Trending
    A smartphone displaying a facial recognition scan interface beside legal documents and a gavel.
    A smartphone displaying a facial recognition scan interface beside legal documents and a gavel.
    Regulatory Monitor

    Victoria Milan's BIPA Suit: A Privacy Promise Collides with Reality

    ByDII Regulatory Monitor··5 min read

    Key Points

    • •Plaintiff Darius Barlow filed a class action lawsuit in Illinois against Victoria Milan, alleging the dating platform violated the state's Biometric Information Privacy Act.
    • •Under the Illinois Biometric Information Privacy Act, non-compliant companies face statutory damages ranging from $1,000 for negligent violations to $5,000 for intentional violations.
    • •Approximately 35 percent of United States dating app users completed identity verification by mid-2024, up from negligible adoption levels recorded in 2019.
    • •Meta settled a landmark lawsuit under the Illinois Biometric Information Privacy Act for $650 million in 2021 over similar facial recognition allegations.

    Victoria Milan, a dating platform catering to users seeking extramarital affairs, is defending allegations that its selfie verification system violated Illinois' Biometric Information Privacy Act by collecting facial scan data without proper consent or disclosure. The lawsuit highlights a fundamental tension in the dating industry: platforms cannot simultaneously promise absolute discretion whilst building databases of permanent biometric identifiers. For operators marketing on anonymity, facial verification isn't merely a compliance risk—it's a contradiction of their core value proposition.

    Person holding smartphone with dating app interface
    Person holding smartphone with dating app interface

    The lawsuit, filed in the Northern District of Illinois by plaintiff Darius Barlow, claims the platform's identity verification process captured and stored biometric identifiers without meeting the state's requirements for written consent, purpose disclosure, or data deletion schedules. Victoria Milan requires users to submit selfies for verification—standard practice across the industry. What distinguishes this case is the platform's simultaneous promise of discretion to users whose presence could end marriages or damage careers.

    Dating platforms can't have it both ways: you either collect permanent biometric data and accept the liability that comes with it, or you market on discretion and find another way to verify users.

    BIPA's $650M shadow

    Illinois enacted BIPA in 2008, making it the strictest biometric privacy law in the United States. The statute requires companies collecting biometric identifiers—fingerprints, retina scans, facial geometry—to obtain written consent, disclose the purpose and duration of data collection, and establish publicly available retention and deletion schedules. Crucially, it grants Illinois residents a private right of action, allowing individuals to sue directly rather than relying on regulatory enforcement.

    Create a free account

    Unlock unlimited access and get the weekly briefing delivered to your inbox.

    No spam. No password. We'll send a one-time link to confirm your email.

    That provision has made BIPA the preferred legal avenue for privacy class actions. Meta settled a facial recognition lawsuit under BIPA for $650M in 2021. Clearview AI, Snapchat, TikTok, and Google have all faced BIPA litigation. Statutory damages range from $1,000 per negligent violation to $5,000 per intentional or reckless one.

    Gavel and legal documents on desk representing litigation
    Gavel and legal documents on desk representing litigation

    According to the complaint, Victoria Milan's verification flow asks users to submit a selfie but fails to provide the required written consent form, fails to disclose what the biometric data will be used for or how long it will be retained, and fails to publish retention and deletion policies. The platform operates under the tagline 'The world's best dating site for married and attached people'—a positioning that makes the alleged compliance failure particularly acute.

    Verification theatre meets operational reality

    Facial verification has become table stakes for dating platforms trying to address catfishing, bots, and the broader trust crisis eroding user confidence. Tinder introduced photo verification in 2020. Bumble rolled out its version the same year. Hinge added selfie verification in 2021.

    The technical implementation varies, but the basic flow is consistent: users submit a selfie, often mimicking a specific pose. The platform's system compares the facial geometry in the selfie against profile photos to confirm the same person uploaded both. Some operators claim they don't store the biometric data after verification. Others are less specific.

    For mainstream platforms, the privacy-versus-safety trade-off is defensible. Most users understand that verification reduces fraud risk, and they're willing to share biometric data if it improves match quality and safety. The calculation changes when the platform markets itself on discretion.

    Biometric data is permanent. You can change a password or cancel a credit card. You cannot change your facial geometry.

    Victoria Milan's homepage promises 'anonymous and discreet' connections. Its FAQ emphasises that 'your secret is safe with us'. The platform allows users to blur photos and offers a 'panic button' to quickly exit the site if a spouse approaches.

    Person using biometric facial recognition on mobile device
    Person using biometric facial recognition on mobile device

    Building a biometric database of users seeking affairs isn't just a BIPA violation—it's a security liability. If Victoria Milan's servers were breached, users wouldn't just face the typical identity theft risk. They'd face blackmail, extortion, and exposure to partners, employers, and communities. For a user base that selected the platform specifically for anonymity, that's not a bug in the product—it's the product failing at its core promise.

    What compliance teams should be checking

    The Victoria Milan lawsuit is a reminder that BIPA applies to any company collecting biometric data from Illinois residents, regardless of where the company is headquartered. Victoria Milan is owned by Digisec Media Limited, registered in Cyprus. That doesn't insulate it from US state privacy law if it serves US users.

    Operators running facial verification features should be auditing their BIPA compliance now, particularly those with user bases that include Illinois residents. That means confirming that written consent is obtained before biometric collection, that purpose and retention policies are clearly disclosed, and that those policies are publicly available. It also means confirming that biometric data is either not stored after verification or, if it is stored, that deletion schedules are documented and followed.

    Platforms marketing on discretion face a harder question: whether facial verification is compatible with their positioning at all. If your value proposition is anonymity, building a biometric database undermines that promise structurally. Alternative verification methods—document checks, third-party identity services, decentralised verification—exist, though none are frictionless.

    The Illinois lawsuit is in early stages, and Victoria Milan has not yet filed a response. But BIPA class actions rarely end in full defence victories. The statute's private right of action, statutory damages structure, and track record of large settlements make it a powerful plaintiff tool.

    Key Takeaways

    • •Dating app compliance teams operating in Illinois must audit selfie verification features to ensure explicit written consent forms and published data deletion schedules exist.
    • •Dating platforms marketing anonymity face severe legal and reputational risks when capturing permanent biometric data, making non-biometric verification methods necessary.

    Frequently Asked Questions

    D
    DII Regulatory Monitor

    Policy & Regulation Desk

    The DII Regulatory Monitor tracks legislation, enforcement action, safety rules and compliance across dating industry markets.

    More articles by DII Regulatory Monitor

    Comments

    Join the discussion

    Industry professionals share insights, challenge assumptions, and connect with peers. Sign in to add your voice.

    Your comment is reviewed before publishing. No spam, no self-promotion.

    More in Regulatory Monitor

    View all →
    Regulatory Monitor
    A mobile smartphone displaying a digital identity verification interface held by a user.

    Dating Apps' Design Flaw: A Regulatory Time Bomb for Single Parents

    Child sex offenders are significantly more likely to use dating apps than non-offenders, according to research published…

    Monday 14th April · 1 min readRead →
    Regulatory Monitor
    Legal documents and an insurance policy resting on an office desk beside a smartphone showing a dating application.

    Match Group's $3.9M Insurance Battle: A Lesson in Notification Precision

    Match Group is suing insurance broker Marsh USA for $3.9M after a 48-hour notification delay allegedly voided coverage f…

    Thursday 2nd April · 1 min readRead →
    Regulatory Monitor
    A teenager holding a smartphone displaying restricted social media application icons alongside identity verification graphics.

    Australia Banned Teens From Social Media. Snap Lost 3 Million Daily Users. Dating Apps Are Next.

    Snapchat has shut down or restricted 415,000 Australian teen accounts since the under-16 social media ban took effect Sn…

    Friday 20th February · 1 min readRead →
    Technology & AI Lab
    Two cardboard moving boxes stacked inside an empty room during a home relocation.

    HER's 'U-Haul Fall': Smart Strategy or Stereotype Sellout?

    HER is offering three couples up to $7,500 each in moving costs if they've been together six months or less The company …

    Thursday 24th October · 1 min readRead →