Understand why Apple Photos facial recognition is not a threat to privacy
A $32 billion lawsuit alleging that the Apple Photos app’s facial recognition feature violates a state privacy law was allowed to proceed by a court on August 4, 2026. The case has been compared to Meta’s use of the technology, although the two companies’ approaches are poles apart when it comes to protecting privacy. By allowing the action to proceed, the court demonstrates a fundamental misunderstanding of how the appeal works.
History of the lawsuit against Meta for using facial recognition
To properly understand the current situation, it is necessary to recall a facial recognition lawsuit against Meta that dates back to 2015. Facebook applied facial recognition to photos uploaded by users to suggest friends to be tagged in the images. When tagging someone in one or more photos, Facebook tried to recognize that same face in other images to offer tagging suggestions.
A group of Facebook users in the state of Illinois claimed that this practice was illegal, violating the Biometric Information Privacy Act (BIPA). As facial recognition was performed on Meta’s servers and the company was able to identify faces, it was, in fact, breaking the law, being forced to close a $650 million settlement.
More on this story: Ring controversy drives Apple to create doorbell with facial biometrics and local encryption
Apple is now being sued under the same Illinois state law, the Biometric Information Privacy Act (BIPA). This law establishes that companies cannot collect biometric information without obtaining prior consent from users.

Apple’s approach is completely different when it comes to data processing
There’s a crucial problem with the claim: Apple doesn’t actually collect biometric data to perform facial recognition in its Photos app. As the company itself indicated in a 2021 machine learning research paper, the recognition algorithm operates entirely on the user’s own device.
The Photos app uses a series of machine learning algorithms, which run privately on the device, to help organize images, Live Photos, and videos. A fundamental algorithm for this function recognizes people based on their visual appearance.
Furthermore, what the iPhone does is simply indicate that “all these photos appear to be of the same person”, without having any knowledge of that person’s identity. The only person who can give them a name is the iPhone user themselves.
Learn more: Apple prepares top-of-the-line cell phone for 2026 with invisible biometrics and unprecedented processor
Users can then manually add names to people in their photos and find them by typing the name into the search bar. The company’s privacy policy on photos reinforces this practice.
Apple doesn’t access your photos or videos. Photos uses on-device machine learning to provide features like the People and Pets album.
It is surprising that this court case is ongoing for its sixth year in the legal system, when a few minutes’ research would show that the allegation presented is demonstrably false. Courts and lawmakers should be actively praising Apple’s approach to protecting privacy, rather than confusing it with the privacy-compromising practices of companies like Meta.
This is yet another example of how both courts and legislators fundamentally fail to understand the technology they are trying to regulate. The best example of this, without a doubt, is related to end-to-end encryption. Several countries have threatened or tried to ban it without having the slightest understanding of how it really works.
While it is understandable that neither judges nor politicians can be experts in all areas in which they work, they do have access to experts. It is inexplicable that processes and attempts at legislation can advance for so many years without anyone identifying such fundamental flaws.















