Apple is facing a proposed $32.5 billion class-action lawsuit alleging that its Photos app unlawfully collected and stored biometric facial data from millions of Illinois iPhone users without obtaining the written consent required under the Illinois Biometric Information Privacy Act (BIPA). Plaintiffs contend Apple’s facial-recognition technology creates unique “faceprints” that qualify as protected biometric identifiers under Illinois law and that the company failed to provide legally required notice and retention policies. Apple argues that the feature is privacy-protective, that the data is anonymized and inaccessible, and that it does not constitute the type of biometric information covered by the statute. Federal courts have nevertheless allowed the case to proceed as a class action, potentially encompassing approximately 6.5 million Illinois residents, making it one of the largest biometric privacy cases ever brought against a technology company.
Sources
- https://www.thetimes.com/business/companies-markets/article/apple-32bn-lawsuit-biometric-data-iphones-3tq3w68kz
- https://news.bloomberglaw.com/class-action/apple-iphone-users-win-class-certification-for-biometric-suit
Key Takeaways
- Illinois’ Biometric Information Privacy Act continues to be one of the nation’s most powerful privacy laws, allowing significant statutory damages when companies allegedly collect biometric identifiers without informed written consent.
- The lawsuit challenges Apple’s long-standing privacy-focused public image by arguing that even privacy-branded technologies must comply with strict biometric consent requirements.
- The federal courts’ decision to certify the class dramatically raises Apple’s potential financial exposure, ensuring the dispute will become a closely watched test of biometric privacy law as applied to consumer artificial intelligence and facial-recognition technologies.
In-Depth
The lawsuit against Apple represents another chapter in the growing legal battle over who controls biometric information in the digital age. While technology companies increasingly promote facial recognition as a convenience feature, courts are being asked to determine whether those capabilities cross legal boundaries established to protect consumers’ most personal data. Illinois lawmakers anticipated many of these concerns nearly two decades ago when they enacted BIPA, requiring companies to obtain informed written consent before collecting biometric identifiers such as fingerprints and faceprints.
Plaintiffs argue Apple’s Photos application automatically analyzes photographs to generate facial templates that allow the software to recognize individuals across a user’s image library. According to the complaint, that process constitutes the collection of biometric data under Illinois law, regardless of whether Apple ultimately uses the information for organizational purposes rather than advertising or surveillance. Because BIPA authorizes substantial statutory damages for each alleged violation, the financial exposure grows rapidly when millions of users are involved.
Apple maintains that its technology was designed with privacy in mind, emphasizing that facial-recognition information is protected, anonymized, and not readily associated with an individual’s identity. The company contends these technical safeguards distinguish its implementation from the practices the Illinois statute was intended to prevent.
Regardless of the eventual outcome, the litigation underscores an increasingly important principle: companies cannot rely solely on technical privacy protections if courts conclude statutory consent requirements were not satisfied. As artificial intelligence and biometric technologies become standard features on consumer devices, this case could influence how technology firms design, disclose, and deploy facial-recognition capabilities for years to come.

