In March 2024, a federal class-action lawsuit filed in the U.S. District Court for the Northern District of Illinois alleges that Delta Air Lines’ official mobile application violates multiple state and federal privacy statutes—including the Illinois Biometric Information Privacy Act (BIPA), the California Consumer Privacy Act (CCPA), and the federal Computer Fraud and Abuse Act—by covertly harvesting sensitive user data. The complaint, Smith v. Delta Air Lines, Inc. (Case No. 1:24-cv-01892), names five named plaintiffs from Illinois, California, and New York, and seeks statutory damages of $5,000 per BIPA violation and $750 per CCPA violation, potentially totaling over $1.2 billion for an estimated 240,000 affected users in Illinois alone. At the heart of the dispute is Delta’s use of third-party SDKs (software development kits) embedded in its iOS and Android apps to collect granular behavioral telemetry—including screen taps, scroll velocity, session duration, precise geolocation coordinates accurate to within 3 meters, and facial biometric templates generated during optional ‘Face ID’ login—without transparent disclosure or affirmative opt-in consent.
The Technical Architecture Behind the Allegations
According to forensic app analysis conducted by plaintiffs’ expert Dr. Elena Rostova, a digital forensics specialist at the University of Illinois at Chicago, Delta’s mobile app (version 11.12.0, released January 2024) integrates at least nine third-party tracking SDKs. These include AppsFlyer (used for attribution and marketing analytics), Adjust (for device fingerprinting and campaign measurement), Amplitude (for behavioral cohort analysis), and OneSignal (for push notification targeting). Crucially, the complaint cites internal Delta engineering documentation obtained via discovery—dated October 2023—which states: “Amplitude event capture must remain enabled across all user segments to ensure full funnel visibility,” confirming intentional, non-consent-based data collection.
Biometric Capture Without BIPA Compliance
Delta’s app offers optional Face ID and Touch ID authentication on iOS and Android. However, the lawsuit contends that when users enable Face ID, the app generates and transmits a proprietary biometric template—not merely a cryptographic hash—to Delta’s servers hosted on Amazon Web Services (AWS) us-east-1 region. Forensic packet captures show that this template, measuring between 2,140 and 2,360 bytes per enrollment, is transmitted unencrypted over HTTP before TLS 1.3 negotiation completes—a violation of NIST SP 800-63B standards for biometric data handling. Under Illinois BIPA, companies must obtain written consent before collecting biometric identifiers and must publish a publicly available retention schedule. Delta’s privacy policy, last updated February 2024, contains no mention of biometric data retention timelines, nor does it specify how long facial templates are stored. Public AWS S3 bucket logs—reviewed by plaintiffs’ counsel—show Delta retains biometric templates for 36 months unless manually deleted by the user.
Location Tracking Beyond Operational Necessity
While airlines routinely request location access for features like gate change alerts or baggage tracking, Delta’s app requests ‘Always Allow’ location permissions on iOS—even when background location is disabled in system settings. The complaint documents that Delta’s app transmits GPS coordinates every 90 seconds when foregrounded and every 12 minutes when backgrounded, regardless of whether the user has booked a flight or accessed location-dependent features. Analysis of 1,247 anonymized telemetry logs shows median precision of 2.8 meters (±0.4m) using GNSS + Wi-Fi RTT fusion—far exceeding the 50-meter threshold deemed necessary for airport navigation by FAA Advisory Circular 120-118. In one documented instance, a plaintiff’s device transmitted location pings while inside a residential apartment complex in Evanston, IL, for 72 consecutive hours—despite no active flight itinerary.
Legal Frameworks at Stake
The lawsuit invokes three primary legal pillars: BIPA, CCPA, and the Computer Fraud and Abuse Act (CFAA). Each imposes distinct obligations. BIPA, enacted in 2008, is among the strictest biometric privacy laws globally. It requires informed written consent, prohibits profiting from biometric data, mandates destruction within 3 years of the last interaction, and allows private right of action with statutory penalties. Since its 2020 Rosenbach ruling, Illinois courts have held that procedural violations alone—such as failing to provide a retention schedule—are sufficient for damages, even absent demonstrable harm. The CCPA, effective since 2020 and strengthened by the CPRA amendments in 2023, grants consumers rights to know, delete, and opt out of the sale or sharing of personal information. Critically, the CPRA defines ‘sharing’ as disclosing personal information to a third party for cross-context behavioral advertising—precisely what Delta’s integration with Adjust and AppsFlyer enables.
BIPA Precedents and Delta’s Exposure
Delta faces heightened risk due to Illinois’ track record of imposing significant settlements under BIPA. In 2023, Facebook settled a similar biometric class action for $650 million; in 2022, TikTok paid $92 million; and in 2021, Clearview AI agreed to a $50 million settlement. What distinguishes Delta’s case is the scale of technical evidence: Plaintiffs submitted 47 pages of decompiled SDK source code, network traffic logs showing 14,328 unique biometric transmissions over 30 days across 3 test devices, and internal Slack messages where a Delta product manager wrote: “We’re not asking for consent because Amplitude says it’s not required if we don’t label it ‘biometric.’” That statement—captured on April 12, 2023—is cited in the complaint as evidence of willful noncompliance.
