Law & policy·8 min read·25 August 2026

A customer uploads her photo. Here’s exactly what the law says.

Every virtual try-on app asks a shopper to upload a photo of herself. That’s the whole product. It’s also the whole legal question, and almost nobody selling try-on explains it properly.

We’re not a law firm and this isn’t legal advice. But we read the primary texts — the GDPR articles, the EU AI Act, CNIL’s own guidance — instead of paraphrasing a competitor’s compliance page, and we’re publishing what we found, including the parts that are genuinely unresolved.

Is a photo of a customer “biometric data” under GDPR?

Not automatically. GDPR Recital 51 states that processing photographs “should not systematically be considered to be processing of special categories of personal data as they are covered by the definition of biometric data only when processed through a specific technical means allowing the unique identification or authentication of a natural person.” Article 4(14) confirms it: biometric data is personal data resulting from technical processing of physical characteristics “which allow or confirm the unique identification” of a person.

Read that carefully, because the test is about purpose, not about whether a photo was taken.

A system that detects body landmarks to drape a garment correctly is doing “specific technical processing of physical characteristics.” That’s condition one. But it isn’t trying to work out which specific person this is, or match her against other photos of her. That’s condition two, and a garment-rendering pipeline doesn’t do it. Both conditions have to hold for Article 9’s stricter regime — explicit consent, no easy alternative, extra safeguards — to apply.

On the plain text, an ordinary virtual try-on photo is personal data under Article 6. It is not, by default, biometric data under Article 9.

Where this gets genuinely contested, and we’d rather flag it than pretend it’s settled: some privacy lawyers argue that body shape itself can be read as revealing information adjacent to health data. That’s an advocate’s argument, not a regulator’s guidance — we could not find a CNIL or EDPB opinion addressing virtual try-on directly, in either direction. Treat the Article 6 reading as well-founded on the text, not as a guarantee no counterparty will push back.

One thing that would flip this analysis: storing a reusable face or body template, matching a returning customer against it, or inferring and recording attributes like age or ethnicity. That’s identification, and it changes the legal category. The product has to stay ephemeral-input, generated-output, no template — not just say so in a privacy policy.

Does this need a DPIA (data protection impact assessment)?

We checked CNIL’s actual list of processing operations that require a mandatory DPIA — délibération n° 2018-327 — line by line, in its current form as published. It names 14 categories: healthcare data, genetic data, HR profiling, constant employee monitoring, whistleblowing systems, health data warehouses, and others. The only biometric item on the list is processing of biometric data “to uniquely identify a natural person, among whom are so-called ‘vulnerable’ persons (students, elderly people, patients, asylum seekers, etc.).” Virtual try-on, e-commerce, and apparel photo processing appear nowhere on the list.

That’s a genuine finding, not an assumption — we read the list. The one biometric category on it is scoped to recognition and identification, which is precisely the thing a garment-rendering system isn’t doing.

We’re stating what the list says. Whether a specific implementation still warrants a voluntary DPIA under GDPR’s general Article 35 trigger — high risk to individuals, new technology, large scale — is a separate question, and it’s the kind of judgment call a DPO makes about a specific product, not something a blog post can answer for every vendor in this category.

What does the EU AI Act actually say about this?

Recital 16 gives, as its own worked example of a feature that could sit outside regulated “biometric categorisation,” something unmistakably describing virtual try-on: “filters categorising facial or body features used on online marketplaces could constitute such an ancillary feature as they can be used only in relation to the principal service which consists in selling a product by allowing the consumer to preview the display of the product on him or herself and help the consumer to make a purchase decision.”

Read the wording precisely, because it matters: the recital says “could constitute,” not “constitutes,” and it never uses the phrase “virtual try-on.” It’s a strong, favourable signal from the legislator — not a blanket exemption stamped on every implementation.

Separately, and this is live right now: Article 50 transparency obligations applied from 2 August 2026. Providers of systems that generate synthetic image content must mark the outputs “in a machine-readable format and detectable as artificially generated or manipulated.” Penalties under Article 99 reach €15M or 3% of worldwide turnover.

