Facial recognition lawsuits in the United States have produced some of the largest privacy settlements in history, including a $1.4 billion agreement between Texas and Meta, a $650 million class action against Facebook, and a five-year Federal Trade Commission ban on Rite Aid’s use of the technology. Wrongful arrest cases brought by people misidentified by police algorithms are moving through federal courts, and new class actions filed in 2026 against Amazon Ring and Disney signal that litigation is spreading well beyond Illinois, the state whose biometric privacy statute has driven most of the case law so far.
Why Illinois Drives Most of the Litigation
The Illinois Biometric Information Privacy Act, enacted in 2008, is the single most important statute behind these cases. BIPA requires private entities to give written notice before collecting biometric data such as a face scan, explain the purpose and retention period, and obtain a signed release. It also requires published data retention and destruction policies.1Justia. Illinois Compiled Statutes, 740 ILCS 14
What makes BIPA unusually powerful is its private right of action. Anyone whose rights are violated can sue without showing identity theft or any other concrete harm beyond the violation itself. The Illinois Supreme Court confirmed that reading in its 2019 decision in Rosenbach v. Six Flags, holding that a technical violation is enough to make someone “aggrieved.” More than 1,500 lawsuits followed.1Justia. Illinois Compiled Statutes, 740 ILCS 14 Statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless one, multiplied across the number of scans a company performs, created enormous exposure.
That exposure peaked with the Illinois Supreme Court’s 2023 ruling in Cothron v. White Castle, which treated every single scan as a separate violation. Potential damages in that case alone were estimated at $17 billion. In August 2024, Governor J.B. Pritzker signed an amendment providing that repeated scans of the same person by the same method count as one violation, capping recovery at one per person.2American Bar Association. How Will Proposed Amendments to Illinois BIPA Affect the Use of Biometric Data In April 2026, the Seventh Circuit ruled in Clay v. Union Pacific Railroad Co. that the amendment applies retroactively in federal court, eliminating the per-scan damages model there. Illinois state courts have not yet ruled on retroactivity.3DLA Piper. Seventh Circuit Holds BIPAs 2024 Damages Amendment Applies Retroactively
The Biggest Class Action Settlements
Facebook: $650 Million
The case that put BIPA on the national map was In re Facebook Biometric Information Privacy Litigation, filed in 2015 in the Northern District of California. The suit alleged that Facebook’s “Tag Suggestions” feature scanned user photos, extracted facial geometry, and stored the templates without written consent. Judge James Donato granted final approval of a $650 million settlement on February 26, 2021. The class covered Illinois Facebook users whose facial geometry was extracted after June 7, 2011, and each class member received at least $345.4Robbins Geller Rudman & Dowd. In Re Facebook Biometric Info Privacy Litigation
TikTok: $92 Million
TikTok settled a combined BIPA and federal Video Privacy Protection Act class action for $92 million, with final approval in August 2022 from a judge in the Northern District of Illinois. The 2019 lawsuit alleged TikTok collected users’ faceprints without consent. The settlement required TikTok to stop collecting biometric information without disclosure, cease transmitting U.S. user data abroad without disclosure and legal compliance, and delete previously uploaded content from users who never posted it. Illinois residents received a larger share because of the state-specific claims.5Hunton Andrews Kurth. Judge Approves $92 Million TikTok Settlement
Clearview AI: $51.75 Million in Equity
Clearview AI built its database by scraping billions of photos from social media and the public internet. In a multidistrict class action in the Northern District of Illinois, the court granted final approval on March 20, 2025 of a settlement valued at about $51.75 million. Because Clearview lacked cash for a traditional payout, the class received a 23 percent equity stake. Payment triggers include an IPO, a sale or merger, or a revenue-based option that expires in September 2027. A retired federal judge was appointed as Settlement Master to oversee the stake and monitor the company’s books.6Justia. In Re Clearview AI Inc Consumer Privacy Litigation
Clearview also reached a separate settlement with the ACLU in May 2022 in a BIPA case filed in Cook County Circuit Court. That deal permanently bans Clearview from making its database available to most private businesses nationwide. Within Illinois, the company cannot sell access to any entity, including law enforcement, for five years, and it must offer Illinois residents a way to block their facial data from the system. Clearview was also required to delete older facial vectors and pay $250,000 in attorney fees.7ACLU. ACLU v. Clearview AI
State-level cases against Clearview continue. Vermont refiled a suit in April 2025 under its Consumer Protection Act, alleging the company collected biometric identifiers from Vermonters, including children, without consent. In December 2025, a Washington County Superior Court judge dismissed the case on jurisdictional grounds, finding Clearview did not conduct substantial business in the state. Attorney General Charity Clark said her office was considering an appeal and called the ruling “a call to the Legislature to act.”8VTDigger. Judge Throws Out Vermonts Lawsuit Against Clearview AI
Snapchat: $35 Million
Snap Inc. settled a BIPA class action for $35 million over allegations that its Lenses and Filters collected biometric data without written consent. In Boone v. Snap Inc., filed in the Circuit Court of DuPage County, the class covered Illinois residents who used the features from November 2015 onward. After fees and costs, roughly $23 million was distributed, with individual payments of about $16. Snap denied that its Lenses violate BIPA, maintaining they do not collect data used to identify specific people.9TechCrunch. Snap $35 Million Settlement in Illinois BIPA10Top Class Actions. Snapchat Biometric Privacy $35M Class Action Settlement
Google Education: $8.75 Million
In H.K. v. Google LLC, filed in McDonough County, Illinois, plaintiffs alleged Google collected face and voice models from students through its Workspace for Education platform without written consent. The court granted final approval of an $8.75 million settlement on October 17, 2025. The class covered individuals enrolled in Illinois schools between March 2015 and May 2025 who used the platform, and payments began in February 2026.11Google Education BIPA Settlement. H.K. v. Google LLC Settlement
State Attorney General Cases
While BIPA empowers individuals, state attorneys general have brought their own actions and sometimes recovered much larger sums. In July 2024, Texas Attorney General Ken Paxton announced a $1.4 billion settlement with Meta to be paid over five years. The suit, filed in February 2022, was the first enforcement action under the Texas Capture or Use of Biometric Identifier Act and centered on Facebook’s “Tag Suggestions” feature. Paxton’s office described it as the largest privacy settlement ever secured by a single state.12Texas Attorney General. Attorney General Ken Paxton Secures $1.4 Billion Settlement With Meta Meta said it was “pleased to resolve this matter” and noted that it had shut down its facial recognition system in 2021 and deleted faceprints of more than a billion people.13WBAL-TV. Meta Agrees to Settlement With Texas in Privacy Lawsuit
Texas also secured a $1.375 billion settlement with Google for alleged violations of state laws including the biometric identifier act. The Texas statute allows civil penalties of $25,000 per violation, giving the attorney general substantial leverage in enforcement talks.14NPR. Biometrics Facial Recognition Laws Privacy
The FTC’s Rite Aid Ban
In December 2023, the Federal Trade Commission announced that Rite Aid would be banned from using facial recognition technology for surveillance purposes for five years. The agency found that between 2012 and 2020 Rite Aid deployed AI facial recognition in hundreds of stores to flag potential shoplifters, using a database of “persons of interest” built from low-quality images taken from security cameras, phones, and news coverage. The company failed to test the system for accuracy or train employees on how to use it.15FTC. Rite Aid Banned From Using AI Facial Recognition
The result was thousands of false-positive matches. Employees confronted, searched, and publicly accused innocent shoppers. The FTC specifically found the technology generated more false positives in stores located in predominantly Black and Asian communities than in predominantly white ones.15FTC. Rite Aid Banned From Using AI Facial Recognition Under the consent order, Rite Aid must delete all images and algorithms developed from the system, notify consumers when their biometric information is processed, implement an information security program, and submit to independent third-party assessments. As of 2024, the order remained pending final approval in bankruptcy court and federal district court, as Rite Aid had filed for bankruptcy.16FTC. Rite Aid Corporation, FTC v.
