{"id":4078,"date":"2021-09-27T13:02:35","date_gmt":"2021-09-27T18:02:35","guid":{"rendered":"https:\/\/blogs.luc.edu\/compliance\/?p=4078"},"modified":"2021-09-27T13:02:35","modified_gmt":"2021-09-27T18:02:35","slug":"landmark-settlement-for-a-privacy-violation-brings-big-tech-to-its-knees","status":"publish","type":"post","link":"https:\/\/blogs.luc.edu\/compliance\/?p=4078","title":{"rendered":"Landmark Settlement for a Privacy Violation Brings Big-Tech to its Knees"},"content":{"rendered":"<p><span style=\"font-family: 'times new roman', times, serif\"><em>Annalisa Kolb <\/em><\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\"><em>Associate Editor <\/em><\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\"><em>Loyola University Chicago School of Law, J.D. 2023<\/em><\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">On Friday, February 26, 2021, U.S. District Court Judge James Donato approved a <a href=\"https:\/\/www.chicagotribune.com\/business\/ct-biz-facebook-privacy-settlement-approval-20210227-okljqhsiargl7ijvzzfcotpyby-story.html\">650 million-dollar settlement<\/a> against tech giant Facebook for violating the <a href=\"https:\/\/www.ilga.gov\/legislation\/ilcs\/ilcs3.asp?ActID=3004&amp;ChapterID=57\">Illinois Biometric Information Privacy Act<\/a>. Chicago attorney <a href=\"https:\/\/edelson.com\/Facebook-Settlement\">Jay Edelson<\/a> filed the class action lawsuit in 2015, alleging that Facebook had failed to obtain consent from users before using facial recognition technology to scan and digitally store uploaded photos. <!--more--><\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">The Judge stated that the settlement was one of the largest ever for a privacy violation, paying out at least $345 to every class member who filed for compensation. Judge Donato <a href=\"https:\/\/www.chicagotribune.com\/business\/ct-biz-facebook-privacy-settlement-approval-20210227-okljqhsiargl7ijvzzfcotpyby-story.html\">wrote in a statement<\/a> that this case is \u201ca major win for consumers in the hotly contested area of digital privacy.\u201d The class includes any Facebook user located in Illinois, who has lived in Illinois for at least six months, and for whom Facebook created and digitally stored facial recognition data after June 7, 2011. The deadline to submit a claim was November 23, 2020.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\"><strong>Article III injury in privacy cases <\/strong><\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">Historically, it has been notoriously difficult to prove Article III\u2019s \u201cinjury-in-fact\u201d requirement in order to establish standing in privacy litigation. The Supreme Court has established the beginnings of a framework for analyzing Article III\u2019s \u201cinjury-in-fact\u201d requirement in <a href=\"https:\/\/www.americanbar.org\/groups\/business_law\/publications\/blt\/2018\/07\/data-breach\/\">two of its decisions<\/a>. Specifically, in <a href=\"https:\/\/1.next.westlaw.com\/Document\/I4b728737801d11e28a21ccb9036b2470\/View\/FullText.html?originationContext=typeAhead&amp;transitionType=Default&amp;contextData=(sc.Default)\"><em>Clapper v. Amnesty International USA <\/em>(2013)<\/a>, the Court held that the plaintiff\u2019s anticipation or fear of a possible data breach was not concrete enough to establish injury, reasoning that injury must be \u201ccertainly impending\u201d to constitute injury and may not be overly speculative. Later, in <a href=\"https:\/\/1.next.westlaw.com\/Document\/I041b593a1b6011e6a807ad48145ed9f1\/View\/FullText.html?originationContext=typeAhead&amp;transitionType=Default&amp;contextData=(sc.Default)\"><em>Spokeo, Inc. v. Robins<\/em> (2016),<\/a> the Court specified that a \u201crisk of real harm\u201d may be enough to establish injury-in-fact if the risk of injury is concrete and particular. The Court further explained that although a statute may provide a private right of action, there still must be an alleged concrete and particularized harm to establish standing. Concrete, however, does not necessarily require the harm to be tangible. The Court reasoned that because Congress may be better equipped to determine when the risk of potential harm is sufficiently concrete, statutory non-compliance could constitute the basis of an injury without plaintiffs establishing any additional harm beyond the one identified by the statute.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\"><strong>The Illinois Biometric Information Privacy Act and Facebook\u2019s violation<\/strong><\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">The <a href=\"https:\/\/1.next.westlaw.com\/Document\/I02b0d0c7b3de11e2af9be44072a78d39\/View\/FullText.html?originationContext=docHeader&amp;contextData=(sc.Default)&amp;transitionType=Document&amp;needToInjectTerms=False&amp;docSource=b081a06d231943888027fb4b10ec66b7\">Illinois Biometric Information Privacy Act<\/a>\u00a0 (\u201cBIPA\u201d) was passed in 2008 to safeguard the security and safety of Illinois citizens in an environment where biometric identifiers are collected and used more and more frequently. The Illinois Legislature specifically <a href=\"https:\/\/www.aclu-il.org\/en\/campaigns\/biometric-information-privacy-act-bipa#:~:text=BIPA%20is%20currently%20the%20one,women%20and%20people%20of%20color.\">recognized<\/a> the unique sensitivity of biometric data as it cannot be changed if compromised and is as unique to a person as their fingerprint. \u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">BIPA <a href=\"https:\/\/www.aclu-il.org\/en\/campaigns\/biometric-information-privacy-act-bipa#:~:text=BIPA%20is%20currently%20the%20one,women%20and%20people%20of%20color.\">requires<\/a> that a company that collects a person\u2019s biometric information obtains a written release from that person before collection, provides notice that data is being collected and stored, informs of the duration information will be stored, and for what purpose data was collected. BIPA provides a statutory private right of action to anyone who is \u201caggravated\u201d under BIPA. The term \u201caggravated\u201d has been a point of contention within courts, with some ruling that a violation of any aspect of BIPA is sufficient to establish injury. In contrast, others held there must be both a violation of BIPA and another independent claim of injury.