Apple is facing a $32.5 billion class-action lawsuit in the United States over allegations that its Photos app unlawfully collected and processed users’ biometric data without obtaining the consent required under Illinois law. The Apple lawsuit, certified by a federal judge in Illinois, claims the company’s facial recognition technology automatically scans images stored in users’ photo libraries and generates unique biometric identifiers, or “faceprints,” without first providing the legally mandated notice or obtaining written permission. If Apple is found liable, the potential damages could reach $32.5 billion, making it one of the largest biometric privacy cases ever brought against a technology company.

The case is based on the Illinois Biometric Information Privacy Act (BIPA), one of the strictest biometric privacy laws in the United States. BIPA requires companies to inform individuals before collecting biometric identifiers such as facial geometry and to obtain written consent before storing or using that data. The plaintiffs allege Apple’s Photos app violated these requirements by automatically identifying faces in photos and creating digital face templates without proper authorization. Apple denies wrongdoing and argues that its facial recognition technology operates privately and securely, with the biometric data remaining encrypted and inaccessible to the company.

Apple Photos App at the Center of the Lawsuit

According to the complaint, Apple’s Photos app uses facial recognition technology to:

  • Scan faces appearing in photos stored on an iPhone.
  • Create unique biometric “faceprints” for individuals.
  • Group images of the same person together.
  • Synchronize this information across Apple devices using iCloud.

The plaintiffs argue that these processes occur without the written notice and consent required under Illinois law. Apple maintains that the feature is designed to organize personal photo libraries while protecting user privacy through on-device processing and encryption — a position consistent with its wider stance on device data, including its refusal to build an iCloud encryption backdoor for the UK government.

Lawsuit Snapshot

ItemDetails
DefendantApple Inc.
ProductApple Photos app
AllegationUnauthorized collection of biometric face data
Estimated DamagesUp to $32.5 billion
JurisdictionIllinois, United States
Law InvokedIllinois Biometric Information Privacy Act (BIPA)

Why Illinois’ Biometric Privacy Law Matters

The lawsuit relies on the Illinois Biometric Information Privacy Act (BIPA), enacted in 2008 to regulate the collection and use of biometric information.

The law generally requires companies to:

  • Notify individuals before collecting biometric identifiers.
  • Obtain written consent.
  • Explain how long biometric data will be retained.
  • Disclose how the information will be used and stored.

BIPA has previously resulted in major settlements involving technology companies because it allows individuals to seek statutory damages for each alleged violation. That per-violation structure is what turns a consumer feature into a multi-billion-dollar exposure: with a class of millions, statutory damages multiply quickly regardless of whether any individual can show financial harm.

Federal Judge Allows Class Action to Proceed

A federal judge has certified the case as a class action, allowing millions of affected Illinois users to pursue their claims collectively.

According to court filings:

  • The class could include approximately 6.5 million Illinois residents.
  • Plaintiffs seek statutory damages under BIPA.
  • Apple had sought dismissal of the claims but was unsuccessful at this stage.

Potential Financial Impact

MetricEstimate
Estimated Class Members~6.5 million
Maximum Claimed Exposure$32.5 billion
Current StatusClass action certified; litigation continues

Apple’s Response

Apple disputes the allegations and argues that its Photos app is designed with privacy protections.

According to the company’s legal position:

  • Facial recognition data is encrypted.
  • Face templates are not directly accessible to Apple.
  • The feature primarily operates on users’ devices.
  • The technology is intended to help users organize photo libraries rather than identify individuals for commercial purposes.

The certification of the class action does not determine liability. It allows the claims to proceed collectively, while Apple will have the opportunity to defend its practices during the litigation. The company is simultaneously fighting on other legal fronts, including a bid to block OpenAI’s alleged use of its trade secrets.

Why the Case Matters

The lawsuit could have broader implications for the technology industry.

If the plaintiffs ultimately succeed, the decision could:

  • Increase scrutiny of facial recognition features.
  • Influence how companies obtain consent for biometric technologies.
  • Encourage additional privacy-related litigation.
  • Shape future development of AI-powered photo management tools.

The case also highlights the growing legal risks facing companies that use biometric technologies, even when the processing is designed for consumer convenience rather than advertising or surveillance. Regulators elsewhere are moving in the same direction — the EU has mandated labels for AI-generated content and deepfakes under its AI Act.

Looking Ahead

The class-action lawsuit against Apple represents one of the most significant biometric privacy cases currently before U.S. courts. At the heart of the dispute is whether the Photos app’s facial recognition feature complies with Illinois’ strict consent requirements under the Biometric Information Privacy Act. While plaintiffs argue that Apple unlawfully created biometric “faceprints” without obtaining written permission, the company maintains that its technology is privacy-focused, encrypted, and primarily processed on users’ devices.

Looking ahead, the litigation could set an important precedent for how courts evaluate facial recognition technologies used in consumer products. A final ruling may influence privacy compliance standards across the technology industry, particularly as AI-powered photo organization, biometric authentication, and on-device machine learning become increasingly common features in smartphones and other connected devices.

Frequently Asked Questions

What is the Apple lawsuit about?

It is a certified class action in Illinois alleging that the Apple Photos app scanned faces in users’ photo libraries and created biometric “faceprints” without the written notice and consent required by the Illinois Biometric Information Privacy Act. Claimed damages run up to $32.5 billion.

Has Apple been found guilty or ordered to pay?

No. Class certification only lets the claims proceed together; it does not decide liability. Apple denies wrongdoing and will defend its practices in court, so the $32.5 billion figure is a maximum claimed exposure, not an award or settlement.

Who can be part of the class action?

The class covers Illinois residents — roughly 6.5 million people by the court’s estimate — because BIPA is an Illinois state law. Users outside Illinois, including in India, are not covered by this particular case, though the ruling could influence privacy standards more widely.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.