A single class-action settlement just put a real number on what brands owe consumers for scanning their faces without asking first: $2.925 million. That’s the price tag one retailer paid for deploying an AI virtual try-on tool without proper biometric consent. If your brand runs AR try-on, virtual fitting rooms, or face-scanning filters, the biometric data settlement isn’t background noise. It’s a preview of your own exposure.
The case itself won’t make headlines the way a data breach does. No hackers, no leaked database, no viral apology post. Just a company that scanned faces to power a try-on feature and didn’t get the legal consent framework right. That’s the whole story. And it’s exactly why marketing and legal teams should be paying closer attention than they are.
What Actually Happened, and Why It Matters More Than the Number Suggests
The settlement stemmed from claims under biometric privacy statutes, most notably the type modeled on Illinois’ Biometric Information Privacy Act (BIPA), which requires companies to get written consent before collecting facial geometry, retina scans, fingerprints, or similar identifiers. Virtual try-on tools, by design, capture facial mapping data to render makeup shades, glasses, or apparel onto a user’s image in real time. That mapping is biometric data under most state definitions, full stop.
The brand in question allegedly rolled out its try-on feature without the disclosures and written releases BIPA-style laws require. No opt-in checkbox explaining data retention. No clear disclosure of how long facial scans were stored or whether third-party AI vendors touched that data. The plaintiffs argued that’s a statutory violation regardless of whether any data was ever misused or leaked.
Under biometric privacy laws, intent doesn’t matter and harm doesn’t matter. The violation is the collection itself, absent proper consent. That’s a fundamentally different risk model than the one most marketing teams are used to.
That distinction should worry every brand running or considering AR shopping tools. Marketing teams are trained to think about data risk in terms of breaches and misuse. Biometric privacy law doesn’t work that way. You can do everything else right, and just skip the consent paperwork, and still write a seven-figure check.
Virtual Try-On Isn’t a Novelty Feature Anymore. It’s a Compliance Surface.
Virtual try-on adoption has exploded across beauty, eyewear, and fashion. Retailers cite conversion lifts and return-rate reductions as the business case, and the data backs that up: AR-powered shopping experiences reliably increase purchase confidence, per multiple retail commerce research summaries. The upside is real. But every one of these tools, whether built in-house or licensed from a vendor like Perfect Corp, ModiFace, or a TikTok/Meta AR effect, involves capturing and processing facial data in some form.
That means every brand deploying try-on tech is now, functionally, a biometric data controller. Not a marketing department. A data controller, subject to the same category of law that governs fingerprint scanners at gyms and facial recognition at airports. Most CMOs haven’t reframed the risk that way yet, and that gap is exactly where settlements like this one come from.
We’ve covered the mechanics of this exposure before in our breakdown of AR try-on biometric consent requirements, and the core fixes haven’t changed. What’s changed is the price of ignoring them. A theoretical risk is now a documented settlement number that plaintiffs’ attorneys will cite in every future demand letter.
The Consent Gap: Where Brands Keep Getting This Wrong
Three recurring failure points show up across biometric litigation, and they’re almost identical every time:
- No standalone written consent. Burying biometric data collection inside a general privacy policy or terms-of-service checkbox doesn’t satisfy BIPA-style requirements. Several states require a separate, specific disclosure naming the biometric identifier collected and its purpose.
- No retention or destruction schedule disclosed. Laws like BIPA require companies to publish a retention schedule and guidelines for permanently destroying biometric data once the purpose is fulfilled. Most try-on tools quietly keep scan data indefinitely, or don’t document a policy at all.
- No accounting for third-party vendor handling. If your try-on tool is white-labeled or built on a third-party AI rendering engine, that vendor may be processing and storing facial geometry on its own servers. Your consent language needs to disclose that transfer explicitly. Most brand legal teams never audit what the vendor actually does with the scan data after the session ends.
None of these are exotic legal requirements. They’re checklist items. But checklist items get skipped when a feature ships under a growth deadline and legal review gets treated as a formality instead of a gate.
How This Connects to the Broader FTC and State Law Squeeze
Biometric consent doesn’t sit in isolation. It’s converging with a wider regulatory tightening around AI-driven consumer-facing tools. The FTC has made clear that AI tools making representations to consumers, including synthetic or AI-rendered visuals, fall under existing endorsement and deception frameworks. Our coverage of FTC endorsement disclosure rules for AI shopping agents outlines how these obligations stack on top of, not instead of, state biometric statutes.
That stacking is the real risk multiplier. A brand running an AR try-on tool without biometric consent could simultaneously be violating state privacy law and FTC disclosure expectations if the tool also makes implicit claims (like showing a “realistic” result) without adequate disclaimers. Regulators and plaintiffs’ firms are increasingly treating these as bundled violations, not separate silos.
There’s also a parallel with the synthetic media compliance wave sweeping state legislatures. States are moving fast on rules governing AI-generated likenesses, and our analysis of how synthetic performer law intersects with platform AI labels shows how quickly this regulatory patchwork is expanding beyond biometric statutes into likeness rights generally. Virtual try-on tools that generate a rendered image of the user’s face arguably touch both categories at once: biometric collection and synthetic likeness generation.
What a Defensible Consent Framework Actually Looks Like
Rebuilding consent practices isn’t a one-time legal memo. It’s an operational rebuild that touches product, legal, and marketing simultaneously. A realistic framework includes:
