Skip to content

Power

A Store Camera May Put Your Face on a Watch List

Retailers publicly describe cameras that count shoppers, monitor checkouts and compare faces with watch lists. Those are different systems, and the usual CCTV sign rarely tells you which one is operating.

Simone AchebePower — Surveillance

August 24, 2026 · 8 min read

A navy cotton baseball cap in a shopping basket beneath a store entrance camera and surveillance notice.

Take an ordinary navy cotton-twill baseball cap, worn with the curved brim low over the brow. To a shopper, it changes the face presented to the camera. To most retail computer-vision systems, it is merely another variable: less visible forehead, different shadow, perhaps a poorer image. The cap does not tell you what the camera is doing with the image it still captures.

That uncertainty is useful to retailers. A single ceiling-mounted camera can feed several systems, whether at the same time or after a software upgrade: conventional recording for later review, traffic measurement, checkout monitoring, or software that extracts facial features and compares them with stored records. The lens is visible. The function usually is not.

Public disclosures show that all of these systems exist in retail, but they do not justify treating every camera as facial recognition. The distinction matters because the harm changes with the mechanism. A counter that records one person entering is not a watch list. A system that flags a possible missed scan is not identifying the shopper.

A biometric match can follow someone into the store before an employee has seen any conduct at all.

The camera has to do something before it can know you

Face detection means software locates a face within an image, often by drawing an invisible box around it so another system can crop, count or analyze that region. It can power audience measurement, camera focus and basic visitor counts without assigning a name or comparing the face with a database.

The navy cap may reduce the quality of that detection if the brim blocks landmarks around the eyes. It may not. Modern systems are trained on faces seen from varied angles and under poor retail lighting, while an entrance camera can capture several frames as a person approaches. One weak frame does not settle the matter.

Facial recognition goes further by converting visible facial features into a biometric template, a numerical representation used for comparison. Verification compares that template with one claimed identity, as when a customer deliberately unlocks an account. Identification searches across many stored templates to find a possible identity. Retail loss prevention commonly raises a narrower version of identification: watch-list matching.

A watch-list system compares a new face against a retailer-controlled set of enrolled images, usually people the operator associates with earlier incidents or exclusions. It does not need to name every shopper. It needs only to produce a similarity score high enough to trigger an alert, after which an employee may inspect the result or act on it.

That last handoff is where a probability becomes a social fact. The system reports a candidate, not knowledge. Yet the person under the cap may experience the output as a guard approaching, service being refused or an accusation made within earshot of other customers.

Retail has disclosed several different camera businesses

Amazon’s Just Walk Out stores provide the cleanest example of computer vision without a public claim of facial recognition. Amazon describes cameras and other sensors tracking which products shoppers take or return so the system can assemble a virtual cart. The commercial purpose is automated checkout. Amazon has said the system does not use facial recognition, and that statement should be reported as a limit on the disclosed system rather than stretched into a theory about every Amazon camera.

Self-checkout monitoring occupies another lane. Retailers and vendors have publicly promoted computer vision that watches the relationship between products, scanner activity and the bagging area, then sends an alert when the software detects a possible missed scan. Sam’s Club has also described exit technology that uses computer vision to check carts against purchase records. These systems can scrutinize conduct without resolving a face into an identity.

That is still surveillance, particularly when an uncertain alert shifts the burden onto a shopper, but calling all of it facial recognition obscures what must be challenged.

The public record on watch lists is more direct. A Reuters investigation documented Rite Aid’s use of facial recognition across hundreds of US stores before the chain stopped the program. In a later complaint, the Federal Trade Commission alleged that Rite Aid failed to take reasonable safeguards against false-positive matches and that employees sometimes acted on alerts by confronting or removing people. The resulting order barred the company from using facial recognition for five years and imposed requirements around notice, testing and consumer complaints.

In Britain, Facewatch openly markets a cloud-based facial-recognition service to retailers. Participating businesses upload images to watch lists, cameras capture people entering, and the service compares incoming faces with those records. The UK Information Commissioner’s Office investigated the company and later said its revised system met data-protection requirements, a regulatory conclusion that did not erase the basic power arrangement: the retailer helps decide whose image enters the list, while everyone crossing the threshold supplies a face for comparison.

