Apple Inc. is facing a class-action lawsuit in Illinois alleging its Photos app violates state biometric-data privacy laws [1].
The case centers on how the company handles facial images. Because Illinois has some of the strictest biometric privacy protections in the U.S., a ruling against Apple could establish a significant legal precedent for how tech companies sync and store personal identifiers across cloud services.
Plaintiffs in the suit said the Photos app treats facial images as biometric identifiers [1]. The legal challenge specifically targets the way the app syncs photos and associated data via iCloud, arguing that this process violates the Illinois Biometric Information Privacy Act, known as BIPA [1].
There is a significant discrepancy regarding the financial stakes of the litigation. One report indicates the lawsuit seeks roughly $32.5 million in damages [1]. However, other reports suggest a much higher figure, with some claiming the amount sought is $32.5 billion [2] or $32 billion [3].
BIPA requires companies to obtain written consent before collecting or distributing biometric identifiers. The lawsuit alleges that Apple failed to meet these requirements when processing facial data for its photo organization features. The litigation focuses on the automated nature of the iCloud sync, and whether that process constitutes the unauthorized collection of biometric data under state law [1].
Apple has not provided a public response to the specific allegations in this filing. The case remains in the early stages of the legal process in Illinois [1].
“The case centers on how the company handles facial images.”
This lawsuit highlights the growing tension between cloud-based convenience and stringent regional privacy laws. Because BIPA allows for statutory damages per violation, the gap between the reported $32.5 million and $32 billion claims reflects the massive financial risk Apple faces if the court determines that every single synced photo constitutes a separate violation of the law.


