Every story tagged Biometric Data, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
3 stories · open in the command center
A federal judge has certified a multi-billion-dollar class action lawsuit against Apple under Illinois' Biometric Information Privacy Act, with potential damages reaching $32.5 billion for alleged violations related to the Photos app's face recognition feature. The case covers approximately 6.5 million Illinois users and establishes significant legal precedent for biometric data handling, following similar major settlements against Meta ($650M) and Instagram ($68.5M). For IT leaders, this underscores the escalating regulatory and financial risks of deploying facial recognition and biometric processing features without explicit user consent, particularly across state-specific privacy laws.
Chinese platforms are creating new marketplaces where individuals license their biometric data and likenesses for AI-generated content, with ambiguous terms that pose significant risks around data governance, intellectual property rights, and regulatory compliance. This emerging trend signals that IT organizations must urgently establish policies around biometric data protection, synthetic media provenance, and third-party risk management as deepfakes and AI-generated content become commercially viable. The vague licensing practices highlight critical gaps in data privacy frameworks and present potential liability exposures for enterprises that may inadvertently use or be impacted by unauthorized synthetic media.
Yoti's age verification service shares sensitive user data—including facial photos and device fingerprints—with third-party vendors, creating significant privacy and compliance risks for organizations implementing this technology. This practice raises critical concerns for IT leaders regarding vendor data handling, regulatory exposure under GDPR and similar frameworks, and potential reputational damage if customer data is misused. Technology organizations must reassess their identity verification vendor partnerships and establish stricter data governance requirements to minimize liability and maintain customer trust.