The reference image isn't linked to any particular iPhone or person:
We built Apple Reference Image to avoid using an explicit, public
credential for photographers, and to avoid even implicit public
association between different photos taken by the same sensor. The
final reference image is instead signed by Apple’s signing service,
after validation by PCC. That signature is backed by Apple’s
strongest technical guarantees.
Our implementation also protects the
confidentiality of the image itself, including from Apple. Merely
capturing a reference image should never expose the actual pixels to
Apple or anyone else. We achieve this through the exceptional privacy
properties of PCC — the nodes themselves are architected so that not
even Apple can access image data, just as Apple cannot see the
information processed for Apple Intelligence in PCC.