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">The Seventh Circuit applied <em>Spokeo<\/em> in <a href=\"https:\/\/1.next.westlaw.com\/Document\/Ied1583808f0511eab2c3c7d85ec85a54\/View\/FullText.html?originationContext=typeAhead&amp;transitionType=Default&amp;contextData=(sc.Default)\">Bryant v. Compass Group USA Inc (2020)<\/a>, where the plaintiff alleged that a vending machine owner violated BIPA by collecting her fingerprint without obtaining her written consent. The Court held that the violation of the plaintiff\u2019s rights, the collection of her private biometric information, was sufficient to establish concrete injury without alleging any further tangible consequences.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">Many separate cases were filed against Facebook, later consolidated in federal court, alleging Facebook violated BIPA by collecting biometric data without notice or consent through its <a href=\"https:\/\/www.facebook.com\/help\/tag-suggestions?__tn__=*s-R\">\u201ctag suggestions\u201d<\/a> feature. The \u201ctag suggestions\u201d feature detects faces on newly uploaded images, compares them to faces on past uploaded images, and gives you suggestions on who to tag in the new photo. <a href=\"https:\/\/www.supremecourt.gov\/DocketPDF\/19\/19-706\/124149\/20191202180045158_19-__%20BIPA%20Cert%20Petition%2012.2%20Final.pdf\">Facebook sought to dismiss the case<\/a>, arguing that the plaintiffs lacked standing as they only alleged that Facebook collected their biometric data in violation of BIPA without alleging any additional concrete tangible damages.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\"><strong>Implications of this decision<\/strong><\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\"><a href=\"https:\/\/1.next.westlaw.com\/Document\/Iaa2d1a80421111e8a054a06708233710\/View\/FullText.html?docFamilyGuid=Iab3a44c0421111e8b375e4804c62cc0e&amp;ppcid=8dea162cab784a5293e081cbd15ade9e&amp;transitionType=History&amp;contextData=%28sc.Default%29\">The District Court<\/a>, in this case, had the job of deciding whether a statutory privacy injury was sufficiently real and concrete to establish injury-in-fact under Article III. The District Court rejected Facebook\u2019s standing argument, holding that the Illinois Legislature created a right to privacy regarding personal biometric data. Further, BIPA violations cause actual and concrete harm sufficient to establish Article III\u2019s \u201cinjury-in-fact\u201d. The <a href=\"https:\/\/1.next.westlaw.com\/Document\/Id4524460b9f811e991c3ae990eb01410\/View\/FullText.html?docFamilyGuid=I144716b0ba1a11e9ae1ba4cff724dfcb&amp;ppcid=8dea162cab784a5293e081cbd15ade9e&amp;transitionType=History&amp;contextData=%28sc.Default%29\">Ninth Circuit affirmed<\/a> and the Supreme Court <a href=\"https:\/\/1.next.westlaw.com\/Document\/I0bb7a4573c2211eab8aeecdeb6661cf4\/View\/FullText.html?docFamilyGuid=I0bb7a4583c2211eab8aeecdeb6661cf4&amp;ppcid=8dea162cab784a5293e081cbd15ade9e&amp;transitionType=History&amp;contextData=%28sc.Default%29\">denied<\/a> certiorari.<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\">The implications of this decision on a corporation\u2019s internal legal risk analyses are enormous, posing potentially billion-dollar risks to tech giants who collect biometric data. Plaintiffs have a considerable incentive to pursue BIPA violations in pursuit of similar multimillion dollar settlements without having to establish a financial injury. Ultimately, this case illustrates how an established and specific state law like BIPA protects consumers and may offer some peace of mind during a time when public concern over the implications of surveillance technology is growing. But is it enough?<\/span><\/p>\n<p><span style=\"font-family: 'times new roman', times, serif\"><a href=\"https:\/\/www.itgovernance.eu\/blog\/en\/things-to-consider-when-processing-biometric-data\">Biometric data<\/a> is highly sensitive due to its immutable nature. If an individual\u2019s biometric data is compromised in a data breach, there is very little they can do to stop an adversary from potentially using that data in <a href=\"https:\/\/www.beyondtrust.com\/blog\/entry\/is-your-identity-at-risk-from-biometric-data-collection\">devastating ways<\/a>. While BIPA requires consent and sets guidelines when collecting biometric data, it is not difficult to comply with and does not necessarily decrease the risk of a data breach. As long as data is stored and accessed on the internet, there is always a risk of a data breach and therefore risk of subsequent litigation. Corporations should seriously consider if collecting biometric data is worth the risk, even if they comply with BIPA.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On Friday, February 26, 2021, U.S. District Court Judge James Donato approved a 650 million-dollar settlement against tech giant Facebook for violating the Illinois Biometric Information Privacy Act. Chicago attorney Jay Edelson filed the class action lawsuit in 2015, alleging that Facebook had failed to obtain consent from users before using facial recognition technology to scan and digitally store uploaded photos.<\/p>\n","protected":false},"author":98,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[290,293,570,783,1622,1623],"class_list":["post-4078","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-biometrics","tag-bipa","tag-data-collection","tag-facebook","tag-privacy","tag-cybersecurity"],"_links":{"self":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/4078","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/users\/98"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4078"}],"version-history":[{"count":0,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/4078\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4078"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4078"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4078"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}