CCPA Enforcement Trends
Since July 2023, the California Privacy Protection Agency (CPPA) has issued 17 enforcement actions, with average fines of $227,000 per violation. Notably, in February 2024, the CPPA fined Sephora $1.2 million for sharing user data with Meta and Pinterest without opt-out mechanisms. Delta’s app fails two core CCPA requirements: First, its ‘Do Not Sell or Share My Personal Information’ link—located in the footer of the mobile app’s Settings > Privacy page—redirects users to delta.com/privacy instead of a functional opt-out webform, violating CCPA §1798.120(b). Second, Delta’s privacy policy lists ‘AppsFlyer’ under ‘Service Providers’ but omits its role in behavioral advertising, contravening CPRA §1798.140(v)(1)(A), which mandates explicit disclosure of each third party’s purpose.
How Delta Compares to Industry Peers
A comparative audit of 12 major airline apps—conducted by the nonprofit Digital Privacy Alliance in Q1 2024—reveals Delta’s practices diverge significantly from industry norms. While all carriers collect basic booking data, only Delta and United Airlines deploy SDKs capable of real-time biometric template extraction. Southwest Airlines’ app, by contrast, uses only first-party analytics and disables all third-party trackers when users decline ‘Personalized Offers’ in the initial onboarding flow. JetBlue’s app complies with BIPA by displaying a standalone biometric consent dialog before Face ID enrollment, complete with a 3-year retention disclosure and immediate deletion option. Alaska Airlines’ iOS app limits location pings to once per minute only when actively navigating to a gate—verified via Apple’s App Store privacy nutrition labels.
| Airline | Biometric Consent Required? | Location Pings (Foreground) | Third-Party SDKs | CCPA Opt-Out Functional? |
|---|---|---|---|---|
| Delta | No (implied consent) | Every 90 sec | 9 (AppsFlyer, Adjust, Amplitude, etc.) | No (redirects to homepage) |
| United | Yes (separate dialog) | Every 2 min | 6 | Yes |
| American | No (no biometric auth) | On-demand only | 3 | Yes |
| Southwest | No biometric auth | None (GPS disabled by default) | 1 (internal only) | Yes |
What Travelers Can Do Right Now
While litigation proceeds—expected to reach class certification by late 2024—users retain actionable steps to limit exposure. First, disable location services for the Delta app entirely: On iOS, go to Settings > Privacy & Security > Location Services > Delta > select ‘Never’; on Android, navigate to Settings > Apps > Delta > Permissions > Location > ‘Deny’. Second, revoke biometric permissions: iOS users should go to Settings > Face ID & Passcode > Delta > toggle off; Android users must uninstall and reinstall the app to reset biometric enrollment. Third, exercise CCPA rights by submitting a verified consumer request directly to Delta’s designated privacy portal at delta.com/privacy-request—though plaintiffs’ attorneys note that Delta’s current form lacks fields for ‘opt out of sharing’, rendering it noncompliant.
Technical Mitigations for Power Users
For technically proficient travelers, network-level controls offer stronger protection. Installing a DNS-based ad/tracker blocker like NextDNS (with ‘Privacy Blocklist’ enabled) reduces SDK traffic by 68% according to independent tests. Alternatively, using Apple’s Lockdown Mode—available on iOS 16+—blocks all third-party trackers by default and prevents SDK initialization. A controlled experiment showed Lockdown Mode reduced Delta app’s outbound data volume from 4.2 MB/hour to 1.1 MB/hour, primarily by disabling Adjust and AppsFlyer payloads. Importantly, none of these measures impair core functionality: boarding pass scanning, flight status checks, and rebooking remain fully operational.
Corporate Accountability Mechanisms
Shareholders also hold leverage. Delta’s 2023 Proxy Statement (SEC Form DEF 14A) discloses that its Board’s Technology & Innovation Committee oversees ‘data governance frameworks,’ yet minutes from the November 2023 meeting—obtained via FOIA request—show no discussion of BIPA compliance or third-party SDK audits. Institutional investors managing over $14 billion in Delta stock—including CalPERS and the New York State Common Retirement Fund—have filed resolutions demanding annual public reporting on privacy risk assessments. If approved at the 2025 Annual Meeting, such reporting would mandate disclosure of SDK inventory, data retention periods, and third-party data processing agreements—information currently withheld from consumers.
Regulatory Momentum and Future Implications
The Delta lawsuit arrives amid accelerating federal privacy legislation. The American Data Privacy and Protection Act (ADPPA), though stalled in Congress, passed the House Energy and Commerce Committee in 2022 with bipartisan support and would preempt state laws like BIPA—potentially limiting statutory damages but establishing national minimum standards for biometric consent. Meanwhile, the Federal Trade Commission has signaled aggressive enforcement: In January 2024, it announced a $25 million settlement with Epic Games for COPPA violations involving children’s location and behavioral data—a precedent cited repeatedly in the Delta complaint. FTC staff guidance explicitly warns against ‘dark patterns’ in consent flows, noting that pre-ticked boxes or buried disclosures violate Section 5 of the FTC Act.
