TL;DR: Virginia resident Charles Sigwalt filed a class action in Seattle federal court against Amazon, claiming Ring's Familiar Faces feature converts the faces of anyone walking past a doorbell camera into mathematical "faceprints," without their knowledge or consent. Amazon already disables the feature in Illinois, Texas, and Portland because those places have biometric privacy laws. Everywhere else? Fair game. The lawsuit seeks $5 million or more in damages and could force the question: do you need someone's permission before your doorbell scans their face?

Your Neighbor's Doorbell Just Got Facial Recognition

Amazon announced Familiar Faces in September 2025 and launched it in the US in December 2025. By April 2026, it reached the UK. The pitch: instead of a generic "someone's at the door" alert, Ring tells you "Dad is at the door" or "your mail carrier is here."[1]

Each Ring owner can create up to 50 profiles of "frequent visitors." The camera watches who shows up, learns their faces over time, and matches them to names. Sounds convenient, if you're the person who bought the doorbell.[2]

But here's the part Amazon glosses over: the camera doesn't just scan people who opt in. It scans everyone. Family members. Delivery drivers. Postal workers. The neighbor's kid cutting through your yard. Anyone within the camera's field of view gets their face converted into a mathematical template (a faceprint) and stored on Amazon's cloud servers.[1][3]

Nobody asked those people if they wanted to be in Amazon's facial recognition database. Nobody told them it was happening.

The Lawsuit: "Millions of Americans" Scanned Without Consent

Charles Sigwalt, a Virginia resident, filed the class action in the U.S. District Court for the Western District of Washington (Amazon's home turf). His complaint argues that "millions of other Americans passed by a Ring security camera and unknowingly had their facial recognition information collected."[1]

The legal claims stack up:

  • Virginia consumer protection law: deceptive trade practices
  • Virginia's appropriation statute: using someone's likeness without consent
  • Virginia's Computer Crimes Act: unauthorized computer use
  • Intrusion upon seclusion: violating reasonable privacy expectations
  • Negligence and unjust enrichment: profiting from data collected without care

Sigwalt is seeking nationwide class certification (covering everyone in the US whose face was captured by Familiar Faces) plus a Virginia-specific subclass. Damages sought: at least $5 million.[3][4]

How Faceprints Work (And Why They're Dangerous)

Familiar Faces doesn't just take photos. It converts each face into a mathematical template, a faceprint. Think of it like a fingerprint, but for your face. A unique numerical representation that can identify you across any Ring camera, anywhere.[2]

Amazon says the data is encrypted and never shared. They claim unidentified faces auto-delete after 30 days. Saved profiles? Those stick around for 180 days. And all of it lives on Amazon's cloud servers, not on the doorbell itself.[2]

The lawsuit disputes the 30-day claim. It alleges that saved profiles persist even after a Ring owner cancels their subscription, meaning your faceprint could outlive the account that created it.[2]

Here's what makes biometric data different from a stolen credit card number: you can't change your face. Once a faceprint leaks, it's compromised forever. The complaint makes this point explicitly: biometric data "cannot easily be changed once compromised."[4]

And Ring has been breached before. In 2023, the FTC hit Amazon with a $5.8 million settlement over Ring's privacy failures.[5] That track record doesn't inspire confidence about the security of millions of faceprints sitting on Amazon's servers.

Amazon Knows This Is a Problem. They Proved It.

The most damning detail in this case isn't technical. It's geographic.

Ring disabled Familiar Faces in three places:[2][3]

  • Illinois: has BIPA, the toughest biometric privacy law in the country
  • Texas: requires consent before capturing biometric identifiers
  • Portland, Oregon: restricts facial recognition in public accommodations

Amazon turned the feature off in those jurisdictions because the legal risk was obvious. The lawsuit's argument writes itself: Ring "clearly has the ability to follow biometric privacy laws…but chooses not to."[2]

If Amazon can respect consent requirements in Illinois, Texas, and Portland, why not everywhere else? The answer is straightforward: because everywhere else, there's no law forcing them to.

