Franchise Legal: Eyes on You—Retail Biometrics Under Scrutiny
November 10, 2025
Legal

By Kirsten Thompson and Alexandra Quigley, Dentons Canada LLP

Retailers are adopting biometric technologies like facial recognition at a rapid pace, attracted by the promise of increased security, more effective asset protection, and customization of the retail experience, all at relatively low cost.[1] However, Canadian privacy regulators have begun focusing their attention on the use of biometric technology by retailers, and have set the bar for permissible use extremely high. This creates challenges for Canadian retail organizations. U.S.-based retailer head offices may be rolling out biometric technology across North America without appreciating the significantly different regulatory environment in Canada that may make the use of the technology challenging. In addition, U.S. vendors of the technology are eager to sell in Canada, and many make promises that, while true in the United States, will cause regulatory difficulty in Canada.

This article explores the recent uptick in the use of biometric technologies by Canadian retailers—specifically, their use of facial recognition technology—and recent responses from privacy regulators and best practices.

Biometric Information is Broader Than Retailers Think

“Biometric information” is largely undefined (or poorly defined) in Canadian privacy laws. Retailers are forced to rely on equally vague guidance materials published by privacy regulators. This lack of definition creates uncertainty for retailers wanting to adopt such technologies, compounded by the fact that privacy regulators often take an unpredictable enforcement approach.

In Québec, the Commission d’accès à l’information, or CAI (the provincial privacy regulator), considers “biometrics” to be something that “can identify or authenticate a person based on their unique characteristics.[2] These characteristics can include physical traits (e.g., fingerprints), behaviours (e.g., gait), and biological samples (e.g., DNA). In British Columbia, the Office of the Information and Privacy Commissioner (OIPC) has taken the position that biometric information is “distinctive, unlikely to vary over time, difficult to change and largely unique to the individual”[3] and that biometrics are “intimately related to our identity.”[4] At the federal level, the Office of the Privacy Commissioner of Canada (OPC) used a somewhat circular definition in its recent guidance for processing biometrics for businesses: “information about biometric characteristics that has been extracted from a biometric sample.”[5] This definition implies that biometric information includes even non-identifying information e.g., face detection, (which simply locates a human face in a field of view) not just face recognition (which identifies who the face belongs to).[6]

For the purposes of this article, we use biometric information exclusively to refer to personal information that identifies or authenticates an individual on the basis of their uniquely identifying characteristics. Retailers should be aware that the regulators may use a broader definition than what is used in sales and marketing materials for such systems.

What Are the Rules?

The privacy laws of Canada, Alberta and British Columbia regulate “personal information,” which is information about an identifiable individual. Biometric information is regulated because it is personal information. As such, an organization’s use of biometrics must comply with privacy obligations and requirements under Canada’s federal privacy law (Personal Information Protection and Electronic Documents Act, PIPEDA[7]), the Alberta private-sector privacy law (Alberta Personal Information Protection Act[8]), or the British Columbia private-sector privacy law (British Columbia Personal Information Protection Act[9]), where applicable.

Québec takes a different approach, requiring the use of biometric technologies be disclosed to the CAI before they are put in to use. The Act to establish a Legal framework for information technology (LFIT) requires this if the technology. It:

  1. Verifies or confirms a person’s identity by means of a process that captures biometric characteristics or measurements (e.g., employee time clocks using fingerprints); or
  2. Creates a bank of biometric characteristics or measurements (e.g., a reference set of known persons against which an unknown image will be checked).

Note that the first use requires the individual’s express consent, and the CAI’s guidance on the level of detail disclosures require to obtain such consent often surprises retailers.

Retailers should allow plenty of lead time (by law, a minimum of 60 days before the creation of the database of for the second use case) to submit materials to the CAI. The CAI takes a rigorous approach to its review and rejects far more proposals than it permits.

