Skip to content

Security1 publisher3 min readPublished

A retail-theft bill would wire loss prevention into ICE, and security teams own the plumbing

CORCA puts a retail crime coordination center inside Homeland Security Investigations. Critics say the data-sharing trigger is any "threat," with retailers as direct suppliers.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • The Combating Organized Retail Crime Act (CORCA) establishes an Organized Retail and Supply Chain Crime Coordination Center within ICE's Homeland Security Investigations division.
  • CORCA passed the House in June by a vote of 348-60.
  • Senate supporters are pushing for CORCA's inclusion in the annual defense policy bill, considered must-pass legislation that Congress has cleared for more than 60 consecutive years.
  • The 348 yes votes represent about 85 percent of the 408 votes cast on CORCA in the House.
  • Jina John, ACLU senior policy counsel for AI, privacy and technology, said CORCA is very broadly and vaguely drafted and establishes mechanisms for data sharing among entities, including getting data directly from retailers.

Compiled by The WatchSomething wrong?How this is made

Why it matters

A bill written about shoplifting rings would build its coordination machinery inside an immigration agency: the Combating Organized Retail Crime Act establishes an Organized Retail and Supply Chain Crime Coordination Center within Immigration and Customs Enforcement's Homeland Security Investigations division [1]. It passed the House in June by 348-60, and Senate supporters are pushing to attach it to the annual defense policy bill, which Congress has cleared for more than 60 consecutive years [2][3] - roughly 85 percent of votes cast in the House, on a vehicle that rarely fails [4].

For anyone running loss prevention, fraud, or physical security at a retailer or carrier, this is not a policy abstraction. According to Jina John, senior policy counsel for AI, privacy and technology at the ACLU, the bill is broadly and vaguely drafted and establishes mechanisms for data sharing among participating entities, including getting data directly from retailers [5]. John said the sharing trigger is any "threats" related to retail and supply chain crime, and that the practical effect is giving DHS access to retail surveillance: mall and train station cameras, Flock cameras, and automated license plate readers [6]. She and colleague Nina Patel said the bill inadequately defines "organized retail crime," "retailers," and what kinds of data can be shared [7]. John also drew the contrast that matters for procurement: rather than the government buying data from brokers, already a contentious practice, CORCA gives it an avenue to get the data freely [8].

What sits on the receiving end is the point of contention. Spencer Reynolds, senior counsel at the NAACP Legal Defense and Education Fund's Justice in Public Safety Project, said the ICE fusion center has collated data including cell phone location and health information, and that adding retail data makes that worse [9]. "Together, this information allows ICE to hunt down people, find their families and associates, and pull them from their communities," Reynolds said, adding that the agency has been openly engaging in racial profiling in recent years [10]. Patel called the design "a very large and very dangerous surveillance network" [11].

Backers describe a narrower thing. Senate Judiciary Chairman Chuck Grassley said in a statement that his bill is targeted and bipartisan, coordinating federal, state and local law enforcement while aligning existing resources [12]. A Senate Judiciary Committee spokesperson said it gives DHS no additional enforcement authorities and is housed in Homeland Security Investigations to build on that unit's existing role against transnational and organized crime [13]. Supporters also say it would only enhance existing information sharing and could help fight cyber-enabled crime [14]. The American Trucking Associations supports the bill and its legislative director, Alex Rosen, disputed opponents' claims [15]. Note that "no additional enforcement authorities" and "no new data flows" are different assertions, and only the first has been made.

The bill also creates criminal penalties for laundering proceeds from selling stolen goods and sets a $5,000 threshold for the combined value of stolen property over a year for charging purposes [16]. Aggregating a year of incidents to clear a federal bar means internal shrink records become case-building material.

Watch whether the definitions of "retailer," "organized retail crime," and shareable data get tightened before the defense bill is finalised, and whether sharing is case-by-case or standing. If your camera, ALPR, and fraud-analytics contracts and customer privacy notices do not contemplate immigration enforcement as a downstream recipient, that gap is now a disclosure question, not a hypothetical.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories