PrivacySignal
Enforcement

Apple Faces $32.5 Billion Lawsuit Over Facial Recognition in iPhone Photos App

PetaPixel · · International · Enforcement

Apple is facing a lawsuit seeking approximately $32.5 billion over allegations that the facial recognition features built into its iPhone Photos app collected or processed biometric data without adequate user consent. The case targets one of Apple's core organizational tools for personal photo libraries.

Why this matters: Your iPhone has been quietly grouping photos by face for years. Most people clicked through that feature without thinking much about it. This lawsuit says that process may have involved biometric data collection that users never meaningfully agreed to. Facial recognition is not like collecting an email address. It maps your physical identity. If Apple processed that data without clear, informed consent, the people affected are essentially every iPhone user who ever let the Photos app organize their pictures. The dollar figure is enormous, but the real issue is simpler: did users actually know what was happening to their face data, and did they have a real choice?

Who should care: Lawyers · Privacy officers · Compliance · Cybersecurity · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Enforcement
B Bloomberg Law News · · International

Vermont Joins Multi-State Data Privacy Enforcement Consortium

Vermont has joined a multi-state consortium focused on coordinating data privacy enforcement across participating states. The collaboration is aimed at strengthening regulatory action against companies that handle personal data, by pooling resources and aligning enforcement efforts.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
S Schlichter Bogard LLC · · International

Health Data Privacy Lawsuit Against Cigna Brought on Behalf of Plaintiffs Represented by Schlichter Bogard Will Proceed

A health data privacy lawsuit against Cigna will move forward, with plaintiffs represented by the law firm Schlichter Bogard. The case clears an early procedural hurdle, allowing claims about how the insurer handled sensitive health information to be litigated.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals · General readers · Policy

#enforcement#healthcare#privacy Read original →
Enforcement
W Wilson Sonsini · · International

EU AI Act Enforcement Phase Begins

The EU AI Act has entered its enforcement phase, marking the transition from rulemaking to active compliance obligations for companies operating AI systems in the European Union. Organizations now face real regulatory scrutiny, not just preparation deadlines.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Administrators · General readers · Policy

#enforcement#ai-governance#ai Read original →
Enforcement
The Guardian — Privacy · · International

Apple launches legal challenge against UK government demand to access data

Apple has filed a legal complaint at the UK's Investigatory Powers Tribunal challenging a Home Office demand for backdoor access to encrypted iCloud data belonging to British users. The challenge comes roughly a year after the government dropped a similar request, suggesting the underlying dispute over encryption access never fully went away.

Who should care: Lawyers · Privacy officers · Compliance

#enforcement Read original →
Enforcement
HIPAA Journal · · US Federal

FTC; Utah; California Sue Him & Hers Over Business and Data Sharing Practices

The Federal Trade Commission, along with Utah and California, has filed suit against telehealth company Hims & Hers, alleging unlawful business and data sharing practices. The action marks a coordinated federal-state enforcement effort targeting the San Francisco-based company.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals

#enforcement#healthcare Read original →
Enforcement
HIPAA Journal · · US Federal

CISA Issues Updated Guidance on Minimum Elements of an SBOM

CISA, the FBI, the NSA, and 15 international partners have released updated guidance defining the minimum required elements of a Software Bill of Materials (SBOM), a structured record of the components that make up a software product. The joint guidance builds on earlier frameworks and reflects growing international coordination around software supply chain transparency.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals

#enforcement#healthcare#regulation Read original →