A proposed class action targeting Ring’s ‘Familiar Faces’ feature spotlights growing concerns over passive biometric data collection, regulatory gaps, and security risks in connected security systems.
Connected cameras and access systems are increasingly marketed as straightforward security tools, yet their capabilities can extend well beyond recording video or opening a door. A recent proposed class action over Ring’s “Familiar Faces” function has sharpened scrutiny of that shift, with the complaint alleging that the feature scans people caught on camera and builds biometric templates that may later be used for recognition. According to reporting on the case, the claim is that this process can affect not only the owner of the device, but also visitors, neighbours and passersby.
That dispute matters because biometric data is unlike many other forms of personal information. A password can be reset and a payment card can be replaced; a face cannot be changed. Privacy lawyers note that this permanence is one reason facial recognition and other biometric tools draw close attention from regulators and courts. The concern is heightened when identification happens passively, without a person knowingly entering data or even realising that analysis is taking place.
The broader issue is not limited to one product. Smart cameras, building-access systems and mobile applications are increasingly able to collect information that sits behind the intended function of the device. A system bought for security may also generate biometric identifiers, location data or other sensitive material. For organisations, that turns procurement into a governance problem. It is no longer enough to ask whether the technology works; leaders also need to know what data it captures, where it is stored, how long it is kept, who can reach it and whether a vendor may use it for secondary purposes.
The legal backdrop is uneven but increasingly demanding. Illinois’s Biometric Information Privacy Act, widely known as BIPA, is one of the toughest state laws in this area. It generally requires notice and written consent before biometric data is collected, and it gives individuals a private right of action. Legal guides also note that the Illinois Supreme Court has recently clarified that some healthcare-related biometric data used for operational purposes may fall outside BIPA’s reach, underscoring that the boundaries of the law can be narrow and fact-specific.
The cybersecurity angle is equally important. Biometric templates are valuable precisely because they are persistent, which also makes them difficult to protect once exposed. If a password file is compromised, users can change their credentials; if facial-recognition data is leaked, there is no equivalent reset. That is why privacy and security teams are being urged to work together, with procurement officers asking vendors about retention, deletion, subcontractors and data ownership, and with organisations revisiting feature settings after software updates, which can quietly introduce new capabilities long after installation.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





