on when the next disclosure happens
- 🚪 The sticker is the whole warning system — Right now, a small sign by the door is legally sufficient in Washington, which means most shoppers will never know
What You Can Actually Do Right Now
This is the part where your concern is completely valid. If you've ever wondered whether being somewhere in public means surrendering data you didn't agree to give — this story confirms that, yes, that's exactly what's happening, and the rules haven't caught up. That feeling of "wait, shouldn't I know about this?" is correct. You should know. You just don't have a legal right to yet, in most places.
Here's the one useful thing to do right now: look at the door before you walk in. Not at your phone. At the door. A growing number of stores using face-scanning technology are posting some kind of notice — sometimes a small sign, sometimes a sticker — because even where it's not legally required, companies are aware of the liability risk (meaning the chance they could get sued) if something goes wrong and they never told anyone. If you see a notice mentioning biometric data, security technology, or facial recognition, that store is using it. You now know. You can ask questions, push back, or make a different choice.
Consumer advocates and legal analysts tracking this space — including those cited in the National Law Review's retail surveillance analysis — argue that any store using this technology should be required to post, at minimum: what the system does, how long your face data is kept, and whether there's any way to opt out. Three things. Plain English. At the entrance. That's not a radical demand. It's what we already expect from, say, a loyalty card sign-up form.
Washington explicitly protected people from police face-scanning — then left the door wide open for stores to do the same thing with almost no disclosure rules. The technology is faster than the law, and right now, the only thing standing between your face data and a private database is a small sticker a retailer chose to put up voluntarily.
The engagement question we keep coming back to: if a store uses face-based identity technology, what would you want posted at the entrance? Purpose? How long they keep your data? An opt-out option? All three? Drop your answer in the comments — because right now, the answer to all of those questions in Washington is: nothing, nothing, and nothing. That's not a tech problem. That's a policy problem wearing a tech disguise.
Washington's 2020 law looked at facial recognition and decided the dangerous part was the police. But a small sticker on a Spokane grocery door, stuck there voluntarily, tells you everything you need to know about who actually ended up with more power in that bargain — and it wasn't the shoppers.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore News
Your Face at the Border Doesn't Get Deleted. It Gets Filed for 75 Years.
Your face gets scanned at the border. You assume it's just for crossing. But who gets access to that photo afterward — and for how long — is a fight happening right now, without you in the room.
biometricsSomeone Is Building a Fake You — And Your Bank Has 30 Seconds to Stop It
Fraudsters aren't breaking into your existing accounts anymore — they're opening brand-new ones in your name and spending months building a fake financial life before you ever notice. Here's why that "prove it's you" step is the only thing standing between your name and their mess.
ai-regulationYour Kid's App Says "Verified" — Here's Why That's a Lie
Age verification is finally showing up on your kid's apps — but the messy, delayed rollout means a popup is not the same as protection. Here's what parents actually need to know.
