Body data and virtual try-on: privacy rules and consent patterns
Virtual try-on and size tools collect photos and measurements. What the GDPR and Illinois BIPA require, when body data becomes special category data, and consent patterns that work.

KEY TAKEAWAYS Summary by the editors
- Under GDPR Article 9, biometric data is a special category only when processed to uniquely identify a person, so whether a try-on or measurement tool triggers the stricter regime depends on what it does with images and measurements; get legal advice per feature.
- Where explicit consent is the basis, GDPR Article 7 requires that the controller can demonstrate it, that the request is clearly distinguishable from other matters, and that withdrawal is as easy as giving consent.
- Data minimisation and storage limitation under Article 5 favour processing on the device, deleting images after measurement and keeping only what the purpose needs.
- Illinois' Biometric Information Privacy Act requires consent before collecting biometric identifiers and provides a private right of action with damages of $1,000 per violation, or $5,000 if intentional or reckless.
- Zalando told Just Style in 2023 that photos used by its body measurement tool did not leave customers' phones and that customers controlled data sharing, an example of a privacy-by-design pattern that other retailers can adopt.
Virtual try-on and body measurement tools can fall under strict privacy rules because they process photos, body measurements and sometimes face data. Whether the data counts as special category or biometric data depends on the purpose and the technology, so retailers should decide the legal basis per feature, collect the minimum, and give customers a clear, revocable choice. This article is an editorial overview, not legal advice.
Why is body data a privacy issue for fashion retailers?
Fit and try-on tools need personal inputs: height and weight, measurements derived from photos or a phone video, or a photo used to render clothes on the customer. Zalando's measurement tool, for example, asks customers for two photos of themselves in well-fitting clothing, as Just Style reported in 2023. Such inputs can reveal health information, body shape and, in the case of face images, identity. Even when a retailer only wants to recommend a size, the data can be sensitive in the hands of attackers or in the wrong context.
When does the GDPR treat this as special category data?
Article 9 of the GDPR prohibits processing special categories of personal data, which include genetic data, data concerning health and biometric data processed to uniquely identify a natural person. The article does not define biometric data further. A measurement tool that only calculates dimensions to suggest a size is not obviously identifying anyone, but a face scan used to recognise a returning customer would be. Health data can arise where measurements allow inferences about a person's health. These boundaries are contested and depend on the facts, so document the analysis for each feature.
The main exception for retail is explicit consent under Article 9(2)(a), unless EU or Member State law says the prohibition cannot be lifted by the individual. Article 9(4) also lets Member States keep or add further conditions for genetic, biometric or health data, so national rules can add requirements.
| Feature | Data involved | Key privacy questions |
|---|---|---|
| Size recommendation from purchase history | Past orders, returns | Is profiling transparent, and can the customer opt out? |
| Size recommendation from photos or video | Body images, derived measurements | Are images deleted after measurement, and do they stay on the device? |
| Avatar or 3D fitting room | Body measurements, avatar model | How long is the avatar kept, and can the customer delete it? |
| Photo based try-on (customer's own image) | Face and body images | Is any face recognition used, and is the image used to train models? |
| Aggregated measurement datasets for size charts | Anonymised body measurements | Is the data truly anonymised, and was consent for this use obtained? |

What does valid consent look like?
Article 7 sets out conditions. The controller must be able to demonstrate that the person consented. A consent request inside a wider declaration must be clearly distinguishable from other matters, intelligible, easily accessible and written in clear, plain language. People can withdraw consent at any time, must be told so before consenting, and withdrawal must be as easy as giving consent. In assessing whether consent is freely given, a key question is whether a service depends on consent to processing that the service does not need.
- Ask at the moment of use, with a short explanation of what is captured, why, for how long and who sees it.
- Use a separate, unticked choice for each purpose, and do not bundle try-on consent with marketing or terms of service.
- Offer an equivalent route without body data, such as a manual size guide, so refusing does not block purchase.
- Provide a visible control to view, export and delete the stored profile, and make withdrawal one tap.
- Log the consent version, time and scope so that you can demonstrate it later.
How do data minimisation and storage limits shape the design?
Article 5 requires personal data to be limited to what is necessary for the purpose, kept in identifiable form no longer than needed, used for specified purposes and kept accurate. In try-on design this points to concrete choices: process images on the device, extract only the measurements needed, delete the images immediately, expire dormant profiles, and avoid reusing customer images for model training unless a separate, specific consent is given. Zalando told Just Style that photos in its body measurement tool do not leave customers' phones and that customers control their data-sharing preferences. That is the retailer's own statement, but it illustrates the pattern.
Using aggregated body data to improve size charts can be valuable, but anonymisation must be real, and purpose limitation means consent or another lawful basis should cover that second use.
What does the Illinois BIPA add for retailers selling in the US?
Illinois' Biometric Information Privacy Act, signed on 3 October 2008, requires private entities to obtain consent before collecting or disclosing biometric identifiers, to store them securely and to destroy them in a timely manner. It gives individuals a private right of action, with damages of $1,000 per violation and $5,000 if the violation is intentional or reckless. In 2019 the Illinois Supreme Court held in Rosenbach v. Six Flags that plaintiffs need not prove actual injury, and a $650 million settlement was approved in 2021 in the Facebook biometric litigation. Whether a particular try-on feature collects biometric identifiers, such as face geometry, turns on the statute's definitions, so check each feature before launching in Illinois. Other US states have their own rules.

What should a retailer do before launching?
- Map each data flow: what is captured, where it is processed, who is the processor, where it is stored and when it is deleted.
- Complete a data protection impact assessment where the processing is likely to carry high risk, and record the legal basis per feature.
- Check vendor contracts for restrictions on using your customers' images to train the vendor's models.
- Test the consent flow with real users for clarity, and measure refusal rates as a product metric.
- Prepare an incident plan, because body images and measurements are more damaging to customers if leaked than a typical order history.
Frequently asked questions
Is virtual try-on data biometric data under the GDPR?
Not automatically. Article 9 covers biometric data processed to uniquely identify a person. A tool that only derives measurements to suggest a size may fall outside that, while one that uses face recognition would be inside it. The analysis depends on the facts and local law, so seek legal advice.
Do retailers need explicit consent for body measurement tools?
Where the data is special category data, explicit consent is the main available ground for retailers. Even where it is not, a clear and revocable consent choice is good practice. Under Article 7, consent must be demonstrable, distinguishable from other matters and as easy to withdraw as to give.
Can retailers use customers' try-on photos to train AI models?
Only with a lawful basis covering that separate purpose, which for sensitive images usually means specific consent. Purpose limitation in Article 5 restricts reuse beyond the original purpose, and vendor contracts should state whether images are used for training.
What is the Illinois Biometric Information Privacy Act?
A state law, signed on 3 October 2008, requiring consent before collecting biometric identifiers, secure storage and timely destruction. It allows private lawsuits with damages of $1,000 per violation, or $5,000 where the violation is intentional or reckless.
One edition every weekday morning. Read in five minutes. Free for industry professionals.




