A federal judge in Illinois on September 30, 2026 rejected most of Apple's attempt to end a certified class action alleging that the Photos app on iPhones, iPads and Macs builds facial "faceprints" of Illinois residents without their written consent, ruling that end-to-end encryption does not stop Apple from being in "control" of data it syncs to its own servers.
In Short
A judge decided that a lawsuit claiming Apple's Photos app makes face maps of people in Illinois without asking them can keep going toward trial. This matters because Apple argued it could not be responsible for data it says it cannot read, and the judge said that being able to lock, move or delete the data is enough to count as controlling it. The case will now be decided on the facts, and one group of users whose claim rested only on cropped photos has been removed.
The ruling
Judge Nancy J. Rosenstengel of the US District Court for the Southern District of Illinois signed the 34-page memorandum and order in Jane Doe, et al. v. Apple Inc., case 3:20-CV-421-NJR, on September 30, 2026. The document was filed as Document 373 and, according to its final paragraph, was to "remain provisionally sealed until October 7, 2026," with any motions to redact due by that date.
The order resolves two motions. Apple had moved for summary judgment on the whole case, arguing that it "neither collects nor possesses any biometric identifiers or biometric information." The plaintiffs had asked for partial summary judgment on Apple's liability. According to the order, "the Court grants Apple's motion only as it pertains to so-called face crops. The remainder of Apple's motion is denied. Plaintiffs' motion for partial summary judgment is also denied."
That leaves Apple without the early exit it sought and the plaintiffs without a liability finding. The questions that matter most - whether Apple's faceprints are "scans of face geometry," whether they can identify a person, and whether Apple controls the faceprints that stay on users' devices - are now questions of fact.
The case is being litigated under the Illinois Biometric Information Privacy Act, known as BIPA, which the order describes as a statute enacted in 2008 when Illinois "had the foresight to protect its citizens against the unknown and unwanted collection of their biometric identifiers and information." It is the law that has driven most of the large facial recognition disputes in the United States, because it gives individuals a private right to sue.
What the parties agree on
One of the more striking passages in the order concerns what is not disputed. "There is no dispute that Apple did not develop, publish, and comply with a written data retention and destruction policy with respect to the Photos app's facial recognition technology," the court wrote. "Nor did it provide notice and obtain written consent from any Illinois user."
Those two obligations are the core of BIPA sections 15(a) and 15(b). Section 15(a) requires a private entity "in possession" of biometric data to publish a retention schedule and destruction guidelines. Section 15(b) bars an entity from collecting, capturing, purchasing, receiving or otherwise obtaining a person's biometric identifier without notice and written consent. Because Apple did neither, the case turns on a narrower question: whether what the Photos app produces is biometric data at all, and whether Apple, rather than the device owner, is the entity that has it.
How the People album works
The order sets out the technology in more detail than Apple has made public, drawing on the parties' statements of undisputed facts, expert reports and testimony.
Apple preinstalls Photos on iPhones, iPads, Macs and Apple TVs, and, according to the order, it "cannot be uninstalled by users." Photos taken with the Camera app land in Photos unless the user has chosen a third-party camera app. Software inside Photos then sorts images of people into the People album (renamed "People & Pets" when cats or dogs are detected, according to a footnote).
The pipeline described in the order runs in four stages:
- Detection. Every photo is run through a deep neural network that detects faces, face landmarks and upper torsos, then draws "bounding boxes" around faces and upper bodies.
- Cropping. From each bounding box the algorithm produces a "face crop" and a "torso crop." According to the order, the network "detects faces and face landmarks" but "does not map the coordinates of the face"; landmark information is used only to size and place the box.
- Embedding. Face crops pass through a convolutional neural network, or CNN, whose final layers output "a 128-dimensional vector, or 'embedding vector,' made up of 128 decimal-point numbers." Apple employees, internal Apple documents and the plaintiffs call these vectors faceprints.
- Clustering. A clustering algorithm scores the similarity between faceprints and, when they are close enough, groups the photos in the People album. Apple assigns each cluster a unique numerical identifier.
It is undisputed, the court noted, that the 128 numbers "are not the measurements of distances between points on an individual's face." Yet they can be used to tell faces apart. The plaintiffs' machine learning expert, Dr. Sheryl Brahnam, explained that faceprints of the same person cluster close together in the "embedding space" while those of different people sit further apart, and that "by setting a threshold on the distance between vectors of the same person, the system can decide whether two images represent the same person."
