Biometric Data Privacy: What Counts as Sensitive Biometric Information
You click "try on" on an eyewear website. Ten seconds later, you see yourself wearing three different frames. Cool feature, right? Here's the thing nobody mentions: in those ten seconds, software may have quietly mapped your face to 468 specific anatomical reference points, measuring the distance between your eyes, the width of your cheekbones, the height of your nose bridge, and stored that geometric blueprint somewhere you can't see or access. You didn't sign anything. You didn't read a disclosure. You just wanted to see if the frames looked good.
A virtual glasses try-on isn't just a photo filter, it measures your facial geometry, and a recent federal court ruling says that data has legal protections companies can't simply sidestep by calling their product health-related.
A recent ruling from the Seventh Circuit, a federal appeals court that covers Illinois, Indiana, and Wisconsin, just made that invisible transaction a lot more visible. And the lesson buried inside this court case is something every online shopper should understand, because it changes how you think about every "try before you buy" feature you've ever clicked.
Virtual Try-On Face Mapping: Photo vs. Biometric Data
This is the part that trips everyone up. When you think "they took a photo of my face," you probably think: so what? Photos are everywhere. Your face is on Facebook, Instagram, your company's website. What's the big deal?
The big deal is the difference between a snapshot and a blueprint.
Think of it this way. A face photo is like a postcard of your house, it shows what the front looks like. Face geometry is the architectural blueprint, it records the actual measurements, distances, and proportions. One tells you what something looks like. The other tells you exactly how it's built. And those are very different things, legally and practically.
Virtual try-on software doesn't just look at your face. It measures it. According to technical documentation reviewed by EDUCBA, these systems detect approximately 468 anatomical reference points across your face, landmarks like the corners of your eyes, the tip of your nose, the edges of your jawline. From those points, the software extracts specific measurements: the distance between your pupils, how wide your face is at the cheekbones, how high your nose bridge sits. It uses those numbers to recommend frames that will physically fit your face. This article is part of a series, start with Retail Facial Recognition Washington Privacy Gap.
That's not a filter. That's a facial geometry extraction. And once software measures you, you've crossed from "person looking at a shopping tool" into "source of regulated biometric data." (Biometric data means the physical measurements unique to your body, your face geometry, fingerprints, voice pattern, iris. The stuff nobody else has in exactly your configuration.)
Virtual Try-On Glasses in Court: A Legal Precedent
Illinois has a law called BIPA, the Biometric Information Privacy Act. It's one of the strongest consumer biometric protection laws in the country. Under BIPA, if a company collects your facial geometry, they have to tell you about it in writing before they collect it. They need your written consent. They can't sell your biometric data. And they have to have a clear, publicly available policy explaining how long they'll keep it and when they'll destroy it.
Violate those rules? Each negligent violation costs $1,000 in statutory damages. Each reckless or intentional one costs $5,000. Per person. Multiply that by the number of people who clicked "try on," and you start to understand why class action lawyers are paying very close attention to virtual fitting rooms.
The eyewear company in this case, a manufacturer of specialty computer glasses, tried a specific legal maneuver. Their glasses are marketed for eye health: reducing blue light exposure, easing digital eye strain. So they argued their product fell under a healthcare exemption in BIPA, which would have shielded them from the law's consent requirements entirely.
The Seventh Circuit didn't buy it.
"Better-appearing glasses are not medical treatment." Judge Frank H. Easterbrook, Law.com
Four words. Entire case revived. The court's point was sharp: just because a product has a health-adjacent purpose doesn't mean the data collection tied to it gets a free pass. The company needed actual evidence that its virtual try-on tool qualified as a healthcare application. Claiming health benefits on the product page isn't the same thing. As DiCello Levitt noted in their case analysis, the court revived the class action and signaled a more skeptical approach to BIPA's healthcare exemption going forward. Previously in this series: Try On Sunglasses Online A Court Just Said Your Face Is Wort.
The company didn't even dispute that facial geometry counts as biometric data under the law. They just hoped the exemption would save them. It didn't.
