FTC allegations about Rite Aid facial recognition
A regulator complaint describes harmful false matches in a retail surveillance deployment.
READING ROOM ↗Collecting and using personal data creates questions about purpose, access and retention.
Privacy risk depends on data practices throughout a system’s lifecycle.
People may have little visibility into how information about them is collected or used.
NIST’s GenAI Profile includes data privacy among its risk areas.
A risk category is not evidence that a specific product leaked data.
What information is retained, who can access it, and how can an affected person challenge its use?
Deployment-specific data flows and access controls need investigation.
Map data uses before drawing conclusions about an individual system.
General risk framing; no unsupported breach or severity claim.
Links provide context. Read the stated relationship; inclusion does not imply misconduct, endorsement or a legal obligation.
Federal Trade Commission · Primary source · Regulator complaint
Published 2023-12-19 · Accessed 2026-10-07
NIST · Primary source · Government technical report
Published 2024-07 · Accessed 2026-10-07
DOI: 10.6028/NIST.AI.600-1
Review dates track editorial checks. Updates may reflect corrections or added context; they are not new incidents. Private draft revisions are omitted.
Initial sourced historical collection. Review date describes this record, not the date of the event.