Facial Recognition

Facial Recognition Law in the United States, Sorted by Who Is Pointing the Camera

Key Takeaways

  • Washington's RCW 43.386.080 bars a state or local agency from using a facial recognition service for ongoing surveillance, real-time identification or persistent tracking absent a warrant, exigent circumstances, or a court order limited to locating a missing or deceased person.
  • The same section prohibits using facial recognition results as the sole basis for probable cause, running a search against a sketch or manually produced image, and applying the technology on the basis of race, immigration status, religion or protected characteristics.
  • Portland, Oregon prohibits private entities from using face recognition technologies in places of public accommodation, and gives an injured person a claim for damages or $1,000 per day of violation, whichever is greater.
  • The FTC barred Rite Aid from using facial recognition for surveillance for five years after alleging its system generated thousands of false positives that disproportionately affected people of colour.
  • Faces fall through some biometric statutes by design: Washington's commercial biometric chapter excludes photographs and data generated from them, which is part of why facial recognition needed separate legislation.

Why This Area Does Not Sort by State

Most privacy topics can be mapped by jurisdiction: here is what California requires, here is what Virginia requires. Facial recognition resists that treatment, because the rules that exist were written in response to two quite different anxieties and they landed in different bodies of law.

One anxiety is about the state — police identifying people at a protest, agencies making consequential decisions from an automated match. The instruments that answer it look like criminal procedure and administrative law: warrants, judicial reporting, published accountability documents, mandatory human review.

The other is about commerce — a shop deciding who to follow around the aisles. The instruments that answer it look like consumer protection: prohibitions, private damages, and agency orders.

Sorting by deployer rather than by state is therefore the only arrangement that reflects how the law is actually built. This guide takes that approach, using the most fully developed example of each: Washington's statute on government use, Portland's ordinance on private use, and the FTC's action against a national retailer.

Government Use: Publish Before You Deploy

Washington's chapter 43.386 RCW, enacted in 2020, is the most complete state framework for public-sector facial recognition. Its first move is procedural: an agency has to say in advance that it intends to use the technology, and then explain itself in public.

RCW 43.386.020(1) requires a state or local government agency using or intending to develop, procure or use a facial recognition service to file a notice of intent with a legislative authority, specifying a purpose for which the technology is to be used. Before deploying, the agency must produce an accountability report for that service.

The report is not a formality. Among other things it must state clearly how and when the service will be deployed and by whom, including the factors determining where, when and how it is deployed, and whether it will operate continuously or only in specific circumstances. Where another entity operates the service on the agency's behalf, the report must describe that entity's access and any applicable protocols. It must also set out the agency's training procedures and its processes for periodic operational testing. Under subsection (4) the final report is updated every two years and submitted to a legislative authority.

Three further duties sit alongside the report. RCW 43.386.030 requires that where an agency uses a facial recognition service to make decisions producing legal or similarly significant effects, those decisions be subject to meaningful human review — with the significant-effects category defined to include the provision or denial of financial and lending services, housing, insurance, education enrolment, criminal justice, employment opportunities, health care services, access to basic necessities such as food and water, and decisions that impact civil rights. RCW 43.386.040 requires testing, RCW 43.386.050 addresses performance differences across subpopulations, and RCW 43.386.060 requires training for personnel.

"Meaningful human review" is itself defined at RCW 43.386.010(7) as review or oversight by one or more individuals trained under RCW 43.386.060 "who have the authority to alter the decision under review." A reviewer without the power to change the outcome does not satisfy it.

The Warrant Line, and What Cannot Be Done at All

Accountability reporting governs ordinary use. RCW 43.386.080 governs the uses the legislature treated as categorically more dangerous, and it draws a line that will be familiar from search-and-seizure law.

Under subsection (1), a state or local government agency may not use a facial recognition service to engage in ongoing surveillance, conduct real-time or near real-time identification, or start persistent tracking unless a warrant is obtained authorising that use, exigent circumstances exist, or a court order is obtained for the sole purpose of locating or identifying a missing person or identifying a deceased person. The statute permits an ex parte order in that third case where an officer certifies, and the court finds, that the information is likely to be relevant to that purpose.