Australia supplies another disclosed case. Consumer group CHOICE reported facial-recognition use by major retailers including Bunnings and Kmart. In 2024, Australia’s privacy regulator found that Bunnings had breached privacy law through its collection of facial images and biometric information; Bunnings disputed the finding and sought review. The dispute turned on a named deployment and an official decision.

It does not establish that every retailer using theft-prevention language has installed the same machinery.

That restraint matters. Loss-prevention vendors sell license-plate readers, cart-containment systems, object detection, pose analysis and conventional video management alongside facial tools. A store can buy one without buying the others. Suspicion is not documentation.

The watch list is the institution inside the machine

Recognition accuracy receives most of the attention because demographic performance gaps and poor images can produce false matches. The deeper question is how someone gets enrolled.

A law-enforcement watch list may have formal inclusion rules, however contestable. A retail list can be built from incident footage, internal reports or images shared across participating locations, subject to the retailer’s policy and local law. If an employee associates the wrong face with an event, the error can persist beyond the original encounter. Better matching software will then retrieve the wrong record more efficiently.

The incentive is easy to see. Retailers pay vendors because automated alerts promise to concentrate employee attention, reduce losses and create a record for internal investigations. Vendors receive subscription, hardware or service revenue. Shoppers bear the cost of false suspicion in time, privacy and the difficulty of correcting a file they may not know exists.

Human review does not dissolve that structure. An employee who receives a match alert often sees a selected image, a confidence indicator and an allegation already attached to the candidate. The review begins after the software has framed the person as worth examining. The navy cap becomes evidentiary texture: perhaps it looks similar to one in an old image, perhaps it hides enough detail to make the match less reliable, perhaps the employee reads it as suspicious because the system has already spoken.

A CCTV sign establishes less than it appears to

A sign saying “CCTV in operation” establishes that cameras are present or claimed to be present. It does not establish facial recognition, and it does not rule it out. The same is true of broad phrases such as “video analytics” or “AI-powered security,” which may cover counting, object tracking, checkout analysis or biometric comparison.

A notice that explicitly names facial recognition establishes more. It indicates that the operator represents biometric comparison as part of the system, though the words alone still do not explain whether the comparison verifies a consenting customer, searches a retailer watch list or connects to another database. Nor does the sign reveal how long templates remain, which vendor processes them, how matches are reviewed or how a person can contest an alert.

Useful notice answers those points in accessible text or through a working link. It identifies the responsible company, the purpose of collection, the categories of data retained, the parties receiving it and the route for complaints or access requests. Legal duties vary by jurisdiction, especially in US states and cities with biometric-privacy rules, so signage should be read as evidence of what the operator discloses, not as proof that the deployment is lawful.

Absence of a facial-recognition notice proves even less. It may mean the store does not use the technology. It may mean notice appears in a privacy policy, at another entrance or nowhere despite a legal obligation. Without a company statement, vendor document, regulator finding, court record or credible reporting, the defensible conclusion is that the deployment has not been publicly established.

Look again at the cap beneath the entrance camera. Its cotton weave and low brim are visible facts. The camera housing is another. Everything beyond them requires a paper trail.

Questions people ask

Can a baseball cap stop retail facial recognition?

A low brim can hide facial landmarks or reduce image quality, but it does not reliably prevent detection or matching. Entrance systems can capture several angles across multiple frames, and the effectiveness depends on camera position, lighting and the particular model. A cap is clothing, not a dependable privacy control.

Does a

CCTV sign mean the store uses facial recognition?

No. CCTV generally means video surveillance, which may involve recording, live monitoring or other analytics. Facial recognition requires biometric comparison, and a generic camera notice does not establish that step. A specific disclosure, company document, regulatory record or credible investigation carries more evidentiary weight.

Is checkout monitoring the same as a facial-recognition watch list?

No. Checkout computer vision can analyze products, scanner events and hand movements without identifying a shopper. A watch-list system creates a facial template and compares it with stored images. Both can generate consequential errors, but they use different data and demand different forms of accountability.

What should a facial-recognition notice tell shoppers?

It should identify who operates the system, why faces are processed, whether images are compared with a watch list, how long data is retained, who receives it and how a person can challenge a match. A small sign that says only “security technology in use” leaves the decisive machinery undisclosed.

Was this worth your time?
ShareFacebook
surveillancesurveillancefacial recognitionretail technologyloss prevention

One update a day

Today's story, in your inbox

One story each morning — no hype, no filler, no algorithm deciding for you.

Read next