Skip to main content

Is Reverse Face Search Legal?

In most places, running a reverse face search is not illegal in itself, but what you do with the result can be. Face data is treated as sensitive biometric data under GDPR and several US state laws, and the deciding factors are usually your purpose, your jurisdiction, and whether the person consented. This page explains the shape of the rules. It is not legal advice, and if a decision carries real consequences you should take advice for your own jurisdiction.

Last reviewed

In short

  • The search itself and the use of the result are regulated separately.
  • GDPR treats facial recognition data as a special category needing an explicit legal basis.
  • Illinois BIPA is the strictest US regime and carries a private right of action.
  • Verifying someone you are already dealing with is treated very differently from profiling a stranger.
  • Stalking, harassment, and unmasking someone against their will are unlawful almost everywhere.

What exactly do these laws regulate?

Most face-related privacy law regulates the processing of biometric identifiers rather than the act of looking at a photograph. A face embedding, the numeric descriptor a face search engine computes, is generally treated as a biometric identifier because it can single out one individual. That framing matters: a rule may be triggered by the computing and storing of that descriptor, independently of whether you ever act on the result.

How does GDPR treat face search in Europe?

Under the GDPR, biometric data processed for the purpose of uniquely identifying a person is a special category of personal data under Article 9, and processing it is prohibited unless a specific exception applies, most commonly the individual's explicit consent. The UK GDPR takes materially the same approach. There is a narrow household exemption for purely personal activity, but regulators have read it narrowly, and it is generally understood not to cover publishing or acting on results about other people.

What about the United States?

There is no single federal biometric privacy statute, so the answer is state by state, and the differences are substantial.

  • Illinois BIPA requires informed written consent before collecting biometric identifiers and lets individuals sue directly, which is why it produces most of the litigation.
  • Texas and Washington have comparable biometric statutes enforced by the state attorney general rather than by private lawsuits.
  • California's CCPA and CPRA classify biometric information as sensitive personal information with rights to know, delete, and limit its use.
  • Several other states have enacted broad consumer privacy laws that treat biometric data as sensitive and require consent for processing it.

What separates lawful use from unlawful use?

Purpose is usually what decides it. Checking whether a person you are already dealing with is who they say they are, or finding where your own photographs have been reposted, are the uses regulators and platform terms treat most favourably. Building a dossier on a stranger, tracking someone's movements, revealing an anonymous person's identity, or feeding results into an employment, housing, credit, or insurance decision are where legal exposure concentrates, and some of those uses are separately regulated whatever the data source.

What does FaceSearch require of you?

Our terms require that you have the legal right to search each image you upload and that you comply with the law where you are. Using the service to stalk, harass, intimidate, or unmask a person against their will is prohibited and is grounds for termination. We do not permit use for automated decisions about employment, housing, credit, or insurance. Uploaded photos are deleted within 24 hours of the search completing, and face descriptors are not retained after deletion.

Sources