Grocery Outlet Wants to Prevent Shoplifting. Can They?

I missed this story when Biometric Update originally published it:

“Facial recognition systems are scanning shoppers as they enter a growing number of Grocery Outlet stores in the San Francisco Bay Area, comparing their faces against watchlists of people suspected of theft, violence, or other unlawful conduct.

“Signs disclosing the use of biometric face-matching software have been documented at Grocery Outlet stores in Pleasant Hill and Concord, as well as four San Francisco locations in the Mission, Portola, Bayview, and Richmond districts.

“The signs direct customers to the privacy policy for SAFR Guard, the system being used by the stores.”

Author Anthony Kimery notes that there are privacy concerns related to those people whose images are captured, but whose faces are NOT on a watchlist.

In addition, Grocery Outlet operates through independent operators, adding one complication to any concerns about privacy violations.

But at least Grocery Outlet isn’t located in Illinois, where their scanning of everybody’s faces could get them (and their independent operators) into BIPA trouble. They are primarily a Pacific (California, Oregon, Washington) and Atlantic (Maryland, Ohio, Pennsylvania) operation.

Can Bredemarket Discuss Privacy?

Repurposed from part of a prior post.

I have discussed privacy for years, even before I started Bredemarket.

The first wave of BIPA lawsuits began a decade after the original BIPA was passed, while I was still at IDEMIA (and working with the International Biometric + Identity Association.

GDPR took effect at about the same time, which incidentally made it hard for me to recruit French nationals for internal Anaheim biometric testing. Could we guarantee their right to be forgotten?

And of course privacy accelerated after I formed Bredemarket, and Bredemarket clients had to state how they protected biometric data privacy.

In addition to my text work, there are videos.

Privacy.

California SB 690 Revisited

It’s been over a year since I looked at California SB 690, a bill which sought to amend a 1967 (!) law, the California Invasion of Privacy Act (CIPA), designed for the age of the landline telephone.

“[A] ton of lawsuits tried to apply 1967 law to modern use cases, including (Fisher Phillips) ‘routine website technologies such as cookies, pixels, search bar/form, chatbots, and session replay tools.’”

Back in mid 2025 SB 690 passed the Senate, but bill sponsor Senator Anna Caballero deliberately paused Assembly consideration.

The pause is over.

“The Privacy and Consumer Protection Committee of the California State Assembly heard testimony on support and opposition to SB 690 late Wednesday, July 1….

“After hearing from several key stakeholders, the bill’s sponsor, Senator Anna Caballero, again amended the bill Wednesday. As amended, the bill: (1) applies only to California’s pen register and trap and trace statute, California Penal Code §§ 638.50 and 638.51, and (2) removes the private right of action for a violation of these statutes. The amended bill instead provides the California attorney general with the authority to bring claims.”

Private right of action is a biggie which has made millions of dollars for Illinois lawyers—I mean Illinois consumers via the Biometric Information Privacy Act (BIPA). Removing private right of action aligns CIPA with 21st century California privacy law, the California Privacy Rights Act (CPRA).

Google Gemini.

Are those enough acronyms for you?

Back to SB 690. As is usual in legislation, some Assemblypersons thought the amendments were great, some didn’t, and others thought they didn’t go far enough. Whether the increased support guarantees passage remains to be seen.

BIPA Violations and “Investigative Journalism”

When I saw this statement in Biometric Update’s summary of a a BIPA lawsuit against Google for voiceprint use, I had to laugh.

“NotebookLM Audio Overviews can be used to generate podcasts, directly competing with investigative audio journalism and narration work.”

Invesigative audio journalism?

Have any of the plaintiffs ever HEARD a NotebookLM Audio Overview?

I shared one over a year ago when my LinkedIn profile was used to create the audio overview “Career Detective.” It’s so fawning about my amazing background that it is nowhere near investigative journalism.

Or maybe investigative journalisn is just that bad.