Why This Case Matters Beyond Illinois

Most facial recognition lawsuits lean on Illinois's Biometric Information Privacy Act (BIPA). It's the go-to statute because it includes a private right of action, meaning regular people can sue, not just regulators. BIPA cases have cost companies hundreds of millions in settlements.

This case is different. Sigwalt is suing from Virginia, using Virginia state laws plus common law claims. He's not relying on BIPA at all.[4]

That matters because it tests whether biometric privacy rights exist outside the handful of states with specific biometric statutes. If Sigwalt wins, it signals that companies can't just avoid Illinois and Texas and call it a day. Consumer protection laws, computer crime statutes, and common law privacy rights could fill the gap everywhere else.

The proposed nationwide class makes the stakes even higher. A court ruling that Ring violated the privacy rights of everyone captured by Familiar Faces would reach far beyond Virginia.

The Pushback Amazon Ignored

Amazon didn't launch Familiar Faces into a vacuum. They launched it into a wall of opposition and did it anyway.

Senator Ed Markey (D-MA) demanded Amazon abandon the feature before it rolled out, warning it "could be used to record the biometric data of people who never consented to have their faces scanned."[5]

The Electronic Frontier Foundation flagged the risk that biometric data "could be used for mass surveillance or be leaked in a potential data breach." The EFF pointed out that facial recognition laws typically require "affirmative consent before a company collects or processes a faceprint."[4][5]

Amazon's response to all of this was to launch the feature anyway, in every state where they legally could.

Ring says the feature is "opt-in," disabled by default and turned on by the doorbell owner. But that framing misses the point entirely. The doorbell owner opted in. The mail carrier didn't. The neighbor walking their dog didn't. The kid riding their bike past the house didn't. "Opt-in" only describes one side of the transaction.

The Neighborhood Surveillance Network Nobody Voted For

Ring already has a complicated history with surveillance. Amazon partnered with over 2,000 police departments to share Ring footage. The company only stopped letting cops request footage without a warrant in 2024, after years of pressure.[1]

Familiar Faces adds a new layer. It's not just video anymore: it's biometric identification. Every Ring doorbell becomes a node in a facial recognition network that covers sidewalks, porches, driveways, and streets across America.

Nobody elected this system. No city council voted to deploy facial recognition on residential streets. Amazon just sold it to homeowners as a convenience feature and let the network build itself.

The complaint raises concerns about minors, too. Kids walk past Ring cameras constantly. There are no age-specific protections, no parental consent mechanisms, no separate policies for children's biometric data.[4]

What You Can Do

Check Your Ring Settings

If you own a Ring camera, go to Device Settings → Smart Alerts → Familiar Faces. You can disable the feature entirely. Your neighbors will thank you.

Ask Your Neighbors

If you see a Ring doorbell on a nearby home, the owner may not realize Familiar Faces is scanning passersby. A conversation costs nothing.

Support Biometric Privacy Laws

Illinois, Texas, and Portland proved that laws work: Amazon turned the feature off where required. Push your state legislators to pass biometric consent requirements.

File an FTC Comment

The FTC is actively looking at biometric data practices. Consumer complaints build the case for federal action. File at ftc.gov.

What Happens Next

Amazon will need to formally respond to the complaint within 21 days. Watch for a motion to dismiss. Amazon will likely argue that Ring owners, not Amazon, are responsible for how they use the feature. They may also challenge nationwide class certification, trying to limit the case to Virginia.

The core question the court will face: does a company need your consent before its product scans your face? In three jurisdictions, the answer is already yes. This case asks whether that should be the rule everywhere.

References

  1. TechCrunch: Amazon faces class action lawsuit over Ring facial-recognition feature
  2. The Register: Ring faces class action over facial-recognition feature
  3. Biometric Update: Amazon Ring sued over facial recognition feature as privacy fight moves to federal court
  4. CBS News: Amazon faces lawsuit over Ring facial recognition software
  5. US News: Amazon's Ring sued over facial recognition feature