Why Everyone Gets This Wrong (And It's Not Your Fault)
Here's the misconception that makes this confusing: most people think a virtual try-on is basically a Snapchat filter. You see yourself with dog ears, or in this case, with frames on your face. It feels like a visual trick, the app just drapes an image over your camera feed. Nothing's really being measured, right?
Wrong. And here's exactly why that instinct makes total sense but leads you astray.
The output looks like a filter. Glasses appear on your face. They move when you move. It feels playful and visual. What you can't see is the step happening before that image renders: the software is extracting geometry from your face in real time, crunching those 468 data points, and using the resulting measurements to figure out which frame width actually fits your face proportions. The measurement is invisible. The result looks like magic. You experience the magic and miss the measurement entirely.
According to an analysis by ArentFox Schiff, most companies quietly classify virtual try-on measurements under "usage data" in their privacy policies rather than labeling them as biometric data. That's not an accident. "Usage data" sounds boring and harmless. "Biometric data" sounds like something that belongs in a spy movie. Companies know which one you're more likely to scroll past.
And here's the kicker the Seventh Circuit underlined: Illinois's BIPA explicitly carves out photographs from its protections. A regular photo of your face isn't covered. But, and this is the part that matters, biometric information derived from a photograph absolutely is. The law doesn't care what you started with. It cares what you extracted. Measure a face from a photo, and you've created protected biometric data, even if all you had going in was a selfie. Up next: Your Face Is Being Scanned At The Grocery Store And Washingt.
What You Just Learned
- 🧠 Measurement ≠ photoA snapshot of your face and a geometric map of your face are legally different things, even if both start with your camera.
- 🔬 Healthcare branding isn't a legal shieldSaying your product supports eye health doesn't automatically exempt your data collection from biometric privacy law. Courts want evidence, not marketing copy.
- ⚖️ The damages are real and they stack$1,000 per negligent violation per user means a company with a million try-on sessions is looking at potential exposure that makes settlement look very attractive, very fast.
- 💡 "Usage data" might mean your faceThat phrase in a privacy policy can quietly cover facial geometry measurements. Now you know to look for it.
The Bigger Pattern You Should Know About
This case isn't a one-off oddity. Since BIPA took effect in July 2017, more than 25 cases have been filed in Illinois courts alone against an unexpectedly wide range of businesses, video game companies, food manufacturers, gas stations, even restaurant chains, all over face geometry collection in ordinary, everyday settings. The eyewear case fits into a broad and accelerating wave of enforcement.
That matters because virtual try-on is everywhere now. Glasses, jewelry, hats, makeup, hair color. Furniture companies let you "place" a couch in your living room using your phone's camera. The same underlying technology, facial landmark detection feeding into measurement and recommendation, powers more shopping experiences than most people realize. At CaraComp, where we work with facial comparison technology professionally, this distinction between a face image and face geometry is one we deal with constantly. The court's logic here tracks exactly: it's not what you collected. It's what you extracted from it, and whether you told anyone you were doing it.
The ruling from the Seventh Circuit, as Quarles Law Firm analyzed in their breakdown of the decision, signals that courts are tightening the standards for healthcare exemption claims. Going forward, "we sell a health product" won't be enough. Companies will need to show, with actual evidence, that their data collection qualifies as a healthcare activity. That's a meaningfully higher bar, and it closes a loophole a lot of companies were quietly counting on.
When a shopping site measures your face, not just photographs it, but measures it, that's biometric data collection. Under laws like BIPA, you're entitled to a clear written disclosure and your explicit consent before that happens. If you never saw either, the company may have skipped a legal requirement. Now you know to look for it.
So here's the question worth sitting with: the next time a website asks to access your camera for a "fitting" or a "try-on," you now know there's a difference between a site that drapes a graphic over your image and one that quietly extracts a geometric map of your face. One of those is a filter. The other is a measurement. And measurements, it turns out, have a paper trail, or they're legally supposed to.