- A standalone biometric consent screen that appears before any camera or upload feature activates, written in plain language naming exactly what’s collected (facial geometry, not just “photos”).
- An explicit opt-out path that doesn’t degrade the shopping experience into an obstacle course. Friction is fine; punishment isn’t.
- A published retention and deletion schedule, ideally automated so scan data purges on a fixed timeline without manual intervention.
- Vendor data-processing addendums that specifically address biometric data handling, not generic data-processing boilerplate. If you’re licensing AR tech, get your legal team to read the vendor’s actual data flow, not just their marketing one-pager.
- Geographic gating where necessary. Illinois, Texas, and Washington have the most developed biometric statutes, but more states are drafting similar language. Assume any state could adopt equivalent rules within a product cycle, and build for the strictest jurisdiction by default.
Treat biometric consent the same way you’d treat a data-sharing rider in a vendor contract: it’s not legal theater, it’s the mechanism that determines whether a seven-figure settlement lands on your desk or someone else’s.
Brands already building rigorous data-sharing riders for AI vendor tools have a head start here. The contractual discipline is transferable. Biometric processing clauses just need to be as specific and enforceable as the ones already governing creator-matching platforms and training-data licensing.
Operationalizing This Without Killing Conversion
Here’s the pushback marketing teams will raise, and it’s fair: won’t a consent screen tank conversion on the exact feature designed to boost it?
Maybe slightly, at first. But the data suggests users are more tolerant of clear, well-designed consent flows than brands assume, particularly when the value exchange (better fit accuracy, fewer returns) is obvious. Sprout Social’s consumer trust research consistently shows transparency correlates with higher brand trust scores, not lower engagement. A one-screen, well-designed consent flow costs you a fraction of a percent in conversion. A biometric class action costs millions, plus the legal fees, plus the reputational hit, plus the multi-year discovery process. That math isn’t close.
The smarter framing: consent isn’t a tax on the feature. It’s the feature’s license to operate at all.
The Takeaway
Audit every AR or virtual try-on tool in market today, this week, not next quarter, and confirm you have standalone biometric consent, a published retention schedule, and a vendor data-processing addendum specifically naming biometric handling. If any of those three is missing, you’re not managing risk. You’re waiting for your own settlement number.
FAQs
What counts as biometric data in a virtual try-on tool?
Facial geometry mapping, the underlying data used to overlay makeup, glasses, or apparel onto a user’s image, is generally classified as biometric data under state statutes like BIPA. This applies even if the brand never stores a photo, since the geometric mapping itself is the regulated identifier.
Does a general privacy policy cover biometric consent requirements?
No. Most biometric privacy laws require a standalone, specific disclosure naming the biometric identifier collected, its purpose, and retention terms. Burying this inside a broader privacy policy or terms-of-service agreement typically doesn’t satisfy the legal standard.
Are brands liable if a third-party AR vendor mishandles the data?
Yes, in most cases. Brands deploying a licensed try-on tool remain responsible for ensuring consent and data-handling practices meet legal standards, even if a vendor’s infrastructure processes the actual biometric scan. Vendor contracts need explicit biometric data-processing terms to allocate this risk properly.
Which states have the strictest biometric privacy laws right now?
Illinois’ BIPA remains the most litigated and strictest framework, with Texas and Washington also maintaining biometric-specific statutes. Several other states are drafting similar legislation, so brands operating nationally should build consent practices to the strictest applicable standard rather than patching state by state.
How does this settlement connect to FTC rules on AI-generated content?
Biometric consent violations can compound with FTC endorsement and deception concerns if the AI try-on tool also makes implied claims about accuracy or realism without proper disclosure. Regulators increasingly view these as overlapping compliance failures rather than separate issues.
FAQs
What counts as biometric data in a virtual try-on tool?
Facial geometry mapping, the underlying data used to overlay makeup, glasses, or apparel onto a user’s image, is generally classified as biometric data under state statutes like BIPA. This applies even if the brand never stores a photo, since the geometric mapping itself is the regulated identifier.
Does a general privacy policy cover biometric consent requirements?
No. Most biometric privacy laws require a standalone, specific disclosure naming the biometric identifier collected, its purpose, and retention terms. Burying this inside a broader privacy policy or terms-of-service agreement typically doesn’t satisfy the legal standard.
Are brands liable if a third-party AR vendor mishandles the data?
Yes, in most cases. Brands deploying a licensed try-on tool remain responsible for ensuring consent and data-handling practices meet legal standards, even if a vendor’s infrastructure processes the actual biometric scan. Vendor contracts need explicit biometric data-processing terms to allocate this risk properly.
Which states have the strictest biometric privacy laws right now?
Illinois’ BIPA remains the most litigated and strictest framework, with Texas and Washington also maintaining biometric-specific statutes. Several other states are drafting similar legislation, so brands operating nationally should build consent practices to the strictest applicable standard rather than patching state by state.
How does this settlement connect to FTC rules on AI-generated content?
Biometric consent violations can compound with FTC endorsement and deception concerns if the AI try-on tool also makes implied claims about accuracy or realism without proper disclosure. Regulators increasingly view these as overlapping compliance failures rather than separate issues.
Top Influencer Marketing Agencies
The leading agencies shaping influencer marketing in 2026
Agencies ranked by campaign performance, client diversity, platform expertise, proven ROI, industry recognition, and client satisfaction. Assessed through verified case studies, reviews, and industry consultations.
Moburst
-
2