Wrongful Arrest Lawsuits
More than a dozen known cases involve people arrested after police relied on an incorrect algorithmic match. The people publicly identified are disproportionately Black.17ACLU. More Than a Dozen Wrongful Arrests Due to Police Reliance on Facial Recognition Technology
Robert Williams v. Detroit
Robert Williams was arrested at his Detroit home in January 2020 for a felony larceny he did not commit. Police matched his expired driver’s license photo through facial recognition software despite the actual perpetrator having different physical characteristics. Williams had an alibi. Charges were dropped, and in June 2024 he reached a settlement with the City of Detroit requiring significant policy changes. The Detroit Police Department must now prohibit arrests based solely on facial recognition results, require independent corroborating evidence before conducting lineups from algorithmic leads, provide mandatory training on the risks and racial biases of the technology, and audit all cases involving facial recognition warrants since 2017.18University of Michigan Law School. Flawed Facial Recognition Technology Leads to Wrongful Arrest and Historic Settlement
Porcha Woodruff
Porcha Woodruff was arrested in Detroit in February 2023 while eight months pregnant, accused of a carjacking based on a photo lineup generated from facial recognition results. She spent 10 hours in jail before charges were dropped. Woodruff filed Woodruff v. Oliver in the Eastern District of Michigan. In August 2025, U.S. District Judge Judith Levy granted summary judgment to the officer who prepared the arrest warrant, finding that Woodruff’s attorney had not demonstrated the officer lacked probable cause at the time. Her legal team indicated they plan to appeal.19CBS News Detroit. Woman Wrongly Accused of Carjacking Loses Lawsuit Against Detroit Police
Robert Dillon v. Jacksonville Beach
On June 10, 2026, the ACLU and ACLU of Florida filed suit on behalf of Robert Dillon, a 52-year-old Fort Myers resident arrested in August 2024 for allegedly luring a child at a fast-food restaurant in Jacksonville Beach, more than 300 miles from his home. Police ran a grainy surveillance image through facial recognition software operated by the Pinellas County Sheriff’s Office and got a false match. The complaint alleges officers concealed exculpatory information when applying for the arrest warrant, including that the suspect was a restaurant regular, that Dillon had never been to Jacksonville Beach, and that license plate reader databases showed no record of his vehicle in the area. All charges were eventually dropped and Dillon’s arrest record was expunged. The suit seeks damages and policy changes on police use of facial recognition.20ACLU. Dillon v. City of Jacksonville Beach21ACLU of Florida. Florida Man Sues Police Over Wrongful Arrest Due to False Facial Recognition Match
New 2026 Consumer Suits: Ring and Disney
Two class actions filed in 2026 show the litigation moving beyond BIPA and Illinois. On June 1, 2026, Virginia resident Charles Sigwalt filed a proposed nationwide class action against Amazon in the Western District of Washington. The suit targets Ring’s “Familiar Faces” feature, launched in December 2025, which uses AI to scan the faces of anyone passing a Ring doorbell camera and create mathematical “faceprints” to identify recurring visitors. The complaint alleges that neighbors, delivery workers, and passersby are enrolled in a biometric database with no knowledge and no opt-out. It brings claims under Virginia consumer protection, computer crime, and privacy laws, plus the FTC Act’s prohibition on unfair and deceptive practices, and seeks at least $5 million. Ring itself disables the feature in Illinois, Texas, and Portland, Oregon, where biometric privacy laws exist, but offers no similar protections elsewhere.22TechCrunch. Amazon Faces Class Action Lawsuit Over Ring Facial Recognition Feature23Biometric Update. Amazon Ring Sued Over Facial Recognition Feature
On May 15, 2026, Summer Christine Duffield of Riverside County, California, filed a $5 million class action against The Walt Disney Company in the Southern District of New York. The complaint alleges Disney scans guests’ faces at its theme parks and converts them into numerical identifiers matched with ticket data to verify entry, all without adequate disclosure or consent, and that children are scanned. It raises claims under the California Constitution’s right to privacy, the California Unfair Competition Law, and common law intrusion upon seclusion. Like the Ring suit, it points out that Disney complies with biometric privacy laws in states that have them, such as Illinois and Texas, but does not offer comparable protections at its California parks.24Los Angeles Times. Disney Faces $5 Million Lawsuit Over Use of Facial Recognition Technology
What Federal Law Does and Doesn’t Cover
There is no federal law governing the collection, use, or retention of biometric information in the United States. A recent proposal that would have required the TSA to inform air travelers of their right to opt out of facial screening stalled in Congress.14NPR. Biometrics Facial Recognition Laws Privacy25Security Industry Association. Guide to State and Local Laws on Facial Recognition Technology Most of those state laws are enforced by attorneys general rather than by private lawsuits, which is why Illinois has produced far more filings than any other state.
Constitutional claims against law enforcement use of the technology remain unsettled. The Supreme Court’s 2018 decision in Carpenter v. United States held that prolonged digital surveillance of a person’s movements can be a search requiring a warrant. Scholars have argued that continuous facial recognition in public spaces fits within Carpenter‘s reasoning, but no court has directly applied the ruling to the technology. Equal protection claims face a different hurdle: existing doctrine requires plaintiffs to show both discriminatory effect and discriminatory intent, which is difficult to establish when the discrimination flows from an algorithm rather than a human decision-maker.26Every CRS Report. Facial Recognition Technology: Federal Law Enforcement and Select Legal Issues