The change is more consequential for IT teams than a fresh sign at the entrance. A retailer’s CCTV estate can look unchanged while its video-management platform, loss-prevention service, cloud analytics add-on, or facial-recognition watchlist function creates a separate biometric-data practice. Erie County’s Biometric Transparency and Privacy Act makes that distinction central: conventional recording remains permitted; converting people in the footage into persistent, searchable biometric records does not.
Next City’s report traces the ordinance to the broader public attention around Wegmans’ notices in Manhattan and Brooklyn. Gothamist first reported in January that signage at those stores said the chain could collect biometric identifier information including face, eye, and voice data. Wegmans subsequently told Gothamist it deploys facial-recognition-equipped cameras at a “small fraction” of stores it considers at elevated risk, to identify people previously flagged for misconduct. The company said it does not collect retinal scans or voiceprints, does not share facial-recognition scan data with third parties, and retains images and video only as long as needed for security.
The county law is real, but the chronology in the supplied account needs correcting. Erie County legislators approved the measure on April 30, 2026; County Executive Mark Poloncarz signed it on May 26, 2026; and the county’s Consumer Protection Division says it took effect on June 5, 2026. Legislator Lawrence Dupre had introduced earlier versions in January, with a later revised introduction moving through the legislature in April. Those dates matter because the law was already in force for more than two months when this story was republished on August 20.
Erie County’s rule is a ban with a data-destruction tail
The county describes Local Law No. 1-2026 as a prohibition on commercial establishments collecting, storing, procuring, using, selling, or otherwise monetizing a customer’s biometric identifier information in commercial settings. Its listed coverage includes facial recognition, fingerprints, voice recognition, iris scans, and gestures.
The practical wrinkle is the treatment of data that businesses held before the law took effect. The county required a covered establishment already possessing biometric information to notify the Consumer Protection director within 30 days, disclose the type and amount of information held, publish a destruction policy conspicuously at the business, and then file an affidavit certifying permanent deletion or destruction within 30 days after the notice.
Those were not merely future-facing obligations. With a June 5 effective date, the notice-and-policy deadline was July 5, and the subsequent certification deadline generally fell in early August. By August 20, affected businesses should be past the transition period. The county can seek civil penalties of $1,000 to $5,000 per day for a continuing violation.
That implementation detail changes the story from a broad policy pronouncement into a compliance event. A retailer that switched off a facial-recognition camera but left an old watchlist, feature-vector database, exported face templates, or cloud backup intact could still have a problem. The same is true of vendors that market incident investigation tools, theft-prevention analytics, or “known offender” matching under names that avoid the phrase facial recognition.
The law draws a usable line between cameras and identification
The most important operational point for store operators, managed service providers, and security integrators is that Erie County did not outlaw cameras. Poloncarz said during the signing ceremony that businesses may continue using surveillance for anti-theft, anti-fraud, and property protection, provided they do not convert captured information into retained biometric information for later use.
That leaves a clearer dividing line than the public debate often suggests. A camera recording a shop floor for later review is not automatically facial recognition. Video becomes a biometric system when software extracts or analyzes physiological or behavioral characteristics to identify, or help identify, a person—and then uses or retains that output.
For an IT administrator, “we only use cameras” is therefore not an adequate answer. The relevant audit questions are more specific:
- Does the video platform offer face matching, person re-identification, voiceprint matching, gait analysis, or a suspect/watchlist feature, even if it is not currently marketed as biometric surveillance?
- Does any managed-security provider, cloud VMS, or loss-prevention contractor receive clips, images, templates, or alert feeds that can be used to identify a customer?
- Are biometrics generated by a device, stored in a separate tenant, retained in backups, or sent to a vendor’s support and analytics environment?
- Can ordinary access-control or employee authentication tools capture customer data incidentally, and are commercial premises properly segmented from employee-only systems?
A signed vendor attestation is useful, but it will not substitute for checking configuration, retention settings, export paths, and contractual data-use terms. This is particularly relevant when a retailer’s surveillance hardware has gained AI features through a firmware update or a cloud subscription rather than an obvious new installation.
New York City’s sign rule exposed a practice; Erie County makes it prohibited
New York City’s 2021 biometric-identifier law took a different approach. It requires covered retailers, food-and-drink establishments, and entertainment venues that collect, use, or retain biometric identifier information to post clear entrance notices. It also prohibits selling that information and gives consumers a private right of action for certain violations.
The city’s rule did what transparency laws often do: it made a previously obscure practice visible. Wegmans’ mandated storefront notices sparked reporting and a public response precisely because many shoppers had assumed that security cameras were only recording video, rather than feeding an identification system.
But a disclosure is not consent, and it does not stop collection. Under New York City’s framework, a shopper may learn that face geometry, an iris scan, a fingerprint, or a voiceprint could be collected, then decide whether to walk in. Erie County chose to eliminate that choice for most commercial operators by prohibiting the activity instead.
The distinction has consequences for technology procurement. A New York City retailer might treat an entrance notice, a policy document, and limits on selling data as the core compliance controls. In Erie County, those steps do not authorize new customer biometric collection. A product that is lawful to deploy with proper disclosure in one jurisdiction may require disabling a feature—or rejecting the product entirely—in another.
The government exemption leaves the broader surveillance question open
The submitted report properly flags a major boundary: Erie County’s commercial ban does not regulate government agencies acting within their official duties, and it also contains exemptions for financial institutions. That means the law constrains private-sector collection within its scope; it does not function as a general ban on state, local, or federal government biometrics.
There is an important difference between that legal limitation and a claim that a particular retailer’s biometric data is being supplied to immigration authorities. Wegmans told Gothamist it does not share facial-recognition scan data with third parties. The reporting reviewed here does not establish that Wegmans’ customer biometric data has been provided to ICE, nor does Erie County’s law prove it has. Privacy advocates’ concern is about the potential risk created when sensitive, durable identifiers exist in commercial databases and can become subject to legal demands, breaches, or policy changes.
That is a defensible concern without overstating the record. Passwords can be reset after a breach; a person’s face cannot be reissued. Biometric templates may be mathematically derived rather than stored as a conventional photograph, but they can still be personal data used for recognition and matching. Data minimization—collecting less, retaining it for less time, and keeping it out of secondary systems—remains the strongest technical control.
A county ordinance now creates a new configuration risk
For consumers, the immediate result is straightforward: a store in Erie County should not be building a facial-recognition or comparable biometric profile simply because someone walked through its doors. For businesses, the compliance risk is more technical than putting up or removing a sign.
The county’s transition deadlines have passed. Organizations operating in Erie County should now be able to identify every surveillance and identity product that processes customer video, audio, or behavioral data; document that biometric functions are disabled or outside the law’s scope; confirm historical data was destroyed where required; and preserve proof of those actions. The law’s daily penalties make an undocumented assumption about a camera vendor’s “AI analytics” a costly one.