State-level activity is equally consequential. Texas enacted the Texas Identity Theft Enforcement and Protection Act (TITEPA) in September 2023, granting residents private right of action for unauthorized biometric collection with penalties up to $10,000 per violation. Vermont’s Data Broker Regulation Act, effective July 2024, requires companies like Adjust and Amplitude to register with the Attorney General and disclose data sourcing practices. These laws collectively create a patchwork that forces multistate corporations to adopt the strictest standard—effectively making BIPA the de facto national benchmark.
Broader Cultural Shifts in Traveler Expectations
Beyond legal liability, Delta’s predicament reflects a profound cultural shift. A 2024 Pew Research Center survey of 3,217 U.S. adults found that 78% believe airlines should require explicit consent before collecting location data—and 63% say they’d switch carriers if an app collected biometrics without clear explanation. This aligns with findings from the 2023 Global Traveler Privacy Index, where Delta ranked 11th out of 15 major carriers in ‘transparency score,’ scoring just 2.4/5.0 on clarity of data practices, compared to JetBlue’s 4.7/5.0. Notably, 41% of respondents aged 18–34 reported deleting airline apps after encountering opaque privacy notices—a demographic critical to Delta’s loyalty program growth.
The tension between convenience and control is central to modern travel tech. Delta’s app boasts 32 million downloads and processes over 1.2 million boarding passes daily—efficiencies built on data aggregation. Yet as plaintiffs’ lead attorney Maria Chen observed in a March 2024 press briefing: “A traveler scanning a QR code at JFK shouldn’t have to choose between seamless transit and fundamental privacy. The law doesn’t force that trade-off—and neither should corporate design.”
This case may catalyze industry-wide redesign. IATA’s Passenger Digital Identity Working Group, comprising 28 airlines including Delta, published draft guidelines in April 2024 advocating for ‘zero-knowledge biometric verification,’ where facial templates never leave the user’s device. Such approaches—already piloted by Lufthansa at Munich Airport—eliminate server-side storage risks entirely. Whether Delta adopts them voluntarily—or is compelled by court order—will signal whether privacy can coexist with innovation in air travel.
For now, the lawsuit remains active, with Delta filing a motion to dismiss on May 15, 2024, arguing that plaintiffs lack standing because ‘no concrete harm’ occurred. U.S. District Judge Andrea Wood is expected to rule by August 2024. Regardless of outcome, the scrutiny has already triggered internal reviews: Delta’s Chief Privacy Officer confirmed in an internal memo dated April 30, 2024, that the company is auditing all third-party SDKs and will issue revised privacy disclosures by Q3.
Travelers should recognize that privacy isn’t a luxury—it’s infrastructure. Just as runway lighting and air traffic control systems operate unseen to ensure physical safety, robust data governance ensures digital autonomy. When an app knows your face, your location, and your habits more precisely than you know yourself, the question isn’t whether technology serves us—but who, ultimately, holds the keys.
The Delta lawsuit doesn’t merely test statutory language; it tests whether convenience justifies invisibility. And in an era where 68% of U.S. adults report feeling ‘constantly monitored’ by digital services—according to the 2024 Norton Cyber Safety Insights Report—the answer carries weight far beyond airline terminals.
As forensic evidence mounts and regulatory pressure intensifies, one truth emerges with clarity: transparency is no longer optional. It is the minimum viable product for trust—and trust, in travel, remains the most valuable boarding pass of all.
- Delta’s app transmits biometric templates averaging 2,250 bytes per enrollment
- Location pings occur every 90 seconds foregrounded, every 12 minutes backgrounded
- 9 third-party SDKs identified, including AppsFlyer, Adjust, and Amplitude
- Biometric templates retained for 36 months unless manually deleted
- Plaintiffs seek $5,000 per BIPA violation and $750 per CCPA violation
- Disable location permissions for the Delta app in device settings
- Revoke biometric permissions via OS-level controls (not app settings)
- Submit CCPA requests directly via delta.com/privacy-request
- Install DNS-based blockers like NextDNS to reduce SDK traffic
- Enable Apple’s Lockdown Mode for maximum tracker prevention
The stakes extend beyond compensation. They define the boundaries of acceptable surveillance in public-facing digital services. For Delta—and for every company building apps that touch our bodies, our movements, and our identities—the message is unambiguous: consent must be conspicuous, data must be contained, and privacy must be prioritized—not as an afterthought, but as architecture.
When travelers open an airline app, they expect efficiency—not excavation. They seek reassurance—not reconnaissance. And as courts, regulators, and consumers converge on this principle, the Delta case becomes less about one company’s code—and more about the collective covenant we demand from every digital gateway we cross.
Whether flying domestically or internationally, the right to move freely includes the right to move anonymously in digital space. That right, once assumed, now requires assertion. And in asserting it, travelers aren’t rejecting progress—they’re ensuring it travels in the right direction.
Delta’s next flight plan won’t be charted in the skies alone. It will be plotted in courtrooms, boardrooms, and the quiet moments when users decide—tap or delete, share or shield, trust or terminate. Those decisions, multiplied across millions, will determine not just Delta’s future—but the future of travel itself.



