
Most spectators at sporting events never realize that their face was scanned and potentially converted into a file that is stored by a private company that never asked for your explicit permission.
This is actually happening these days at some of the most popular entertainment venues in the country. There are several legal questions surrounding this kind of surveillance that can be a good basis for a class action privacy lawsuit. Contact our data privacy lawyers to discuss and to learn more about your legal options.
Facial recognition and facial authentication systems have become one of the most discussed technology upgrades in the sports and entertainment venue industry. According to a 2025 industry survey, nearly half of venue operators named biometric technology among their top priorities for the year.
The venues note that this increases efficiency and can mean faster entry lines. They usually don't mention the behavioral and demographic data collected and sold.
Several NFL stadiums now use facial authentication software to manage access to premium seating areas. Some venues even allow fans to link their face to a payment method so they can purchase a beer without ever reaching for a wallet. The technology has also expanded into security functions, and security scanners can flag individuals who have been previously banned from the facility.
The distinction between facial authentication and facial recognition is important because authentication systems will convert a fan-provided photo into an encrypted digital token for identity verification while recognition systems capture and store actual images of faces and run comparisons against databases in real time.
For fans who opt into a biometric program and understand exactly how their data will be used, this may not be a huge issue, but some attendees have no clear picture of what is being collected and whether it might be shared with third parties, including law enforcement.
A class action lawsuit was filed on May 15, 2026 in federal court, alleging that Disneyland and Disney California Adventure began using facial recognition technology at park entrances starting around April 28, 2026, without obtaining meaningful consent from visitors.
The complaint was brought by a park guest who visited Disneyland on May 10 with her children, claiming that Disney converts visitors' facial images into biometric numerical values that are then compared against photos taken when a ticket was first used, all without clearly informing guests that this process is taking place.
The lawsuit seeks $5 million in damages and asks the court to require Disney to obtain explicit written consent before scanning any visitor's face.
Disney's position is that signs are posted near entrances indicating that facial recognition is in use, and that alternative entry lanes are available for visitors who do not wish to be scanned.
One attorney representing the plaintiff said that the burden of protecting privacy should not fall on the guest and if a company wants to collect biometric data this sensitive, it should be required to ask first, and that request should be written and voluntary.
The lawsuit reflects a broader pattern developing across the country as venues rush to adopt biometric systems while regulators and courts are still working to catch up.
When a company collects your facial geometry and stores it as a data point, that data can later be sold or misused. Most of us have no awareness it is even happening.
If facial recognition is combined with location tracking within a venue and marketing databases, a company can build a detailed behavioral profile of each attendee.
The United States does not have a single federal law governing the collection of biometric data by private companies, but the Biometric Information Privacy Act in Illinois requires companies to provide written notice before collecting biometric data, and publish a public policy explaining how long data will be kept and how it will be destroyed.
California has a relevant law in place as well. Businesses operating in California must disclose biometric collection and give consumers the ability to limit how their data is used and shared. The California Consumer Privacy Act has broadened those protections further.
Other states including Washington, New Jersey, and Texas have enacted their own biometric privacy statutes, though with varying standards and enforcement mechanisms.
One of the central debates in facial recognition cases is the difference between opt-in and opt-out consent with sports and concert venues saying that posting signage or burying language in a terms of service agreement satisfies their disclosure obligations. Privacy advocates and plaintiffs' attorneys argue that passive disclosure is not genuine consent.
If you attended a sporting event or another large public venue and were subjected to facial recognition scanning without your clear knowledge and informed consent, you may have a viable legal claim depending on the state where the venue is located and the specific circumstances of how the technology was deployed. Potential claims in these cases can include:
Biometric privacy litigation requires a thorough understanding of both the technology involved and the legal framework that governs it and our attorneys pursue facial recognition and biometric privacy cases on behalf of individuals whose data was collected without proper consent.
We understand how these systems work and how to build a strong class action case when a company has treated privacy obligations as an afterthought.
We take biometric privacy cases on a contingency fee basis, which means you owe nothing unless we recover on your behalf. If you attended a venue where facial recognition was used and you were not clearly informed or given a genuine choice, contact The Lyon Firm today for a free and confidential consultation.
Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there: