Apple Faces $32.5B Lawsuit Over Photos Facial Recognition
MichaelJayBerlin / Shutterstock
Toggle Dark Mode
Another month, another class-action lawsuit. Apple is now poised to face a legal challenge that its facial recognition feature in the Photos app is a violation of biometric privacy laws. And the craziest part is that it could cost the company up to $32.5 billion.
The case itself, which was brought against Apple in March 2020, is now moving forward after receiving certification as a class action lawsuit in June. It began six years ago, when a relatively small group of iPhone users filed a putative class action in Illinois alleging that the “People” album in the Photos app on iPhone, iPad, and Mac was in violation of the state’s Biometric Information Privacy Act (BIPA).
The act in question was passed in 2008 to address concerns about how technology was collecting and using various biometric identifiers such as retina or iris scans, fingerprints, voiceprints, and faceprints. It bans companies from collecting a person’s biometric information without prior notice and written consent.
Apple added facial recognition capabilities to the Photos app in 2016 with the release of iOS 10, running entirely on-device. In fact, the early implementation was so privacy-focused that it didn’t even exchange facial recognition data via iCloud Photos; the facial recognition had to run on each iPhone, iPad, and Mac independently, and if users wanted to assign names to faces, they had to do it separately on each device.
However, the plaintiffs in the Illinois class action are claiming that Apple is collecting “face Biometric Data without obtaining consent, let alone the ‘informed written consent’ required by BIPA.”
The court filing goes on to add that “Defendant’s devices, further, collect Biometric Data from all individuals, including minors, whose faces appear in Apple Device users’ photographs — not just from Apple Device users (emphasis in original).
Plaintiffs also maintain that because this facial recognition feature cannot be disabled, all Apple device users who take or store photographs are being forced to allow Apple to collect Biometric Data from every photo they store.
Defendant indiscriminately collects Biometric Data for all photographic subjects, including customers, non-customers, and minors incapable of providing informed consent.
Hazlitt et al v. Apple Inc.
This is likely where the staggering damages of $32.5 billion are coming from, as the lawsuit is asking for statutory damages of $5,000 “for each intentional and reckless violation,” and $1,000 for “each negligent violation.”
Since this case is being brought under an Illinois law, the “class” consists only of residents of that state. However, the plaintiffs’ initial filing had asked for the class to cover anyone in Illinois whose face appeared in one or more photographs taken or stored on an Apple device running the Photos app from March 4, 2015 until present, whether it was their own device or not. This would have not only encompassed the entire 12.7 million-person populace of the state, but also anyone who was a resident of Illinois over the past eleven years.
That could easily have racked the maximum damages up into the $100 billion range. However, class action lawsuits can’t be certified unless the plaintiffs can prove that the class members can be reliably identified and that they share a common, uniform injury. Apple’s lawyers successfully argued that the original definition was impossibly broad, untraceable, and unmanageable as a single lawsuit.
As a result, in granting the class certification, US District Judge Nancy Rosenstengel narrowed the lawsuit to essentially include Illinois residents who owned Apple devices and actively used the facial recognition feature. She also set the start date to September 13, 2016 — the date when iOS 10 was released to the public.
That’s still 6.5 million residents of Illinois, so if the plaintiffs can prove that Apple intentionally and recklessly violated BIPA, each of those folks could find themselves receiving sizeable checks. Of course, the usual legal and administrative fees will likely shave off about half of that.
However, companies rarely face a jury for the statutory maximum; they almost always agree to a much smaller settlement. For example, when Google and Meta faced similar cases under BIPA, the companies settled for considerably less — $650 million for Facebook, $100 million for Google Photos, and $68.5 million for Instagram — resulting in payouts of between $32.50 and $397 per person.
Apple might similarly settle to avoid the risk of a multi-billion-dollar penalty. Fortunately for Apple, because this specific class action was narrowed strictly to device owners, a settlement wouldn’t likely force the company to disable the “People” album in Illinois. Instead, Apple could likely resolve the lawsuit — much like Google did — by simply introducing an explicit opt-in consent screen for device owners in a future software update.
While this would undoubtedly satisfy the terms of the settlement and shield Apple from this massive class action, it technically wouldn’t clear the company from the underlying requirements of BIPA. Under the strict letter of the law, Apple still theoretically needs consent from everyone whose face is scanned in a photo — even strangers in the background. However, Apple will likely treat that lingering technical violation as a calculated risk, since it’s effectively impossible to create an ascertainable class of random people who don’t own any Apple devices but happened to appear in photos taken by someone else’s iPhone, iPad, or Vision Pro.
Although Ben Lovejoy makes a compelling case over at 9to5Mac as to why this isn’t a privacy threat — and I’ll be the first to agree — laws can be weird sometimes, especially when they were written when the iPhone was barely one year old.
When BIPA was written in 2008, legislators weren’t thinking of on-device processing and the privacy guardrails it offered. The law was written as a blunt instrument that simply made it illegal for any company to “capture” a faceprint without written permission. This means such a case will likely descend into semantics on the meaning of words like “capture,” “obtain,” and “possess” — and the plaintiffs are well aware of this.
For instance, the lawsuit argues that the mere fact that Apple designed the Photos app and wrote the code that “captures” the face geometries makes it responsible for asking for consent, regardless of where the data is stored. It’s the act of capturing the faceprint here, not what Apple does with it afterward. Similarly, the minute a user turns on iCloud Photos, that data is uploaded to Apple’s servers, putting them in “possession” of the biometric data. The case argues that even if the data is end-to-end encrypted, such that Apple can’t read it, it’s still on Apple’s servers.
In other words, Apple could find itself falling prey to an 18-year-old law that hasn’t kept up with the times. In a situation like that, it would hardly be surprising if the company chose to simply settle for a nine-figure amount rather than risking a jury taking it to ten or eleven.


