
Apple is facing a potential multibillion-dollar legal battle in Illinois over allegations that its Photos app collected users’ biometric information without proper consent.
The class-action lawsuit, reported by The Times, claims that Apple’s facial recognition technology creates digital faceprints from images stored on iPhones, raising questions about privacy and compliance with Illinois’ strict biometric data protection laws.
If the case succeeds, Apple could face damages of up to $32.5 billion on behalf of millions of affected consumers.
Lawsuit targets Apple’s facial recognition technology
At the center of the dispute is the Photos app’s ability to automatically identify people in images and organise pictures based on faces.
The lawsuit alleges that Apple’s system analyses photographs to generate unique facial data, commonly referred to as faceprints, without obtaining explicit permission from users.
According to the complaint, these facial identifiers are created through algorithms that process repeated images of individuals, allowing the system to recognize people appearing across a user’s photo library.
Plaintiffs raise concerns over biometric data storage
The lawsuit argues that Apple’s approach creates privacy risks because biometric information is considered highly sensitive and cannot be changed like a password if compromised.
The plaintiffs claim that after collecting enough facial samples, Apple’s technology can identify individuals and store related information within the Photos app.
The legal action argues that users were not adequately informed about this process or given the opportunity to provide consent before the alleged collection occurred.
iCloud syncing becomes another point of dispute
The lawsuit also raises concerns about Apple’s iCloud service.
Plaintiffs allege that when photos are synchronized across Apple devices through iCloud, associated facial recognition data may also be transferred or stored, potentially creating additional privacy concerns.
They argue that this practice could violate Illinois regulations governing the collection and handling of biometric information.
Millions of Illinois residents included in lawsuit
The case has been filed on behalf of approximately 6.5 million Illinois consumers.
Under the state’s biometric privacy law, potential damages can reach thousands of dollars per violation, which is why the lawsuit’s estimated value could rise to $32.5 billion if Apple is found liable.
The final amount would depend on the court’s findings and how violations are calculated.
Apple argues Photos data is not biometric information
Apple has attempted to dismiss the lawsuit, arguing that its photo organization technology does not qualify as a biometric identifier under Illinois law.
The company maintains that the mathematical data used to group photos cannot recreate a person’s face and cannot be directly connected to an individual’s identity.
Apple has also pointed to privacy protections built into its ecosystem, arguing that its approach differs from systems that store identifiable facial recognition databases.
However, an Illinois judge ruled in June that the lawsuit met the requirements to proceed as a class action.
Illinois biometric privacy law at the center of the case
The lawsuit is based on the Illinois Biometric Information Privacy Act (BIPA), one of the strictest biometric privacy laws in the United States.
Enacted in 2008, the law regulates how private companies collect, store, and share biometric identifiers, including fingerprints, voiceprints, retina scans, iris scans, and faceprints.
Under BIPA, companies must obtain informed consent before collecting biometric data and must maintain proper safeguards to protect that information.
The Apple case highlights a growing legal debate over how artificial intelligence and automated image recognition technologies handle personal data. As companies increasingly use machine learning to organise photos and improve digital services, courts are being asked to define where convenience ends and biometric privacy concerns begin.



