Instagram Biometric Privacy Class Action Investigation: What Instagram Users Should Know

Instagram paid $68.5 million to settle allegations it scanned faces without permission from millions of Illinois users.

Instagram reached a $68.5 million class action settlement in 2023 after it was alleged the company collected and stored facial recognition biometric data without explicit user consent. The settlement affected approximately 4 million Illinois residents who used Instagram between August 10, 2015, and August 16, 2023. Each eligible user received a $32.56 payout, with distributions completed by June 2024—though the claim deadline passed on September 27, 2023, so new claimants cannot join.

The lawsuit centered on Instagram’s use of facial recognition software to scan faces in photos and videos. The company continued collecting this biometric data even when users disabled their individual facial recognition settings, and it scanned faces of unnamed people appearing in photos without their knowledge or consent. This practice violated Illinois’s Biometric Information Privacy Act (BIPA), a 2008 law widely recognized as one of the strictest biometric privacy statutes in the country.

Table of Contents

How Did Instagram Collect Biometric Data Without Permission?

instagram deployed facial recognition software across its platform to automatically scan and analyze faces in images uploaded by users. The technology worked by identifying facial features and creating digital maps of users’ faces—biometric identifiers that are far more difficult to change or conceal than a password or username. The company used this capability to power features like automatic tagging suggestions and face-based search, but it did this without obtaining the explicit written consent that BIPA requires. What made this practice particularly invasive was its scope.

Instagram scanned not only the faces of account holders who uploaded photos, but also the faces of unnamed people who appeared in those photos—friends, family members, and strangers who had no direct relationship with Instagram and never agreed to having their facial features analyzed and stored. Even users who manually disabled facial recognition in their account settings discovered that Instagram continued extracting biometric data in the background. Unlike disabling location tracking or limiting ad targeting, turning off facial recognition in your account settings did not stop the company from analyzing your face in photos. A practical example illustrates the consent gap: if you posted a family photo from a vacation, Instagram scanned the faces of everyone in that image—yourself, your spouse, your children, the stranger who photobombed the shot—and stored their biometric information without any of those individuals signing a consent form. This happened millions of times per day across Instagram’s roughly 2 billion monthly users, though the settlement only covered Illinois residents due to that state’s unique legal protections.

What Violations Did Instagram Commit Under Illinois Biometric Privacy Law?

BIPA establishes strict requirements for companies that collect, store, or use biometric information—a category that includes facial recognition data, fingerprints, iris scans, and other unique biological markers. The law requires companies to inform individuals in writing that they are collecting biometric data, explain why and how it will be used, obtain explicit written consent before collection begins, and implement a secure retention schedule for deleting the data. Instagram violated multiple BIPA provisions. The company did not provide clear written notice to the millions of Illinois users whose faces it scanned. It did not obtain explicit written consent before beginning to collect their facial data.

It continued collecting biometric data from users who believed they had disabled facial recognition through their privacy settings. Perhaps most significantly, Instagram’s terms of service—which users clicked through in a box before creating an account—did not constitute the kind of specific, informed written consent BIPA requires for biometric collection. A buried line in a generic privacy policy is not the same as informing someone “we will scan your face and store the data” and asking them to explicitly agree. The company’s conduct was not an accident or oversight—it was systematic. Instagram operated facial recognition infrastructure continuously from 2015 through 2023, processing billions of images and collecting biometric data on an enormous scale. This eight-year period is why the settlement class is so large and why even per-claimant payouts required a pool of tens of millions of dollars.

Major Biometric Privacy Settlements Against Tech CompaniesMeta (Facebook)650$ millionsMeta (Instagram)68.5$ millionsGoogle1400$ millionsSource: Class action settlements and state attorney general announcements (2021-2024)

Who Qualified for the Settlement and Who Was Left Out?

To receive payment from the Instagram settlement, a person needed to have a qualifying claim: residency in Illinois at any point during the violation period (August 10, 2015 – August 16, 2023) and an Instagram account during some or all of that time. The settlement did not require proof of actual injury or damage. If you lived in Illinois and used Instagram during those eight years, you were eligible to submit a claim. However, the settlement covers only Illinois residents due to BIPA’s unique statutory framework. Users in other states harmed by the same facial recognition practices received no payment from this settlement.

A California user whose face Instagram scanned during the same period had no claim under the $68.5 million pool, even though the company’s conduct was identical. This disparity exists because BIPA, passed in 2008, created remedies that no other state had matched until recent years. Other states with stricter biometric laws have pursued their own settlements—Texas Attorney General Ken Paxton secured a separate $1.4 billion settlement with meta in July 2024 for similar biometric violations—but those settlements cover only residents of those specific states. The deadline to submit a claim to the Instagram settlement was September 27, 2023. That deadline has passed, and the settlement administrator is not accepting new claims. If you were an eligible Illinois resident but did not file a claim by that date, you cannot recover from this particular settlement.

