Victoria Milan's BIPA Suit: A Privacy Promise Collides with Reality
Key Points
- •Plaintiff Darius Barlow filed a class action lawsuit in Illinois against Victoria Milan, alleging the dating platform violated the state's Biometric Information Privacy Act.
- •Under the Illinois Biometric Information Privacy Act, non-compliant companies face statutory damages ranging from $1,000 for negligent violations to $5,000 for intentional violations.
- •Approximately 35 percent of United States dating app users completed identity verification by mid-2024, up from negligible adoption levels recorded in 2019.
- •Meta settled a landmark lawsuit under the Illinois Biometric Information Privacy Act for $650 million in 2021 over similar facial recognition allegations.
Victoria Milan, a dating platform catering to users seeking extramarital affairs, is defending allegations that its selfie verification system violated Illinois' Biometric Information Privacy Act by collecting facial scan data without proper consent or disclosure. The lawsuit highlights a fundamental tension in the dating industry: platforms cannot simultaneously promise absolute discretion whilst building databases of permanent biometric identifiers. For operators marketing on anonymity, facial verification isn't merely a compliance risk—it's a contradiction of their core value proposition.
The lawsuit, filed in the Northern District of Illinois by plaintiff Darius Barlow, claims the platform's identity verification process captured and stored biometric identifiers without meeting the state's requirements for written consent, purpose disclosure, or data deletion schedules. Victoria Milan requires users to submit selfies for verification—standard practice across the industry. What distinguishes this case is the platform's simultaneous promise of discretion to users whose presence could end marriages or damage careers.
Dating platforms can't have it both ways: you either collect permanent biometric data and accept the liability that comes with it, or you market on discretion and find another way to verify users.
BIPA's $650M shadow
Illinois enacted BIPA in 2008, making it the strictest biometric privacy law in the United States. The statute requires companies collecting biometric identifiers—fingerprints, retina scans, facial geometry—to obtain written consent, disclose the purpose and duration of data collection, and establish publicly available retention and deletion schedules. Crucially, it grants Illinois residents a private right of action, allowing individuals to sue directly rather than relying on regulatory enforcement.
Create a free account
Unlock unlimited access and get the weekly briefing delivered to your inbox.
That provision has made BIPA the preferred legal avenue for privacy class actions. Meta settled a facial recognition lawsuit under BIPA for $650M in 2021. Clearview AI, Snapchat, TikTok, and Google have all faced BIPA litigation. Statutory damages range from $1,000 per negligent violation to $5,000 per intentional or reckless one.
According to the complaint, Victoria Milan's verification flow asks users to submit a selfie but fails to provide the required written consent form, fails to disclose what the biometric data will be used for or how long it will be retained, and fails to publish retention and deletion policies. The platform operates under the tagline 'The world's best dating site for married and attached people'—a positioning that makes the alleged compliance failure particularly acute.
Verification theatre meets operational reality
Facial verification has become table stakes for dating platforms trying to address catfishing, bots, and the broader trust crisis eroding user confidence. Tinder introduced photo verification in 2020. Bumble rolled out its version the same year. Hinge added selfie verification in 2021.
The technical implementation varies, but the basic flow is consistent: users submit a selfie, often mimicking a specific pose. The platform's system compares the facial geometry in the selfie against profile photos to confirm the same person uploaded both. Some operators claim they don't store the biometric data after verification. Others are less specific.
For mainstream platforms, the privacy-versus-safety trade-off is defensible. Most users understand that verification reduces fraud risk, and they're willing to share biometric data if it improves match quality and safety. The calculation changes when the platform markets itself on discretion.
Biometric data is permanent. You can change a password or cancel a credit card. You cannot change your facial geometry.
Victoria Milan's homepage promises 'anonymous and discreet' connections. Its FAQ emphasises that 'your secret is safe with us'. The platform allows users to blur photos and offers a 'panic button' to quickly exit the site if a spouse approaches.
Building a biometric database of users seeking affairs isn't just a BIPA violation—it's a security liability. If Victoria Milan's servers were breached, users wouldn't just face the typical identity theft risk. They'd face blackmail, extortion, and exposure to partners, employers, and communities. For a user base that selected the platform specifically for anonymity, that's not a bug in the product—it's the product failing at its core promise.
What compliance teams should be checking
The Victoria Milan lawsuit is a reminder that BIPA applies to any company collecting biometric data from Illinois residents, regardless of where the company is headquartered. Victoria Milan is owned by Digisec Media Limited, registered in Cyprus. That doesn't insulate it from US state privacy law if it serves US users.
Operators running facial verification features should be auditing their BIPA compliance now, particularly those with user bases that include Illinois residents. That means confirming that written consent is obtained before biometric collection, that purpose and retention policies are clearly disclosed, and that those policies are publicly available. It also means confirming that biometric data is either not stored after verification or, if it is stored, that deletion schedules are documented and followed.
Platforms marketing on discretion face a harder question: whether facial verification is compatible with their positioning at all. If your value proposition is anonymity, building a biometric database undermines that promise structurally. Alternative verification methods—document checks, third-party identity services, decentralised verification—exist, though none are frictionless.
The Illinois lawsuit is in early stages, and Victoria Milan has not yet filed a response. But BIPA class actions rarely end in full defence victories. The statute's private right of action, statutory damages structure, and track record of large settlements make it a powerful plaintiff tool.
Key Takeaways
- •Dating app compliance teams operating in Illinois must audit selfie verification features to ensure explicit written consent forms and published data deletion schedules exist.
- •Dating platforms marketing anonymity face severe legal and reputational risks when capturing permanent biometric data, making non-biometric verification methods necessary.
Frequently Asked Questions
Policy & Regulation Desk
The DII Regulatory Monitor tracks legislation, enforcement action, safety rules and compliance across dating industry markets.
Comments
Join the discussion
Industry professionals share insights, challenge assumptions, and connect with peers. Sign in to add your voice.
Your comment is reviewed before publishing. No spam, no self-promotion.
