A startup based in Chicago is building a face recognition model for security camera applications. They scraped 50,000 publicly visible social media profile photos to build their training dataset without obtaining consent from any of the individuals pictured.
An AI training dataset contains 50,000 images of faces scraped from the web. The company did not collect consent from the individuals pictured. Which privacy regulation would apply to a company processing this dataset in Illinois?
- A.A. FERPA - educational records law
- B.B. Illinois BIPA (Biometric Information Privacy Act) - requires informed consent before collecting or using biometric identifiers including face geometry
- C.C. HIPAA - health information protection
- D.D. CAN-SPAM - anti-spam email regulation
Why B is correct
The Illinois Biometric Information Privacy Act (BIPA) is one of the strictest biometric data laws in the US. It requires written consent before collecting biometric identifiers (including facial geometry derived from images) and prohibits selling or profiting from biometric data. BIPA has been the basis for major class action lawsuits against AI face recognition companies (including the Clearview AI settlement). FERPA covers student records. HIPAA covers protected health information. CAN-SPAM covers commercial email.
Know someone studying for AI Security Fundamentals? Send them this one.