8 October 2026International edition
Vol. I · No.
8 October 2026
AI in Fashion
DAILY
The daily briefing on AI in the fashion business
Where fashion meets artificial intelligence.
Commerce & Marketing · Guide

Can fashion retailers use customer data to train AI under GDPR?

Personalisation, recommendations and chatbots run on customer data. How legal basis, transparency, profiling rules and data subject rights apply when fashion e-commerce uses that data for AI.

KEY TAKEAWAYS Summary by the editors

  1. Fashion retailers can use customer data for AI under GDPR if they have a valid legal basis, inform customers, minimise data and respect their rights; legitimate interest is a common basis for AI development.
  2. France's CNIL sets three conditions for relying on legitimate interest in AI development: a lawful and clearly defined interest, necessity, and no disproportionate impact on individuals.
  3. Under Article 21 GDPR, customers can object at any time to processing for direct marketing, including related profiling, after which the data may no longer be used for that purpose.
  4. Article 22 GDPR gives individuals the right not to be subject to solely automated decisions with legal or similarly significant effects, subject to exceptions and safeguards.
  5. The CNIL notes that data subject rights apply to training datasets and, where a model is not anonymous, to the model itself, which may require retraining or output filters.

Yes, but not freely. A fashion retailer can use purchase histories, browsing behaviour or service conversations to train and run AI only if it has a valid legal basis for that specific purpose, tells customers clearly, limits the data to what is necessary and can honour their rights, including objection to marketing profiling. Legitimate interest is a common basis for AI development, but it requires a documented balancing test, and some uses, such as solely automated decisions with significant effects, face stricter rules.

Which AI uses in fashion e-commerce involve personal data?

Most customer-facing AI in fashion processes personal data at some point. Typical cases include product recommendations based on browsing and purchase history, personalised emails and offers, size and fit recommendations using body measurements or returns history, chatbots that handle orders and complaints, fraud and returns-abuse scoring, and customer segmentation for planning. Each has two phases with distinct questions: training or tuning a model, and running it on individual customers.

GDPR questions by fashion AI use case
Use casePersonal dataKey GDPR point
Product recommendationsBrowsing, purchases, wishlistLegitimate interest or consent depending on tracking; objection right for marketing
Personalised marketingProfile, email engagementArticle 21 objection to direct marketing including profiling
Size and fit adviceMeasurements, returns historyMinimisation; measurements can be sensitive in customers' eyes
Customer service chatbotOrder data, free textTransparency; free text may contain unexpected sensitive data
Returns-abuse or fraud scoringOrder and return patternsArticle 22 if blocking customers is solely automated
Training a model on historical customer dataLarge datasetsPurpose compatibility, information, rights over training data

What legal basis can a retailer use?

The CNIL, France's data protection authority, published recommendations on AI development and the GDPR, stating that the idea that GDPR prevents AI innovation in Europe is false. It describes legitimate interest as one of the most common legal bases for developing AI, especially for private actors, subject to three conditions:

  1. A legitimate interest: lawful, clearly defined and linked to the organisation's activities; a commercial interest can qualify.
  2. Necessity: the interest cannot be achieved by less intrusive means, and data minimisation applies.
  3. No disproportionate impact: benefits must be weighed against the impact on individuals' rights, with safeguards to reduce risks.

Processing must also match customers' reasonable expectations. A shopper may expect their purchase history to shape recommendations on the same site; they may not expect their service chats to be used to train a model shared with third parties. Where tracking technologies such as cookies collect browsing data, ePrivacy consent rules apply in addition to GDPR.

woman in blue and white floral shirt holding her face
Read also
How does AI personalisation work in fashion e-commerce?

How do profiling and automated decisions affect fashion AI?

Two GDPR articles matter most for personalisation and scoring. Under Article 21, customers can object at any time to processing for direct marketing, which includes profiling related to it; after an objection, the data may no longer be used for that purpose. Personalisation engines must therefore be able to exclude objecting customers from marketing models and outputs.

Article 22 gives individuals the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. Exceptions exist for contract necessity, legal authorisation and explicit consent, with safeguards including the right to human intervention. A recommendation carousel rarely reaches that threshold. Automatically blocking a customer from returns or from paying on account could, so such systems need human review or a careful exception analysis.

How should customers be informed?

The CNIL treats individual information as the default, delivered through forms, messages or privacy notices, ideally with a reasonable delay between notice and model training. General notices are acceptable where individual information is impossible or would require disproportionate effort. Information should be clear; the CNIL suggests diagrams can help explain the difference between training data, the model and its outputs. For retailers, the practical step is a privacy notice section that names AI uses specifically instead of hiding them under generic analytics language.

What happens when a customer exercises their rights?

According to the CNIL, access, rectification, erasure, restriction, portability and objection apply to training datasets and, where a model is not anonymous, to the model itself. Honouring rights over a model may by default mean retraining, which the CNIL says may take up to three months; where that is disproportionate, it suggests effective filters around the model. Retailers should design pipelines so that deleting or excluding a customer also reaches training datasets and feature stores.

woman in black top
Read also
AI for fashion e-commerce managers: a practical guide

What should a fashion e-commerce team do now?

  • List AI uses of customer data in the AI inventory and the record of processing activities.
  • Document a legitimate interest assessment for each training purpose, or obtain consent where tracking or expectations require it.
  • Minimise and pseudonymise training data; drop fields such as free-text notes unless needed.
  • Update privacy notices to describe AI personalisation, chatbots and model training in plain language.
  • Build objection and deletion into pipelines, not just the CRM.
  • Review vendor terms to prevent customer data being used to train models for other clients.
  • Run a data protection impact assessment for large-scale profiling or scoring that could affect customers significantly.

Ownership should be shared. The e-commerce or CRM team usually owns the use case, the data protection officer reviews the legal basis and notices, and data engineering makes sure objections and deletions propagate. Without that division, rights requests tend to be honoured in the customer database while copies persist in analytics and training environments.

The limits are real. Rich personalisation depends on data that customers may not expect to be used, and every additional field increases breach and compliance exposure. Retailers that collect less, explain more and give customers a simple way to switch off personalisation generally carry lower legal risk.

Frequently asked questions

Can I use customer data to train an AI model under GDPR?

Yes, if you have a valid legal basis for that purpose, inform customers, minimise the data and can honour their rights. The CNIL considers legitimate interest a common basis for AI development, subject to necessity and a balancing test.

Is personalised product recommendation profiling under GDPR?

Usually yes, since it evaluates personal preferences. Customers can object to profiling used for direct marketing under Article 21, and retailers must then stop using their data for that purpose.

When does Article 22 GDPR apply to e-commerce AI?

When a decision based solely on automated processing has legal or similarly significant effects, for example automatically blocking a customer from returns or payment options. Exceptions require safeguards such as human intervention.

Do customers have the right to be removed from AI training data?

According to the CNIL, data subject rights such as erasure and objection apply to training datasets and, where the model is not anonymous, to the model itself, which can require retraining or output filters.

GuideThe complete guide to AI in fashion e-commerce, marketing and retailRead the complete guide
Get the Daily

One edition every weekday morning. Read in five minutes. Free for industry professionals.

Newsletter

More on Regulation

View all