Skip to main content
Ring's Facial Recognition Lawsuit: Where Consent Ends and Liability BeginsLawful Basis for Processing
5 min readFor Privacy Officers

Ring's Facial Recognition Lawsuit: Where Consent Ends and Liability Begins

What Happened

In December, Ring launched its Familiar Faces feature, an AI-powered facial recognition system that identifies regular visitors to a user's doorbell camera. This feature sends customized notifications when specific people arrive. However, Charles Sigwalt from Virginia filed a class action lawsuit in Seattle, claiming Ring collects and processes facial recognition data from passersby without their consent. The lawsuit alleges that millions of Americans have unknowingly had their biometric information captured by Ring cameras.

While Ring requires users to opt in to Familiar Faces, the lawsuit highlights a critical issue: the feature processes facial data from anyone who passes by, regardless of their consent.

Timeline

September: Ring announces the Familiar Faces feature. Privacy concerns are raised by organizations like the Electronic Frontier Foundation and Senator Ed Markey about non-consensual facial recognition.

December: Despite the pushback, Ring launches the feature, stating that face data is encrypted, not shared, and unidentified faces are deleted after 30 days.

Monday (filing date): Charles Sigwalt files the class action lawsuit in Seattle, alleging privacy violations affecting millions of Americans who passed Ring cameras.

This isn't Ring's first privacy issue. In 2023, Amazon settled with the Federal Trade Commission for $5.8 million over allegations of improper access to private customer videos. The FTC's complaint revealed that employees had full access to customer videos without business justification.

Which Controls Failed or Were Missing

The main failure isn't technical. It's a misunderstanding of who needs to consent when deploying biometric processing in public spaces.

Missing consent mechanism for third parties: Ring created an opt-in system for device owners but didn't establish a way to obtain consent from those being scanned. Passersby were treated as incidental data subjects rather than individuals with privacy rights.

Inadequate lawful basis assessment: Ring likely relied on the device owner's legitimate interests as the lawful basis for processing. However, a legitimate interests assessment requires balancing your interests against the rights of data subjects. When processing biometric data from people with no relationship to your service, that balance is unfavorable.

No meaningful transparency for affected individuals: Ring's encryption and deletion policies apply to the device owner's relationship with the company. But what about the mail carrier or delivery driver? They received no notice that their facial data was being captured and analyzed.

Failure to account for special category data protections: Biometric data used for unique identification falls under Article 9 of the GDPR as special category data. Processing requires explicit consent or a narrow exemption. Ring's approach assumes the device owner's consent covers everyone the camera sees, which doesn't meet the "freely given, specific, informed and unambiguous" standard for explicit consent.

What the Relevant Standard Requires

Under GDPR Article 9, biometric data processed for unique identification requires explicit consent from the data subject unless a specific exemption applies. The device owner's consent doesn't extend to third parties captured by the camera.

Article 6 requires identifying a lawful basis before processing personal data. If relying on legitimate interests under Article 6(1)(f), you must conduct a legitimate interests assessment weighing your interests against the data subject's rights. When processing involves special category data and individuals with no direct relationship to your service, your interests rarely outweigh their rights.

Article 13 requires providing transparency information at the point of collection. For a doorbell camera scanning passersby, this creates a practical problem: how do you inform someone walking by that their biometric data is being processed? The difficulty of providing notice doesn't excuse the obligation. It suggests the processing model itself may be incompatible with the regulation.

Article 5(1)(c) limits processing to what's necessary for your stated purpose. Ring's purpose is to help device owners identify regular visitors. But the system must scan and analyze every face to determine if it's a "regular visitor." This creates a necessity problem: you're processing biometric data from everyone to serve a feature that benefits a small subset of people.

Lessons and Action Items for Your Team

Map your biometric processing to specific individuals: If deploying facial recognition or similar technologies, identify every category of person whose data you'll process. Include employees, visitors, passersby, and anyone else who might be captured. Document your lawful basis and how you'll meet transparency obligations.

Don't assume device owner consent covers third parties: This applies beyond facial recognition. If building IoT devices, smart home features, or workplace monitoring tools, the device buyer isn't the only data subject. You need a lawful basis for everyone whose data you process.

Test your legitimate interests assessment against adversarial scenarios: Before launching a feature that processes special category data from non-users, have someone challenge your legitimate interests assessment. Ask: would this hold up if a supervisory authority reviewed it after a complaint? If processing biometric data from people who didn't choose to interact with your service, the answer is likely no.

Build consent mechanisms for affected third parties or redesign the feature: Ring could have required users to obtain consent from people they want to tag in Familiar Faces before processing their biometric data. Alternatively, they could have designed the feature to work without biometric processing, perhaps using device-level face matching that never leaves the doorbell. When your feature design conflicts with consent requirements, change the design.

Review your historical privacy incidents before launching sensitive features: Ring launched Familiar Faces after settling with the FTC over improper video access. That settlement should have prompted a comprehensive review of privacy controls across all features, especially those involving surveillance or biometric data. If your organization has a history of privacy incidents, treat new features in related domains with extreme caution. Supervisory authorities and plaintiffs will cite that history as evidence of a pattern.

Document your deletion timelines and verify they execute: Ring claims unidentified faces are deleted after 30 days. Can you prove it? Build audit logs that demonstrate deletion actually occurs. Test your deletion processes regularly. If you're making retention promises to justify processing, those promises must be enforceable and verifiable.

The lawsuit's outcome will clarify how courts interpret consent requirements for biometric processing in consumer devices. But you don't need to wait for a verdict to act. If your feature requires processing special category data from people who didn't opt in, you're building on a weak legal foundation. Fix the foundation before you face your own class action.

You Might Also Like