A nine-figure beauty brand just got a costly lesson in biometric law: face-scanning technology isn’t a marketing feature, it’s a regulated data process. The Charlotte Tilbury biometric fine should be required reading for every brand running or planning an AI virtual try-on tool, because the same mistakes are sitting in dozens of martech stacks right now.
If your team has shipped a “try before you buy” AR feature without a biometric-specific legal review, you’re not alone. You’re also not covered.
What Actually Happened With Charlotte Tilbury
Charlotte Tilbury’s Magic Mirror and Virtual Try-On tools scan a user’s face to map makeup shades, contours, and skin tone in real time. That’s convenient for shoppers. It’s also a biometric identifier under laws like Illinois’ Biometric Information Privacy Act (BIPA), which requires explicit written consent, disclosed retention schedules, and a public data destruction policy before any facial geometry is captured.
Regulators and plaintiffs’ attorneys alleged the brand collected facial scan data without meeting those threshold requirements. The result: a settlement that adds Charlotte Tilbury to a growing list of beauty and retail brands, alongside prior actions tied to other AR try-on providers, that have paid out for skipping consent architecture in favor of shipping fast.
Facial geometry captured for a “fun” try-on filter is legally indistinguishable from a fingerprint scan in states with biometric privacy statutes. Treat it with the same caution, or pay the same price.
This isn’t an isolated incident. Our earlier coverage of a multi-million dollar biometric settlement in the try-on space flagged the exact same pattern: fast deployment, thin consent language, no retention clock. Brands keep making this mistake because AI vendors sell the technology, not the compliance framework around it.
Why This Keeps Happening
Three forces collide here. Marketing wants frictionless UX (no one wants a five-click consent wall before a lipstick swatch). Legal teams are often looped in after the tool is already live. And most AR/AI vendors treat biometric compliance as the brand’s problem, not theirs, buried in a vendor contract’s indemnification clause nobody reads closely.
Add to that a patchwork of state laws. BIPA in Illinois carries statutory damages of $1,000–$5,000 per violation, which is why class actions there get expensive fast. Texas and Washington have their own biometric statutes with different notice requirements. California folds biometric data into CCPA’s sensitive personal information category, triggering opt-out rights rather than opt-in consent. There is no single national standard, which means a try-on tool compliant in one state can be a liability magnet in another.
The Compliance Checklist: Nine Things to Verify Before Launch
Use this as a pre-launch gate, not a post-mortem. Every item should have a named owner and a sign-off date.
- Explicit, standalone consent capture. A general privacy policy checkbox does not satisfy BIPA or similar statutes. Consent language for biometric capture must be separate, specific, and require an affirmative action, not a pre-checked box.
- Written retention and destruction schedule. Publish how long facial scan data is stored and the exact trigger for deletion (end of session, 30 days, account closure). Vague language like “as needed for business purposes” is what triggered prior settlements.
- Data minimization by design. Ask whether you need to store the biometric template at all, or whether on-device processing with no server-side retention meets the use case. Our data minimization policy framework walks through this tradeoff in detail.
- Third-party vendor audit. Get contractual confirmation from your AR/AI vendor on where facial data is processed, whether it’s used to train models, and whether it’s shared with sub-processors. If the vendor can’t answer this in writing, that’s a red flag.
- Geofenced consent flows. Illinois, Texas, and Washington require different disclosure language. Your consent modal should detect jurisdiction and serve the applicable notice, not a one-size-fits-all disclaimer.
- Right to delete, honored quickly. Users need a real, findable way to request deletion of their facial scan data, and your team needs an SLA (30 days is a reasonable benchmark) to actually execute it.
- No biometric data reuse for ad targeting. If your try-on tool’s facial data ever feeds a lookalike audience model or personalization engine beyond the immediate session, that’s a separate consent event requiring its own disclosure.
- Employee and contractor training. Whoever manages the AR vendor relationship should understand biometric law basics, not just campaign KPIs.
- Documented legal review before launch, not after. This sounds obvious. It is routinely skipped when marketing timelines compress around product launches or seasonal campaigns.
Notice what’s missing from that list: nothing about turning off the feature. Virtual try-on drives real conversion lift, often cited in the double digits for beauty and eyewear categories. The fix isn’t abandoning AI-powered AR. It’s building consent infrastructure that matches the risk.
How This Connects to Broader Biometric and Privacy Trends
The Charlotte Tilbury case doesn’t exist in isolation. It’s part of a wave of biometric consent litigation touching everything from AR filters to loyalty program facial recognition. We’ve previously broken down what brands must fix under GDPR and CCPA biometric consent rules, and the enforcement pattern is consistent: regulators go after retention gaps and consent ambiguity first, accuracy of the AI second.
It also overlaps with adjacent compliance zones your team may already be tracking. AI-driven personalization tied to loyalty programs raises similar GDPR and CCPA data pipeline questions. If your brand runs try-on tools and loyalty-linked facial recognition, treat both under the same governance umbrella rather than as separate legal reviews.
Regulators consistently penalize retention ambiguity and consent shortcuts before they scrutinize whether the AI itself works well. Fix the paperwork first.
What Brand and Agency Teams Should Do This Quarter
Start with an inventory. List every tool in your stack that captures a camera feed, uploads a photo, or scans a face, even briefly. That includes AR filters, virtual try-on, video-based skin analysis quizzes, and AI shopping assistants that ask users to upload a selfie for “personalized” recommendations.
For each tool, answer: where does the facial data go, how long is it kept, and can the vendor prove it in writing? If the answer is “we’re not sure,” that’s your priority fix. Legal and marketing should co-own this audit, not hand it off entirely to IT or an outside agency.
Budget for it too. A proper biometric compliance retrofit, updated consent flows, vendor contract renegotiation, legal review, isn’t free, but it’s a fraction of what a class action settlement costs. Charlotte Tilbury’s payout, and the earlier AR try-on consent failures we’ve covered, make that math easy.
Industry benchmarks from eMarketer continue to show AR shopping features growing as a conversion driver, and Statista data on consumer AR adoption suggests this isn’t a passing trend. The tools are staying. The compliance bar is just rising to meet them, and the FTC has signaled increasing interest in AI-driven consumer data practices broadly, not just biometric-specific statutes.
FAQ
Frequently Asked Questions
What was the Charlotte Tilbury biometric fine actually about?
The fine stemmed from allegations that Charlotte Tilbury’s AI-powered virtual try-on and Magic Mirror tools collected facial scan data without meeting biometric privacy law requirements, including explicit consent and a published retention and destruction schedule.
Does BIPA apply to brands outside Illinois?
BIPA applies to any company that collects biometric data from Illinois residents, regardless of where the company is headquartered. Similar statutes exist in Texas and Washington, and CCPA treats biometric data as sensitive personal information in California.
Is a general privacy policy enough to cover biometric consent?
No. Most biometric privacy statutes require standalone, specific consent for biometric data collection, separate from a general privacy policy or terms of service acceptance.
Can brands still use AI virtual try-on tools safely?
Yes. The technology itself isn’t the liability. The risk comes from skipping consent architecture, retention disclosures, and vendor due diligence. Brands that build these controls in before launch can keep using try-on tools with substantially lower legal exposure.
Who should own biometric compliance review internally?
Legal and marketing should co-own it, with IT or the martech vendor providing technical documentation on data flow. Treating it as purely a legal or purely a technical issue tends to create gaps.
How often should brands audit AR and AI try-on vendors?
At minimum annually, and any time the vendor updates its data processing terms, model training practices, or sub-processor list.
Pull your AR and AI try-on tools into a single compliance inventory this week, assign an owner to each of the nine checklist items above, and get legal sign-off before your next campaign launch, not after a complaint lands.
Top Influencer Marketing Agencies
The leading agencies shaping influencer marketing in 2026
Agencies ranked by campaign performance, client diversity, platform expertise, proven ROI, industry recognition, and client satisfaction. Assessed through verified case studies, reviews, and industry consultations.
Moburst
-
2

The Shelf
Boutique Beauty & Lifestyle Influencer AgencyA data-driven boutique agency specializing exclusively in beauty, wellness, and lifestyle influencer campaigns on Instagram and TikTok. Best for brands already focused on the beauty/personal care space that need curated, aesthetic-driven content.Clients: Pepsi, The Honest Company, Hims, Elf Cosmetics, Pure LeafVisit The Shelf → -
3

Audiencly
Niche Gaming & Esports Influencer AgencyA specialized agency focused exclusively on gaming and esports creators on YouTube, Twitch, and TikTok. Ideal if your campaign is 100% gaming-focused — from game launches to hardware and esports events.Clients: Epic Games, NordVPN, Ubisoft, Wargaming, Tencent GamesVisit Audiencly → -
4

Viral Nation
Global Influencer Marketing & Talent AgencyA dual talent management and marketing agency with proprietary brand safety tools and a global creator network spanning nano-influencers to celebrities across all major platforms.Clients: Meta, Activision Blizzard, Energizer, Aston Martin, WalmartVisit Viral Nation → -
5

The Influencer Marketing Factory
TikTok, Instagram & YouTube CampaignsA full-service agency with strong TikTok expertise, offering end-to-end campaign management from influencer discovery through performance reporting with a focus on platform-native content.Clients: Google, Snapchat, Universal Music, Bumble, YelpVisit TIMF → -
6

NeoReach
Enterprise Analytics & Influencer CampaignsAn enterprise-focused agency combining managed campaigns with a powerful self-service data platform for influencer search, audience analytics, and attribution modeling.Clients: Amazon, Airbnb, Netflix, Honda, The New York TimesVisit NeoReach → -
7

Ubiquitous
Creator-First Marketing PlatformA tech-driven platform combining self-service tools with managed campaign options, emphasizing speed and scalability for brands managing multiple influencer relationships.Clients: Lyft, Disney, Target, American Eagle, NetflixVisit Ubiquitous → -
8

Obviously
Scalable Enterprise Influencer CampaignsA tech-enabled agency built for high-volume campaigns, coordinating hundreds of creators simultaneously with end-to-end logistics, content rights management, and product seeding.Clients: Google, Ulta Beauty, Converse, AmazonVisit Obviously →
