CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
privacy

Examples of Biometric Data: What BIPA Really Protects

"Try On" Sunglasses Online? A Court Just Said Your Face Is Worth $5,000
A facial scan overlay illustrates examples of biometric data, like the geometric measurements used to fit eyewear online.

Here's something that should stop you mid-scroll: the same facial measurement, the same data points mapped across your cheekbones, nose, and eyes, can be totally fine under privacy law in one situation, and a potential lawsuit waiting to happen in another. Not because the technology changed. Not because the data is different. Because of why it was collected and who did the collecting.

A federal appeals court recently brought this to life in the most unexpectedly relatable way possible: sunglasses.

TL;DR

Biometric privacy law doesn't just protect "your face data", it protects your face data differently depending on whether it was collected in a medical context or a retail one, and a new court ruling just made that line a lot sharper.

BIPA Damages: How This Ruling Changed Facial Privacy

Gunnar Optiks sells eyewear. They offer a virtual try-on feature on their website, the kind where you upload a photo or use your camera, and the glasses appear on your face. Cute feature, right? Except that tool doesn't just display glasses on your screen. It maps your facial geometry (the precise measurements and proportions of your face) to figure out how frames will sit on your actual head.

That mapping is biometric data. And in Illinois, biometric data collection is governed by a law called BIPAthe Biometric Information Privacy Act. Passed unanimously by the Illinois legislature in 2008, according to the ACLU of Illinois, BIPA is still the most protective biometric privacy law in the country. It requires companies to get your written consent before collecting your biometric data, tell you what they're doing with it, and have a published policy for destroying it.

Gunnar argued their tool was exempt from BIPA. Their logic: glasses protect your eyes. Eyes are a healthcare matter. Therefore, facial scans taken to fit glasses are healthcare data. Healthcare data has its own federal privacy rules (you've probably seen the acronym HIPAA, the Health Insurance Portability and Accountability Act, basically the big federal law that keeps your medical records private), and BIPA carves out an exception for data collected in actual healthcare contexts.

A lower court agreed with them. Case dismissed.

Then the 7th Circuit Court of Appeals, one step below the Supreme Court, looked at this again and said: not so fast. This article is part of a series, start with Retail Facial Recognition Washington Privacy Gap.


Biometric Data Definition: Understanding Privacy Boundaries

Here's where it gets genuinely interesting. The appeals court didn't say healthcare exemptions never apply to eyewear. It said the exemption is much more specific than "this product is related to eyes."

The real rule, as it's emerging from courts interpreting BIPA: the healthcare exception applies when a licensed professional collects your biometric data as part of actual medical care, when you're a patient, in a healthcare setting, receiving treatment or a professional fitting. A virtual try-on tool for non-prescription sunglasses on a retail website? That's not a healthcare context. That's shopping.

"An individual trying on non-prescription glasses using software that captures biometric information is not a 'patient in a health care setting.'" Illinois First District Appellate Court, Freeman Mathis & Gary, citing Marino v. Gunnar Optiks

So here's the surgical distinction the courts are drawing: if you go to an optometrist, and they use a scanning tool to fit your prescription lenses, that's a healthcare context. BIPA steps back. But if you're on a company's website, no doctor in sight, trying on sunglasses for style? BIPA is very much in the room.

Same company. Same technology. Same face scan. Completely different legal outcome, determined entirely by whether you needed a prescription.

$5,000
per intentional or reckless BIPA violation, per person, with no actual harm required to sue
Source: Illinois BIPA, via LegalClarity

That number matters. Under BIPA, as LegalClarity explains, you don't need to show that a company did anything harmful with your face scan. The unauthorized collection itself is the violation. A class action with thousands of customers could mean millions of dollars in exposure, over a virtual try-on feature that took less than a second to run.


Why Your Gut Feeling About This Is Wrong (And Why That's Understandable)

Most of us think about data privacy the way we think about physical belongings. My face is my face. If someone measures it, they measured it, end of story. The same rules should apply whether a store did it or a doctor did it.

That's genuinely intuitive. And it's exactly wrong. Previously in this series: The Scariest Deepfake Isnt A Face Its The Approved Stamp On .