What would you want that disclosure to actually say before you click "continue"?
Biometric Law and Why It Treats Faces Differently
Biometric law exists because a face measurement can't be reset the way a password can. If a retailer's database leaks your login, you change it. If it leaks your facial geometry, that measurement is permanently yours and permanently exposed. That's the reasoning behind statutes like BIPA, and it's why courts read biometric law narrowly against the companies collecting the data rather than broadly in their favor.
What Counts as Biometric Information Under the Statute
Biometric information covers more than fingerprints and iris scans. Under Illinois's statute, biometric information includes any data generated from measuring a biological characteristic, including the facial distances a try-on tool calculates. A company doesn't need to store a scan labeled "biometric" for the law to apply; if the underlying number was derived from your face's geometry, it likely qualifies.
Data Retention: How Long Storage Periods Actually Run
Data collected through virtual try-on tools doesn't disappear once your session ends. Companies typically retain it according to whatever schedule sits in their internal policy, and BIPA requires that schedule to be written down and made public. If a shopper never sees a retention policy, that's itself a signal the required disclosure step may have been skipped.
Biometric Data and the Consent Requirement
Biometric data collection under BIPA hinges on consent obtained before, not after, the measurement happens. A pop-up disclosed after you've already tried on ten frames doesn't satisfy the law's timing requirement. The consent has to be informed, written, and given in advance, which is why so many virtual try-on tools now bury a checkbox in onboarding screens that shoppers rarely read.
Biometric Privacy and the Limits of a Healthcare Label
Biometric privacy protections don't evaporate just because a product claims a wellness angle. The Seventh Circuit's ruling made clear that a company must prove its tool functions as genuine healthcare technology, not simply market itself that way. That distinction protects shoppers from companies rebranding ordinary data collection as medical necessity to dodge consent rules.
How Companies Protect, or Fail to Protect, Facial Measurements
To protect biometric data properly, a company needs written policies, secure storage, defined deletion timelines, and upfront consent, all four, not just one. Many virtual try-on providers protect the image you see on screen while doing far less to secure the underlying measurement data sitting in a database. That gap between visible product and invisible storage is exactly where BIPA lawsuits tend to start.
Storage Practices That Trigger Legal Exposure
Storage of facial geometry without a public retention policy is one of the more common BIPA violations, separate from the consent issue entirely. Even a company that gets consent right can still be liable if its storage practices are undocumented or indefinite. Courts have treated silence about storage duration as its own actionable gap, not a minor paperwork lapse.
The Biometric Information Privacy Act's Broader Reach
The Biometric Information Privacy Act was written in 2008, long before virtual try-on tools existed, yet its language reaches them because it defines biometric identifiers by function rather than by specific technology. That drafting choice is why a law aimed originally at fingerprint timeclocks now governs eyewear websites, furniture apps, and makeup filters alike.
Biometric characteristic data, the individual measurements that make up a full facial map, carries the same legal weight whether it's collected by a fingerprint scanner or a try-on camera. The statute doesn't distinguish by device; it looks at what was measured and how it's used afterward.
Collecting biometric information such as pupil distance or jaw width triggers the same written-consent obligation as collecting a fingerprint, because the statute treats both as biometric identifiers derived from the body. Destroying biometric records on schedule is just as legally required as collecting them properly in the first place, and companies that skip a destruction policy remain exposed even years after collection stopped.
An individual's bodily privacy interest doesn't depend on whether the measurement came from a scanner in a lab or a camera on a phone. Privacy legislation like BIPA was built around that idea: the source of the measurement matters less than the fact that it was taken from a living person's body without their informed agreement. This is also why security failures around biometric databases carry outsized risk, a breach doesn't just expose a password, it exposes a measurement the person can never change, which is part of why regulators and plaintiffs' attorneys treat biometric security lapses more seriously than typical data breaches.
