Attorney Advertising · Informational Only · Not Legal Advice · Editorial Policy

Apple Biometric Privacy Class Action Alleges Unauthorized Iris and Retinal Scans

A class action lawsuit filed in July 2026 alleges that Apple’s Face ID system captures iris and retinal scan data without obtaining separate written consent from users, potentially violating Illinois’s strict Biometric Information Privacy Act (BIPA). However, the lawsuit’s core technical claim remains disputed: while Face ID uses infrared imaging to create a 3D facial map with 30,000+ invisible dots, Apple’s official documentation makes no claim to capturing iris or retinal data. The allegation centers on Face ID’s attention-tracking feature, which detects whether a user is looking at their device, but whether this detection process creates a detailed iris scan—or merely detects eye direction—has not been independently verified.

If certified as a class action, the potential exposure could reach billions of dollars. The case was filed by Samantha Mettler, an Illinois resident, represented by attorney Blake Hunter Yagman of Yagman PLLC. Mettler seeks $1,000 to $5,000 per violation under BIPA on behalf of all Illinois residents whose iris or retinal data was allegedly collected through Face ID or its attention-tracking features. The lawsuit names individuals and businesses whose devices may have used this technology without proper written disclosure or consent—a requirement that BIPA enforces strictly, though a 2024 amendment now permits electronic signatures to satisfy the written-consent rule.

Table of Contents

Does Face ID Actually Capture Iris and Retinal Data?

The lawsuit’s technical foundation requires careful unpacking. apple‘s official documentation describes Face ID as a system that projects 30,000+ invisible infrared dots onto the face and uses an infrared camera to map facial geometry in three dimensions. This 3D facial mapping is distinctly different from iris or retinal scanning, which would require capturing detailed images of the iris (the colored ring of the eye) or the retina (the light-sensitive tissue at the back of the eye). Apple has never publicly documented Face ID as collecting iris or retinal data—only facial geometry.

The allegation in the lawsuit claims that Face ID’s attention-tracking feature—which determines if a user is looking at their phone—may incidentally capture sufficient iris detail to constitute an iris scan. This is a technical claim about what the hardware is capable of, not what Apple has officially deployed or intended. No independent security researchers or academic studies cited in the case materials have verified this claim. The core problem: a device capable of detecting eye direction does not necessarily mean it is capturing and storing a high-resolution iris map. Without independent analysis or discovery in the litigation, whether this incidental capture actually occurs remains unproven.

Iris Scanning Technology: Optic ID vs. Face ID

Apple does operate iris-scanning technology, but not through Face ID. Optic ID is Apple’s iris-recognition system, available exclusively on the Apple Vision Pro headset. Optic ID uses near-infrared imaging and machine learning to recognize an individual’s unique iris pattern, similar to how fingerprint scanners work. The probability of a random person unlocking a device protected by Optic ID is less than 1 in 1 million, according to Apple’s security documentation.

Iris data captured during Optic ID enrollment is converted into an encrypted mathematical representation and stored only in the device’s Secure Enclave; the raw images are discarded after processing. The distinction between Face ID and Optic ID matters legally and technically. Because Optic ID is deployed only on Vision Pro—a specialized headset worn by a small subset of users—it is unlikely to be the focus of this Illinois class action, which centers on broader Face ID deployments across millions of iPhones and iPads. The lawsuit’s allegation that Face ID captures iris data through attention-tracking is not the same as claiming Apple runs its documented Optic ID system through iPhones. This confusion between the two technologies may reflect either a fundamental misunderstanding in the complaint or a technical claim that requires discovery and expert testimony to establish.

Illinois’s Biometric Information privacy Act is one of the nation’s strictest state-level privacy statutes. BIPA requires that before any organization collects a biometric identifier—defined to include face, iris, fingerprints, voice, or any other physical characteristic used for identification—it must first obtain written notice and written consent from the individual. The statute requires companies to disclose the specific purpose for collection, how long the biometric data will be retained, and when it will be destroyed. Simply noting biometric collection in a terms-of-service document is insufficient; BIPA demands explicit written authorization targeting the specific biometric data type.

A 2024 amendment to BIPA expanded what constitutes “written consent,” permitting electronic signatures and digital onboarding consent to satisfy the statute’s requirements. This change was significant because it allowed companies to gather consent through digital workflows rather than requiring wet signatures. However, the amendment does not eliminate the requirement for disclosure or consent—it merely clarifies that digital methods are acceptable. For Face ID, if Apple’s initial setup process disclosed that the device would use infrared imaging to detect eye direction and the user consented to that disclosure, the question becomes whether the attention-tracking feature and any incidental iris detection it performs fall within the scope of that consent. If it does not, then separate consent would be required.