How and When Did Eligible Users Receive Their Payouts?

Eligible claimants who submitted timely claims received $32.56 per claim by June 2024. The payment was distributed either via direct deposit (for claimants who provided banking information) or by check mailed to their address on file. Direct deposit payments typically arrived within days, while mailed checks could take one to two weeks depending on postal service timing. To check whether you received your payment, the settlement administrator maintained a claims database where users could search by name or email address to verify their claim status. If you had a valid claim and submitted documentation by September 27, 2023, the payment should have reached you by mid-2024.

If you claimed you never received the money, the settlement administrator offered a missing payment process where you could request reprocessing of a check or electronic transfer. Contact information for the settlement administrator was included in settlement notices, though attempting to trace a payment months after distribution became completed can be difficult. The relatively small per-claimant payout—$32.56—reflects the enormous size of the class. With 4 million eligible claimants and $68.5 million available (minus attorneys’ fees and administrative costs), each person received a modest amount. This is common in biometric privacy settlements, where the class size is so large that even substantial settlement funds produce small individual payouts. By contrast, some fraud class actions with fewer but more severely harmed members produce larger per-claimant checks.

What Prompted This Settlement and Why Did It Take Eight Years?

The Instagram biometric privacy violations spanned from August 2015 to August 2023—an eight-year window during which the company operated facial recognition without obtaining BIPA-compliant consent. The lawsuit was eventually filed by Illinois residents and their attorneys, who recognized that Instagram’s practices violated the state’s biometric privacy law. Instagram and its parent company Meta negotiated a settlement in 2023 and agreed to pay $68.5 million to resolve the claims, though the company did not admit wrongdoing. Why did this case take so long to reach settlement? Biometric privacy is a newer area of law, and many tech companies initially believed they could rely on vague consent language buried in privacy policies. BIPA, despite being passed in 2008, did not generate substantial enforcement activity against major tech platforms until the late 2010s. Class action attorneys had to litigate the question of whether facial recognition analysis constitutes “collection” of biometric data under the statute, whether Instagram’s terms of service satisfied the “explicit written consent” requirement, and whether the class of harmed users was ascertainable.

These legal questions required years of motion practice and appeals before settlement became likely. Other large tech companies faced similar BIPA suits. Facebook (Meta) also settled a biometric privacy case for $650 million in 2021 related to its facial recognition features. Google faced BIPA litigation over its Photos app. Snap Inc. settled biometric privacy claims. The Instagram settlement represents one of many judgments that these companies faced after the privacy community and regulators recognized the scope of facial recognition deployment.

Are There Other Biometric Privacy Settlements or Ongoing Cases?

Yes. The $68.5 million Instagram settlement is one of several major biometric privacy settlements involving tech companies. The broader pattern shows that BIPA violations have become a significant liability for any company using facial recognition or similar biometric technology. Meta’s $650 million settlement from 2021 stemmed from Facebook’s use of facial recognition in photo tagging. That settlement affected millions of Facebook users and resulted in larger per-claimant payouts in some cases, depending on the number of eligible claimants.

Google faced BIPA lawsuits over its Photos app’s facial recognition. Snap Inc. settled Illinois biometric privacy claims over Snapchat’s lenses feature. Beyond Illinois, other states have begun enforcing their own biometric privacy laws. Texas Attorney General Ken Paxton’s $1.4 billion settlement with Meta in July 2024 was the largest penalty ever obtained by a single state against any company and addressed similar facial recognition practices affecting Texas residents.

What Does This Mean for Your Privacy Going Forward?

The Instagram settlement established important precedent: companies cannot assume that vague privacy policies or buried consent language satisfy biometric privacy laws. If a company collects facial recognition data, it must disclose this practice clearly, obtain explicit written consent, and honor user requests to delete biometric information. The settlement also reinforced that biometric data collection from unnamed people in photos (third parties) is subject to privacy law, not just the data collection from account holders themselves. However, a key limitation remains: the settlement only required Meta to pay money to Illinois residents.

It did not force Instagram to delete the biometric data it collected, and it did not mandate fundamental changes to how Instagram’s facial recognition features operate. The settlement was a financial remedy, not an injunction restructuring the company’s practices. Users in other states harmed by identical conduct received nothing unless they lived in a state with its own biometric privacy law and filed separate claims there. This illustrates a broader problem in biometric privacy enforcement: protections vary dramatically by state, and most Americans live in jurisdictions with no BIPA-equivalent law.


You Might Also Like