Apple does not dispute that its CNN was trained on "a labeled dataset of thousands of cropped photos of faces from Flickr, stock photography, and Apple's own data," and that it generates a faceprint for each photo. The software also builds a model for each person in a library, against which incoming faceprints are compared.
Names, contacts and a knowledge graph
Labels are where identity enters. Users can name clusters, and Photos "intelligently suggests names from the users' Contacts," according to the order. The app also generates a knowledge graph of people important to the user, inferred from the number of photos of a person, relationships set in Contacts, and "the frequency of communications in the Messages app."
To work out who owns the device, Photos looks at the location where photos were taken and how often certain people appear. Apple disputes that this amounts to using "identity information," but the order records that Apple's Senior Machine Learning Engineering Manager for Photos testified that the app looks at signals including "whether the photos are taken from the user's home, the number of selfies, and the number of photos with that person in them." After clustering photos of the inferred user, Photos asks: "Is this a photo of you?"
Where the data sits
For users who do not upload photos to iCloud, faceprints stay on the device. The plaintiffs claim on-device faceprint data is not encrypted, which Apple disputes; Apple admits, according to the order, that "the faceprint is not stored within the device's 'Secure Enclave.'"
For users with iCloud Photos turned on, face crops and some metadata, including user-supplied labels, are uploaded to Apple's servers in an end-to-end encrypted format. Under Apple's "Standard Data Protection" setting, Apple keeps access to the encryption keys. Under "Advanced Data Protection," according to the order, "the vast majority of their iCloud data is end-to-end encrypted, the encryption keys are stored only on the user's device, and the data is inaccessible to Apple."
The pivotal fact for the case came in July 2024. According to the order, Apple released software updates that "allow the transmission of users' faceprints to iCloud," referred to in the litigation as the Sync Update. It applies to users on iOS 17.6 or later with iCloud Photos enabled, at least 10 gigabytes of iCloud storage, and more than 5,000 photos or videos. The update lets a user's other signed-in Apple devices download and decrypt the faceprint so each device does not have to regenerate it. Clustering still runs locally on each device. Apple says the data is uploaded end-to-end encrypted; a footnote records that the plaintiffs dispute this but "do not adequately support this claim with a citation to a relevant portion of the record."
The three subclasses
On June 5, 2026, the court certified the case as a class action with three subclasses, according to the order:
- Local Device Class: every Illinois citizen whose Apple device put a photograph of that citizen into a People album at any time between September 13, 2016, and the present.
- iCloud Subclass: every Illinois citizen who had an Apple device with a People album tagged with that citizen's name or other identifier and an iCloud account enabled for photo storage, over the same period.
- iCloud Faceprint Subclass: every Illinois citizen with a device running iOS 17.6, macOS Sonoma 14.6 or iPadOS 17.6 or later, with at least 10 gigabytes of iCloud photo storage, 5,000 or more assets in the iCloud library, and a photograph of that citizen placed in a People album, at any time between March 25, 2025, and the present.
The order does not state how many people fall into any of the subclasses.
Face crops: the one point Apple won
The court sided with Apple on face crops. Apple presented evidence that the crop is produced without mapping the coordinates of the face and that any landmark information used to make it is not passed to the faceprinting network. "Once that process occurs, the face crop is only that: a cropped image of a face," the court wrote.
The plaintiffs argued that the detection step uses geometric information about where a face sits in an image. The court was not persuaded: "the location of a face within a photo says nothing about that face's geometry, and Plaintiffs have not identified any record evidence suggesting that this information would be sufficient to identify a person."
The consequence was immediate. Because the iCloud Subclass claimed only that face crops, user-entered information and other metadata were synced to iCloud, it "does not have a viable legal theory on which to proceed," and the court decertified it under Federal Rule of Civil Procedure 23(c)(1)(C). Its members were not dropped from the case altogether; according to the order, they "remain part of the Local Device Class."
Faceprints: what counts as a scan of face geometry
BIPA defines a biometric identifier as "a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry." The statute was written in 2008, when, as the order puts it, facial recognition "had relied for decades on the measured distances and angles between facial landmarks like the eyes, nose, and mouth." The order observes that "facial recognition technology no longer requires measurements of the face" and that deep neural networks "derive information directly from the pixels in an image."
Apple's position was that it "merely 'scans' photographs, not faces," and that "face geometry" means a "three-dimensional representation of the facial structure." In Apple's account, the CNN processes two-dimensional patterns of color and intensity, the faceprint corresponds to no visible feature or measurement, and it "cannot be used to recreate a face."