The class action was filed on July 4, 2026, in the U.S. District Court for the Northern District of Illinois, Western Division. Samantha Mettler, a DeKalb County resident, sued on behalf of a proposed class consisting of all Illinois residents whose iris or retinal data was collected via Face ID or attention-tracking without separate written consent. The lawsuit seeks statutory damages ranging from $1,000 to $5,000 per violation—a distinction between negligent violations ($1,000 each) and intentional or reckless violations ($5,000 each).

The financial exposure hinges on class certification and the number of alleged violations. If the class encompasses millions of Illinois iPhone and iPad users, and if each device or each instance of biometric collection counts as a separate violation, the total damages could reach billions of dollars. This potential scale explains why Apple would vigorously defend against class certification and the underlying factual claims. A comparison: a class of 2 million members, each with a single $1,000 negligent violation, would total $2 billion in liability before attorney fees and costs. If violations are counted per unlock or per use of attention-tracking, the numbers multiply.

Who Is Included in the Proposed Class?

The proposed class is limited to Illinois residents whose iris or retinal data was collected through Face ID or attention-tracking features. This geographic limitation is deliberate: BIPA is an Illinois state statute and does not create federal rights. Residents of other states may have privacy laws that protect biometric data, but those statutes often differ in scope, damages, and enforcement mechanisms, making a national class action impractical. A resident of California, for example, would fall outside this lawsuit despite using the same iPhone model, because California’s CCPA (California Consumer Privacy Act) provides different protections and different remedies.

Inclusion in the class would likely be determined automatically based on device records: if your iPhone or iPad is registered to an Illinois address and Face ID or attention-tracking was enabled, you would be part of the class—assuming the class is certified. You would not need to file a claim individually; the settlement or judgment would apply to all class members. However, as of July 2026, the case remains in the early stages. No motion to dismiss has been ruled upon, and no class certification motion has been decided. The class definition may be narrowed, expanded, or redefined as the litigation proceeds.

The Technical Claim and Its Verification Status

The lawsuit’s allegation that Face ID’s attention-tracking feature captures iris data rests on a technical claim: that the infrared imaging system capable of detecting eye direction can also create a detailed iris map without the user’s knowledge. Iris maps, if created, would contain biometric identifiers as defined by BIPA—unique patterns in the iris that could theoretically be used to unlock a device or identify an individual. An analogy: a camera capable of photographing a fingerprint is not the same as a camera designed to photograph and store fingerprints. Similarly, hardware capable of detecting whether an eye is open does not automatically mean it is storing iris data.

As of mid-2026, no independent security researchers, academic institutions, or regulatory bodies have publicly verified that Face ID creates and stores iris scans. Apple’s own security documentation makes no such claim. The burden of proof in litigation will fall on the plaintiff to demonstrate, through expert testimony or device analysis, that Face ID does in fact capture and store iris data. If discovery reveals that the attention-tracking feature operates only on facial geometry—or on eye-direction detection that does not constitute a true iris scan—the lawsuit’s factual foundation collapses, regardless of whether Apple disclosed the feature’s capabilities.

Case Status and What Comes Next

As of July 2026, this class action remains in the early pleadings stage. The complaint has been filed, and defendants (Apple) have not yet filed a motion to dismiss that has been publicly ruled upon. Before any class can be certified, the court must determine that the case meets four requirements: commonality (all class members face the same legal issue), numerosity (enough members to justify a class), typicality (the named plaintiff’s claims are typical of the class), and adequacy of representation (the plaintiff and attorney will fairly represent the group). Apple will almost certainly contest class certification, arguing that individual variations in device settings, usage patterns, or consent histories make a class action inappropriate.

Potential class members should monitor the case docket through the U.S. District Court for the Northern District of Illinois or through class action settlement websites for updates on certification, any motions to dismiss, or settlement negotiations. If the case proceeds to settlement, class members would typically be notified by mail or email with instructions on how to claim compensation. At this stage, individuals do not need to take action unless they receive official notice from the court or a settlement administrator. Until class certification occurs, the case represents an allegation and a legal theory, not an established fact or a finalized claim.


You Might Also Like

Caring for someone with dementia? Find practical guides at HelpDementia.com. Working out a skin routine? Evidence-based answers at AcneAdvocate.com. Forgot the name of a movie? Identify it at FindThisMovie.com. Was your data exposed? Track active breaches at DataBreachRadar.com.

We use cookies to run this site, measure how it’s used, and show ads. Choose “Essentials only” to limit cookies to what the site needs to work. Privacy Policy.