A startup based in Chicago is building a face recognition model for security camera applications. They scraped 50,000 publicly visible social media profile photos to build their training dataset without obtaining consent from any of the individuals pictured.
An AI training dataset contains 50,000 images of faces scraped from the web. The company did not collect consent from the individuals pictured. Which privacy regulation would apply to a company processing this dataset in Illinois?
- A.Illinois BIPA (Biometric Information Privacy Act) - requires informed consent before collecting or using biometric identifiers including face geometry
- B.FERPA - educational records law, since consent transfers automatically to model weights
- C.CAN-SPAM - anti-spam email regulation
- D.HIPAA - health information protection
Why A is correct