Signed Away: Your Biometric Data Has No Lawyer
And Malta, which is already operating under the General Data Protection Regulation — specifically Article 9 of Regulation (EU) 2016/679, which classifies biometric data used for unique identification as a special category requiring explicit consent and a lawful basis — needs to understand what is happening in that Chicago courtroom, because the legal philosophy underneath it will eventually surface here too.
There is a federal courtroom in Chicago where litigators are currently waiting for an answer to a question that sounds academic until you realize it controls whether you have any legal rights at all: does a biometric identifier have to *identify* a specific person before the law protects it?
Read that again. Because depending on how the court rules, the scan of your face at a border checkpoint, the geometry of your palm at a hotel check-in, the rhythm of your keystroke pattern on a work laptop — none of it may qualify for legal protection if it cannot be proven to link back to *you* individually. The law would protect the concept of your identity while leaving the data itself unguarded.
This is the split that privacy litigators across the United States are watching in silence, because the answer will redraw the map of biometric privacy litigation for the next decade. And Malta, which is already operating under the General Data Protection Regulation — specifically Article 9 of Regulation (EU) 2016/679, which classifies biometric data used for unique identification as a special category requiring explicit consent and a lawful basis — needs to understand what is happening in that Chicago courtroom, because the legal philosophy underneath it will eventually surface here too.
Here is what makes biometric law genuinely different from every other area of data privacy, and why most people sign away these rights without knowing they have them.
When a company collects your email address, the damage from misuse is recoverable in theory. You change the address. You revoke access. The identifier is replaceable. When a company collects the geometry of your face, the depth map of your iris, or the vascular pattern of your hand, the identifier is *you*. There is no new version. There is no reset. If that data is breached, sold, or misused, you carry the exposure permanently. This is why Illinois passed the Biometric Information Privacy Act — the Biometric Information Privacy Act, known as BIPA — which remains the sharpest biometric privacy law in the United States, requiring informed written consent before collection and giving individuals a private right of action. It is also why VGW Holdings, operator of sweepstakes platforms Chumba Casino, Global Poker, and Luckyland Slots, just settled with the New York Attorney General Letitia James for $8 million — not over biometrics specifically, but over what happens when operators collect data about users without those users fully understanding what they consented to, or whether they consented at all.
The VGW settlement is instructive precisely because there was no admission of liability. Eight million dollars changes hands and the company says nothing happened. That structure — the settlement without acknowledgment — is one of the most powerful tools a corporation has, because it buys silence at scale. It ends the litigation, it limits the precedent, and it lets the company walk back into the market with its terms of service largely intact. The Attorney General gets a number she can announce. The company gets a clean exit. The individual user gets nothing except the theoretical comfort of knowing a regulator noticed.
Under Maltese law and EU law, the architecture should work differently. The GDPR's Article 82 gives individuals the right to compensation from both controllers and processors for material and non-material damage caused by a GDPR infringement. The Information and Data Protection Commissioner in Malta has enforcement powers under Chapter 586 of the Laws of Malta. But rights on paper and rights in practice are separated by the same distance that separates a map from a driver. Most people in Malta who have had their biometric data collected — at gyms, at workplaces using fingerprint attendance systems, at events using facial recognition entry — have never seen the data protection impact assessment that Article 35 of the GDPR requires before high-risk processing begins. Most have never been shown a copy of their explicit consent document. Most do not know they can request erasure under Article 17, or that the organization holding their face geometry may be in breach of its lawful basis obligations right now.
I spent time years before the suits with people who understood that information asymmetry is power — that the person who knows what you signed is always stronger than the person who signed it. That lesson applies nowhere more precisely than biometric data law. The companies collecting this information have legal teams who wrote the consent forms. They know exactly what was consented to and what wasn't. The person whose face was scanned does not.
The Chicago case pending before the federal court may narrow or widen the definition of what counts as a biometric identifier under BIPA. But whatever it