Apple faces a class action worth up to $32.5 billion over the collection of biometric information from users of its Photos app, after the US Court of Appeals for the Seventh Circuit on Thursday denied the company’s appeal against a ruling certifying the class.
As many as 6.5 million consumers in the US state of Illinois could seek $5,000 each in damages, on the basis that Apple illegally collected their biometric information through a facial-recognition feature without proper notice, consent or retention policies.
The claimants allege Apple collected their biometric data without consent in violation of the Illinois Biometric Information Privacy Act, a state law passed in 2008 owing to concerns about how emerging technology was increasingly collecting and using biometric identifiers such as retina or iris scans, fingerprints, voiceprints or faceprints that are biologically unique to an individual.
The law bans companies from collecting a person’s biometric information unless they first provide notice and obtain the person’s written consent.
Plaintiffs in the class action allege that Apple’s Photos app, which comes pre-installed on Apple devices, automatically uses facial-recognition technology to scan individual faces and create a unique “faceprint” for each person detected in the user’s photo library.
They claim that once the software has a sufficient sampling of images, the Photos app then applies an algorithm to identify the iPhone user, creating biometric information that is stored on the device and catalogued in the app.
In 2017, Apple began syncing photographs and associated data across multiple Apple devices, if those devices were logged into iCloud with the user’s Apple ID. Plaintiffs claim that this data is biometric information under the Illinois law, and that the company collects and stores the biometric information on its servers.
Apple has sought to have the case thrown out, arguing that whether the alleged data qualifies as biometric identifiers or information depends on individualised proof about each user’s choices and labels.
The company has said the Photos app has privacy safeguards, so that the numerical vectors it uses to organise photo albums cannot recreate a face and are not inherently linked to a person’s name or identity. Apple said it cannot access vector data, does not decrypt or use album labels, and does not know who appears in a user’s albums, whether any album is labelled, or what any label says.
In June an Illinois judge ruled that consumers had met the requirements to pursue a class action. Thursday’s appeal court decision leaves that certification in place.
Andrew Schlichter, lawyer for the plaintiffs, told The Times: “The allegation that Apple created faceprints of people appearing in photos, including children, and stored those faceprints on its cloud-based servers — without obtaining consent or telling device users what it was doing — raises serious privacy concerns. We are pleased with the court’s decision to certify a class, which means that Apple will have to answer for its alleged conduct as to all affected Illinois citizens.”
Apple was contacted for comment.
The case is the latest legal and regulatory pressure on the company’s handling of user data and its control of mobile platforms. Apple last year withdrew its Advanced Data Protection encryption tool from UK iCloud users rather than meet a Home Office request for access, and the Competition and Markets Authority has said it will take action against Apple and Google over their mobile platforms.
Regulators elsewhere have also turned to consumer data cases. The Information Commissioner’s Office fined the genetic testing firm 23andMe £2.31 million over a data breach affecting UK residents.