Judge for yourself whether this AI-generated “podcast” would compete with a real investigative podcast:

Jurisdictional Privacy and Consent

Where are you?

Who are you?

The answers to these questions affect if or how you obtain consent to use one’s personally identifiable information, or PII.

Privacy regulations can change when you cross country or even city lines, and they can also change depending on who you are: an individual, a business, or a government agency.

How?

  • On the other extreme, some entities in some jurisdictions must obtain express written consent. If I am a homeowner in Schaumburg, Illinois, and I use a doorbell camera to identify friends or foes approaching my door, the Biometric Information Privacy Act (BIPA) prohibits me from capturing their biometrics without their consent, and lets them sue me if I do it anyway.

Before you collect PII, check the laws in your jurisdiction first.

Oh, and check the laws in other jurisdictions in case they try to enforce their laws in your jurisdiction.

By the way: if you’re a software or hardware vendor, don’t assume that you bear no responsibility and that only your customer does.

You must educate your customers.

And Bredemarket can help you with my content-proposal-analysis services.

CPA
CPA.

(Told you I’d bring this landing page back.)

Oklahoma Consumer Data Privacy Act…For Now

Yet another state has passed its own data privacy law, with the Oklahoma Consumer Data Privacy Act signed last month and taking effect in 2027. The key particulars:

“OKDPA grants consumers a set of rights…including rights of access, deletion, correction, and portability, and rights to opt-out of targeted advertising, sale, or profiling “in furtherance of a decision that produces a legal or similarly significant effect concerning the consumer.””

As for enforcement:

“Enforcement authority rests with the Oklahoma Attorney General.The bill includes a mandatory 30-day cure period, which does not sunset. The law imposes civil penalties of up to $7,500 per violation.”

As of now, between 19 and 22 states have privacy laws, depending upon how you count.

  • Some aren’t counting Florida because of its limited scope. It only applies to companies with over $1 billion in revenue.
  • Some aren’t counting Illinois because BIPA only applies to biometrics.
  • Some aren’t counting Oklahoma yet because it’s so new.

But we can agree that many states have privacy laws.

For now

And if some have their way, they will all disappear, to be replaced by a single uniform federal law. However, the level of preemption of state laws is an issue of discussion. The Future of Privacy Forum has addressed preemption here.

And if you need to write about privacy, biometric or otherwise, Bredemarket can help. Click below to book a free meeting with me.

Content for tech marketers.

Here is a video about my services.

Bredemarket: Services, Process, and Pricing.

Who Can Write My Biometric Company’s Product Marketing Content?

Someone who is a biometric product marketing expert.

Someone who has three decades of expertise in biometrics.

I remember ANSI/NIST-CSL 1-1993.

Someone who has worked with fingerprints, faces, irises, voices, DNA, and other biometric modalities.

Some modalities. Butts and tongues not included.

Someone who understands the privacy landscape in Europe (GDPR), Illinois (BIPA), California, and elsewhere.

BIPA is a four-letter word.

Oh…and someone who can write.

A slight exaggeration.

So who can write this stuff?

I know someone. Bredemarket.

Some great videos


Biometric product marketing expert.
Questions.
Services, process, and pricing.

Francesco Fabbrocino’s Five Rules of Fraud Prevention…and Bredemarket’s Caveat to Rule 2

Francesco Fabbrocino of Dunmor presented at today’s SoCal Tech Forum at FoundrSpace in Rancho Cucamonga, California. His topic? Technology in FinTech/Fraud Detection. I covered his entire presentation in a running LinkedIn post, but I’d like to focus on one portion here—and my caveat to one of his five rules of fraud detection. (Four-letter word warning.)

The five rules

In the style of Fight Club, Fabbrocino listed his five rules of fraud detection:

1. Nearly all fraud is based on impersonation.

2. Never expose your fraud prevention techniques.

3. Preventing fraud usually increases friction.

4. Fraud prevention is a business strategy.

5. Whatever you do, fraudsters will adapt to it.

All good points. But I want to dig into rule 2, which is valid…to a point.

