Can You Sue Someone for Recording Your Face With Smart Glasses?

A flat two-tone editorial illustration split down the middle. On the left, on cream, a plain grey featureless head in
AI-generated editorial illustration. Not a documentary image.

Three States wrote a Biometric law, one lets the person Filmed Act, and only over a faceprint

Every question in this cluster eventually arrives at the same dead end. A pair of Meta Ray-Bans looks exactly like ordinary sunglasses, the capture light is easy to miss and easier to defeat, and by the time anyone suspects they are on camera the clip is already on a phone. So the natural next question, once someone accepts they cannot tell and cannot stop it, is whether the law gives them anything back afterwards. For the recording itself, in almost the entire United States, the honest answer is no.

That is worth stating flatly, because the coverage around biometric privacy tends to leave the opposite impression: that a thicket of face-scanning laws now stands between a person and a stranger's camera. Three states have written a biometric-privacy statute with real penalties attached. Two of them do not let the person who was filmed do anything at all. That leaves one, Illinois, and even there the law is not interested in the fact that a camera pointed at a face. It is interested in something narrower and stranger: whether a piece of software took that face and turned it into a number.

The law does not care about the picture

Start with what these statutes actually protect, because it is not what the word "recording" suggests. Washington's biometric law says it in the plainest words any of the three manage. A "biometric identifier," under RCW 19.375, means data drawn from "automatic measurements of an individual's biological characteristics" — a fingerprint, a voiceprint, a retina or iris scan, "or other unique biological patterns." Then the exclusion, spelled out: the term "does not include physical or digital photographs, video or audio recordings."

Illinois draws the same line. Its Biometric Information Privacy Act, the strongest of the three, defines a biometric identifier as "a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry" — the phrase quoted by the Illinois Supreme Court in Rosenbach v. Six Flags. A scan of face geometry is not a photograph of a face. It is the measured distance between eyes, the shape of a jaw, rendered as a mathematical template a computer can match. The picture is raw material; the identifier is what a program makes out of it.

So the ordinary act these devices perform, filming a face, saving a photo, sits on the excluded side of the line in all three states. The recording is not the violation. The thing the law reaches only comes into existence when something processes that image into a faceprint, and that is a separate step the glasses, as sold, do not take.

What would actually trip it

This is where the smart-glasses version of the question stops being hypothetical. The device is a camera, a microphone and a link to a phone; the one piece it lacks is the software that converts a face into a template. When that piece is bolted on, the biometric step happens — and it has been demonstrated. Two Harvard students paired a pair of Ray-Ban Meta glasses with a commercial face-search engine in 2024 and pulled strangers' names and addresses out of a live video feed, the demo at the centre of our account of whether these glasses can identify people. The glasses supplied the picture. A different tool made the faceprint.

That division is the whole of it. A wearer who merely records is doing the excluded thing. A wearer, or an app, or a company harvesting the footage: that runs face recognition on the capture is doing the regulated thing. The biometric laws were written for the second actor, and for a specific kind of second actor: a business building a database of faces. It is why the cases that have actually bitten are not about a person on a train. They are about companies.

The one state that hands the person a lever

Illinois is the only one of the three that lets the individual, rather than a state official, do something about it, and it does so with unusual force. Section 20 of BIPA, as reproduced in Rosenbach, gives a prevailing party liquidated damages of "$1,000 or actual damages, whichever is greater" for a negligent violation, and "$5,000 or actual damages, whichever is greater" for one that is intentional or reckless, plus attorneys' fees and an injunction. No other biometric statute in the country attaches a private dollar figure like that to each violation.

The reach of it comes from a second holding. Six Flags had argued that a person who suffered no concrete harm, whose fingerprint was scanned without consent but never leaked or misused, was not "aggrieved" and could not sue. In 2019 the Illinois Supreme Court rejected that unanimously. An individual, it held, "need not allege some actual injury or adverse effect, beyond violation of his or her rights under the Act, in order to qualify as an 'aggrieved' person." The violation is the injury. That single sentence is why BIPA, alone among these laws, turned into something a plaintiff could wield.