Privacy law is structured around relationships and purposes, not around the data itself. Think of it this way: your blood pressure reading is just a number. But the same number means something completely different depending on whether a doctor recorded it in your chart versus a gym kiosk sent it to a marketing database. The information is identical. The relationship, and therefore the legal protection, is entirely different.

BIPA works the same way with your face. The question isn't "was your facial geometry measured?" The question is: "Who measured it? Were they a licensed healthcare professional? Were you there as a patient seeking care?" If yes to both: healthcare exception may apply. If you're just a person on a website trying to see if those frames look good on you: full BIPA protections kick in, consent required, written policy required, and the company needs a plan for deleting your data.

The reason people get this wrong is completely fair, we've been taught to think "data privacy = protect the data." But BIPA's structure reveals something more specific: protect the person in the relationship where data gets collected. The data is the symptom; the relationship is the diagnosis.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

A Building Permit Analogy That Actually Helps

Think about building permits. A contractor can use the same lumber, the same concrete, the same crew to build a house or a hospital. But the legal requirements are completely different, a hospital has specialized oversight, licensed architects, healthcare-specific codes. A house just needs a builder's license and standard inspections.

The materials didn't change. The context changed. And context rewrites the entire rulebook.

Your face measurement is the lumber. The facial geometry scan is technically identical whether a doctor runs it or a sunglasses website does. But the moment it moves from a licensed clinical relationship to a retail transaction, it crosses into a completely different legal framework, and the obligations that come with it are not optional.

At CaraComp, we think about this a lot, because the facial recognition tools that power everything from identity verification to try-on features all start with the same underlying technology. What changes the legal picture isn't the algorithm. It's the context the algorithm operates in, who commissioned it, why, and what relationship the person in front of the camera has to the person running the scan. Up next: Your Face Is Being Scanned At The Grocery Store And Washingt.

What You Just Learned

  • 🧠 Same scan, different rulesThe same facial geometry measurement has different legal status depending on why and by whom it was collected
  • βš–οΈ The prescription line is realCourts are drawing a sharp distinction between clinical eyewear fittings by licensed professionals and retail virtual try-ons, even for the same product type
  • πŸ’° No harm required to sueUnder BIPA, the unauthorized collection itself is the legal injury, up to $5,000 per person per intentional violation, no identity theft needed
  • πŸ—ΊοΈ Illinois BIPA reaches farA company based in any state that collects biometric data from Illinois residents should assume BIPA applies to them, per Quarles Law's analysis of the 7th Circuit ruling

Why "Try It On" Eyewear Features Matter for BIPA Compliance

Virtual try-on features are everywhere now. Glasses, hats, makeup, hair color, dozens of apps and retail sites use your camera to map your face and overlay a product. Most people tap "allow camera access" and move on. Which, honestly, is a normal thing to do.

But after the 7th Circuit's ruling, here's a more informed version of that moment: if you're in Illinois (or if the company is collecting data from people in Illinois), that camera permission might carry real legal weight. The company may be required to have a published biometric data policy. They may need your written consent. They definitely need a plan for when they delete your face data.

If none of those things were offered before you hit "allow", that's not just a bad look. Under BIPA, it may be a violation.

Key Takeaway

When a company scans your face, the important question isn't just "did they scan it", it's "in what context?" A retail website trying on sunglasses is not the same as a licensed optometrist fitting prescription lenses, even if the technology is identical. Context is a legal element, not a footnote. Before you tap "allow camera access," it's worth asking: do they have a biometric data policy? Did they ask for your written consent? If not, the law, at least in Illinois, may have something to say about that.

Here's the part that sticks with me most: the 7th Circuit's ruling actually narrowed the healthcare exemption. Companies that thought "we sell an eye-related product, so we're in the clear" now have a harder case to make. More biometric collection now falls under BIPA's full requirements, not less. The law isn't loosening. The walls are getting closer together.

So the next time someone tells you "it's just a virtual try-on, it's not a big deal", you now know that a federal appeals court looked at the exact same sentence and disagreed. Your face, mapped as data points on a retail website, is not the same as your face measured in a doctor's office. The law sees the difference. The question is whether the companies collecting your face data do, too.

