A Face Scan Before You Even Say Hello

Walk into a certain building in downtown Spokane and your face becomes data before you've said a word. The system measures the distance between your eyes, the shape and size of your features, the width of your lips, even the tilt of your brow. All of it gets converted into a unique string of code that identifies you, whether you consented to it or not.

This isn't science fiction. It's happening now in Washington, and it highlights a growing tension between commercial convenience and personal privacy. Retailers and building operators are increasingly turning to facial recognition technology to manage security, track shoppers, and in some cases gauge customer behavior. The problem is that very little law currently governs how private businesses in Washington can collect, store, or use this kind of biometric data.

Why Retail Facial Recognition Is Different From Government Use

Much of the public conversation around facial recognition focuses on police and government agencies, and for good reason. Washington does have a law addressing facial recognition technology, but that statute is aimed squarely at state and local government agencies, including law enforcement. It sets requirements around accountability, testing, and oversight when public entities deploy the technology.

What that law does not cover is private business use. Retailers, landlords, and building managers operating facial recognition systems for security or marketing purposes fall largely outside its scope. That leaves a significant gap: the same technology capable of building a searchable database of your face can be deployed in a shopping center with far less transparency than if it were used by a police department.

This isn't a hypothetical concern. Walmart experimented with facial recognition technology as early as 2015 and even filed a patent in 2012 exploring how the technology could be used to monitor customer emotions while they shop, according to reporting cited by the Spokesman-Review. That kind of application, reading a shopper's mood rather than simply verifying identity, illustrates how far commercial uses of this technology can extend once the underlying data is captured.

The parallel to law enforcement deployments is instructive. In Western Australia, police recently used live facial recognition technology in public spaces and generated a result almost immediately after rollout, an arrest tied directly to the system's first real-world trial. That case shows how quickly facial recognition can move from pilot project to active use once it's deployed, whether by a government agency or a private operator. Washington's retail sector appears to be following a similar trajectory, just without the same oversight structure that governs public sector deployments.

What This Means For You

If you shop, work, or simply pass through certain buildings in Washington, there's a real chance your face has already been scanned and converted into a biometric identifier, without a clear legal framework dictating how long that data is kept, who can access it, or whether it can be sold or shared with third parties.

Unlike financial data or even browsing history, your face isn't something you can change if it's compromised or misused. A leaked biometric database, or one shared without your knowledge for marketing purposes, creates risks that are harder to undo than a stolen password. And because private sector use isn't tightly regulated in Washington, the burden currently falls on consumers to notice signage, ask questions, and decide whether to enter a space at all.

This doesn't mean facial recognition technology is inherently harmful. It can genuinely improve security and reduce theft. But the lack of clear rules around consent, data retention, and third-party sharing means shoppers are often left in the dark about how their biometric information is being used once it's captured.

Actionable Takeaways

Watch for posted signage at store entrances or building lobbies disclosing the use of facial recognition or biometric scanning technology, and take note of who operates the space if you have concerns.

Ask retailers directly about their data retention and sharing policies when facial recognition is in use; businesses that respect privacy should be able to answer clearly.

Support and follow state legislative efforts aimed at closing the private sector gap in Washington's facial recognition law, since public pressure has historically driven stronger consumer privacy protections.

Consider limiting visits to locations where facial scanning is mandatory for entry if you're uncomfortable with biometric data collection, especially where no opt-out is offered.

The technology behind facial recognition isn't going away, and its presence in everyday retail spaces is likely to expand before lawmakers catch up. Until Washington closes the regulatory gap between government and private sector use, staying informed about where and how your face is being scanned remains one of the few tools consumers have to protect their own biometric privacy.