Recent Regulatory Decisions of Note for Retailers

Biometrics in Québec: CAI sets a high bar for retailers using facial recognition technologies for theft and prevention

The CAI recently prohibited the creation and use of a biometric database proposed by a grocery retailer, which wished to use facial recognition to prevent fraud and theft.

The retailer notified the CAI of its intentions to commence a pilot project to use facial recognition technology in some of its stores, with the stated aim to counter shoplifting and fraud. According to the retailer, facial recognition would be based on images captured by CCTV cameras installed at the entrances and exits of its stores. An algorithm would be used to compare these images against a database of reference images compiled by the retailer using CCTV footage of prior shoplifting or fraud events involving people of legal age and who were the subject of police intervention If there were a match between the image captured by the CCTV cameras and one in the reference database, an alert would be sent to the person managing the database. The retailer indicated it would not obtain express consent from individuals.

When the CAI expressed concern, the retailer argued it was not actually seeking to verify or confirm the exact identity of individuals, but rather to prevent shoplifting and fraud based on a simple “match” of faces entering the store with faces captured from prior CCTV shoplifting and fraud incidents. The CAI nonetheless found that the act of confirming whether individuals belonged to a specific group of people (e.g., potential shoplifters) was verification of identity within the meaning of the applicable legislation.

The CAI reviewed the retailer’s submission and rejected it on multiple grounds:

  • The proposed process was mandatory (in other words, it was going to be applied to every person entering the store and there was no alternative or ability of a person to withdraw consent).
  • Express consent was required and the retailer said it would not be obtaining such consent.
  • The invasion of privacy was disproportional given the sensitivity of the biometric information. The CAI noted that the proposed process was based on police interventions for shoplifting and fraud rather than on actual judgements deciding the guilt of the persons involved and therefore was a breach of the right to be presumed innocent, which meant the proposed process could not support the legitimacy of processing requirement in the Québec privacy law.

Biometrics in British Columbia: Consent is key, even if it’s difficult to obtain

In 2023, the OIPC investigated four large department-style stores in British Columbia for their use of facial recognition technology for the stated purpose of loss prevention and protecting staff and customers.[10] As in the Québec case, the systems collected facial images or videos of individuals entering the stores, created biometric templates from those faces, and compared these to a database of previously collected photos and biometric templates representing persons of interest who had allegedly been involved in incidents the company’s stores in the same region. Specifically, the OIPC assessed whether the stores properly notified customers, obtained valid consent and whether the stated purpose of collection of personal information were reasonable. At the time of the OIPC investigation, the stores had been using this technology for approximately three years.

Following its investigation, the OIPC published a report with the following findings:

  • The stores were required to obtain consent prior to, or at the time of, collecting individuals’ images and creating facial biometrics;
  • While the stores had posted notices at their entrance doors referring to the use of facial recognition technology or biometrics, the OIPC found that the notices did not provide sufficient information detailing what personal information was collected and the intended purposes of collection. The OIPC found that the stores erred by assuming that customers would understand what biometric information is and the implications and risks associated with facial recognition technology.
  • The stores did not obtain explicit consent and while the OIPC acknowledged that this posed a “significant undertaking” in a retail environment, it nonetheless maintained that explicit consent was “necessary, proportionate and commensurate [when] asking people to hand over to a retailer extraordinarily detailed and sensitive personal information.”
  • The stores did not demonstrate a reasonable purpose to collect personal information through facial recognition technology, considering the:
    • Quantity of sensitive information collected;
    • Issues of accuracy and limits to effectiveness with the facial recognition systems; and
    • Availability of less intrusive means to achieve the stated purposes of data collection.

This last point is generally the most difficult one for retailers. When considering the adoption of biometric technologies, organizations must demonstrate that they have explored other, less intrusive means to achieve the same purposes, and that the alternatives are not as effective or cost prohibitive. This means that retailers contemplating something like CCTV cameras with facial recognition to reduce theft would need to demonstrate that alternatives such as asset protection officers, asset tags, etc are less effective at solving theft issues. This requires more than just vague assurances or beliefs—retailers will need to have hard data and cost figures, and potentially numbers from a pilot project. Note that in Québec, any such pilot project would require prior notice to the CAI, but if rejected, would limit sunk costs by a retailer and/or allow it to make improvements that may get the pilot project approved (the results of which could support a wider adoption).