Judge Rosenstengel rejected that reading as too narrow. Relying on dictionary definitions, the court held that "scan" means "to examine by point-by-point observation or checking," and that geometry can mean a "configuration" or "the spatial arrangement of objects or constitutent parts," which is "far broader than Apple's suggested definition." The order leans on the Northern District of California's 2018 ruling in the Facebook Tag Suggestions litigation, which held that limiting scans of face geometry to techniques that literally measure distances "cannot be squared with the legislature's clear intent to regulate emergent biometric data collection technology in whatever specific form it takes."
The expert evidence
The court then found enough evidence for a jury to conclude that faceprints are scans of face geometry. According to the order:
- Dr. Brahnam testified that pixels in 2D photos "encode information" about 3D surfaces and shapes, that early CNN layers detect edges, lines, corners and color variations, and that deeper layers recognize "facial contours and the shapes of the mouth and eyes."
- Dr. Atif Hashmi, retained by the plaintiffs to review Apple's source code, said a faceprint from a CNN trained on human faces can be reverse-engineered through model inversion to reconstruct the original face "to a certain degree of accuracy." From this, the plaintiffs' experts argued that CNNs "inherently maintain and are able to determine spatial relationships among shapes present within a face," since otherwise a reconstructed face "may have an eye where the mouth should be."
- Apple's own biometrics expert, Dr. Creed Jones, agreed that CNNs "operate directly" on image pixels and that "face recognition algorithms are designed to maximize the distinctions between human faces." The court noted that Dr. Jones "does not dispute that CNNs 'scan' the pixels of an image" and does not "offer an alternative theory of how the CNN is able to distinguish between faces other than some reliance on geometry in its broadest sense."
Apple's internal vocabulary also counted against it. Citing an August 20, 2026 Northern District of Illinois ruling in Fleury v. Union Pacific, the court said a defendant's own use of biometric terminology can "shed light on [its] nature and purpose."
The plaintiffs did not win the point outright, however. Dr. Jones opined that faceprints "do not represent measurements of a person's face," and that the shapes a CNN picks up "are more accurately described as local intensity patterns in the pixels of a photograph than geometric shapes," produced by a "sum-of-products response to intensity patterns." According to the order, "A jury crediting Dr. Jones's opinions over Dr. Brahnam's could conclude that Apple's CNN does not scan face geometry."
Can a string of 128 numbers identify a person?
The second element of the definition is identification. Apple argued that Photos merely groups similar faces and that only users can identify the people in them, by labeling clusters with information Apple cannot read. It also argued that identification requires an enrollment step, in which known identities are added to a database alongside biometric templates - in the way a fingerprint identifies a criminal suspect only if it is already on file.
The court held that what matters is capability, not use. Citing a line of Illinois federal decisions and the Ninth Circuit's 2024 ruling in Zellmer v. Meta Platforms - "even if a company does not use face scans to identify a person, BIPA applies if it could" - the order says the relevant question is whether "the output of the technology, i.e., the faceprint, is capable of identifying a person."
The record, according to the order, includes testimony from Apple employees that a "faceprint can be used to uniquely identify a person," and Apple patent applications stating that "a faceprint is a feature vector defined in n-space that uniquely identifies a face image but does not associate a name with the face." For the iCloud Faceprint Subclass, the faceprints are synced to the cloud and associated with an iCloud account "which includes significant identifying information." And for users who add identifying information to their People album, "their faceprints are, without a doubt, connected to their identity."
The enrollment argument was rejected as reading "into BIPA a requirement that does not exist in its text." The court added that Apple's own expert defined enrollment as including "the capture of one or more samples to be used for later comparison," which Dr. Hashmi said is what happens when Apple's algorithm analyzes faceprints of people verified by the user or by the knowledge graph.
A footnote cuts the other way: "none of the named Plaintiffs labeled their People albums with anything more than a first name."
Apple again kept the question open for trial. Dr. Jones said the CNN would produce a 128-number vector even from an image with no face in it, one that "would not look, to the human eye, any different than a faceprint," and that reconstructing a face from a faceprint is "unrealistic, if not impossible" because model inversion requires intimate knowledge of a model Apple has not published. Apple engineers testified that the output is merely "a number of bits and bytes." On that evidence, the court said, a jury could find faceprints are not capable of identifying anyone.
