Biometric Data Definition: 5 Million Faces Scanned at Malls

Five million shoppers walked past mall directories in Canada, had their faces turned into strings of numbers, and never got a court ruling on whether that was okay — because the lawsuit trying to represent them got thrown out on a technicality that had nothing to do with right or wrong.
A court can block a group lawsuit over biometric data — your face, your fingerprints, the stuff that's uniquely you — without ever deciding whether collecting it was fair. Legal loss and moral cleared are two very different things.
Here's the part that should stop you mid-scroll: nobody disputes that the scanning happened. Canada's federal and provincial privacy commissioners already investigated and confirmed it. Cadillac Fairview, which runs shopping centers like Toronto's Eaton Centre and Vancouver's Pacific Centre, installed cameras inside those wayfinding directories — you know, the touchscreen maps that show you where the food court is — back in 2018. The cameras weren't just taking pictures. They were running your face through software that measured it and estimated your age and gender, all without a sign anywhere near the screen telling you that was happening.
So what actually is a biometric data definition we should be working with here? In plain terms: biometric data means measurements of your body or behavior that are unique enough to identify you — your face, your fingerprint, your voice, even the way you walk. It's not a photo. It's digital representations of your biological characteristics, turned into numbers a computer can compare. That distinction is why regulators treated the mall's numeric face measurements as biometric information even though no facial images were retained.
What biometric data meaning looks like when a mall scans your face
Picture the camera in that mall directory. It's not saving a photo of you to some folder labeled "Shoppers, Tuesday." Instead, it's running automated recognition software that maps dozens of points on your face — distance between your eyes, shape of your jaw, that kind of thing — and converts the whole thing into a short string of numbers. According to the appeal court's own findings, no facial images were retained, and neither Cadillac Fairview nor the mall operators ever received or used the resulting data directly. The company's outside vendor processed it, spit out demographic estimates, and (allegedly) discarded the rest.
That's the technical loophole a lot of companies lean on. If you never store the picture, and you convert someone's face into a temporary numeric code that gets deleted, are you still collecting biometric data? Privacy regulators in this case said yes — because identifiers derived from your body count as biometric information whether or not anyone keeps the original photo. The data generated from your face is still, in that fleeting moment, a measurable physical characteristic tied to one single organism: you. This article is part of a series — start with How To Spot A Deepfake.
Is a converted numeric face-scan still personal information?
Yes. Regulators treat any data derived from your unique physical traits as personal information, even if it's never stored as an image. The moment software measures your face and creates an identifier from it, it counts — deletion afterward doesn't erase the fact that collection happened.
The biometric data definition behind a blocked privacy class action
Now here's where most headlines get sloppy. When you read "lawsuit can't proceed as a class action," your brain fills in the rest: case closed, company's fine. But that's not what the British Columbia Court of Appeal actually said. The court ruled the plaintiffs failed to meet three of five mandatory requirements for group litigation — they didn't adequately explain why a class action was the best method, they couldn't establish an identifiable group of two or more affected people, and they failed to show the claims raised issues genuinely common across that group.
Notice what's missing from that list: any finding about whether the biometric collection itself was legal, ethical, or properly disclosed. The court wasn't grading the mall's privacy practices. It was grading the plaintiffs' paperwork — the legal processing of how you're allowed to sue on behalf of a group. Those are separate exams, and failing one tells you nothing about your score on the other.
Five million people. That number is doing a lot of work here. It's exactly why class actions exist in the first place — no single shopper is going to hire a lawyer over a demographic estimate pulled from thirty seconds near a mall map. Group lawsuits exist so that a harm too small for one person to fight, but too widespread to ignore, still gets a hearing. When the machinery for that group case breaks down on procedure, five million people don't get a "you're fine" — they get nothing. Not a win, not a loss on the merits. Just silence.
What is the biometric data meaning under privacy law?
Under most modern privacy frameworks, biometric data means information generated from a person's biological or behavioral traits — face geometry, fingerprints, iris patterns, voice — used to identify them. Some laws, like Illinois' BIPA, add teeth: a company usually needs a written policy and signed consent before capturing it, not just a sign by the door. Previously in this series: Deepfake Scams One Fake Video Call Cost Her 287 000.
Why "notice at the entrance" isn't the same as real consent
This is where the case gets genuinely interesting, because it's not really about cameras. It's about what counts as telling someone something. Cadillac Fairview did post signs at mall entrances warning that visitors "may be recorded," with a reference to an online privacy policy. What it didn't do was put any warning on the directory screens themselves — the one place where the actual face-scanning was happening.