Rule 2

If the fraudster presents three different identity verification or authentication factors, and one of them fails, there’s no need to tell the fraudster which one failed. Bad password? Don’t volunteer that information.

In fact, under certain circumstances you may not have to reveal the failure at all. If you are certain this is a fraud attempt, let the fraudster believe that the transaction (such as a wire transfer) was successful. The fraudster will learn the truth soon enough: if not in this fraud attempt, perhaps in the next one.

But “never” is a strong word, and there are some times when you MUST expose your fraud prevention techniques. Let me provide an example.

Biometric time cards

One common type of fraud is time card fraud, in which an employee claims to start work at 8:00, even though he didn’t show up for work until 8:15. How do you fool the time clock? By buddy punching, where your friend inserts your time card into the time clock precisely at 8, even though you’re not present.

Enter biometric time clocks, in which a worker must use their finger, palm, face, iris, or voice to punch in and out. It’s very hard for your buddy to have your biometric, so this decreases time clock fraud significantly.

The four-letter word

Unless you’re an employer in Illinois, or a biometric time clock vendor to employers in Illinois.

Illinois state flag. Public domain.

And you fail to inform the employees of the purpose for collecting biometrics, and obtain the employees’ explicit consent to collect biometrics for this purpose.

Because that’s a violation of BIPA, Illinois’ Biometric Information Privacy Act. And you can be liable for damages for violating it.

In a case like this, or a case in a jurisdiction governed by some other privacy law, you HAVE to “expose” that you are using an individual’s biometrics as a fraud prevention techniques.

But if there’s no law to the contrary, obfuscate at will.

Communicating your anti-fraud solution

Now there are a number of companies that fight the many types of fraud that Fabbrocino mentioned. But these companies need to ensure that their prospects and clients understand the benefits of their anti-fraud solutions.

That’s where Bredemarket can help.

As a product marketing consultant, I help identity, biometric, and technology firms market their products to their end clients.

And I can help your firm also.

Read about Bredemarket’s content for tech marketers and book a free meeting with me to discuss your needs.

More information:

Bredemarket: Services, Process, and Pricing.

Amazon’s Take on “Familiar Faces” is Not Available Everywhere

(Part of the biometric product marketing expert series)

Biometric Update reports that Amazon’s Ring products are offering a feature called “Familiar Faces.”

“In September, Amazon revealed a revamped Ring camera lineup featuring two notable AI features, Familiar Faces and Search Party. Familiar Faces uses facial recognition and lets users tag neighbors or friends so future alerts identify them by name rather than generic motion.”

If this sounds, um, familiar, it’s because Google also has a similar feature, called familiar face alerts, in its Nest offerings.

And like Google, Amazon’s Familiar Faces won’t be available to everyone. If you are, um, familiar withg the acronym BIPA, you will know why.

“The feature is slated for December, though it will be disabled in places with stricter biometric laws such as Illinois, Texas, and Portland.”

Is Illinois’ Biometric Information Privacy Act (BIPA) Nullified in Concert Venues?

Illinois music lovers, wanna see a concert? Sounds like you may have to surrender your BIPA protections. 

Specifically, if the concert venue uses Ticketmaster (who doesn’t?), and if the concert venue captures your biometric data without your consent, you may not have legal recourse.

“These Terms of Use (“Terms”) govern your use of Live Nation and Ticketmaster’s websites and applications…

“The Terms contain an arbitration agreement and class action waiver—along with some limited exceptions—in Section 14, below. Specifically, you and we agree that any dispute or claim relating in any way to the Terms, your use of the Marketplace, or products or services sold, distributed, issued, or serviced by us or through us, will be resolved by binding arbitration, rather than in court…

“By agreeing to arbitration, you and we each waive any right to participate in a class action lawsuit or class action arbitration, except those already filed and currently pending as of August 12, 2025.”

See https://legal.ticketmaster.com/terms-of-use/