Control: encryption is not a defense
The section most likely to be read outside biometrics law is the court's treatment of possession and control. Under Illinois case law, including the Illinois Supreme Court's 2023 decision in Cothron v. White Castle, the verbs in BIPA section 15(b) "all mean to gain control," and possession under section 15(a) has been read the same way.
Apple's main authority was G.T. v. Samsung Electronics America, a 2026 Seventh Circuit decision on facts the order calls "closely analogous": Samsung's preinstalled Gallery app allegedly built face templates from photos stored on Samsung phones. The Seventh Circuit held that software that creates face templates that "remain parked within the confines of the user's own personal device not only falls short of triggering BIPA's statutory requirements but strays too far afield from the statute's heartland." Apple argued that G.T. disposed of the Local Device Class, and that encryption disposed of the iCloud Faceprint Subclass because Apple cannot decrypt the data.
"G.T. is not the silver bullet that Apple believes it to be," the court wrote. The difference is the July 2024 Sync Update: "it is undisputed that, with its July 2024 software update, Apple took faceprints from users' devices and began syncing them to its cloud-based servers." That evidence, the court said, shows not only that Apple "likely has possession and control" of the iCloud Faceprint Subclass's data "but that it may also have possession and control for purposes of BIPA over the ondevice faceprints of the Local Device class."
The court relied on testimony from Meera Shah, described as a former senior software engineer and head of product, program and operations for Apple Cloud Services. According to the order, Shah testified that Apple decides whether to make faceprints, what metadata attaches to them, where they are stored on the device, the security measures, whether they are encrypted, their retention period, whether any API can access them, and whether to push an update that would delete faceprints for all users. "It's software. You could write any software that is enabled on iOS and [it] could do what you are asking to be done," Shah said, as quoted in the order.
The court also distinguished Samsung on software ownership. In G.T., Samsung's devices ran Google's Android; here, Apple admitted "that the software installed on Apple devices is owned by Apple, and that Apple determines the contents of its source code."
Two reasons encryption does not settle it
The court gave two reasons for rejecting the encryption argument.
The first is textual. BIPA "contains no explicit defense or carveout for entities with encryption protocols." Section 15(e) separately requires entities to protect biometric data "using the reasonable standard of care within the private entity's industry." According to the order, "Apple might be required to encrypt data under section (e), but that encryption is not an affirmative defense to other provisions." Each subsection has its own focus: for 15(a), a written retention policy; for 15(b), informed consent.
The second is conceptual, and the court illustrated it with an extended analogy about a collector of Ancient Egyptian artifacts who cannot read their hieroglyphs. The collector could still modify the text, display it publicly or destroy it. "The collector thus undoubtedly exercises 'control' over the hieroglyphic text regardless of whether he (or anyone else) can understand it," the court wrote. Applied to Apple: "By dint of its authority over its servers where the data is maintained and its software, it undoubtedly could (among other things) re-write, make available to the public, remove encryption from, or delete entirely, the faceprint data."
According to the order, Apple conceded at oral argument "that it could decide one day to no longer protect the data with end-to-end encryption." The court added: "technological progress may make today's encryption flimsy."
Why user choice did not help Apple
Apple's final control argument was that using the Camera app, storing photos in Photos and syncing to iCloud are optional, so control rests with users. That argument came from Barnett v. Apple, a 2022 Illinois appellate case about Touch ID and Face ID. The court found it does not fit the Photos facts. In Barnett, users chose biometric login and knew their data was being captured. "Here, users do not consent to the collection of their faceprints, they do not know the faceprints are being collected, there is no ability for users to turn off the feature, and there is no user knowledge that faceprints are saved on the device or in the cloud," according to the order.
On that basis the court denied Apple summary judgment on collection and possession for the iCloud Faceprint Subclass. It declined to grant the plaintiffs summary judgment for the Local Device Class because they "conceded that an issue of fact exists as to whether Apple can access faceprints stored on the device." And it reserved ruling on the plaintiffs' request as to the iCloud Faceprint Subclass "until class notice can be issued to the remaining class and subclass, as amended by this Order."
No proof of access needed to be aggrieved
Apple also argued the plaintiffs could not show they were "aggrieved" because there is no evidence Apple ever accessed their faceprints, on device or in the cloud. The court disagreed, citing Seventh Circuit decisions holding that a BIPA violation "is sufficient in and of itself to render an individual an 'aggrieved person,'" and that "a consumer's loss of the power and ability to make informed decisions about the collection, storage, and use of her biometric information" is a concrete injury. "There is no statutory requirement that Apple actually access a user's biometric for him or her to be aggrieved, only that it is possesses, or is in 'control' of the data," the order reads.
