- Why a Selfie Can Be Biometric Data Under GDPR, and Why It Often Isn't
- What GDPR Actually Requires From an AI Try-On Vendor
- Data Residency: What "We Don't Store Photos" Should Actually Mean
- A Compliance Checklist Before You Sign With a Vendor
- Frequently Asked Questions
- Conclusion
Every AI virtual try-on tool asks the shopper for a selfie and a full-body photo. The direct answer to whether that puts a retailer's website inside GDPR's biometric data rules: it depends entirely on how the vendor processes that photo, not on the fact that a photo was uploaded. This post breaks down when a selfie counts as biometric data under GDPR, what that means for the contract a retailer signs with an AI try-on vendor, and the specific questions to ask before rolling the feature out to an EU audience.
Why a Selfie Can Be Biometric Data Under GDPR, and Why It Often Isn't
GDPR Article 9 lists biometric data as a special category, defined as personal data from specific technical processing of physical characteristics such as facial images. Retailers often assume this means any photo upload triggers special-category obligations. It does not.
Per guidance from the UK's ICO, a photograph only becomes Article 9 biometric data when it is processed through technical means for the purpose of uniquely identifying or authenticating a natural person, the way facial recognition matches a face against a database. A photo used to render a try-on image, extract a colour palette, or estimate body proportions is processed for feature extraction, not identity matching, so it typically falls outside Article 9.
That distinction matters, but it is not a reason to relax. The selfie is still personal data under standard GDPR obligations (Article 6), and if a vendor ever adds face-matching to recognise returning shoppers, that use case crosses back into special-category territory. A retailer should know exactly which side of that line its vendor operates on, in writing.
What GDPR Actually Requires From an AI Try-On Vendor
Four obligations apply regardless of whether the selfie counts as special-category data.
Legal basis. Try-on is optional by design, so consent (Article 6(1)(a)) is the standard basis: opt-in, specific to the try-on feature, and revocable at any time, not bundled into general terms and conditions.
Data minimisation. The vendor should request only the photos the specific tool needs. Klooset's own flow, for example, asks for a selfie only when colour profiling or the full "Style me" mode is active, not for a size recommendation done from height and weight alone.
Purpose limitation. The contract should state the photo is used only to generate the requested output (try-on render, colour profile, size estimate) and is not repurposed for ad targeting, model training, or resale to third parties.
A Data Processing Agreement. Under Article 28, the retailer is the data controller and the AI vendor is a processor acting on the retailer's instructions. A signed DPA is not optional paperwork, it is the mechanism that assigns responsibility when something goes wrong.
Data Residency: What "We Don't Store Photos" Should Actually Mean
Most try-on vendors claim they do not store photos. That claim needs three follow-up questions: where is the photo processed, for how long, and by which sub-processor.
A photo that is uploaded, sent to a rendering API, and discarded within seconds of generating the output is a very different risk profile from one cached on a server for troubleshooting or model improvement. Retailers should ask for the exact retention window in writing, not a general assurance.
Regulatory scrutiny of facial and biometric data has intensified. Cumulative GDPR fines had surpassed €5.88 billion by 2026, and enforcement against facial recognition processing specifically has produced some of the largest individual penalties on record, including tens of millions of euros levied by Dutch and Italian data protection authorities against companies processing facial data without a valid legal basis.
"Facial recognition tools should only be used if necessary and proportionate, with human involvement alone not always sufficient to safeguard data subjects' rights." Source: European Data Protection Board, Guidelines 05/2022.
The retailer stays liable as the data controller even when the incident originates at the vendor. A vendor operating on EU infrastructure, with EU-based sub-processors and no cross-border transfer to jurisdictions without an adequacy decision, closes off an entire category of risk before it starts.
A Compliance Checklist Before You Sign With a Vendor
Six questions to put in writing before a contract is signed, not after a rollout:
- Does the vendor process photos for feature extraction only, or for unique identification of the shopper? Get this stated explicitly.
- Is a signed Article 28 Data Processing Agreement included, and does it name every sub-processor that touches the photo?
- Where does processing happen, and is storage (if any) located in the EU?
- What is the exact retention period for the uploaded photo and the generated output?
- Is consent collected as a specific, opt-in, revocable action, separate from the general terms of service?
- Does the vendor strip EXIF and embedded metadata from generated images before they reach the shopper or any analytics pipeline?
The related question of return-rate impact is worth pairing with this checklist, since compliance and ROI are usually evaluated by the same stakeholders. Virtual Try-On ROI: The Business Case for Fashion Brands covers the payback side of that decision.
If your legal or procurement team is building a vendor evaluation for AI personalisation tools, book a 30-minute demo, we walk through our DPA, data flow, and EU infrastructure setup directly.
Frequently Asked Questions
Is a selfie always considered biometric data under GDPR?
No. A selfie only falls under Article 9 special-category rules when it is processed through technical means for unique identification or authentication. A selfie processed to generate a colour palette or a try-on render, without any identity-matching step, is standard personal data, not special-category biometric data.
Does a retailer need explicit shopper consent to offer AI virtual try-on?
Yes. Because uploading a photo is optional and the feature adds a service beyond the base transaction, consent under Article 6(1)(a) is the appropriate legal basis. It should be a specific opt-in tied to the try-on feature, not folded into general site terms.
Who is liable if an AI try-on vendor mishandles shopper photos?
The retailer, as data controller, retains liability alongside the vendor. A signed Data Processing Agreement clarifies each party's obligations, but it does not transfer the retailer's responsibility to shoppers whose data was mishandled.
Conclusion
Virtual try-on does not automatically create a GDPR biometric data problem, but the answer depends entirely on how a specific vendor processes the photo, not on the feature itself. Retailers evaluating AI personalisation tools should ask for the processing purpose, retention period, and data residency in writing before signing, not assume compliance from a marketing page. For retailers who want to see exactly how this is handled end to end, request a pilot and review the data flow before it touches a single shopper photo.