We learned yesterday that a judge is allowing a $32B lawsuit to proceed, alleging that Apple Photos face recognition violates a state privacy law.
It has been conflated with Meta’s use of face recognition, despite the two companies’ approaches falling at opposite ends of the privacy spectrum. In allowing the case to proceed, the court fundamentally misunderstands how the feature works …
The earlier claim against Meta
To properly understand the situation, we need begin with a face recognition lawsuit against Meta dating all the way back to 2015.
Facebook applies face recognition to uploaded photos in order to suggest friends to tag. When you tag someone in one or more photos, Facebook will attempt to recognize that face in other photos to offer tag suggestions. A group of Facebook users from Illinois claimed that this was illegal in the state, violating the Biometric Information Privacy Act.
Since that face recognition was carried out on Meta servers, and Meta was able to identify those faces, the company was indeed breaking the law and was rightly forced to settle the claim for $650 million.
Apple is now being sued under the same Illinois state law, the Biometric Information Privacy Act (BIPA). This states that companies aren’t allowed to collect biometric information without seeking consent.
Apple’s approach is totally different
There’s just one small problem with the claim: Apple absolutely does not collect biometric data in order to carry out face recognition in the Apple Photos app. As the company pointed out in a machine learning research paper back in 2021, the recognition algorithm runs entirely on device.
Photos uses a number of machine learning algorithms, running privately on-device, to help curate and organize images, Live Photos, and videos. An algorithm foundational to this goal recognizes people from their visual appearance.
Not only that, but all the iPhone is doing is saying “all of these photos appear to be of the same person” – it has absolutely no idea who that person is. The only person who can assign a name to them is the iPhone user.
A user can then manually add names to people in their photos and find someone by typing the person’s name in the search bar.
The company’s privacy policy on photos echoes this.
Apple does not access your photos or videos […] Photos uses on-device machine learning to deliver […] features like the People & Pets Album.
It’s wild to me that we are now in the sixth year of this lawsuit progressing through the legal system, when just a few minutes’ of research would show that the claim it makes is demonstrably false.
Courts and legislators should be actively applauding Apple’s approach to privacy protection rather than confusing it with the privacy-busting approaches of companies like Meta.
It’s just another example of both courts and legislators fundamentally failing to understand the technology they are attempting to control. The best example, of course, relates to end-to-end encryption. Multiple countries have either threatened or attempted to ban it without having the slightest understanding of how it actually works.
Of course, I understand that neither judges nor politicians can be experts in all of the fields in which they are expected to work. But they do have access to experts, and it is inexplicable to me that lawsuits and attempted legislation can make it many years down the road without anyone identifying such fundamental flaws.
- Apple products on Amazon Renewed
- Official Apple Store on Amazon
- Discounted AirPods Pro 3
- Wireless CarPlay adapter
- AirTag holders and accessories
- Mac Pro-style Mac mini casing
Photo: Apple