And it has been wielded, twice, in ways that map directly onto the fear this cluster keeps circling. Clearview AI built its business by scraping billions of faces off the internet and selling a search engine that matched any photo to a name — the exact capability a face-recognition app running on a glasses feed would need. In May 2022 an ACLU lawsuit brought under BIPA ended in a settlement that, in the ACLU of Illinois's own words, left Clearview "permanently banned, nationwide, from making its faceprint database available to most businesses and other private entities." A private lawsuit, in one state, produced a nationwide limit. And before that, Facebook paid $650 million to settle a BIPA class action brought by Illinois consumers over the face-tagging built into its photos. Both are the same shape: the person whose face was turned into math got a remedy, and got it in Illinois.

Where the law exists but the person waits

Texas and Washington have the statute and not the lever. Both are enforced by the state, not the citizen. Washington's law says so in one line — RCW 19.375.030: "This chapter may be enforced solely by the attorney general." Texas is the same. Its Capture or Use of Biometric Identifier Act has no private right of action; only the attorney general can bring a case, which is exactly why the one enforcement that mattered was a state action.

It was not a small one. In July 2024 Texas announced a $1.4 billion settlement with Meta "to stop the company's practice of capturing and using the personal biometric data of millions of Texans without the authorization required by law" — the state's own description, and, it noted, "the first lawsuit brought and first settlement obtained under" the Act. The conduct was Meta's old face-tagging, the same behaviour Facebook paid Illinois consumers to settle. The difference is who collected. In Illinois the people whose faces were scanned did; in Texas the attorney general did, on their behalf, and the individuals were bystanders to their own case. For anyone thinking about a stranger's glasses, that is the practical distinction: even where a biometric law is on the books, in two of the three states the person filmed cannot start anything. They can only hope the state does.

The catch inside the one law that works

None of this quite reaches the scene people actually worry about, and it is worth being clear about the gap rather than papering over it. BIPA is aimed at a "private entity": a company that collects, stores and profits from biometric identifiers, and is required to publish a retention policy and get written consent first. It was built for Clearview and Facebook, not obviously for a neighbour wearing sunglasses who never builds a database at all. Whether the Act reaches an individual hobbyist running a face-search app on a friend's glasses feed is not a settled question, and this piece will not pretend it is.

The law has also just been pulled back in. In 2023, in Cothron v. White Castle, the Illinois Supreme Court held that "a separate claim accrues under the Act each time a private entity scans or transmits an individual's biometric identifier" — which meant a company that scanned an employee's fingerprint twice a day for years faced a count of violations that White Castle estimated could exceed $17 billion for a single class. The court called the concern real but said "policy-based concerns about potentially excessive damage awards under the Act are best addressed by the legislature." The legislature took the invitation. In August 2024 Illinois amended BIPA so that repeatedly collecting the same biometric from the same person by the same method counts as a single violation, entitled to at most one recovery — the first change to the Act in its sixteen years. (The amendment's enrolled text sits on the Illinois General Assembly's site, which is unreachable from here; its terms are taken from two independent legal summaries and are consistent between them.) The remedy is still the strongest in the country. It is also narrower than the $17 billion headlines made it sound.

So the map is small and worth holding exactly as it is. Recording a face with smart glasses, on its own, is not what any of these three laws forbid; they forbid turning that face into a faceprint without consent. Two of the three states leave the person filmed dependent on an attorney general who may never come. One state lets them sue, has let them win, and even there the statute is pointed at the company that builds the database, not squarely at the stranger holding the camera. That is a real lever, and it is a narrow one — which is the same conclusion this cluster reaches from every other direction. The device that can film you without your knowing gives the law its hardest problem precisely because the person it captures rarely gets the chance to object, and the older, sharper exposure for the wearer still runs through the microphone rather than the lens — the all-party-consent statutes that can make an audio recording a crime where a faceprint claim would never get off the ground.

Sainsbury's Paused Facial Recognition at One Store — a live example of a wrongful faceprint match and how narrow the recourse is

Can I Make Someone Delete a Video of Me Filmed on Smart Glasses? — the US biometric route is the self-executing remedy Europe's erasure right is not in the street case

Do Smart Glasses Collect Children's Data? — the state biometric statutes are the remedy COPPA does not give the filmed child

Sources and verification

This is a report of what these statutes and courts say. It is not legal advice, and it does not tell any reader what their own position is or what they may do.