Katrina Carroll
Data Privacy · Biometric Privacy · Consumer Fraud · Class Actions
“Every case is a proverbial David and Goliath situation, and I relish the fight.
Consent Across the Data Chain
Katrina Carroll litigates what platforms do after a user supplies a photograph or other personal data, and builds class relief around notice, consent, access to court, and the uses that follow.
After the Upload
Katrina Carroll’s privacy cases begin with an ordinary exchange: a person posts a video, verifies a profile photograph, or pays for a meal with a card. The legal work follows the information after that moment. A platform may analyze an image, retain a template, or share data through systems the user cannot inspect. A breach may expose an identifier long after the original transaction. Carroll’s cases test whether the platform gave notice, obtained informed consent, limited use and retention, and provided a remedy for the people affected.
Carroll is the founding partner of Carroll Shamberg in Chicago and has practiced class-action law for 25 years. She earned her bachelor’s degree in political science, with honors, from Northwestern University in 1997 and her J.D. from Seton Hall University School of Law in 2000. She is admitted in Illinois and New Jersey and before the United States Courts of Appeals for the Third and Seventh Circuits.
The TikTok Record
The federal court overseeing In re TikTok, Inc., Consumer Privacy Litigation appointed Carroll as one of three co-lead counsel in September 2020. The consolidated complaint alleged that TikTok collected and used personal information, including biometric data, without sufficient notice and consent. During the settlement review, a source-code expert retained by Carroll and another member of the plaintiffs’ leadership examined the app’s iOS and Android code and relevant server code for two weeks. The leadership group used that technical work to prepare written discovery and deposition questions.
Carroll helped negotiate the resolution and presented the major oral arguments for the plaintiffs. The settlement established a $92 million fund and included measures directed at the data practices alleged in the complaint. The court granted final approval in July 2022 and entered final judgment the following month. The settlement covered a nationwide class and a separate Illinois subclass, with payments allocated differently to reflect their different statutory claims.
Browsing Data in the Ad Auction
In 2026, Carroll represented plaintiff Nicole McGrath in consolidated litigation over Google’s real-time-bidding advertising system. The related complaints allege that Google intercepted and tracked information about Americans’ browsing activity and transmitted that information through its advertising auctions to entities owned by, controlled by, or subject to the jurisdiction of the People’s Republic of China, in violation of the federal Bulk Sensitive Data Rule that took effect in April 2025.
The Northern District of California consolidated the related actions in June 2026. Carroll was admitted to represent McGrath in July, and on August 27 the court appointed Carroll Shamberg, Milberg, and Justice Jagher London & Millen as interim co-lead class counsel. The litigation remains at an early stage; the appointment gives the plaintiffs’ leadership responsibility for the consolidated complaint, discovery, case management, and any settlement discussions.
Photo Verification at Bumble
The Bumble litigation concerned a feature intended to confirm that a dating profile belonged to a real person. Users were prompted to take a photograph while making a specified gesture. The plaintiff alleged that Bumble used facial-recognition technology to collect biometric information through that process without the notice, written consent, retention policy, and deletion schedule required by the Illinois Biometric Information Privacy Act. The complaint applied those duties to data allegedly derived from the safety feature.
Carroll served as co-lead counsel in the litigation. The parties established a $40 million settlement fund for Illinois users of the Bumble and Badoo applications, and the court granted final approval. The alleged biometric processing occurred after a user supplied the verification image. The plaintiffs’ claims attached BIPA’s notice, consent, retention, and deletion duties to the additional information allegedly produced during verification.
Standing After a Breach
Carroll also represented a plaintiff in Lewert v. P.F. Chang’s China Bistro, Inc., an early federal data-breach appeal. P.F. Chang’s announced that payment-card data had been stolen from its system. One named plaintiff alleged fraudulent transactions, the cost of credit monitoring, and the time required to address the breach. The other alleged time spent monitoring his card statements and credit report. The district court dismissed the consolidated case for lack of Article III standing.
In 2016, the Seventh Circuit reversed and remanded. At the pleading stage, the court held that increased risks of fraudulent charges and identity theft were concrete enough to support suit because the alleged theft had already occurred. It also recognized time and money spent addressing fraud and protecting against identity theft as present injuries when tied to an imminent risk. The opinion returned the consolidated case to district court for further proceedings.
A Consumer Practice of Her Own
Carroll founded Carroll Shamberg around data-privacy, consumer-fraud, and product-liability class actions. She also serves on the advisory board of Loyola University Chicago School of Law’s Institute for Consumer Antitrust Studies and on Law360’s Products Liability Litigation Editorial Advisory Board.
Her description of the work is blunt: “Every case is a proverbial David and Goliath situation, and I relish the fight.” In the TikTok, Bumble, and P.F. Chang’s matters, her work has included technical investigation, appellate briefing, oral argument, and remedies defined for nationwide or statewide classes.