The iPhone Photos app has become the target of a $32.5 billion class-action lawsuit in Illinois, over claims that biometric data is collected from images without informed consent.
The iPhone is known for using Face ID as a biometric security system to protect a user's privacy. However, a class action lawsuit claims that Apple is violating user privacy by collecting biometric data in a completely different part of the ecosystem.
The lawsuit accuses Apple of collecting biometric data without user consent in the Photos app, reports The Times. It is alleged that Photos uses facial recognition technology to scan individuals who appear in images, creating a "faceprint" for each person in the photo library.
After collecting enough samples, an algorithm is allegedly used to identify the iPhone user. That data is then stored on the iPhone within the Photos app.
The lawsuit adds that photographs and associated data is synchronized across devices using iCloud. This data is assumed to be biometric data, and a violation of Illinois law.
The suit counts the 6.5 million consumers in Illinois as being harmed, making the total potential value of the lawsuit up to $32.5 billion if Apple loses.
Apple has attempted to have the lawsuit tossed, questioning whether its processes count as biometric identifiers. It insists that there are privacy safeguards so that the vectors used to organize photo albums cannot recreate a face, and aren't linked to a person's name or identity.
Despite the assertion, an Illinois judge ruled in June that the lawsuit met the requirements of a class action. On June 30, the U.S. Court of Appeals for the Seventh Circuit denied Apple's appeal against the ruling, allowing the class-action suit to continue.
An Illinois privacy act
The law at the center of the suit is the Illinois Biometric Information Privacy Act, a state law that came into force in 2008. The law is an attempt to regulate how biometric information is used by private companies.
This includes biometric identifiers such as retina or iris scans, fingerprints, voiceprints, and faceprints. Under the law, companies must get consent from individuals to collect or disclose personal biometric identifiers, store them securely, and also destroy them in a timely fashion.
The act advises a fine of $1,000 per violation, or up to $5,000 per violation if it is deemed intentional or reckless.
The law has been used in a number of cases already, including against Facebook and Google for their respective image-related services. In the case of Facebook, a $650 million settlement was approved in 2021.