Publication

When a Security Device Becomes a Data Collector: What Organizations Need to Know about Biometric Privacy

September 8, 2026

Smart cameras, access systems, and other connected devices are designed to make homes and workplaces safer and more convenient. But as those technologies become more sophisticated, they may also collect far more information than many people realize.

A recent class action involving Ring’s “Familiar Faces” feature has brought renewed attention to that issue. The complaint alleges that the feature scans individuals captured by certain Ring cameras and creates biometric templates, or “faceprints,” that can later be used to recognize them. That may include not only device owners, but also guests, neighbors, and passersby.

The allegations remain unproven, and the case is still developing. But the broader issue extends well beyond one company or product.

As cameras, access systems, mobile applications, and other everyday technologies incorporate facial recognition and biometric capabilities, organizations need to understand not only what those tools do, but also what data they collect.

What Makes Biometric Data Different From Other Personal Information? The Bigger Issue: Invisible Data Collection

Biometric data is different from many other types of personal information. A password can be changed. A credit card can be replaced. A face cannot.

That permanence is one reason biometric information receives heightened attention from regulators, lawmakers, privacy advocates, and courts. Facial recognition can also operate passively, meaning people may be identified without actively providing information or even realizing the technology is being used.

Someone may knowingly unlock a phone using facial recognition. That is very different from walking past a camera and potentially having biometric information created or analyzed without ever choosing to interact with the device.

The issue matters because everyday technologies are increasingly doing more than the single function for which they were originally purchased.

  • A security camera may also include facial recognition.
  • A building-access system may collect biometric identifiers.
  • A mobile application may gather location information.

The technology may have been purchased for legitimate security or operational reasons, but the organization deploying it may not fully understand what is happening behind the interface.

What Do You Actually Know About the Technology You Are Using?

For organizations, this becomes a governance question as much as a privacy question. It is no longer enough to ask whether a security device works.

Leadership should also understand:

  • What information the technology collects
  • Where it is stored
  • How long it is retained
  • Whether it creates biometric templates
  • Who has access to it
  • Whether the vendor may use that data for other purposes

Those questions become particularly important when a third-party controls much of the underlying technology. The original goal may have been simple: improve security, automate building access, identify familiar visitors, or make authentication easier. But adding a new capability can also mean acquiring a new category of data and, with it, new legal and cybersecurity responsibilities.

Is Biometric Data Regulated? Understanding the Developing Legal Landscape

Biometric privacy requirements vary significantly across the United States. Illinois’ Biometric Information Privacy Act, commonly known as BIPA, is one of the best-known examples. It imposes requirements around notice, consent, retention, and handling biometric identifiers and has generated significant litigation involving facial-recognition technology. Other states have adopted their own biometric or comprehensive privacy requirements, and the landscape continues to change.

At the federal level, the Federal Trade Commission has also warned that biometric technologies can create privacy, security, bias, and deceptive-practice risks. The lesson for organizations is not that every camera or biometric tool creates a legal problem. It is that organizations should understand what they are collecting before discovering the answer during litigation, an incident, or a regulatory inquiry.

Security Technology Can Create Cybersecurity Risk Too

Biometric information is valuable because it is persistent. That is also what makes it sensitive. If a password database is compromised, users can reset passwords. If biometric templates or facial-recognition data are exposed, there is no equivalent reset button. That means organizations should consider biometric information alongside other sensitive data when making cybersecurity decisions.

  • Who can access it? 
  • Is it encrypted? 
  • Can it be downloaded? 
  • What vendors or subcontractors can reach it? 
  • How would the organization respond if that information were compromised?

Privacy and cybersecurity quickly become two sides of the same question: What information do we have, and how are we protecting it?

Practical Steps for Organizations

Avoiding every technology that uses biometric or advanced analytics may not be practical, nor is that necessarily the goal. The better approach is to make informed decisions.

  • Before enabling facial-recognition or biometric features, organizations should understand exactly what the feature does and what data it creates.
  • Involve privacy and legal teams where notice, consent, or retention requirements may apply. 
  • Engage cybersecurity teams on how the information is stored, transmitted, and protected. 
  • Task procurement teams with asking vendors about data ownership, subcontractors, retention periods, deletion, and secondary uses.
  • Revisit those decisions over time - software updates can introduce new capabilities long after a device was originally purchased.

The technology sitting on the wall may look exactly the same. What it is capable of doing may have changed considerably.

The Bigger Privacy Question

The Ring lawsuit may ultimately answer important questions about one particular product and feature. But the larger issue is already here. Data collection is increasingly happening in the background through cameras, applications, access systems, connected devices, and technologies people interact with without thinking much about the information being generated.

A device may have been purchased because it made a building more secure or an operation more efficient. Over time, added features can quietly expand both the amount and sensitivity of information being collected.

That makes one question increasingly important for leaders:

Do we actually know what our technology knows about people?

Understanding what information is being collected, why it is being collected, where it goes, and what obligations come with it is becoming a basic part of responsible technology governance.

Contact Our Tech, Privacy & Cyber Risk Team

Concerned about what your connected devices are collecting? Ice Miller’s Tech, Privacy & Cyber Risk team can help you understand your biometric and data exposure. Contact our team.

This publication is intended for general information purposes only and does not and is not intended to constitute legal advice. The reader should consult with legal counsel to determine how laws or decisions discussed herein apply to the reader's specific circumstances.

Related People

Related Services & Industries

Related Categories

<p>Sign up now to receive periodic updates from Ice Miller&rsquo;s legal professionals.</p>

Sign up now to receive periodic updates from Ice Miller’s legal professionals.

Subscribe

Firm Highlights