Full Report
The Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate — and supporters say it could help fight cybercrime. The post Retail theft bill spurs ‘very large and very dangerous’ surveillance fears appeared first on CyberScoop.
Analysis Summary
# Regulation/Compliance: Combating Organized Retail Crime Act (CORCA)
## Overview
The Combating Organized Retail Crime Act (CORCA) is a bipartisan legislative initiative designed to address the rise of large-scale, multi-jurisdictional retail theft and supply chain crimes. The bill focuses on improving information sharing between the private sector and law enforcement, establishing a centralized federal coordination body, and modernizing criminal statutes to include cyber-enabled retail crime and money laundering.
## Key Details
- **Issuing Authority:** U.S. Congress (House and Senate)
- **Effective Date:** Pending (Targeted for inclusion in the annual National Defense Authorization Act)
- **Jurisdiction:** United States (Federal, State, and Local levels; Retail and Supply Chain sectors)
- **Status:** Proposed (Passed House in June; currently under Senate consideration)
## Requirements
### Mandatory Requirements
1. **Reporting Thresholds:** Establishes a $5,000 threshold for the combined total value of stolen property over a one-year period for the purposes of federal charging.
2. **Law Enforcement Cooperation:** Requires federal agencies to align existing resources via a new coordination center to support state and local investigations.
3. **Money Laundering Compliance:** Expands the definition of money laundering to include proceeds derived from the sale of stolen retail goods.
### Recommended Practices
1. **Information Sharing:** Retailers are encouraged to share data regarding "threats" related to retail and supply chain crime with the Department of Homeland Security (DHS).
2. **Surveillance Integration:** Voluntary integration of retail surveillance data (e.g., CCTV, license plate readers) with law enforcement fusion centers.
## Affected Organizations
- **Industries:** Retailers (brick-and-mortar and online), Logistics and Supply Chain providers, Financial Institutions (due to money laundering provisions).
- **Organization Size:** All sizes, though the focus is on those impacted by "organized" (large-scale) theft.
- **Geographic Scope:** All entities operating within the United States.
## Compliance Timeline
- **June 2026:** Passed the House of Representatives (348-60).
- **Current/Near Term:** Senate consideration and potential inclusion in the National Defense Authorization Act (NDAA).
- **Final Deadline:** Full compliance and center operationalization typically occur within 180–365 days of the President signing the bill into law.
## Implementation Guidance
### Assessment Phase
- **Data Inventory:** Evaluate what surveillance and transaction data is currently collected and how it is stored.
- **Risk Assessment:** Identify high-risk nodes in the supply chain or retail locations prone to organized theft.
### Implementation Phase
- **Privacy Policy Updates:** Update privacy disclosures to inform consumers that data may be shared with the DHS/ICE Coordination Center for crime prevention.
- **Reporting Systems:** Establish protocols for aggregating theft losses to meet the $5,000 federal reporting threshold.
### Validation Phase
- **Audit Trails:** Maintain records of all data shared with the Organized Retail and Supply Chain Crime Coordination Center to ensure compliance with emerging privacy concerns and civil liberties protections.
## Technical Requirements
- **Interoperability:** Organizations may need to ensure surveillance systems (CCTV, Automated License Plate Readers) can export data in formats usable by ICE’s Homeland Security Investigations (HSI).
- **Cybersecurity Controls:** Enhanced monitoring for "cyber-enabled" retail crime, such as fraudulent online marketplace transactions and account takeovers used for fencing goods.
## Penalties & Enforcement
- **Fines:** Criminal penalties associated with money laundering and large-scale theft.
- **Other Consequences:** Increased federal surveillance and potential for civil liberties litigation regarding data misuse.
- **Enforcement:** Enforced by the Department of Justice (DOJ) and the newly created Coordination Center within ICE/HSI.
## Related Standards
- **NIST Privacy Framework:** Relevant for managing the privacy risks associated with increased data sharing with government entities.
- **BSA/AML (Bank Secrecy Act):** Aligns with existing Anti-Money Laundering frameworks by adding stolen retail goods as a predicate offense.
## Resources
- **Official Documentation:** [congress-gov/bill/119th-congress/house-bill/2853](https://www.congress.gov/bill/119th-congress/house-bill/2853)
- **Guidance Documents:** DHS Homeland Security Investigations (HSI) Retail Theft Initiative.
## Practical Recommendations
- **Engage Legal Counsel:** Review the broad definitions of "retailer" and "threat" within the bill to understand potential exposure to broad data requests.
- **Strengthen Cyber Defenses:** Since the bill targets cyber-enabled retail crime, organizations should bolster defenses against online fraud and organized "flash mob" coordination via digital platforms.
- **Monitor Privacy Developments:** Given the ACLU’s concerns regarding "dangerous surveillance," organizations should prepare for increased scrutiny from privacy advocates regarding their data-sharing practices with ICE.