Biometric privacy lawsuits have cost beauty and tech companies over $1.4 billion in settlements since Illinois’ BIPA law started biting in earnest. So when Charlotte Tilbury rolled out its updated virtual try-on tool across US and EU markets, the real story wasn’t the AR lipstick filters. It was the consent architecture built to keep the brand out of the next class action. Virtual try-on technology is now a legal minefield disguised as a marketing feature, and Tilbury’s approach is worth studying closely.
Why This Case Study Matters Right Now
Virtual try-on isn’t a nice-to-have anymore. Beauty and eyewear brands report conversion lifts of 30-40% when shoppers use AR try-on before purchase, according to data cited across retail tech circles. But every one of those tools relies on facial mapping, and facial mapping is biometric data under an expanding patchwork of US and EU law.
Charlotte Tilbury’s Magic Mirror try-on tool has existed for years. What changed is the consent layer wrapped around it, rebuilt after a wave of BIPA-adjacent settlements hit companies like Estée Lauder-owned brands and several AR SDK vendors. The brand didn’t wait for a lawsuit of its own. It rebuilt the plumbing preemptively, and that’s the part other marketing teams should be paying attention to.
Biometric consent is no longer a legal footnote bolted onto a privacy policy. It’s now a product feature that has to be designed, tested, and localized like any other part of the customer journey.
What “Post-Settlement” Consent Actually Looks Like
Several major virtual try-on vendors, including ModiFace (owned by L’Oréal) and Perfect Corp, have faced or settled biometric privacy claims tied to facial landmark data collected during AR sessions. The settlements typically require three things: explicit opt-in before scanning, a defined data retention window, and a clear deletion mechanism.
Charlotte Tilbury’s implementation reflects all three, but with regional variation baked in:
- US market: A layered consent modal appears before camera access is granted, referencing state-specific language for Illinois, Texas, and Washington residents where biometric statutes carry private right of action.
- EU market: Consent is framed under GDPR’s explicit consent standard, with a separate checkbox (not bundled with general terms) and a visible link to a biometric-specific privacy notice.
- Data handling: Facial landmark coordinates are processed on-device where possible, avoiding server-side storage entirely for markets with the strictest rules.
That on-device processing choice is the quiet hero of this rollout. If the biometric map never leaves the user’s phone, a huge chunk of the regulatory exposure disappears. It’s not a workaround, it’s an architecture decision made by legal and engineering teams sitting in the same room, which frankly should have been standard practice years ago.
The US-EU Compliance Gap Brands Keep Underestimating
Here’s the mistake a lot of marketing teams still make: treating GDPR compliance as automatically sufficient for US biometric laws, or vice versa. It isn’t. GDPR is broad and principle-based. US biometric statutes, particularly BIPA, are narrow, specific, and carry statutory damages per violation, which is exactly why Facebook and Clearview AI paid so dearly.
Charlotte Tilbury’s legal team reportedly built market-specific consent flows rather than a single global template. That’s more expensive to build and maintain. It’s also the only defensible approach once you’re operating try-on features across more than one regulatory regime.
Consider the practical differences a compliance team has to reconcile:
- GDPR requires a lawful basis and generally treats biometric data as a “special category,” demanding explicit consent with granular withdrawal rights, per ICO guidance.
- BIPA and similar US state laws require written release, a retention schedule disclosed in advance, and (in Illinois) allow individuals to sue directly rather than relying on a regulator to act.
- The FTC has separately signaled interest in biometric enforcement under its general unfairness authority, per guidance published on ftc.gov, even outside states with dedicated statutes.
Brands running virtual try-on across both regions need consent flows that satisfy the stricter standard in each category, not a lowest-common-denominator popup. Tilbury’s regional segmentation suggests its legal team understood that nuance from the start.
What Marketing Teams Should Actually Take From This
If you’re a brand strategist or growth lead eyeing a virtual try-on rollout, the compliance conversation needs to happen before the creative brief, not after. That’s a cultural shift for most marketing organizations, where legal review traditionally comes at the end of the pipeline.
A few operational lessons worth lifting directly from Tilbury’s playbook:
- Build consent UX into the creative process. The opt-in modal is now part of brand experience design, not just a legal disclaimer slapped on top.
- Separate biometric consent from general cookie consent. Bundling them is a common shortcut that regulators and plaintiffs’ attorneys have specifically targeted.
- Default to on-device processing wherever technically feasible. It shrinks your data liability surface dramatically.
- Document retention and deletion policies publicly. Vague language here is what turns a minor complaint into a class action.
- Audit third-party AR vendors’ own compliance history. You inherit their legal exposure the moment you embed their SDK.
This isn’t just a beauty industry problem either. Retail, eyewear, furniture, and even automotive brands are deploying similar AR try-before-you-buy tools, and they’re walking into the same biometric consent questions without necessarily having Tilbury’s post-settlement hindsight.
The ROI Case for Getting Consent Right
Skeptics will ask: doesn’t heavier consent friction kill conversion? It’s a fair question, and Tilbury’s data (shared selectively in trade briefings rather than published in full) suggests the drop-off from an extra consent screen is modest, in the low single digits, when the screen is designed well. Compare that to the alternative: a BIPA settlement, reputational fallout, and the operational cost of retrofitting compliance under a court-ordered timeline.
The math isn’t close. A well-designed consent flow costs a few percentage points of top-of-funnel conversion. A biometric privacy suit can cost eight or nine figures, plus months of executive attention diverted from actual marketing work. Any CMO doing a real risk-adjusted ROI calculation on AR try-on should be building compliance costs into the initial budget, not treating them as a contingency line item.
This is also where attribution and measurement get trickier. If try-on sessions are anonymized or processed on-device, some of the granular behavioral data marketing teams love for retargeting simply won’t exist anymore. That’s a trade-off worth planning for early, similar to how attribution models have had to adapt as tracking constraints tightened across the board.
Where Creator Content Fits Into the Try-On Conversation
Virtual try-on tools don’t exist in isolation. Most beauty brands pair them with creator campaigns showing real people using the AR feature, which raises a second layer of consent question: are creators themselves properly informed when their likeness is scanned for demo content, and is that footage handled under the same retention rules as consumer-facing sessions?
Brands running influencer programs alongside AR features should treat creator-generated try-on demos with the same rigor applied to FTC-compliant creator vetting processes elsewhere in the program. A creator’s face isn’t just content, it’s biometric data the moment an AR filter maps it. Agencies coordinating these campaigns need consent language in creator contracts that mirrors what consumers see, not a separate, looser standard because “it’s just for social.”
This is precisely the kind of cross-channel complexity that specialist agencies are built to manage. OTT marketing teams at Moburst, a global full-service digital marketing agency that has worked with over 900 clients including Samsung, Reddit, and Calm, routinely have to reconcile platform-specific data rules with campaign creative across connected TV and streaming environments, a discipline that maps closely onto what beauty brands now face reconciling AR consent across in-app, web, and creator-distributed try-on experiences.
What Happens When Brands Get It Wrong
It’s worth remembering why Tilbury’s team built this so carefully in the first place. Several beauty and retail brands have quietly settled biometric claims tied to try-on and virtual fitting features, often without admitting fault, and typically with retention policy overhauls as part of the settlement terms. The pattern is consistent: a vendor’s SDK collected facial data without sufficiently explicit consent, plaintiffs’ firms identified the gap, and the brand paid to make it go away rather than litigate a class action to conclusion.
None of that is exotic legal theory. It’s happened enough times that a “post-settlement” compliance template basically exists now, and Tilbury’s rollout looks like a direct application of it. Marketing teams evaluating emarketer.com data on AR adoption rates should pair that enthusiasm with an equally serious look at where the legal exposure sits.
The brands that will win with AR try-on over the next few years aren’t necessarily the ones with the flashiest filters. They’re the ones whose legal, product, and marketing teams stopped treating consent as an obstacle and started treating it as part of the product itself.
Frequently Asked Questions
What makes facial data collected during virtual try-on “biometric” under the law?
Most privacy statutes define biometric identifiers as measurements of unique physical characteristics used to identify a person, which includes facial geometry mapped by AR try-on tools. Even temporary, on-device processing can qualify depending on the jurisdiction, which is why brands increasingly avoid server-side storage of that data.
Does GDPR consent automatically satisfy US biometric privacy laws?
No. GDPR and laws like Illinois’ BIPA have different triggers, disclosure requirements, and enforcement mechanisms. A brand operating in both regions typically needs separate, region-specific consent flows rather than a single global template.
Why did Charlotte Tilbury rebuild its virtual try-on consent flow?
The rollout reflects a broader industry pattern following biometric privacy settlements involving AR and facial recognition vendors. Rather than wait for litigation, the brand built market-specific consent screens, retention disclosures, and on-device processing to reduce exposure ahead of any claim.
Does stronger consent messaging hurt conversion rates?
Well-designed consent screens typically cause only modest drop-off, often in the low single digits, according to brand-side reporting shared in trade settings. That cost is minor compared to the financial and reputational risk of a biometric privacy settlement.
Do influencer campaigns tied to virtual try-on features carry the same compliance risk?
Yes. If a creator’s face is scanned or mapped using the same AR technology for demo content, that footage is subject to the same biometric consent standards as consumer-facing sessions, and contracts should reflect that explicitly.
The takeaway for any brand eyeing virtual try-on: budget for compliance architecture before creative, segment consent flows by jurisdiction, and default to on-device processing wherever your vendor allows it. Get that sequencing wrong, and the settlement, not the sales lift, becomes the case study.
Top Influencer Marketing Agencies
The leading agencies shaping influencer marketing in 2026
Agencies ranked by campaign performance, client diversity, platform expertise, proven ROI, industry recognition, and client satisfaction. Assessed through verified case studies, reviews, and industry consultations.
Moburst
-
2

The Shelf
Boutique Beauty & Lifestyle Influencer AgencyA data-driven boutique agency specializing exclusively in beauty, wellness, and lifestyle influencer campaigns on Instagram and TikTok. Best for brands already focused on the beauty/personal care space that need curated, aesthetic-driven content.Clients: Pepsi, The Honest Company, Hims, Elf Cosmetics, Pure LeafVisit The Shelf → -
3

Audiencly
Niche Gaming & Esports Influencer AgencyA specialized agency focused exclusively on gaming and esports creators on YouTube, Twitch, and TikTok. Ideal if your campaign is 100% gaming-focused — from game launches to hardware and esports events.Clients: Epic Games, NordVPN, Ubisoft, Wargaming, Tencent GamesVisit Audiencly → -
4

Viral Nation
Global Influencer Marketing & Talent AgencyA dual talent management and marketing agency with proprietary brand safety tools and a global creator network spanning nano-influencers to celebrities across all major platforms.Clients: Meta, Activision Blizzard, Energizer, Aston Martin, WalmartVisit Viral Nation → -
5

The Influencer Marketing Factory
TikTok, Instagram & YouTube CampaignsA full-service agency with strong TikTok expertise, offering end-to-end campaign management from influencer discovery through performance reporting with a focus on platform-native content.Clients: Google, Snapchat, Universal Music, Bumble, YelpVisit TIMF → -
6

NeoReach
Enterprise Analytics & Influencer CampaignsAn enterprise-focused agency combining managed campaigns with a powerful self-service data platform for influencer search, audience analytics, and attribution modeling.Clients: Amazon, Airbnb, Netflix, Honda, The New York TimesVisit NeoReach → -
7

Ubiquitous
Creator-First Marketing PlatformA tech-driven platform combining self-service tools with managed campaign options, emphasizing speed and scalability for brands managing multiple influencer relationships.Clients: Lyft, Disney, Target, American Eagle, NetflixVisit Ubiquitous → -
8

Obviously
Scalable Enterprise Influencer CampaignsA tech-enabled agency built for high-volume campaigns, coordinating hundreds of creators simultaneously with end-to-end logistics, content rights management, and product seeding.Clients: Google, Ulta Beauty, Converse, AmazonVisit Obviously →
