The FTC settled charges that Rite Aid deployed AI facial recognition technology in hundreds of stores from 2012 to 2020 without reasonable safeguards, resulting in false-positive matches that disproportionately harmed women and people of color. The proposed order bans Rite Aid from using facial recognition for surveillance for five years and requires comprehensive biometric data safeguards, data deletion, consumer notifications, and a certified security program.
Rite Aid is banned from using facial recognition for surveillance for five years, must delete all collected biometric images and derived algorithms, provide clear notice to consumers about its use, notify consumers when actions are taken based on the system, implement a comprehensive data security program overseen by executives, obtain independent third-party security assessments, and provide annual CEO certifications.
In-house legal teams should review all vendor agreements (especially with technology/AI providers), customer privacy policies, and any data processing agreements where biometric data or automated surveillance is involved. Specific clauses to scrutinize include: data processing specifications (particularly for biometric identifiers), consent mechanisms for surveillance, data retention and deletion schedules, breach notification protocols, audit rights, and representations/warranties regarding algorithmic fairness and accuracy. Given the FTC's order, contracts may need amendments to: (1) explicitly prohibit or restrict AI facial recognition for surveillance purposes, (2) mandate regular disparate impact assessments for automated systems, (3) require robust data minimization and deletion protocols for biometric data, (4) establish certified security programs aligned with FTC expectations, and (5) incorporate consumer notification requirements for false positives or data misuse. Teams should also assess termination rights if a vendor's technology poses uncorrectable consumer risks.
Entity
Rite Aid
Industry
RetailOfficial Press Release
https://www.ftc.gov/news-events/news/press-releases/2023/12/rite-aid-banned-using-ai-facial-recognition-after-ftc-says-retailer-deployed-technology-without
2023190 riteaid stipulated order filed
https://www.ftc.gov/system/files/ftc_gov/pdf/2023190_riteaid_stipulated_order_filed.pdf
2023190 riteaid complaint filed
https://www.ftc.gov/system/files/ftc_gov/pdf/2023190_riteaid_complaint_filed.pdf
Federal Trade Commission Enforcement Page
https://www.ftc.gov/enforcement
"Rite Aid will be prohibited from using facial recognition technology for surveillance purposes for five years to settle Federal Trade Commission charges"
"the retailer failed to implement reasonable procedures and prevent harm to consumers in its use of facial recognition technology"
"facial recognition technology falsely flagged the consumers as matching someone who had previously been identified as a shoplifter"
"Rite Aid’s facial recognition technology was more likely to generate false positives in stores located in plurality-Black and Asian communities than in plurality-White communities"
"Rite Aid will be prohibited from using facial recognition technology for surveillance purposes for five years"
"Delete, and direct third parties to delete, any images or photos they collected because of Rite Aid’s facial recognition system"
The FTC rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices, which had purported to apply the Health Breach Notification Rule to health apps and connected devices that collect consumer health information. The rescission follows the Commission's 2024 update to the Health Breach Notification Rule, which already covers health apps and connected devices like fitness trackers, and implements an executive order directing agencies to eliminate obsolete guidance documents. No company was charged or penalized; this is a deregulatory action.
$12.0M
The FTC alleged that payment processor Humboldt Merchant Services knowingly processed payments for more than 1,000 shell merchant entities serving as fronts for fraudulent companies engaged in unauthorized billing scams, despite red flags including chargeback rates nearly 10 times higher than card-brand thresholds. Under the proposed stipulated order filed in the U.S. District Court for the Eastern District of Michigan, Humboldt will pay $12 million for consumer redress and is permanently banned from processing payments for merchants with a heightened risk of potential fraud.
$4.8M
The FTC charged Canada-based payment processor Nuvei Corporation and its subsidiaries with knowingly processing payments for fraudulent merchants, including more than $30 million in payments for the Reimage tech support scam from 2017 to 2023, as well as merchants making false earnings claims and impersonating government tax authorities. Under the stipulated order filed in the U.S. District Court for the District of Arizona, Nuvei will pay $4.85 million for consumer redress, is banned from serving tech support telemarketers, and must implement robust merchant screening and chargeback monitoring practices. Note: this is a payments-fraud facilitation action under the FTC Act and Telemarketing Sales Rule, not a data privacy violation.
The FTC announced a seven-day extension of the public comment period on its proposed enforcement policy statement regarding personalized pricing, pushing the deadline from Sept. 18, 2026 to Sept. 25, 2026. Personalized pricing refers to using personal data to set prices based on what the company believes an individual consumer is willing to spend. This is a procedural announcement about draft agency guidance, not an enforcement action against any company, and no entity was named, no violation found, and no penalty imposed.
Colorado Attorney General Phil Weiser joined the FTC and 22 state attorneys general in filing a lawsuit against Amazon for manipulating the auctions used to set advertising prices, replacing actual auction results with higher prices since 2019 and overcharging nearly 1.2 million U.S. advertising customers. The FTC estimates total improper surcharges from 2018 to 2026 exceed $20 billion, with costs ultimately passed to shoppers through higher prices. The states seek a permanent injunction and monetary relief; no penalty has been imposed yet as this is a newly filed complaint.
$930K
The FTC finalized orders requiring CMG Media Corporation (doing business as Cox Media Group), MindSift LLC, and 1010 Digital Works LLC to pay a total of $930,000 for falsely claiming they offered an AI-powered service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. The orders also prohibit the companies from making misrepresentations about their advertising services, voice data collection, and consumer consent.