No European supervisory authority has yet issued a decision specifically targeting a fashion AI system as such. What exists is a body of enforcement action against retail profiling, in-store biometric systems, and large-scale facial-recognition scraping—cases whose reasoning transfers directly to the AI tools fashion businesses are deploying today. If you are a data protection officer or compliance lead evaluating a virtual try-on rollout, a customer-segmentation model, or an in-store analytics system, these decisions are your working precedents.
Key takeaways
- Fidelity-card profiling without clear, itemised retention periods breaches Article 13, even when consent is collected.
- In-store facial recognition without a prior proportionality test violates Articles 6, 9, 25(1) and 35 simultaneously—no single fix is sufficient.
- Photographs processed by an AI system to enable unique identification become Article 9 biometric data, regardless of how the system is marketed.
- A DPIA is not optional for high-risk AI processing; it must precede deployment, not follow it.
- Privacy-by-design obligations under Article 25 require data minimisation to be built into the system architecture, not added as a policy layer.
Why fashion AI creates GDPR exposure in the first place
Fashion AI systems tend to combine three data-intensive functions: they personalise recommendations using behavioural and purchase history; they process body or face images for sizing, virtual try-on, or in-store analytics; and they transfer data across jurisdictions when cloud infrastructure or third-party model providers are involved. Each function maps onto an enforcement risk that a decided case has already quantified.
The five pitfalls below are drawn from three decisions: the Italian Garante's June 2023 order against Rinascente for fidelity-card profiling, the Spanish AEPD's resolution against Mercadona for in-store facial recognition, and the Garante's February 2022 order against Clearview AI for biometric data scraping. Together they cover the main vectors of fashion AI risk.
Pitfall 1: Opaque retention periods in profiling systems
What the case established
The Garante's order against Rinascente found that the retailer's fidelity-card programme collected two separate consents—one for marketing, one for profiling—but the accompanying privacy notice failed to state retention periods clearly or to explain the mechanics of the promotional activity in a way that gave data subjects genuine awareness of what they had agreed to. The authority treated the informational deficit as a breach of Articles 5(1)(a) and 13, not merely a presentational shortcoming.
Why it matters for fashion AI
Customer-segmentation and recommendation models in fashion typically ingest years of purchase, browsing, and returns data. If your privacy notice does not specify, for each processing purpose, how long that data is retained and on what basis the retention period was chosen, you are replicating the Rinascente deficiency at scale. A model that continuously retrains on historical data makes this harder, not easier: the retention period for training data is a distinct question from the retention period for inference outputs, and both must be answered.
Best for: Any organisation running a loyalty, CRM, or recommendation system. Limits: Fixing the notice alone is insufficient if the underlying data flows do not match what the notice says.
Pitfall 2: Skipping the proportionality test before deploying biometric analytics
What the case established
The AEPD's resolution against Mercadona is the most operationally instructive decision in this set. Mercadona installed a facial-recognition system across its stores to identify individuals subject to restraining orders. The authority found breaches of Articles 6, 9, 12, 13, 5(1)(c), and 25(1), but the structural failure was the absence of a proportionality test before deployment. The AEPD stated explicitly that, regardless of the legal basis, a proportionality analysis must precede any such processing to determine whether it is necessary for a legitimate aim and to identify measures that limit privacy intrusion to the minimum.
Why it matters for fashion AI
In-store analytics systems—footfall counters, dwell-time trackers, demographic estimators—are increasingly offered to fashion retailers as inventory and layout optimisation tools. When those systems process facial geometry, even transiently, the Mercadona reasoning applies. The question is not only whether you have a legal basis; it is whether you conducted and documented a proportionality analysis before the cameras went live. The AEPD treated the missing analysis as a standalone violation of Article 25(1), which means privacy-by-design is not satisfied by a retrospective DPIA.
Best for: Any retailer evaluating in-store computer-vision analytics, including heat-mapping or demographic inference. Limits: A proportionality test does not guarantee lawfulness; it is a necessary condition, not a sufficient one.
Pitfall 3: Misclassifying facial images as ordinary personal data
What the case established
The Garante's order against Clearview AI confirmed that photographs, when subjected to specific technical processing that enables or confirms unique identification of a natural person, constitute biometric data under Article 4(14) and are therefore subject to the heightened protection of Article 9. The authority rejected the argument that the images were merely publicly available photographs; what mattered was the processing applied to them.
Why it matters for fashion AI
Virtual try-on systems, body-measurement tools, and face-based personalisation features all process photographs of shoppers. If the underlying model extracts facial geometry or body landmarks to enable identification or re-identification—even as a byproduct of a sizing or styling function—the output is Article 9 data. Aiuta, for example, operates a virtual try-on platform that allows shoppers to upload their own image or use an AI-generated model; the data governance architecture for user-uploaded photographs must account for the possibility that the processing crosses the Article 9 threshold, depending on what the model extracts and retains. The Clearview decision means you cannot rely on the consumer-facing framing of a feature to determine its regulatory classification; you must examine what the model actually does to the image.
Best for: DPOs reviewing any system that ingests shopper photographs, body scans, or video. Limits: The Article 9 analysis is model-specific; a vendor's assurance that no biometric data is stored does not resolve the question of what is processed transiently.
