Walmart renews privacy policy on biometric data collection: What does it mean for shoppers?
Collected data may include “imagery of iris or retina” and “face geometry.”

Image by Shutterstock.
- Walmart says it may collect biometric data such as voiceprints, face geometry, iris images, and fingerprints.
- The company says it deletes biometric data after its purpose ends, within three years, or as law requires.
- Walmart says voice data is captured only when customers activate voice features, not during in-store shopping.
- The update comes after Walmart faces an Illinois lawsuit over alleged voiceprint collection without customer consent.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Walmart is ready to collect users’ biometric data, but there’s a catch.
Walmart has recently updated its Customer Privacy Notice, which details what kind of customer data the company may collect in its physical and online stores.
Among the data collected by the company that could be considered “regular,” such as one’s name, telephone number, and email address, the policy notes that the company may also collect users' biometric data.
This information may include “voice prints, imagery of the iris or retina, face geometry, and palm prints or fingerprints.”
Walmart’s Customer Privacy Notice also revealed that the company collects data by its cameras and automated technologies, which may capture images of customers “as part of check out, to help deter theft, or improve store design to better serve our customers.”
If law allows it, the company may also use Flock-style Automated License Plate Readers (ALPR) to collect personal data to “ensure safety, prevent theft and fraud, assist with parking enforcement, and to help maintain the safety of individuals and properties.”
According to Walmart, it won’t keep customers’ biometric identifiers and biometric information forever.
The company will delete the data once its “initial purpose” has been accomplished, within 3 years of a customer’s last interaction with the company, or, in any case, as required by law.
Where does this update come from?
The Walmart Customer Privacy Notice was updated to include information about voice interactions.
While the company adds voiceprints as part of the biometric data it may collect, it states that it doesn’t use this data for biometric analysis.
The company doesn’t record customers when they’re in the store, but rather “only capture voice interactions when you activate a voice feature, such as when you press the microphone button in the search bar or within Sparky.”
Walmart is facing a class-action lawsuit in Illinois after it was accused of violating the Illinois Biometric Information Privacy Act (BIPA).
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The plaintiffs claimed that the company used their customer service phone calls to create voiceprints using AI without users' consent.
However, according to BIPA, a company can only collect biometric information if it meets certain conditions, including informing a subject in writing that their biometric data is being collected or stored.
The subject must also be informed in writing of the specific purpose of data collection and how long it will be collected and stored. Finally, the company must receive a written release executed by the subject of the biometric information.
Considering that each state may have different laws, Walmart’s privacy notice includes wording such as “may collect,” indicating that it has the means and internal regulations to do so, but it doesn’t mean that it actively tracks every customer’s visit. The scope of the tracking may depend on the state, the store, and the technology it implements, noted Gadget Review.
Growing customer surveillance
The surge in changes in privacy policies comes with user backlash against their surveillance.
Many people were concerned when Walmart’s patents related to emotional recognition technology resurfaced, hinting that shoppers' emotions might dictate how much they would pay for their groceries.
While such technology isn’t yet a reality, some are already worried that information available about them may be used to exploit them.
A woman on TikTok shared a case of what could be considered an example of dynamic pricing. She decided to buy $3 shoes, only to find out later that by the time she reached the counter, they were $20.
This isn’t the only surprise people had to deal with while just trying to shop.
There have been multiple cases in which customers were afraid to return to the store after being misidentified by facial recognition technology, resulting in their being escorted from the building without an explanation.
Cybernews has contacted Walmart for additional comment.