Examples of Biometric Data Courts Actually Litigate

When people ask for examples of biometric data, most think only of fingerprints. But the cases shaping BIPA cover a much wider range: facial geometry from photos, iris scans, voiceprints, and even gait patterns captured by security cameras. Each example of biometric data carries the same core idea, a physical or behavioral trait that's unique enough to identify a specific person, turned into a measurable pattern a computer can store and compare.

Physical Identifiers vs. Behavioral Identifiers

Biometric identifiers generally split into two buckets. Physical identifiers are traits your body has regardless of what you do, facial geometry, fingerprints, iris patterns, and hand shape all fall here. Behavioral identifiers are patterns in how you act, your typing rhythm, your walking gait, or the unique cadence of your voice. Courts treat both categories as biometric data under BIPA, because both can be turned into a template that identifies you as reliably as a name.

Biometric Identifiers in the Gunnar Optiks Case

In the Gunnar Optiks dispute, the biometric identifiers at issue were facial geometry points, the measurements a virtual try-on tool captures to figure out where a nose bridge sits or how wide someone's face is. That's a physical identifier, not a behavioral one, which is part of why the healthcare exemption argument turned on who was doing the measuring and why, not on what kind of biometric data was collected.

A useful way to think about examples of biometric data is to separate what's collected from how it's used. A biometric sample is the raw input, a photo, a voice recording, a fingerprint scan. A biometric template is the mathematical summary a system creates from that sample, the compressed set of measurements it actually stores and compares against future scans. BIPA regulates both stages, because a leaked template can be just as dangerous as a leaked photo if it lets someone impersonate you.

Facial recognition is probably the most familiar example of biometric data in daily life, showing up in phone unlock screens, airport security lines, and retail try-on tools like the one at the center of the Gunnar Optiks case. Voice recognition is a close second, banks and call centers increasingly use voiceprints to confirm identity before discussing your account. Both systems work the same way underneath: capture a sample, extract a template, compare it against a stored reference.

Iris recognition is less common in consumer products but shows up in high-security settings, some government facilities and a handful of phone models use it because the iris has an extremely stable pattern that barely changes over a lifetime. Fingerprint scanning remains the most widely deployed biometric technology overall, built into most smartphones and used for building access across countless offices. Each of these technologies raises the same legal question BIPA is built to answer: who collected this pattern, under what relationship, and with what consent.

Less commonly discussed, but still legally significant, are DNA and blood samples used for identification purposes. These aren't the biometric identifiers at issue in the Gunnar Optiks case, but several state biometric privacy laws, including BIPA, explicitly name genetic markers alongside facial and fingerprint data because they serve the same identifying function, a unique pattern tied permanently to one person.

Biometric information becomes sensitive precisely because it can't be changed. You can reset a password or cancel a credit card after a data breach, but you cannot get a new face or a new set of fingerprints. That permanence is exactly why courts and legislatures treat biometric data collection with more caution than an ordinary data security matter, the security failure, if one happens, has no simple fix.

For businesses building authentication systems, the practical guidance emerging from cases like this one is straightforward: identity verification through biometrics is legal and often more secure than a password, but the security benefits don't override the consent requirements. A company still needs written permission, a retention policy, and a real answer to the question "in what context was this biometric sample collected?" before it can rely on facial recognition, voice recognition, or any other biometric technology to confirm who someone is.

Frequently asked questions

What are examples of biometric data covered under BIPA?

Examples of biometric data include facial geometry scans, like the measurements and proportions mapped across your cheekbones, nose, and eyes when using a virtual try-on tool for eyewear. This kind of facial mapping counts as biometric data under BIPA regardless of the technology used, because it captures unique physical characteristics tied to your identity.

Is a facial scan from a virtual try-on tool considered biometric data?

Yes, a facial scan from a virtual try-on tool is biometric data. When a website tool maps your facial geometry to show how eyewear frames will sit on your face, that mapping qualifies as biometric data under BIPA, triggering requirements like written consent, disclosure of use, and a published data destruction policy.

Does a doctor's office collecting facial measurements count as an example of biometric data under BIPA?

Yes, but the legal treatment differs by context. If a licensed optometrist scans your face to fit prescription lenses as part of patient care, that falls under BIPA's healthcare exception. The same facial geometry data collected through a retail website's non-prescription try-on feature is not exempt, since no doctor or patient relationship exists.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search