Pitfall 4: Conducting the DPIA after deployment
What the case established
The Mercadona resolution treated the absence of a prior DPIA as a component of the Article 35 breach. The AEPD's reasoning, consistent with the EDPB's guidelines on Article 35, is that a DPIA for high-risk processing must precede the start of processing. A retrospective assessment does not cure the violation; it may reduce the penalty, but it does not establish compliance.
Why it matters for fashion AI
Fashion AI deployments frequently involve processing that meets one or more of the Article 35(3) criteria: systematic and extensive profiling with significant effects (recommendation engines that gate promotional pricing); large-scale processing of special-category data (body-measurement or facial-geometry systems); and systematic monitoring of publicly accessible areas (in-store analytics). The EU AI Act, which is now entering its phased application, adds a parallel obligation for certain AI systems to undergo conformity assessment—but that obligation does not replace the GDPR DPIA; both apply. Compliance leads should treat the DPIA as a gate, not a formality, and schedule it before any pilot deployment, including internal proofs of concept that process real customer data. The Taylor Wessing analysis of fashion and the AI Act notes that fashion AI systems generally fall into lower-risk categories under that regulation, but lower AI Act risk does not reduce GDPR obligations.
Best for: Any organisation in pre-deployment or pilot phases for AI systems that profile customers or process body or face data. Limits: A DPIA identifies risks; it does not resolve them. Mitigation measures must be implemented and documented before go-live.
Pitfall 5: Undisclosed or inadequately documented international transfers
What the case established
The Rinascente order noted deficiencies in the disclosure of data transfers as part of the broader informational failures in the fidelity-card programme. While the transfer issue was not the primary ground of the sanction, the Garante treated inadequate transfer disclosure as part of the Article 13 breach: data subjects were not given sufficient information about where their data went and on what legal basis.
Why it matters for fashion AI
Fashion AI deployments almost invariably involve third-party model providers, cloud infrastructure, and analytics platforms headquartered outside the EU. A virtual try-on system may send shopper images to a model hosted in a non-EEA jurisdiction; a recommendation engine may rely on a foundation model accessed via an API. Each of these flows requires a transfer mechanism—Standard Contractual Clauses, an adequacy decision, or another Article 46 instrument—and each must be disclosed in the privacy notice with enough specificity that a data subject can understand where their data goes. The Reed Smith commentary on beauty tech and privacy observes that the integration of AI into consumer-facing technology in fashion and beauty raises precisely these transfer and disclosure questions under both UK and EU GDPR. Platforms such as Zalando, operating across 29 European markets with AI capabilities spanning recommendation, logistics, and marketplace infrastructure, illustrate the complexity: a multi-jurisdiction deployment requires transfer documentation for each data flow, not a single catch-all clause.
Best for: DPOs conducting Article 30 records reviews and privacy notice audits for any AI system with a non-EEA component. Limits: SCCs alone are not sufficient if the destination country's law prevents the importer from complying with them; a transfer impact assessment is required in that case.
A note on the state of the enforcement record
It bears stating plainly: as of the time of writing, no European supervisory authority has issued a decision specifically against a fashion AI deployment as such. The cases discussed here are enforcement actions against retail profiling (Rinascente), in-store biometric systems (Mercadona), and facial-recognition data scraping (Clearview). They are transferable precedents, not a fashion-AI-specific line of authority. That gap will close. The combination of the GDPR's existing obligations, the AI Act's phased requirements, and the growing scale of AI adoption in fashion retail makes enforcement in this sector a matter of when, not whether.
FAQ
Does a fashion AI system always process biometric data under GDPR? Not automatically. The Clearview decision establishes that photographs become biometric data when processed by a system that enables unique identification. If your system extracts facial geometry or body landmarks for that purpose, Article 9 applies. If it does not, ordinary personal data rules govern.
Is a DPIA required for every fashion AI deployment? Not every deployment, but any system involving systematic profiling with significant effects, large-scale processing of body or face images, or systematic in-store monitoring will typically meet the Article 35(3) threshold. When in doubt, conduct one; the cost of a DPIA is lower than the cost of a post-hoc enforcement finding.
What does a proportionality test involve for an in-store analytics system? Following the Mercadona reasoning, it requires documenting the legitimate aim, assessing whether the processing is necessary and not achievable by less intrusive means, and identifying measures to minimise privacy intrusion. This analysis should be completed before deployment and retained as evidence.
How specific must retention periods be in a privacy notice for an AI system? The Rinascente decision indicates that generic or vague retention language is insufficient. You should state the retention period for each processing purpose, including training data, inference outputs, and any intermediate representations, and explain the criteria used to determine those periods.
Does a lower AI Act risk classification reduce GDPR obligations? No. The AI Act and GDPR are parallel frameworks. A fashion AI system classified as low-risk under the AI Act remains fully subject to GDPR, including Article 35 DPIA obligations, Article 25 privacy-by-design requirements, and Article 9 restrictions on biometric data.
Further reading
- Ordinanza ingiunzione nei confronti di Rinascente S.p.A. — Garante per la protezione dei dati personali
- Resolución PS/00120/2021 — Mercadona, S.A. — AEPD
- Ordinanza ingiunzione nei confronti di Clearview AI — Garante per la protezione dei dati personali
- Fashion meets the AI Act — Taylor Wessing
- Beauty Tech Privacy — Reed Smith
