CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
biometrics

They Paid $10 for Her Iris Scan. Now Her City Wants $47 Million Back.

They Paid $10 for Her Iris Scan. Now Her City Wants $47 Million Back.

Imagine someone in your neighborhood offered you $10 to look into a machine. Just look. Takes two seconds. In return, you get a little money, a "verified human" badge for the internet, and — buried somewhere in the fine print — the permanent record of your iris scan sitting on a server you've never heard of, in a country you didn't know about, with no clear instructions on how to get it deleted. That is roughly what happened to 400,000 people in São Paulo, Brazil. And the city is now suing for $47 million to make it stop.

TL;DR

São Paulo is suing the company behind World ID for collecting iris scans from hundreds of thousands of low-income residents in exchange for small crypto payments — without properly explaining what would happen to that data — and the questions this lawsuit raises are about to show up in your own app downloads.

The company at the center of this is Tools for Humanity, the organization that runs World ID (previously called Worldcoin). Their product is a biometric identity system — meaning it uses your body, specifically your iris, to prove you're a real human being and not a bot. The technology itself is not science fiction. It's already running. And in São Paulo, prosecutors say the way it was rolled out crossed a serious line.


What Actually Happened in São Paulo

According to Biometric Update, São Paulo prosecutors opened a $47 million lawsuit against the operators of World ID after a city council investigation found that residents — concentrated in lower-income neighborhoods — were scanning their eyes into orb-shaped devices in exchange for small crypto payments.

Here's the part that matters: they were not clearly told where that iris data was going. It was being stored on Amazon Web Services infrastructure. It was, potentially, being transferred outside Brazil. Those are not small details. That's your most permanent personal identifier — your iris cannot be changed the way you change a password — sitting on foreign servers under terms most people never read.

400,000
São Paulo residents had their iris data collected — many in low-income areas — in exchange for small crypto payments, before prosecutors stepped in
Source: Biometric Update / Bitcoin.com News

Brazil's national data protection authority had already told World ID to stop offering financial incentives for the scans. That order went out. And then, according to Bitcoin.com News, the company kept right on offering rewards through its app anyway. The city council investigation found this out, and the lawsuit followed. The core accusation isn't just "you collected data." It's "you collected data from vulnerable people, you didn't explain it properly, and then you kept going after regulators told you to stop." This article is part of a series — start with Your Face 47 Times A Night The New Law That Turns Your Phone.

"Regulators now understand that 'user consent' via a checkbox during signup is theater — not protection." — Expert analysis, Biometric Update

That quote is doing a lot of work. Think about every app you've ever downloaded. You tapped "I agree" on a screen. You moved on with your life. Nobody expects you to read 47 pages of legal text. The problem is that courts and companies have long treated that tap as your full, informed, freely given agreement. Regulators are now saying: not anymore. Not for body data.


Why Your Body Is Different From Your Password

Biometric data — your face, iris, fingerprints, voice, the physical stuff that is uniquely yours — gets treated differently under the law for one simple reason: you can't reset it. If someone steals your password, you change it. If a company leaks your iris scan, you have that iris for the rest of your life. There is no patch, no reset, no "forgot my eye" button.

This is why lawmakers in the United States have been building specific rules around it. Illinois has had its Biometric Information Privacy Act — the one most people call BIPA — for years. States including Colorado have added similar protections, requiring companies to get your real, informed consent before collecting body data, and in some cases capping how long they can keep it (three years is one common limit). According to Reed Smith, these laws come with private rights of action — meaning individuals, not just government agencies, can sue companies that break the rules. The financial exposure is real.

The EU has its own framework. Brazil has its Lei Geral de Proteção de Dados — its version of data protection law. The specifics differ by country, but the direction is the same everywhere: consent must be freely given, specific, informed, and unambiguous. Paying someone $10 in crypto to stare into a device, with no plain-language explanation of what you're agreeing to, is not that. It is the opposite of that.

Why This Fight Is Coming to You

  • Age checks are going biometric — Gaming platforms, social media, and streaming services are already rolling out face-scan age verification. Your kids' apps will ask for this soon, if they haven't already.
  • 🔐 Account recovery is changing — "Forgot your password?" is slowly being replaced with "verify with your face." Once that scan is taken, the São Paulo questions apply: where does it live, and can you delete it?
  • 💼 Employers are in this too — Timekeeping, building access, and background checks are all going biometric in workplaces. Most employees don't know what happens to those scans when they leave the job.
  • 🗺️ Regulators are watching this case — The São Paulo lawsuit sets a template. Expect more cities and states to challenge data collection practices using the same three-question framework: what was collected, why was it needed, and can users delete it?

Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Court-ready facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

The Three Questions Regulators Are Now Forcing Onto Every App

The São Paulo case essentially handed regulators worldwide a checklist. According to the analysis in the lawsuit and the broader compliance picture outlined by Liminal, three failures drove this lawsuit: transparency (what exactly gets collected?), purpose limitation (why is this specific data actually necessary?), and data control (can users demand permanent deletion?). Those three failures are not unique to São Paulo. They're built into almost every biometric signup flow you've ever been through. Previously in this series: That Voice On The Phone Sounds Exactly Like Your Boss It Tak.

The transparency problem is the easiest to understand. When an app asks to "verify your identity," most people have no idea whether that means it's checking your face against a photo you uploaded, running a live scan, or storing a permanent template of your facial geometry (a digital map of your face's measurements) on a server somewhere. Those are wildly different things with wildly different risks — and the screens look almost identical.

The purpose limitation problem is sneakier. "We need your face to verify you're over 18" and "we need your face to build a permanent verified identity profile tied to your device, your account history, and your future logins" are not the same thing. But they can be presented as the same single step in an app onboarding flow. Baird Holm LLP tracks the expanding state-level legislation on this and notes that newer laws are specifically targeting this kind of scope creep — the gap between what a company says it needs and what it actually keeps.

The deletion problem is the one almost nobody talks about — and it's the most important. According to HID Global, the regulatory push in 2026 is explicitly moving toward privacy-by-design, meaning companies must build deletion rights in from the start, not bolt them on later when someone complains. The São Paulo case is a preview of what happens when deletion is an afterthought: a lawsuit, a regulator order, and 400,000 people who still don't know if their iris data is actually gone.


What You Can Actually Do Right Now

Look, nobody's saying you should refuse every biometric check. Some of this technology is genuinely useful. The issue isn't whether companies can collect your biometric data — it's whether they've earned the right to do it by being honest about what they're doing.

Before you complete any biometric verification — face scan, fingerprint, iris check — three questions are worth asking. First: what exactly is being collected and stored? Not "your identity" or "a verification." The specific data type. Second: where does it live, and is it leaving the country? Third: how do you delete it when you're done? If an app can't answer those three things in plain English before it scans you, that's not a minor inconvenience. That's a consent problem. Up next: License Plate Readers Identity Data Pennsylvania Regulation.

If you've ever worried that an account, a profile, or an online claim to be you might not actually protect your identity — that fear is exactly right. Verifying who's real and what data about real people is being used legitimately is exactly the kind of problem that services like CaraComp exist to address. Not to scare you, but to give you actual visibility into how your identity shows up online, before someone else makes decisions about it.

Key Takeaway

Convenience is not the same thing as consent. The São Paulo case is a $47 million argument that "you tapped agree" is not enough when what you agreed to was the permanent capture of your most irreplaceable physical identifier. Every app that asks for your face, your fingerprint, or your iris should be able to answer three questions before you comply: what's collected, where it lives, and how you delete it. If they can't, the answer is not your eye.

Here's the detail that should stick with you: World ID kept offering payment for iris scans even after Brazil's national data regulator told it to stop. Not a gray area. Not a misunderstanding. A direct order, ignored. And the reason it took a city-level, $47 million lawsuit to force a response is that most people who scanned their irises have no idea any of this happened. They looked into the orb, got their crypto, and moved on.

Your iris is not a password. It's not a username. It is the most permanent identifying marker your body produces — and the next app that asks for it should have to work a lot harder than a single checkbox to earn it.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search