The remaining subsections are flat prohibitions rather than conditions:

  • No application of a facial recognition service to an individual based on religious, political or social views or activities, participation in a noncriminal organisation or lawful event, or actual or perceived race, ethnicity, citizenship, place of origin, immigration status, age, disability, gender, gender identity, sexual orientation or other protected characteristic
  • No use of the technology to create a record describing an individual's exercise of First Amendment rights or rights under Article I, section 5 of the state constitution
  • No use of facial recognition results as the sole basis to establish probable cause in a criminal investigation; results may be used only alongside other lawfully obtained information and evidence
  • No use of the technology to identify an individual from a sketch or other manually produced image
  • No substantive manipulation of an image for use in a facial recognition service in a manner inconsistent with the provider's intended use and training

The prohibition on sketches and on manipulated images is unusual and worth pausing on: it regulates the input rather than the output, closing off two practices that would otherwise let an agency generate a match from something that was never a photograph of anyone.

Warrant use is audited from the bench. RCW 43.386.070 requires that each January, any judge who issued or denied a surveillance warrant under RCW 43.386.080 during the preceding year report to the administrator for the courts — recording whether the warrant was granted as applied for, modified or denied, the period of surveillance authorised and the duration of any extensions, the identity of the applying officer and agency and the person who authorised the application, and the nature of the public spaces where surveillance was conducted. Agencies that applied for such warrants separately report summarised non-identifying demographic data about the individuals named as subjects.

Two exemptions bound the chapter. RCW 43.386.090 removes agencies mandated to use a specific service by federal regulation or order, those acting through partnership with a federal agency to fulfil a congressional mandate, and use in association with a federal agency to verify the identity of travellers at an airport or seaport — though such agencies must still report that use to a legislative authority. RCW 43.386.100 exempts the Department of Licensing's facial recognition matching system for drivers' licences.

Private Use: One City Said No

Against that detailed regulatory approach for government, the most aggressive American rule on private-sector facial recognition is far simpler. It is a municipal prohibition.

Portland, Oregon's City Code chapter 34.10 is titled, without ambiguity, "Prohibit the use of Face Recognition Technologies by Private Entities in Places of Public Accommodation in the City of Portland." Section 34.10.030 provides that, subject to the chapter's exceptions, "a Private Entity shall not use Face Recognition Technologies in Places of Public Accommodation within the boundaries of the City of Portland."

The definitions are drawn to catch the technology by function. "Face Recognition" at section 34.10.020(A) means the automated searching for a reference image in an image repository by comparing the facial features of a probe image with features of images in that repository — a one-to-many search — typically returning ranked candidate images or a negative result. "Face Recognition Technologies" extends to automated or semi-automated processes that assist in identifying, verifying, detecting or characterising an individual's facial features, or capturing information about an individual based on their face. A private entity is any legal entity however organised, excluding a government agency.

The stated purpose in section 34.10.010 rests on accuracy rather than on privacy alone: the council recorded that face recognition technologies "have been shown to falsely identify women and People of Color on a routine basis," and that vendor testing has found wide ranges in accuracy and error rates differing by race and gender.

Enforcement is the part that gives the ordinance teeth. Section 34.10.050 provides that any person injured by a material violation has a cause of action against the private entity for damages sustained, "or $1,000 per day for each day of violation, whichever is greater," along with such other remedies as may be appropriate. A per-day floor of that kind means an injured plaintiff need not prove the value of the harm to recover something substantial.

The Federal Answer Has Been an Enforcement Order

Congress has not legislated on commercial facial recognition. The FTC has instead used its existing authority, and its most detailed statement of what it considers unlawful came in an action against a retailer.

In its December 19, 2023 action against Rite Aid, the Commission alleged that from 2012 to 2020 the company deployed AI-based facial recognition in hundreds of stores to identify potential shoplifters, and failed to take reasonable measures to prevent harm to consumers.

The alleged injury was not abstract. According to the Commission, the system generated thousands of false-positive matches, and employees acting on them followed consumers, searched them, ordered them out of stores, called the police, and publicly accused them of shoplifting, sometimes in front of friends or family. The Commission alleged those harms disproportionately affected people of colour, with more false positives in plurality-Black and Asian communities than in White communities.

