Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Does Facebook’s collection of photos violate privacy laws?

By Brian Wheelin on September 9, 2015
Email this postTweet this postLike this postShare this post on LinkedIn

An Illinois man recently filed a proposed federal class action alleging that Facebook violates state law protecting the privacy of biometric data through its alleged collection of facial recognition data from over a billion faces on uploaded photos.

As many Facebook users are aware, the social networking service automatically matches persons in uploaded photos.  According to the lawsuit, this is done by scanning geometric data from faces after users “tag” (provide the name) a person in a photo not known to Facebook.

The named plaintiff in the suit, Frederick Gullen, is not a Facebook user and alleges that he never consented to Facebook allegedly acquiring his facial features taken from a photograph uploaded by another person. He seeks to represent a class of Illinois residents who are non-Facebook users but have been tagged in photos on Facebook.

The Illinois Biometric Information Privacy Act regulates capturing, using and transferring facial scans and other data “as biometric identifiers.” The state statute also covers “biometric information,” which it defines “as any information, regardless of how it is captured, converted, stored, or shared, based on an individual’s biometric identifier used to identify an individual…”

Illinois law prohibits companies that collect biometric data from selling it to third parties. During a 2012 U.S. Senate hearing, Facebook refused to commit that such information would not be sold.

Facebook has stated publicly that it considers the suit to be meritless and that it intends to defend itself vigorously.  While Facebook has yet to formally respond to the Complaint, one of the arguments it will likely make is that the statute at issue excludes information derived from photographs.

The case is Gullen v. Facebook Inc., case number 1:15-cv-07681 in the U.S. District Court for the Northern District of Illinois.

Photo of Brian Wheelin Brian Wheelin

Brian Wheelin is a member of the firm’s Business Litigation Group, where he focuses his practice on complex commercial litigation, including privacy and cybersecurity matters.

Brian has first-chaired cases to verdict as well as argued appeals before the United States Second Circuit and…

Brian Wheelin is a member of the firm’s Business Litigation Group, where he focuses his practice on complex commercial litigation, including privacy and cybersecurity matters.

Brian has first-chaired cases to verdict as well as argued appeals before the United States Second Circuit and state appellate courts in Connecticut and New York. He represents both individuals and companies in commercial litigation matters encompassing business torts, contract breaches, and disputes related to employment, real estate, and intellectual property.

Brian serves on the firm’s Electronic Discovery Committee. Read his full rc.com bio here.

Read more about Brian WheelinEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo