"Try On" Sunglasses Online? A Court Just Said Your Face Is Worth $5,000
Here's something that should stop you mid-scroll: the same facial measurement — the same data points mapped across your cheekbones, nose, and eyes — can be totally fine under privacy law in one situation, and a potential lawsuit waiting to happen in another. Not because the technology changed. Not because the data is different. Because of why it was collected and who did the collecting.
A federal appeals court recently brought this to life in the most unexpectedly relatable way possible: sunglasses.
Biometric privacy law doesn't just protect "your face data" — it protects your face data differently depending on whether it was collected in a medical context or a retail one, and a new court ruling just made that line a lot sharper.
The Ruling That Changed the Rules for Your Face
Gunnar Optiks sells eyewear. They offer a virtual try-on feature on their website — the kind where you upload a photo or use your camera, and the glasses appear on your face. Cute feature, right? Except that tool doesn't just display glasses on your screen. It maps your facial geometry (the precise measurements and proportions of your face) to figure out how frames will sit on your actual head.
That mapping is biometric data. And in Illinois, biometric data collection is governed by a law called BIPA — the Biometric Information Privacy Act. Passed unanimously by the Illinois legislature in 2008, according to the ACLU of Illinois, BIPA is still the most protective biometric privacy law in the country. It requires companies to get your written consent before collecting your biometric data, tell you what they're doing with it, and have a published policy for destroying it.
Gunnar argued their tool was exempt from BIPA. Their logic: glasses protect your eyes. Eyes are a healthcare matter. Therefore, facial scans taken to fit glasses are healthcare data. Healthcare data has its own federal privacy rules (you've probably seen the acronym HIPAA — the Health Insurance Portability and Accountability Act, basically the big federal law that keeps your medical records private), and BIPA carves out an exception for data collected in actual healthcare contexts.
A lower court agreed with them. Case dismissed.
Then the 7th Circuit Court of Appeals — one step below the Supreme Court — looked at this again and said: not so fast. This article is part of a series — start with Retail Facial Recognition Washington Privacy Gap.
The Prescription Line Is the Actual Line
Here's where it gets genuinely interesting. The appeals court didn't say healthcare exemptions never apply to eyewear. It said the exemption is much more specific than "this product is related to eyes."
The real rule, as it's emerging from courts interpreting BIPA: the healthcare exception applies when a licensed professional collects your biometric data as part of actual medical care — when you're a patient, in a healthcare setting, receiving treatment or a professional fitting. A virtual try-on tool for non-prescription sunglasses on a retail website? That's not a healthcare context. That's shopping.
"An individual trying on non-prescription glasses using software that captures biometric information is not a 'patient in a health care setting.'" — Illinois First District Appellate Court, Freeman Mathis & Gary, citing Marino v. Gunnar Optiks
So here's the surgical distinction the courts are drawing: if you go to an optometrist, and they use a scanning tool to fit your prescription lenses, that's a healthcare context. BIPA steps back. But if you're on a company's website, no doctor in sight, trying on sunglasses for style? BIPA is very much in the room.
Same company. Same technology. Same face scan. Completely different legal outcome — determined entirely by whether you needed a prescription.
That number matters. Under BIPA, as LegalClarity explains, you don't need to show that a company did anything harmful with your face scan. The unauthorized collection itself is the violation. A class action with thousands of customers could mean millions of dollars in exposure — over a virtual try-on feature that took less than a second to run.
Why Your Gut Feeling About This Is Wrong (And Why That's Understandable)
Most of us think about data privacy the way we think about physical belongings. My face is my face. If someone measures it, they measured it — end of story. The same rules should apply whether a store did it or a doctor did it.
That's genuinely intuitive. And it's exactly wrong. Previously in this series: The Scariest Deepfake Isnt A Face Its The Approved Stamp On .
Privacy law is structured around relationships and purposes, not around the data itself. Think of it this way: your blood pressure reading is just a number. But the same number means something completely different depending on whether a doctor recorded it in your chart versus a gym kiosk sent it to a marketing database. The information is identical. The relationship — and therefore the legal protection — is entirely different.
BIPA works the same way with your face. The question isn't "was your facial geometry measured?" The question is: "Who measured it? Were they a licensed healthcare professional? Were you there as a patient seeking care?" If yes to both: healthcare exception may apply. If you're just a person on a website trying to see if those frames look good on you: full BIPA protections kick in, consent required, written policy required, and the company needs a plan for deleting your data.
The reason people get this wrong is completely fair — we've been taught to think "data privacy = protect the data." But BIPA's structure reveals something more specific: protect the person in the relationship where data gets collected. The data is the symptom; the relationship is the diagnosis.
A Building Permit Analogy That Actually Helps
Think about building permits. A contractor can use the same lumber, the same concrete, the same crew to build a house or a hospital. But the legal requirements are completely different — a hospital has specialized oversight, licensed architects, healthcare-specific codes. A house just needs a builder's license and standard inspections.
The materials didn't change. The context changed. And context rewrites the entire rulebook.
Your face measurement is the lumber. The facial geometry scan is technically identical whether a doctor runs it or a sunglasses website does. But the moment it moves from a licensed clinical relationship to a retail transaction, it crosses into a completely different legal framework — and the obligations that come with it are not optional.
At CaraComp, we think about this a lot, because the facial recognition tools that power everything from identity verification to try-on features all start with the same underlying technology. What changes the legal picture isn't the algorithm. It's the context the algorithm operates in — who commissioned it, why, and what relationship the person in front of the camera has to the person running the scan. Up next: Your Face Is Being Scanned At The Grocery Store And Washingt.
What You Just Learned
- 🧠 Same scan, different rules — The same facial geometry measurement has different legal status depending on why and by whom it was collected
- ⚖️ The prescription line is real — Courts are drawing a sharp distinction between clinical eyewear fittings by licensed professionals and retail virtual try-ons, even for the same product type
- 💰 No harm required to sue — Under BIPA, the unauthorized collection itself is the legal injury — up to $5,000 per person per intentional violation, no identity theft needed
- 🗺️ Illinois BIPA reaches far — A company based in any state that collects biometric data from Illinois residents should assume BIPA applies to them, per Quarles Law's analysis of the 7th Circuit ruling
What This Means the Next Time You See "Try It On"
Virtual try-on features are everywhere now. Glasses, hats, makeup, hair color — dozens of apps and retail sites use your camera to map your face and overlay a product. Most people tap "allow camera access" and move on. Which, honestly, is a normal thing to do.
But after the 7th Circuit's ruling, here's a more informed version of that moment: if you're in Illinois (or if the company is collecting data from people in Illinois), that camera permission might carry real legal weight. The company may be required to have a published biometric data policy. They may need your written consent. They definitely need a plan for when they delete your face data.
If none of those things were offered before you hit "allow" — that's not just a bad look. Under BIPA, it may be a violation.
When a company scans your face, the important question isn't just "did they scan it" — it's "in what context?" A retail website trying on sunglasses is not the same as a licensed optometrist fitting prescription lenses, even if the technology is identical. Context is a legal element, not a footnote. Before you tap "allow camera access," it's worth asking: do they have a biometric data policy? Did they ask for your written consent? If not, the law — at least in Illinois — may have something to say about that.
Here's the part that sticks with me most: the 7th Circuit's ruling actually narrowed the healthcare exemption. Companies that thought "we sell an eye-related product, so we're in the clear" now have a harder case to make. More biometric collection now falls under BIPA's full requirements, not less. The law isn't loosening. The walls are getting closer together.
So the next time someone tells you "it's just a virtual try-on, it's not a big deal" — you now know that a federal appeals court looked at the exact same sentence and disagreed. Your face, mapped as data points on a retail website, is not the same as your face measured in a doctor's office. The law sees the difference. The question is whether the companies collecting your face data do, too.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
Your Face, Their Loophole: Court Just Killed the "It's Healthcare" Excuse
You might think biometric privacy law is simple: did a company scan your face or not? A federal court ruling over virtual try-on glasses just proved that's only half the question. The other half is what changes everything.
biometrics"It's Healthcare" Won't Save Your Face Scan Anymore
A major eyewear company tried to dodge Illinois's biometric privacy law by calling its face-scanning app "health-related." A federal appeals court said not so fast — and the real test is one most people don't know exists.
biometrics"Better-Appearing Glasses Are Not Medical Treatment": The 4 Words That Just Changed Your Face-Scan Rights
A federal court just ruled that scanning your face to try on glasses virtually isn't a healthcare activity — and that distinction matters for your privacy rights. Here's what the Gunnar Optiks ruling actually teaches us about when biometric privacy laws apply.
