Apple Faces $32.5 Billion Class Action Over Facial Recognition in Photos App

Apple Faces $32.5 Billion Class Action Over Facial Recognition in Photos App

A federal court’s decision to certify a class-action lawsuit against Apple over its Photos application’s face-recognition feature represents one of the most consequential privacy litigation risks in American corporate history — and it illustrates, with uncomfortable clarity, the financial exposure that technology companies now carry when they deploy biometric systems without adequate legal architecture to support them.

The case originates from a complaint filed in March 2020 by approximately ten Illinois residents, who alleged that the “People” feature within Apple Photos violated Illinois’ Biometric Information Privacy Act, known as BIPA. That statute grants citizens explicit rights over their biometric data, requiring companies to give notice before collection and to obtain affirmative consent before processing. BIPA is notably punitive in its remedies: it permits damages of $1,000 per negligent violation and $5,000 per intentional or reckless one. With a certified class now estimated at roughly 6.5 million Illinois residents, the arithmetic produces a potential liability of up to $32.5 billion — a figure that, even for a company of Apple’s capitalisation, is not trivial.

The legal journey to this point has been protracted. Since the original filing, the complaint has been amended four times, extensive discovery has been conducted, and Apple has made multiple unsuccessful attempts to have the claims dismissed. The court’s June certification ruling, which Apple subsequently sought to challenge through an immediate interlocutory appeal, has now been upheld after that appeal request was denied. The case returns to district court, where plaintiffs must still establish on the merits that Apple’s conduct constituted a violation of BIPA — certification being a procedural milestone, not a finding of liability. Nevertheless, the practical and financial pressure on Apple to consider settlement is now considerably greater.

The precedent set by comparable BIPA litigation is instructive. Meta settled a facial-recognition lawsuit — arising from Facebook’s photo-tagging suggestion feature — for $650 million, and faced a separate $68.5 million settlement over Instagram’s alleged collection of biometric data without consent. Those outcomes were reached before trial, and they signal the direction in which large technology defendants have historically moved when confronted with certified BIPA classes. Apple, which has built a substantial portion of its brand identity around privacy, faces a particular reputational dimension that Meta did not, making the litigation doubly uncomfortable for Cupertino.

The broader implication is one that policymakers and corporate counsel across the technology sector would do well to absorb. BIPA has now demonstrated, repeatedly, that it possesses genuine teeth — and that the absence of a federal biometric privacy standard has left companies navigating a patchwork of state-level regimes with vastly different risk profiles. Illinois’ statute is the most aggressive of these, but it is not unique in spirit. Companies that have integrated facial recognition, fingerprint scanning, or other biometric processing into consumer products without robust consent frameworks have, in effect, been accumulating contingent liabilities that are only now becoming visible on balance sheets. The Apple case, whatever its ultimate resolution, makes that exposure impossible to ignore.