Mobile Tech
Apple’s Legal Battle: Multi-Billion Dollar Lawsuit Over Facial Recognition Technology
Another month, another class-action lawsuit. Apple is now poised to face a legal challenge that its facial recognition feature in the Photos app is a violation of biometric privacy laws. And the craziest part is that it could cost the company up to $32.5 billion.
The case itself, which was brought against Apple in March 2020, is now moving forward after receiving certification as a class action lawsuit in June. It began six years ago, when a relatively small group of iPhone users filed a putative class action in Illinois alleging that the “People” album in the Photos app on iPhone, iPad, and Mac was in violation of the state’s Biometric Information Privacy Act (BIPA).
The act in question was passed in 2008 to address concerns about how technology was collecting and using various biometric identifiers such as retina or iris scans, fingerprints, voiceprints, and faceprints. It bans companies from collecting a person’s biometric information without prior notice and written consent.
Apple added facial recognition capabilities to the Photos app in 2016 with the release of iOS 10, running entirely on-device. In fact, the early implementation was so privacy-focused that it didn’t even exchange facial recognition data via iCloud Photos; the facial recognition had to run on each iPhone, iPad, and Mac independently, and if users wanted to assign names to faces, they had to do it separately on each device.
However, the plaintiffs in the Illinois class action are claiming that Apple is collecting “face Biometric Data without obtaining consent, let alone the ‘informed written consent’ required by BIPA.”
The court filing goes on to add that “Defendant’s devices, further, collect Biometric Data from all individuals, including minors, whose faces appear in Apple Device users’ photographs — not just from Apple Device users (emphasis in original).
Plaintiffs also maintain that because this facial recognition feature cannot be disabled, all Apple device users who take or store photographs are being forced to allow Apple to collect Biometric Data from every photo they store.
Defendant indiscriminately collects Biometric Data for all photographic subjects, including customers, non-customers, and minors incapable of providing informed consent.
Hazlitt et al v. Apple Inc.
This is likely where the staggering damages of $32.5 billion are coming from, as the lawsuit is asking for statutory damages of $5,000 “for each intentional and reckless violation,” and $1,000 for “each negligent violation.”
Since this case is being brought under an Illinois law, the “class” consists only of residents of that state. However, the plaintiffs’ initial filing had asked for the class to cover anyone in Illinois whose face appeared in one or more photographs taken or stored on an Apple device running the Photos app from March 4, 2015 until present, whether it was their own device or not. This would have not only encompassed the entire 12.7 million-person populace of the state, but also anyone who was a resident of Illinois over the past eleven years.
That could easily have racked the maximum damages up into the $100 billion range. However, class action lawsuits can’t be certified unless the plaintiffs can prove that the class members can be reliably identified and that they share a common, uniform injury. Apple’s lawyers successfully argued that the original definition was impossibly broad, untraceable, and unmanageable as a single lawsuit.
As a result, in granting the class certification, US District Judge Nancy Rosenstengel narrowed the lawsuit to essentially include Illinois residents who owned Apple devices and actively used the facial recognition feature. She also set the start date to September 13, 2016 — the date when iOS 10 was released to the public.
That’s still 6.5 million residents of Illinois, so if the plaintiffs can prove that Apple intentionally and recklessly violated BIPA, each of those folks could find themselves receiving sizeable checks. Of course, the usual legal and administrative fees will likely shave off about half of that.
However, companies rarely face a jury for the statutory maximum; they almost always agree to a much smaller settlement. For example, when Google and Meta faced similar cases under BIPA, the companies settled for considerably less — $650 million for Facebook, $100 million for Google Photos, and $68.5 million for Instagram — resulting in payouts of between $32.50 and $397 per person.
Apple might similarly settle to avoid the risk of a multi-billion-dollar penalty. Fortunately for Apple, because this specific class action was narrowed strictly to device owners, a settlement wouldn’t likely force the company to disable the “People” album in Illinois. Instead, Apple could likely resolve the lawsuit — much like Google did — by simply introducing an explicit opt-in consent screen for device owners in a future software update.
While this would undoubtedly satisfy the terms of the settlement and shield Apple from this massive class action, it technically wouldn’t clear the company from the underlying requirements of BIPA. Under the strict letter of the law, Apple still theoretically needs consent from everyone whose face is scanned in a photo — even strangers in the background. However, Apple will likely treat that lingering technical violation as a calculated risk, since it’s effectively impossible to create an ascertainable class of random people who don’t own any Apple devices but happened to appear in photos taken by someone else’s iPhone, iPad, or Vision Pro.
Although Ben Lovejoy makes a compelling case over at 9to5Mac as to why this isn’t a privacy threat — and I’ll be the first to agree — laws can be weird sometimes, especially when they were written when the iPhone was barely one year old.
When BIPA was written in 2008, legislators weren’t thinking of on-device processing and the privacy guardrails it offered. The law was written as a blunt instrument that simply made it illegal for any company to “capture” a faceprint without written permission. This means such a case will likely descend into semantics on the meaning of words like “capture,” “obtain,” and “possess” — and the plaintiffs are well aware of this.
One example highlighted in the legal case is that Apple is being held accountable for obtaining consent due to designing the Photos app and creating the code that collects facial geometries. The key issue is the action of capturing the faceprint, rather than Apple’s subsequent use of the data. Additionally, once a user activates iCloud Photos, the data is transferred to Apple’s servers, placing them in possession of the biometric information. The argument presented asserts that even if the data is encrypted end-to-end, preventing Apple from accessing it, it remains stored on Apple’s servers.
In essence, Apple may face consequences due to an outdated law that fails to keep pace with technological advancements. In such a scenario, it would not be unexpected for the company to opt for a settlement amount in the hundreds of millions rather than risk a jury awarding a significantly higher sum.
-
Facebook9 months agoEU Takes Action Against Instagram and Facebook for Violating Illegal Content Rules
-
Facebook10 months agoWarning: Facebook Creators Face Monetization Loss for Stealing and Reposting Videos
-
Facebook8 months agoFacebook’s New Look: A Blend of Instagram’s Style
-
Facebook10 months agoFacebook Compliance: ICE-tracking Page Removed After US Government Intervention
-
Facebook8 months agoFacebook and Instagram to Reduce Personalized Ads for European Users
-
Facebook10 months agoInstaDub: Meta’s AI Translation Tool for Instagram Videos
-
Facebook8 months agoReclaim Your Account: Facebook and Instagram Launch New Hub for Account Recovery
-
Apple10 months agoMeta discontinues Messenger apps for Windows and macOS