Biometric information kept in a retailer's database is only as protected as the security controls wrapped around that database, and weak security turns a routine breach into a permanent exposure of biometric data that no password reset can fix. A company that collects facial geometry but skimps on encryption, access limits, or breach monitoring has not actually protected the biometric information it promised to safeguard in its written policy. That mismatch between stated policy and real security practice is exactly the kind of gap plaintiffs point to when a case moves forward.
Sensitive biometric information carries more legal weight than ordinary account data because it describes a physical trait a person cannot change after a breach. Regulators increasingly treat sensitive biometric categories, face geometry, fingerprints, iris patterns, voiceprints, as requiring stricter handling than a name or an email address, since biometric information can be used to identify someone across many different systems for the rest of their life. That heightened sensitivity is part of why disclosure and consent rules for biometric data are written more strictly than the rules governing typical marketing data collection.
Disclosure of biometric data collection has to happen before the measurement, not folded into a lengthy terms-of-service page a shopper never opens. A disclosure that simply exists somewhere on a website does not satisfy BIPA if it was never presented to the person in a way that let them meaningfully say yes or no. Courts examining these cases have focused less on whether a policy existed in theory and more on whether an actual person saw it and agreed to it before their face was measured.
Risk grows with every additional business collecting facial geometry without a compliance program built around consent, retention limits, and security. A single lawsuit under BIPA can expose a company to statutory damages multiplied across every person who used a try-on tool, which is why the financial risk scales with the size of the user base rather than the size of any actual harm. Compliance with biometric privacy law is not a one-time checkbox; it requires an ongoing policy covering collection, storage, and eventual destruction of the biometric information a company holds.
Verification of a person's identity through facial geometry is one of the more common downstream uses of the same measurement data collected during a try-on session, since the underlying face map can be repurposed for authentication long after the original shopping purpose ends. That reuse is exactly why biometric data privacy rules require companies to state, in advance, what the collected measurements will be used for and whether verification or any secondary purpose is part of that plan.
Collection of biometric data without meeting BIPA's written-policy and consent requirements remains the most frequent basis for a lawsuit, more common than disputes over security or retention alone. Laws like BIPA were built around the idea that collection itself is the moment that matters most, because everything downstream, storage, use, eventual deletion, depends on whether that first step was handled lawfully. Data privacy protections for biometric information continue to expand well beyond Illinois, with more states drafting laws that borrow BIPA's structure of written disclosure, informed consent, and a public retention schedule.
Frequently asked questions
What counts as biometric data under privacy laws like BIPA?
Biometric data refers to physical measurements unique to your body, such as face geometry, fingerprints, voice pattern, or iris structure. In the case of virtual try-on tools, software detects roughly 468 anatomical reference points on a face and extracts measurements like pupil distance and cheekbone width, which qualifies as biometric data even though the input was just a photo or camera feed.
Is a photo of my face the same as biometric data privacy protection?
No. A photo itself is explicitly carved out from BIPA's protections, but biometric information derived from that photo is fully covered. If software measures facial geometry from an image, such as distances between features, it has created regulated biometric data, regardless of the fact that it started as an ordinary picture.
Can a company avoid biometric data privacy rules by calling its product health-related?
Not automatically. A specialty eyewear company argued its virtual try-on tool was exempt from BIPA because the glasses were marketed for eye health, but the Seventh Circuit rejected that defense, stating that better-appearing glasses are not medical treatment. Companies need actual evidence their tool qualifies for a healthcare exemption, not just health claims on a product page.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
ID Scan Data Breach: 170 Million Faces Can't Be Reset
A reported id scan data breach exposed 170 million ID scans. Here's what's actually inside one of those scans, and why replacing your card doesn't undo the damage.
facial-recognitionBiometric Entry: One Setting Flags 42% of Real Fans
A stadium gate that reads your face in under a second isn't proof of a perfect system — it's proof someone chose which kind of mistake to allow. Here's how that choice actually works.
biometricsBiometric Building Access Control: 3 Checks, Not 1
A face match at your building's front door proves who you are — but not that you're allowed in. Here's the three-step check most people never think about, and why NYC lawmakers and building owners are fighting over exactly that gap.