Key Takeaways for Retailers

  • Consent is key: Identify efficient ways to notify customers that their personal information is collected for or by biometric technologies, what these technologies are, along with the purposes of collection. The risks associated with the use of such technologies should be explained.
  • Necessity: Limit the use of biometric information to that which is strictly necessary for the purposes for which it was collected and ensure that the biometric technology effectively meets these purposes.
  • Understanding customers: Avoid assuming customers are familiar with biometrics when integrating new biometric technologies into retail operations.
  • Understanding biometrics: Familiarize yourselves with privacy implications relating to the biometric technologies integrated into retail operations in order to interact with customers and regulators according. Be skeptical of claims from U.S. companies, which operate in a different regulatory environment than the one in Canada. In particular, be skeptical of claims that no personal information is being used (i.e., “it’s just face detection, not face recognition”), or that the information is “anonymous” (this is a defined term in Canada and only refers to specific types of processes).
  • Privacy management programs: Review existing privacy policies, programs and practices to ensure that they account for and document the collection, use and disclosure of biometric information.
  • Privacy impact assessments: Regularly conduct privacy impact assessments for any program, technology or device involving the use of biometric information. Such assessments are required in Québec and are considered a best practice elsewhere in Canada.
  • Contractual parameters: Review and update the terms of agreements relating to or impacted by the use of biometric information. This includes negotiating appropriate use restrictions on personal information, and ensuring allocation of risk through limitation of liability and indemnification clauses is fair and reasonable.
  • Notification: Where necessary, notify privacy regulator(s) in accordance with the legislative and regulatory requirements. Avoid treating this notification as an afterthought; a significant investment of time and resources should go into building your case. Considering working with outside counsel to help reduce the risk your project will be rejected.
  • Build your case: Gather the data you need to support the effectiveness, efficiency, and necessity of your proposed use of biometric technology. Consider carefully constructed pilot projects to demonstrate the need for the technology (and in Québec, give the required notice to the CAI for these pilot projects). Ensure you have considered alternatives, documented any testing, and explain why they are unsuitable. If you are considering using facial recognition, review results and rankings from international testing bodies in respect of effectiveness, bias, and error rates.

[1] Retail Council of Canada, Facial Recognition and Biometrics: Overview and Regulator Guidance, August 26, 2025 <https://www.retailcouncil.org/facial-recognition-and-biometrics-overview-and-regulator-guidance/>.

[2] https://www.cai.gouv.qc.ca/protection-renseignements-personnels/sujets-et-domaines-dinteret/biometrie

[3] Joint investigation of Clearview AI. https://www.oipc.bc.ca/investigation-reports/3505; OIPC Investigation Report 23-02, Canadian Tire Association Dealers’ use of facial recognition technology, [2023] B.C.I.P.C.D. No. 17, page 18.

[4] Investigation Report F12-01 BCIPC 5. Para. 43. https://www.oipc.bc.ca/investigation-reports/1245; OIPC Investigation Report 23-02, Canadian Tire Association Dealers’ use of facial recognition technology, [2023] B.C.I.P.C.D. No. 17, page 18.

[5] https://www.priv.gc.ca/en/privacy-topics/health-genetic-and-other-body-information/biometrics/gd_bio_org-final/

[6] See PIPEDA s.2(1), APPIPS s.2, BC PIPA s.1 and AB PIPA s.1(1)(k).

[7] SC 2000, c 5.

[8] SA 2003, c P-6.5.

[9] SBC 2003, c 63.

[10] OIPC Investigation Report 23-02, Canadian Tire Association Dealers’ use of facial recognition technology, [2023] B.C.I.P.C.D. No. 17