Think about how you actually move through a mall. You walk in past a dozen signs you don't read (parking rules, mask policies from three years ago, an ad for a jewelry sale), then you stop at a touchscreen map because you're trying to find the bathroom, and you lean in close enough for a camera to measure your face. At no point in that sequence did anyone clearly tell you: "this screen is scanning your facial geometry right now." That's the gap privacy advocates keep pointing to — signage at the door is not the same as meaningful notice at the actual point of collection.
The central legal debate in facial recognition cases is the difference between opt-in and opt-out consent, with many venues taking the position that posting signage or burying language in terms of service satisfies disclosure obligations, while privacy advocates argue that passive disclosure is not genuine consent. — analysis reported by ID Tech Wire
A useful comparison: think of a yellow traffic light. It's not the same as red — the company isn't stopped, isn't found guilty, doesn't have to pay anything. But it's absolutely not green either. Green would mean a court looked at the evidence and said "yes, this collection was properly disclosed and consented to." Nobody said that. The light just told everyone to sit and wait, because the specific vehicle carrying the case (the class action format) wasn't roadworthy. The underlying rules of the road — what counts as real consent before biometric collection — are still sitting there, untouched, waiting for a case that actually gets a green or a red.
What You Just Learned
- 🧠 Biometric data — a numeric code made from your face still counts, even if the photo itself is deleted seconds later
- 🔬 Class certification — courts check five separate procedural boxes before a group lawsuit can even start; missing three kills it without touching the facts
- 💡 Notice ≠ consent — a sign at the mall entrance isn't the same as telling you, right at the camera, what it's doing
The misconception behind "case dismissed" headlines
Here's the misconception, laid bare: people read "biometric privacy lawsuit blocked" and hear "the privacy claim was baseless." It's an understandable jump — most of us are used to news where dismissed means disproven. A criminal case gets dropped, we assume innocence. A civil suit gets tossed, we assume the company was right all along. But class certification in Canada (and most places with similar rules) isn't a trial on the facts. It's a gatekeeping step that checks whether a lawsuit is structured correctly to represent a group at all. The privacy commissioners' findings that Cadillac Fairview collected data from millions of people without proper consent were treated as background context in the ruling — not as evidence of guilt or innocence, because that question was never on the table for this specific court to answer.
This is exactly the kind of gap CaraComp spends its time mapping — the space between "a court ruled" and "a court ruled on the thing you think it ruled on." Facial recognition disputes especially get misread this way, because the technology feels invisible and the legal process feels final, when really it's often just one procedural door slamming shut while five others stay open. Up next: How To Spot A Deepfake 1 School Photo Is All It Takes.
When a group privacy lawsuit gets blocked, ask what specifically failed — the facts, or the paperwork rules for suing as a group. Those are two completely different questions, and headlines almost never tell you which one you're reading about.
So back to that engagement question worth sitting with: if a venue — a mall, a stadium, an airport kiosk — asked to scan your face before letting you in, what would you actually want spelled out first? Not a sign at the door about "recording may occur." A real answer to three things: what specifically gets measured, how long it's kept, and who else gets to see it. That's the bar. Anything short of it is a yellow light, not a green one — and now you know the difference well enough to spot it yourself, the next time a headline tries to tell you a lawsuit's failure was really a company's victory.
Frequently Asked Questions
What is the legal definition of biometric data?
Biometric data is information generated from a person's unique biological or behavioral traits — face geometry, fingerprints, iris patterns, voice, or gait — that can identify a specific individual. It doesn't require a stored photo; a numeric measurement derived from your face can still legally count as biometric data.
Does a blocked class action mean the company won the case?
No. A blocked class action usually means the lawsuit failed to meet procedural requirements for group litigation, not that a court reviewed the underlying facts and cleared the company. The privacy questions about consent and disclosure can remain completely unresolved even after the case ends.
Is posting a sign at a store entrance enough for biometric consent?
Many privacy advocates and some laws say no. Meaningful consent generally requires clear notice at the actual point of data collection, not just general signage at an entrance. Passive disclosure buried in a privacy policy or posted far from the camera itself is often considered legally insufficient.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
CCTV Facial Recognition: Why a 98% Match Proves Nothing
A security camera can show you exactly what happened — but it can't tell you who did it. Here's the extra step that turns footage into real identity evidence.
facial-recognitionFacial Recognition Ethics: A "100% Match" Cuffed the Wrong Man
A Reno man was arrested after facial recognition flagged him as a "100% match" for someone four inches shorter with different eye color. Here's what that score actually measures — and why it should never end an investigation.
biometricsNational ID Card Rules: Face Scan Now Guards Every SIM
India now requires a live face scan before a new SIM activates—here's how that biometric check works, why it's not a surveillance database, and what it means for your own phone security.