A try-on render is a photorealistic AI-generated image of a real person. We think Article 50 applies to it. One important nuance: the EU’s Digital Omnibus regulation, in force since 27 July 2026, does grant a transitional period to 2 December 2026 — but only for the Article 50(2) technical-marking obligation, and only for systems already on the market before 2 August 2026. That transition does not cover Article 50(4), the deployer’s duty to disclose that content shown to a consumer is AI-generated or manipulated — and a try-on render shown to a shopper plausibly falls under that second, non-deferred obligation.

Practical read: mark generated images as AI-generated. It’s a corner badge. The cost of skipping it is a lot higher than the cost of adding it.

Who’s the data controller — the brand or the try-on vendor?

Normally, the merchant. CNIL’s own framing is that the controller is whoever “determines the purposes and the means” of processing — and crucially, “the qualification doesn’t depend on a contractual choice but on the facts.” A brand offering try-on to its customers is deciding to do it, to whom, and why. That makes the brand the controller and the vendor the processor.

That has a direct, checkable consequence for anyone shopping for a try-on app. Article 28(3) requires a written data processing agreement between them, covering: processing only on documented instructions; confidentiality; security measures; sub-processor disclosure and consent; assistance with data-subject rights and breach notification; and deletion or return of all data at the end of the contract, with CNIL adding that the processor should provide a certificate of destruction.

A vendor becomes something worse than a processor — a joint or independent controller — the moment it uses shopper photos for its own purposes: model training, analytics, product improvement beyond the immediate render. That’s a materially different, less defensible position, and it’s exactly the question a serious buyer should ask before signing anything.

The checklist we’d actually use to evaluate a try-on vendor

Where does the photo go, and does it come back? Get a specific, contractual answer — not “we take privacy seriously.”

Is there a signed DPA covering Article 28(3)? Ask to see it before you sign, not after.

Are there named sub-processors, and where are they? If the image model is a third-party API outside the EU, that’s a transfer requiring its own legal basis.

Does the vendor train on your customers’ photos? If yes, this is a different, harder legal conversation than a pure rendering service.

Are generated images marked as AI-generated? The deployer disclosure obligation (Article 50(4)) has applied since 2 August 2026 without deferral; the technical machine-readable marking obligation (50(2)) has a grace period to 2 December 2026 for tools already on the market.

Is consent explicit, unbundled, and does browsing without a photo still work? A shopper should be able to decline and still shop.

FAQ

Is a customer’s try-on photo biometric data under GDPR?
Not by default. GDPR Recital 51 and Article 4(14) tie biometric data to processing that allows or confirms unique identification. A system that renders a garment on a photo without identifying the person is processing personal data, not biometric data — provided it doesn’t build or match against a reusable identity template.
Does virtual try-on require a DPIA in France?
CNIL’s mandatory-DPIA list (délibération n° 2018-327), in its current published form, does not name virtual try-on, e-commerce, or apparel photo processing. Its one biometric entry is scoped to uniquely identifying individuals, including vulnerable persons — not garment rendering. Whether a voluntary DPIA is still warranted under GDPR’s general Article 35 criteria is a case-by-case judgment, not something this list settles.
Does the EU AI Act ban or restrict virtual try-on?
No. Recital 16 offers virtual-try-on-like filters on online marketplaces as its own example of a feature that could sit outside regulated biometric categorisation. Separately, Article 50 transparency rules require marking generated try-on images as AI-generated. The technical-marking sub-obligation has a grace period to 2 December 2026 for tools already on the market, but the deployer’s duty to disclose AI-generated content to the shopper has applied since 2 August 2026 without deferral.
Who’s legally responsible for the customer’s photo — the brand or the software vendor?
Normally the brand, as data controller, with the vendor as processor under a signed Article 28(3) agreement. A vendor that uses customer photos for its own purposes — training, analytics — becomes a controller in its own right, which is a different and stricter conversation.

Sources. GDPR, Recital 51 and Article 4(14) · CNIL, “Biométrie à disposition de particuliers” · CNIL, délibération n° 2018-327 (DPIA list), 11 October 2018 · EU AI Act, Recital 16 and Article 3(40) · EU AI Act, Article 50 and Article 99 · CNIL, guidance on identifying controller vs. processor roles.

Last updated 25 August 2026.

S
Sami
Founder of Jedid. Writes here when a number in this category doesn’t hold up, or when something worth arguing about needs arguing in public.

Watch Jedid work on your collection. Live.

Try it on your catalogue before committing. No card required.