The order does not quantify damages. BIPA's statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation are not discussed in the 34 pages, and the order contains no estimate of class size or exposure.
Procedural and drafting notes
Several smaller rulings and details appear in the order:
- Apple asked the court to deem 123 of its additional material facts admitted because the plaintiffs did not respond to them directly. The plaintiffs said 96 were identical to facts already addressed and the other 27 had been covered in substance. The court denied Apple's request.
- The plaintiffs' motion for approval of class notice was denied as moot and without prejudice. They must file an amended motion reflecting the decertified iCloud Subclass "on or before October 14, 2026."
- The operative pleading is the Fourth Amended Complaint (Doc. 251).
- The order contains minor drafting slips. It cites Barnett at "25 N.E.2d at 604" after earlier citing the case at 225 N.E.3d 602, and it spells "posssess" and "constitutent." It refers to "a private entities" in describing section 15(a). None of these affects the holdings.
Why this matters for the marketing community
The ruling is about a photo-sorting feature, but its reasoning reaches into arguments the advertising and measurement industry has relied on as it moved processing onto devices and behind encryption.
The first point is that on-device processing is not, by itself, a safe harbor. The Seventh Circuit's G.T. decision had suggested that data "parked" on a user's phone falls outside BIPA. Judge Rosenstengel's order narrows that: where the vendor owns the operating system, sets retention, decides on encryption and can push an update that changes or deletes the data, a jury may find the vendor controls it, even if the bytes never leave the device. The order explicitly leaves that question to the facts for the Local Device Class, but it treats the vendor's software authority as relevant evidence.
The second is that encryption is not ownership protection. A recurring argument in privacy engineering is that data a company cannot read is data it does not hold. The court rejected that for BIPA purposes. Control, in this order, means the ability to rewrite, publish, decrypt or delete - not the ability to understand. That is a different test from the one many vendors apply when describing encrypted or "zero-knowledge" architectures, and it echoes debates PPC Land has covered elsewhere, such as Ring's decision to drop its own copy of video keys under a new default announced on August 26, 2026, where who holds the keys determined who could process the content.
The third is the definition of biometric data itself. The court accepted that a 128-number embedding - not an image and not a set of measurements - may be a "scan of face geometry." Embeddings are now routine in ad tech, from creative analysis to audience modeling. Most of those embeddings are not derived from faces, and BIPA applies only to the listed identifiers. But any system that turns face images into vectors, including creative tools that detect people in ads or measurement products that analyze viewers, now operates under a ruling that the form of the output is not decisive.
Biometric privacy has carried some of the largest privacy recoveries in the United States. Texas announced a $1.4 billion settlement with Meta on July 30, 2024 over Facebook's photo tag suggestions, payable over five years, and Texas later secured $1.375 billion from Google in a settlement that covered biometric identifiers among other claims, finalized on October 31, 2025. Apple itself agreed to a $95 million settlement over Siri recordings in a separate consent case that PPC Land reported in January 2025.
European regulators have been working the same ground under the GDPR, where biometric data used for identification is special category data. Spain's data protection authority fined Yoti 950,000 euros in March 2026, including 500,000 euros over biometric data. The Hamburg data protection authority's report on Ray-Ban Meta glasses, published on September 10, 2026, examined how the devices treat bystanders' data. And noyb filed a criminal complaint against Clearview AI in Austria in October 2025 after roughly 100 million euros in European fines went unpaid, then sued the Hamburg regulator in April 2026 over PimEyes.
What the Doe v. Apple order adds is a US federal court's reasoning on the technical defenses that big platforms are most likely to raise: that modern neural networks do not "measure" faces, that vectors are not identities, that encrypted data is not held, and that on-device data belongs to the user. On each point the court found Apple's position too narrow to win before trial. It is a district court ruling at summary judgment, not a final judgment, and an appellate court applying G.T. could read the control question differently.
What comes next
The next fixed date in the order is October 14, 2026, the deadline for the plaintiffs' amended class notice motion. The court's ruling on whether Apple collected or possessed the iCloud Faceprint Subclass's data waits until notice goes out to the remaining Local Device Class and iCloud Faceprint Subclass. The questions of whether faceprints are scans of face geometry and whether they can identify a person remain for a jury, as does control over on-device faceprints. The order sets no trial date.
Timeline
- 2008 - Illinois enacts the Biometric Information Privacy Act.
- September 13, 2016 - Start of the class period for the Local Device Class and the former iCloud Subclass.
