US Court Rules Meta’s Photo Tagging Tool Not Biometric Data
8th July 2024
A US Appeals Court has ruled in favour of Meta after a plaintiff claimed that Facebook violated the Illinois BIPA (Biometric Information Privacy Act) by collecting biometric data in the form of a ‘face signature’ from photos uploaded to the social media platform.
Whilst this was a ruling from a US court, and our Supreme Court and/or the Court of Justice of the European Union could well reach a different conclusion, it is a helpful ruling when informing the debate of ‘what is the definition of biometric data?’
Case Details
In Zellmer v. Meta Platforms, the plaintiff Clayton Zellmer alleged that Facebook collected biometric data with its face recognition tool without proper disclosure or consent. When Facebook users upload photos to the platform, it offers the option to ‘tag’ friends who appear in the photos. This feature uses facial recognition technology to facilitate this feature, or rather it used to, as face recognition has been turned off by Facebook since 2021. In this case, the court ruled that Facebook did not violate BIPA as the information stored could not be used to identify an individual. Zellmer, who has never had a Facebook account, was not identified in the photos uploaded to Facebook by his friends.
BIPA is the Biometric Information Privacy Act passed in 2008 in Illinois, USA following an initiative by the ACLU of Illinois. BIPA aims to protect individuals’ biometric data and prohibits private companies from collecting it unless certain criteria are fulfilled.
What is Biometric Data?
Biometrics refers to personal information that can be used to identify an individual based on their physiology. Some examples of biometrics used for identification include fingerprints, DNA, voice, the shape of ears and even gait, i.e. the way a person walks. Biometric data is considered a reliable way of verifying identity, but collecting biometric data can raise many concerns about privacy and individual rights.
According to BIPA, biometric data is “biologically unique to the individual”, and gives the example of “a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry.” BIPA asserts that compromised biometric data is potentially more damaging than other forms of personal data. A person can hardly change their fingerprints or retinas, so biometric data is both deeply personal and immutable compared with other data like social security numbers which can be changed if compromised.
Biometric Data in UK Law
In UK law, biometric data is considered special category data and organisations need a valid lawful condition for processing it. Interestingly, the ICO website says that digital photos showing people’s faces do not constitute biometric data, stating: “If you process digital photographs of individuals, this is not automatically biometric data even if you use it for identification purposes. Although a digital image may allow for identification using physical characteristics, it only becomes biometric data if you carry out “specific technical processing” [which] involves using the image data to create an individual digital template or profile, which in turn you use for automated image matching and identification.”
Just as an aside, and whilst it is not classed as ‘biometrics’ many companies create digital fingerprints on users, i.e. by recording details of their IP, or system details such as MAC address, system name, the web browser you use, keyboard layout, system language, screen size and resolution, details of the chips and components inside your computer. This method is surprisingly effective in identifying users.
The Significance of Zellmer v. Meta Platforms
This case has set a precedent in US law that facial recognition technology as used by Facebook does not constitute biometric data. This is due to Facebook’s face recognition tool and the way it creates a ‘face signature’ or a string of numbers that represents an individual’s face. These face signatures cannot be reverse-engineered to derive more information about that individual, and as the plaintiff had never used Facebook, it would not be able to identify him at all. It is also noted that Facebook does not keep these face signatures permanently, and the data is discarded once the tagging process is complete.
Other Notable BIPA Cases
There have been other cases that relied on BIPA – the case of Patel vs. Facebook Inc. was upheld by the U.S. District Court and the Appeals Court, at which point Facebook opted to settle for $650 million. In Patel vs. Facebook Inc., plaintiffs accused Facebook of violating BIPA by collecting and storing their biometric data without informed consent. So why was Patel vs. Facebook Inc. upheld when the court ruled in favour of Facebook in Zellmer vs. Meta Platforms?
This is a tricky question, as Facebook settled in Patel vs. Facebook Inc. before the case concluded so there was no official court ruling, and then they stopped using face signatures as of 2021. Another notable difference is that the plaintiffs in Patel vs. Facebook Inc. were Facebook users, so the technology did identify their photos and matched them to their Facebook profiles. Previously, in Rosenbach v. Six Flags Entertainment Corp. in 2008, the Illinois Supreme Court ruled that “an individual may maintain a BIPA claim in the absence of harm beyond a technical violation of the statute” – (source: Morrison Foerster), so an individual does not have to be personally harmed by the unauthorised processing of biometric data to make a claim based on BIPA. Conversely, in Zellmer v. Meta Platforms, the court observed it would be “counterintuitive” if BIPA required organisations to obtain consent from persons unknown to them, such as Zellmer who never had an account with Facebook in the first place.
UK and European Cases Involving Biometric Data and Facial Recognition
In 2020 the UK Appeals Court ruled that using automated facial recognition technology in public places breached privacy rights in the case of R v. the Chief Constable of South Wales Police. The Court found there were “fundamental deficiencies” in the legal framework intended to protect the police and their use of this technology. They also did not do enough to ensure the software did not have a racial or gender bias. This case is different from Zellmer vs. Meta Platforms as the technology did use biometric data, and could not prove it was not used in a discriminatory way. Source: Liberty Human Rights
In 2023, the European Court of Human Rights ruled in Glukhin v. Russia that using facial recognition technology in political demonstrations violated Articles 8 and 10 of the European Convention on Human Rights. The plaintiff was identified and located using facial recognition tech in the Moscow subway following a one-man protest he held previously. – source: Article 19
These two cases clearly demonstrate the use of biometric data in a way that could be considered a threat to human rights and that the authorities using them did not have sufficient legal frameworks in place to justify their use of facial recognition technology in this way.
In conclusion, Facebook’s use of facial recognition technology in the US for its tagging feature does not in itself constitute biometric data, as the face signatures created cannot be reverse-engineered to identify an individual. In the UK and EU consent would be required. Real biometric data as defined by BIPA and by UK data protection laws should always have a valid reason for processing and storing, and companies should certainly err on the side of caution concerning biometric data or anything that could be construed as such.
Author: Paul Adams LLB (HONS)
Paul is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.