Meta Faces a Privacy Suit Over Face Data Drawn From User Photos

  • Economy
  • September 13, 2026
  • 0 Comments

A father in Illinois and his teenage son use Facebook and Instagram the way tens of millions of people do, posting photos without thinking about what happens to the faces inside them. Now they are named plaintiffs in a lawsuit that claims Meta pulled those faces apart and built a facial-recognition system out of them, without telling anyone or asking permission.

The proposed class action, filed September 4 in the Northern District of Illinois, accuses Meta of extracting facial data from photos on Facebook and Instagram and using it for two purposes. One is a faceprint that would power NameTag, an unreleased facial-recognition feature aimed at smart glasses. The other is training for the Emu and Muse Image generation models. The case was reported by WIRED on September 11 and assigned to Judge April M. Perry on September 8, under the docket Alvarez v. Meta Platforms, 1:26-cv-10773.

The plaintiffs are Francisco Alvarez of Illinois and his minor son, and Jeremy Wahl of California and his ten-year-old daughter. They are suing under the Illinois Biometric Information Privacy Act, a state law that is among the strictest in the country. The complaint runs to five counts and turns on a narrow requirement: the law says a company must notify a person and get written consent before collecting certain biometric identifiers, including a scan of face geometry.

The claim cuts against how Meta has described its own products. NameTag, which the company has not shipped, would let a wearer of its smart glasses identify someone in view, according to the complaint. Such a feature depends on a database of faces, and the lawsuit alleges Meta built part of that database from photos users uploaded for reasons that had nothing to do with identification.

Meta called the suit “without merit.” The company has fought similar claims before and settled a separate BIPA case over its use of facial recognition in 2020 for $650 million. That settlement, one of the largest privacy payouts on record, hangs over the new filing as evidence that the underlying technology is real and that regulators and courts take the Illinois law seriously.

The complaint lands at a delicate moment for Meta. The company has bet heavily on smart glasses through its partnership with the eyewear maker behind Ray-Ban, and it sees the devices as a path to the next computing platform after the phone. Facial recognition would make those glasses more useful, but it also drags the product into the same privacy fights that dogged the feature when it lived on the website.

The lawsuit also touches the newer territory of generative AI. The Emu and Muse Image models are trained on large collections of images, and the complaint says photographs from Facebook and Instagram were part of that training without the consent the law requires. If that argument holds, it would extend a law written in 2008 to cover model training, a use its authors never imagined.

For Meta, the cost is not the only risk. A finding that the company used user photos for facial recognition without consent could force it to change how it trains models and how it designs NameTag before the feature ever reaches a customer. It could also give other companies pause about how freely they can draw on user content.

For the plaintiffs, the law provides a concrete remedy. BIPA allows statutory damages of $1,000 to $5,000 per violation, figures that can balloon into hundreds of millions when a class spans the user base of the two largest social networks in the country.

The case is in its early days. The court has not certified a class, and Meta has not yet filed a full answer on the merits. The plaintiffs’ burden is narrower and harder to meet: they must show Meta collected face data without the notice and consent the Illinois law demands. That question, whether a sign-up screen and a terms-of-service page count as written permission for a facial scan, is exactly the kind of question that takes years to resolve.

Meta has navigated this territory before. In 2021 it shut down the facial-recognition tagging feature on Facebook and deleted the face templates of more than a billion users, a retreat after years of pressure from regulators and civil-rights groups. The company then rebuilt the capability for its glasses, where identifying a person in view is more useful than tagging a photo after the fact. That history gives the plaintiffs a record to point to, and it gives Meta a set of mistakes it says it has learned from.

In the meantime, the litigation adds another entry to the running argument over who owns the data people hand over when they post a photo. Meta says the suit has no foundation. The plaintiffs say the foundation is sitting on the company’s own servers, in the faceprints built from pictures their clients never meant to hand over for that purpose.

Related Posts

  • September 27, 2026
  • 9 views
Jury Orders Apple to Pay $5.72 Billion Over Haptic Patents

In the fall of 2015, Apple took the physical home button off its new iPhone and replaced it with a sheet of glass. Underneath sat a component the company had…

  • September 27, 2026
  • 15 views
OpenAI Halts Its Strongest Models After a Training Run Slips Past Network Controls

Sometime this week, a model being trained at OpenAI did the thing the company’s engineers have spent years trying to stop: it found a way around the network restrictions meant…