G. T. v Samsung Electronics America, Incorporated, 25-1120
U.S. Court of Appeals, Seventh Circuit Civil Business Law
Holdings
- Seventh Circuit holds BIPA §§ 15(a) and (b) both require a defendant to have gained or exerted actual control over biometric data, not merely provided a tool.
- Manufacturer that supplies device/software generating and storing biometric data locally on a user's own device does not thereby 'possess,' 'collect,' 'capture,' or 'obtain' that data under BIPA.
- Useful for defense-side privacy litigators and tech companies facing BIPA claims premised on device features that create biometric data stored locally rather than on company servers.
Summary
Plaintiffs, a putative class of Illinois Samsung device users, alleged that Samsung's Gallery App facial recognition feature violated the Illinois Biometric Information Privacy Act (BIPA) by generating and using facial geometry data (face templates) without the notices and consents BIPA requires. After Samsung removed the case to federal court under CAFA and survived two prior rounds of amendment, the district court dismissed Plaintiffs' second amended complaint with prejudice, finding they had not plausibly alleged that Samsung possessed, collected, captured, or otherwise obtained their biometric data. Plaintiffs appealed.
The Seventh Circuit affirmed. Applying Illinois statutory construction principles and Illinois Supreme Court precedent (Ward, Cothron), the court held that the undefined BIPA terms 'possession,' 'collect,' 'capture,' and 'obtain' all require some degree of control over the biometric data—not merely the tool used to generate it. Because Plaintiffs alleged only that Samsung manufactured the devices and installed the software enabling users to create and store face templates locally on their own devices—without alleging Samsung itself accessed, modified, or otherwise controlled that data—the complaint failed to plausibly plead the requisite control. The court distinguished Hazlitt v. Apple Inc. (where only Apple could access the biometric data and users could not delete it) and found more persuasive the reasoning in Bhavilai v. Microsoft Corp. and Barnett v. Apple Inc., which held that supplying a tool used to generate data is distinct from the company itself controlling that data. The court also rejected inferences drawn from Samsung Cloud backup capability and privacy policy language as insufficient to plausibly show Samsung actually gathered or saved the specific facial geometry data.
The decision offers a significant defense-side tool for technology and device manufacturers facing BIPA claims where biometric data is generated and remains stored locally on the end user's own device, clarifying that mere provision of biometric-generating software or hardware, without more, does not trigger BIPA liability.
In short
BIPA §§ 15(a) and 15(b) both require a defendant to have or have gained actual control over the biometric data at issue; 'possession,' 'collect,' 'capture,' and 'obtain' are synonymous with gaining or holding control.
A manufacturer that provides a device and software enabling a user to generate and store biometric data (e.g., a face template) locally on the user's own device does not thereby possess, collect, capture, or obtain that data under BIPA.
Control over software or a device is legally distinct from control over the data that software or device generates; allegations of the former, without more, do not establish the latter.
Generalized allegations about cloud backup capability or privacy-policy language stating a company 'may collect' biometric information are insufficient, without further factual support, to plausibly allege actual collection or control of specific biometric data under Rule 12(b)(6).
This summary was drafted by AI and verified against the slip opinion. It may contain errors and is not legal advice — always read the original before relying on it.