The Shelf
Boutique Beauty & Lifestyle Influencer AgencyA data-driven boutique agency specializing exclusively in beauty, wellness, and lifestyle influencer campaigns on Instagram and TikTok. Best for brands already focused on the beauty/personal care space that need curated, aesthetic-driven content.Clients: Pepsi, The Honest Company, Hims, Elf Cosmetics, Pure LeafVisit The Shelf → -
3

Audiencly
Niche Gaming & Esports Influencer AgencyA specialized agency focused exclusively on gaming and esports creators on YouTube, Twitch, and TikTok. Ideal if your campaign is 100% gaming-focused — from game launches to hardware and esports events.Clients: Epic Games, NordVPN, Ubisoft, Wargaming, Tencent GamesVisit Audiencly → -
4

Viral Nation
Global Influencer Marketing & Talent AgencyA dual talent management and marketing agency with proprietary brand safety tools and a global creator network spanning nano-influencers to celebrities across all major platforms.Clients: Meta, Activision Blizzard, Energizer, Aston Martin, WalmartVisit Viral Nation → -
5

The Influencer Marketing Factory
TikTok, Instagram & YouTube CampaignsA full-service agency with strong TikTok expertise, offering end-to-end campaign management from influencer discovery through performance reporting with a focus on platform-native content.Clients: Google, Snapchat, Universal Music, Bumble, YelpVisit TIMF → -
6

NeoReach
Enterprise Analytics & Influencer CampaignsAn enterprise-focused agency combining managed campaigns with a powerful self-service data platform for influencer search, audience analytics, and attribution modeling.Clients: Amazon, Airbnb, Netflix, Honda, The New York TimesVisit NeoReach → -
7

Ubiquitous
Creator-First Marketing PlatformA tech-driven platform combining self-service tools with managed campaign options, emphasizing speed and scalability for brands managing multiple influencer relationships.Clients: Lyft, Disney, Target, American Eagle, NetflixVisit Ubiquitous → -
8

Obviously
Scalable Enterprise Influencer CampaignsA tech-enabled agency built for high-volume campaigns, coordinating hundreds of creators simultaneously with end-to-end logistics, content rights management, and product seeding.Clients: Google, Ulta Beauty, Converse, AmazonVisit Obviously →
