Facial Recognition Database Facing Potential Legal Action For Using Photos, Many of Children, Without Permission

Facial Recognition Database Facing Potential Legal Action For Using Photos, Many of Children, Without Permission

The massive MegaFace dataset may have violated the Illinois Biometric Information Privacy Act, a 2008 law that protects residents from using facial scans without their permission.

A facial recognition database holding more than 4 million photos of nearly 700,000 people is undergoing new scrutiny for its use of photos from Flickr without the express permission of users. 

A New York Times report explores the relationship between the progress of surveillance technology and the availability of huge databases of facial photos on the web, including MegaFace. 

MegaFace was developed by computer science professors at the University of Washington and consisted of downloaded versions of photos from the Yahoo Flickr Creative Commons 100 Million Dataset. The project was part of an effort to make it easier for smaller companies and researchers to further their development of facial recognition technology, among other goals. 

The Yahoo database did not distribute users’ photos directly. Rather, links to the photos were shared so that if a user deleted the posts or made them private, researchers would no longer have access to them. 

But MegaFace made the photo sets downloadable, making it easier for companies to download the data and use it for research purposes. The Flickr dataset was ideal because it had many photos of children, which facial recognition systems typically have a difficult time identifying accurately. 

The University of Washington went on to host the “MegaFace Challenge” in 2015 and 2016, asking companies working on facial recognition to use the data to test the accuracy of their systems. More than 100 organizations and companies participated, the Times reported, including Google, SenseTime and NtechLab. All companies were asked to agree to use it only for “noncommercial research and educational purposes,” and some businesses said they deleted the dataset after the challenge. 

Now, many of the people who posted photos of their children to the site say they were unaware that their children’s faces had been used to develop facial recognition technology. The data set was not anonymized, meaning that the Times was able to find people who had posted the photos through the links provided by Yahoo. 

“The reason I went to Flickr originally was that you could set the license to be noncommercial,” Nick Alt, an entrepreneur in Los Angeles, told the Times after finding out that photos he had taken of children were in the database. “Absolutely would I not have let my photos be used for machine-learning projects. I feel like such a schmuck for posting that picture. But I did it 13 years ago, before privacy was a thing.”

Most people included in the database were not legally required to grant permission to use their photos because they were licensed under Creative Commons. But residents of Illinois are protected under the Biometric Information Privacy Act, a 2008 law that imposes fines for using someone’s fingerprints or face scans without consent. 

The use of Illinois Flickr users’ photos could lead to legal implications if residents decide to pursue lawsuits. Photos themselves are not covered by the law, but scans of the photos should be, according to Faye Jones, a law professor at the University of Illinois. 

“Using that in an algorithmic contest when you haven’t notified people is a violation of the law,” Jones said, adding that people who had their faceprints used without permission have the right to sue and earn $1,000 per use. That fine could go up to $5,000 if the use was “reckless.” 

The combined liability could add up to more than a billion dollars, the Times reported. 

“The law’s been on the books in Illinois since 2008 but was basically ignored for a decade,” Jeffrey Widman, an attorney in Chicago, told the Times. “I guarantee you that in 2014 or 2015, this potential liability wasn’t on anyone’s radar. But the technology has now caught up with the law.”


About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.


  • Maximizing Your Security Budget This Year

    7 Ways You Can Secure a High-Traffic Commercial Security Gate  

    Your commercial security gate is one of your most powerful tools to keep thieves off your property. Without a security gate, your commercial perimeter security plan is all for nothing. Read Now

  • Busy South Africa Building Integrates Custom Access Control System

    Nicol Corner, based in Bedfordview, Johannesburg, South Africa, is home to a six-star fitness club, prime office space, and an award-winning rooftop restaurant. This is the first building in South Africa to have its glass façade fully incorporate fritted glazing, saving 35% on energy consumption. Nicol Corner (Pty) LTD has developed a landmark with sophisticated design and unique architecture by collaborating with industry-leading partners and specifying world-class equipment throughout the project. This includes installing a high-spec, bespoke security and access control system. Read Now

  • Only 13 Percent of Research Institutions Are Prepared for AI

    A new survey commissioned by SHI International and Dell Technologies underscores the transformative potential of artificial intelligence (AI) while exposing significant gaps in preparedness at many research institutions. Read Now

  • Survey: 70 Percent of Organizations Have Established Dedicated SaaS Security Teams

    Seventy percent of organizations have prioritized investment in SaaS security, establishing dedicated SaaS security teams, despite economic uncertainty and workforce reductions. This was a key finding in the fourth Annual SaaS Security Survey Report: 2025 CISO Plans and Priorities released today by the Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment. Read Now

Featured Cybersecurity


New Products

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge. 3

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions. 3