Walgreens · Walgreens Privacy Policy · View original document ↗

Biometric Data Collection and Destruction Schedule

High severity Medium confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Walgreens changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Walgreens Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy states that Walgreens collects biometric information including facial scans for safety, security, and product feature purposes, and commits to permanently destroying that information either when the original collection purpose is satisfied or within three years of the consumer's last interaction with Walgreens, whichever comes first.

This analysis describes what Walgreens's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes a specific biometric data retention and destruction schedule consistent with requirements under statutes such as the Illinois Biometric Information Privacy Act, which mandates destruction within a specified period. The collection of facial scans for product feature purposes alongside security purposes broadens the stated collection scope beyond traditional loss prevention use cases.

Interpretive note: The breadth of 'product feature purposes' as a stated basis for facial scan collection is not defined in the document, and whether this purpose satisfies applicable state biometric consent requirements may vary by jurisdiction.

Consumer impact (what this means for users)

Under this provision, Walgreens may collect facial scan data from customers for security, operational, and product feature purposes and retains that data for up to three years from the consumer's last interaction unless the original collection purpose is satisfied sooner. The agreement states that biometric information is permanently destroyed upon the earlier of purpose fulfillment or the three-year retention limit.

Cross-platform context

See how other platforms handle Biometric Data Collection and Destruction Schedule and similar clauses.

Compare across platforms →

Monitoring

Walgreens has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Biometric Information: such as facial scans for safety, security, and product feature purposes. [...] Biometric Destruction Schedule: We permanently destroy your biometric information when the first of the following occurs: (i) the initial purpose for collecting or obtaining such biometric information has been satisfied; or (ii) within three (3) years of your last interaction with us.

Excerpt from Walgreens's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages the Illinois Biometric Information Privacy Act, which requires written notice, a written release, and a publicly available retention and destruction schedule before collecting biometric identifiers. Analogous statutes in Washington, Texas, and other states may impose similar requirements. The FTC has authority over unfair or deceptive practices related to biometric data under the FTC Act. HHS OCR oversight does not apply to general retail biometric data outside of HIPAA-covered transactions. 2. GOVERNANCE EXPOSURE: High. The collection of facial scans for product feature purposes in addition to security purposes may require assessment of whether the stated notice and consent mechanisms satisfy BIPA's written release requirement for each stated purpose. The three-year retention window tied to last interaction rather than a fixed calendar date creates a rolling retention period that may complicate destruction scheduling across large customer databases. 3. JURISDICTION FLAGS: Illinois creates the highest statutory exposure due to BIPA's private right of action and per-violation damages structure. Washington's My Health MY Data Act and Texas Business and Commerce Code also impose biometric-adjacent requirements. Any store-level biometric collection occurring in Illinois should be reviewed for written consent and publicly posted policy compliance under BIPA Section 15. 4. CONTRACT AND VENDOR IMPLICATIONS: If third-party vendors operate biometric scanning systems in Walgreens stores, vendor agreements should include biometric data handling, retention, destruction, and breach notification obligations consistent with applicable state requirements. Liability for BIPA violations has been asserted against both operators and vendors in prior litigation, though specific case outcomes should be verified independently. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should verify that a publicly available written retention and destruction schedule is posted at each physical location where biometric data is collected, that written individual consent is obtained before collection, and that destruction workflows are operationally tied to the policy's stated triggers. Data mapping should identify all product feature use cases for facial scans to assess whether those purposes require separate consent disclosures.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has authority over unfair or deceptive practices related to biometric data collection and retention under the FTC Act
    File a complaint →
  • State AG
    State attorneys general in Illinois, Texas, and Washington have enforcement authority over biometric privacy statutes applicable to retail collection of facial scan data
    File a complaint →

Provision details

Document information
Document
Walgreens Privacy Policy
Entity
Walgreens
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015995
Document ID
CA-D-00607
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
0f6950919c3da86eab3e4508cb5f4a2245adf341abd12140770ea06252d7325e
Analysis generated
July 9, 2026 09:20 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Walgreens
Document: Walgreens Privacy Policy
Record ID: CA-P-015995
Captured: 2026-07-09 09:20:15 UTC
SHA-256: 0f6950919c3da86e…
URL: https://conductatlas.com/platform/walgreens/walgreens-privacy-policy/provision/CA-P-015995/biometric-data-collection-and-destruction-schedule/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Walgreens's Biometric Data Collection and Destruction Schedule clause do?

This provision establishes a specific biometric data retention and destruction schedule consistent with requirements under statutes such as the Illinois Biometric Information Privacy Act, which mandates destruction within a specified period. The collection of facial scans for product feature purposes alongside security purposes broadens the stated collection scope beyond traditional loss prevention use cases.

How does this clause affect you?

Under this provision, Walgreens may collect facial scan data from customers for security, operational, and product feature purposes and retains that data for up to three years from the consumer's last interaction unless the original collection purpose is satisfied sooner. The agreement states that biometric information is permanently destroyed upon the earlier of purpose fulfillment or the three-year retention limit.

Is ConductAtlas affiliated with Walgreens?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Walgreens.