- 2018 - The Northern District of California rules in the Facebook Tag Suggestions BIPA litigation that a scan of face geometry need not involve express measurements.
- 2020 - Doe v. Apple is opened in the Southern District of Illinois; the year is indicated by its case number, 3:20-CV-421.
- July 2024 - Apple releases the Sync Update, allowing faceprints to be transmitted to iCloud for qualifying users.
- July 30, 2024 - Texas announces a $1.4 billion settlement with Meta over facial recognition data.
- January 3, 2025 - Apple agrees to pay $95 million to settle the Siri recordings class action.
- March 25, 2025 - Start of the class period for the iCloud Faceprint Subclass.
- October 28, 2025 - noyb files a criminal complaint against Clearview AI in Austria.
- October 31, 2025 - Google signs a $1.375 billion privacy settlement with Texas covering biometric identifiers among other claims.
- March 10, 2026 - Spain fines Yoti 950,000 euros over biometric data and consent failures.
- April 30, 2026 - noyb sues the Hamburg DPA over PimEyes.
- June 5, 2026 - The court certifies Doe v. Apple as a class action with three subclasses.
- August 26, 2026 - Ring announces TAKE encryption as its default, dropping its own copy of video keys.
- September 10, 2026 - Hamburg regulator publishes its report on Ray-Ban Meta glasses and bystanders.
- September 30, 2026 - Judge Rosenstengel grants Apple summary judgment on face crops only, decertifies the iCloud Subclass, and denies the rest of both motions.
- October 7, 2026 - The order's provisional seal ends.
- October 14, 2026 - Deadline for the plaintiffs' amended motion for approval of class notice.
Related PPC Land coverage
- Explaining facial recognition - How detection, alignment, embedding and matching work, and the BIPA, GDPR and AI Act rules that govern them.
- Texas secures $1.375 billion from Google in privacy settlement - A single-state settlement covering geolocation, Incognito and biometric identifier claims.
- Apple to pay $95 million settlement over unauthorized Siri recordings class action - Apple's earlier privacy class settlement over voice assistant recordings.
- Criminal charges filed against Clearview AI after regulatory fines fail - noyb's Austrian complaint against a facial recognition company that ignored European fines.
- noyb sues Hamburg DPA as PimEyes keeps scanning faces unhindered - Litigation over a regulator's handling of a facial search engine.
- Spain fines Yoti 950,000 euros over biometric data and consent failures - A GDPR penalty over biometric templates, consent and retention.
- Hamburg regulator finds Ray-Ban Meta glasses expose bystanders without consent - A 53-page report on camera glasses, facial recognition and AI training.
- Ring drops its copy of video keys as TAKE becomes default in September - How a device maker changed who holds encryption keys for customer video.
- Parents lose Meta Pixel wiretap case against Seattle Children's Hospital - A state supreme court ruling on how far a privacy statute's text reaches into automated tracking.
Summary
Who: Illinois residents certified as a class, suing Apple Inc. Judge Nancy J. Rosenstengel of the US District Court for the Southern District of Illinois wrote the order. Expert witnesses Dr. Sheryl Brahnam and Dr. Atif Hashmi for the plaintiffs, Dr. Creed Jones for Apple, and former Apple Cloud Services lead Meera Shah are cited in the ruling.
What: A memorandum and order granting Apple summary judgment only on the point that face crops are not biometric data, decertifying the iCloud Subclass, and denying the rest of Apple's motion and the plaintiffs' motion for partial summary judgment. The court held that a jury could find Photos' 128-number faceprints are scans of face geometry capable of identifying a person, and that end-to-end encryption does not by itself defeat Apple's control of faceprints synced to iCloud.
When: The order is dated September 30, 2026, and was provisionally sealed until October 7, 2026. The class was certified on June 5, 2026. The plaintiffs' amended class notice motion is due by October 14, 2026.
Where: The US District Court for the Southern District of Illinois, case 3:20-CV-421-NJR, under the Illinois Biometric Information Privacy Act. The technology at issue is the People album in Apple's Photos app on iPhones, iPads, Macs and Apple TVs, and Apple's iCloud servers.
Why: Apple conceded it never published a retention policy or obtained written consent from Illinois users, so the case rests on whether faceprints are biometric data and whether Apple controls them. The court's reasoning that on-device processing and encryption do not automatically put data outside a company's control matters for any business that relies on those architectures to limit its legal exposure, including in advertising and measurement.
Discussion