The order bars Rite Aid from using facial recognition technology for surveillance purposes for five years, and requires it to delete the images collected and the algorithms derived from them. Going forward it must notify consumers when their biometric information is enrolled and when action is taken against them on the basis of it, implement an information security programme subject to independent third-party assessment, and provide annual certifications of compliance from its chief executive.

The theory is worth noting for what it does not depend on. There was no facial recognition statute to violate. The case proceeded on the proposition that deploying a system known to misidentify people, without safeguards proportionate to the consequences, is itself the unfair practice.

Why Faces Needed Their Own Law

A reasonable assumption is that facial recognition is already covered by biometric privacy statutes, since a face is a biometric. In at least one significant instance that assumption is wrong, and the reason explains why this separate body of law exists.

Washington regulates commercial biometrics in a different chapter, RCW 19.375, whose definition of a biometric identifier at RCW 19.375.010(1) expressly "does not include a physical or digital photograph, video or audio recording or data generated therefrom." Facial recognition operates on precisely those inputs. The same legislature that had already restricted commercial biometric enrolment in 2017 passed a dedicated facial recognition chapter in 2020, and the gap between the two definitions is a large part of the reason.

That chapter's definition of commercial purpose also excludes security and law enforcement purposes — the exact settings in which facial recognition is most often deployed. A statute drafted to govern fingerprint templates enrolled for marketing does not reach a camera above a shop door scanning for a match against a watchlist.

Whether faces are captured by a general biometric statute is therefore a question that has to be answered state by state from the definitional text, not assumed from the fact that a face is biological.

What This Guide Does Not Cover

This guide describes three regimes in detail rather than surveying fifty states, and the reason is the same one that governs the rest of this site: what could be retrieved and read in full is what appears.

Other states have restricted law enforcement facial recognition, and other cities have adopted municipal bans on government use. Those instruments are real, and their absence here reflects the limits of what this session could source rather than a judgment that Washington and Portland are the only jurisdictions that have acted. A reader assessing a specific city or state will not find that answer in this guide.

The Illinois biometric statute has been the vehicle for a substantial share of American facial recognition litigation because its definition does reach face geometry and because it carries a private right of action. It is covered separately on this site and is not restated here. The commercial biometric statutes of Texas, Washington and Colorado are likewise treated in their own guide, where the comparison is drawn on enforcement design rather than on the technology.

Finally, this guide describes what the cited instruments say. It does not address how any of them applies to a particular deployment, which depends on facts — where the cameras are, who operates them, what the matches are used for — that no guide can supply.

Background

For the underlying law rather than this development: Washington privacy law, Oregon privacy law, Retail & E-Commerce privacy law, Technology & SaaS privacy law.

Frequently Asked Questions

Do police need a warrant to use facial recognition?
In Washington, for certain uses. RCW 43.386.080(1) bars a state or local agency from using a facial recognition service for ongoing surveillance, real-time or near real-time identification, or persistent tracking unless a warrant is obtained, exigent circumstances exist, or a court order is issued solely to locate a missing person or identify a deceased person. Other uses are governed by the chapter's accountability report requirements rather than by a warrant.
Can a facial recognition match alone justify an arrest?
Not under the Washington chapter. RCW 43.386.080(5) provides that a state or local law enforcement agency may not use the results of a facial recognition service as the sole basis to establish probable cause in a criminal investigation, though results may be used in conjunction with other lawfully obtained information and evidence.
Is there anywhere in the United States where private businesses cannot use facial recognition?
Portland, Oregon. City Code section 34.10.030 prohibits a private entity from using face recognition technologies in places of public accommodation within city boundaries, subject to exceptions including where necessary to comply with federal, state or local law.
What did the FTC require of Rite Aid?
The order bars the company from using facial recognition technology for surveillance purposes for five years and requires deletion of collected images and the algorithms derived from them. It also requires notice to consumers when their biometric information is enrolled, an information security programme with independent third-party assessments, and annual compliance certifications from the chief executive.
Does a state biometric privacy law automatically cover facial recognition?
Not necessarily. Washington's commercial biometric chapter defines a biometric identifier to exclude a physical or digital photograph, video or audio recording and data generated from them, and its definition of commercial purpose excludes security and law enforcement purposes. Whether faces are covered depends on the specific definitional text of the statute in question.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.