Back to blog

Virtual Try-On and GDPR: When Body Data Is Not Article 9 Data

· Last updated:
Virtual Try-On and GDPR: When Body Data Is Not Article 9 Data

When a shopper uploads a photograph to a virtual try-on tool, many data protection officers reach instinctively for Article 9 of the GDPR. That instinct is understandable but, in most deployments, legally incorrect. The processing of photographs, video frames and body measurements for the purpose of overlaying a garment does not, as a rule, produce biometric data within the meaning of the regulation — and treating it as though it does creates compliance work that the law does not require while distracting attention from the obligations that genuinely apply.

Key takeaways

  • Photographs and body measurements used solely to render a garment overlay are generally not Article 9 biometric data, because the EDPB reserves that classification for data processed with the purpose of uniquely identifying a person.
  • The correct framework for most virtual try-on deployments is Article 6 of the GDPR: a lawful basis, data minimisation, purpose limitation, and a data protection impact assessment.
  • Article 9 is genuinely engaged only when the system enrolls and matches a face or body template for identification purposes — a narrower case than most implementations.
  • No EDPB guideline and no EU national DPA decision addresses virtual try-on directly; the closest regulatory material is a practical guide published by France's Direction générale des Entreprises.
  • On-device processing that retains no image after the session is the architecture most likely to minimise both legal exposure and DPIA findings.

What does Article 9 actually prohibit?

Article 9(1) of the GDPR prohibits, subject to exceptions, the processing of "biometric data for the purpose of uniquely identifying a natural person." The full text of the regulation makes the purposive element explicit: it is not enough that data is derived from a body. The processing must be directed at unique identification.

The definition in Article 4(14) reinforces this. Biometric data means personal data "resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data."

Two conditions must therefore both be satisfied:

  1. The raw data (a photograph, a video frame, a set of measurements) must be subjected to specific technical processing that produces a measurement of physical or behavioural characteristics.
  2. That processing must be directed at allowing or confirming unique identification.

If either condition is absent, the output is personal data but not special-category biometric data.

What the EDPB Guidelines say about the biometric threshold

The European Data Protection Board addressed this directly in its Guidelines 3/2019 on processing of personal data through video devices. Section 5.1 states that, to qualify as biometric data under the GDPR, "processing of raw data, such as the physical, physiological or behavioural characteristics of a natural person, must imply a measurement of this characteristics" and the result must "allow or confirm the unique identification" of the person.

The EDPB's example is instructive: a CCTV system that stores footage does not automatically process biometric data. Only when the footage is run through a facial recognition algorithm — one that extracts a template used to match the person against a database — does the processing cross into Article 9 territory.

The same logic applies to virtual try-on. A system that takes a photograph, estimates approximate body proportions to scale a garment overlay, and then discards the image is performing a rendering operation, not an identification operation. The output — a visualisation of how a jacket might look — does not allow or confirm the unique identification of the shopper. The Article 9 threshold is not crossed.

What virtual try-on actually processes, and what that means for Article 6

A typical virtual try-on pipeline ingests one or more of the following:

  • A user-supplied photograph or live video feed
  • Self-reported measurements (height, chest, waist, hip)
  • Device-generated depth or pose estimates

None of these are inherently biometric in the Article 9 sense. They are, however, personal data — and in most cases data that relates to a living, identifiable individual. Article 6 of the GDPR therefore applies in full.

For a commercial virtual try-on feature offered to consumers, the most defensible lawful basis is ordinarily consent under Article 6(1)(a), or — where the processing is strictly necessary to deliver a service the user has explicitly requested — the performance-of-contract basis under Article 6(1)(b). Legitimate interests under Article 6(1)(f) is harder to sustain for body imagery, because the reasonable expectations of a shopper uploading a photograph are narrow.

Beyond the lawful basis, the following obligations apply regardless of which basis is chosen:

  • Data minimisation: collect only what is necessary to render the garment. If a 2D overlay requires only a frontal photograph, do not also collect height and weight.
  • Purpose limitation: data collected for try-on must not be repurposed for model training, profile building or advertising targeting without a fresh lawful basis.
  • Storage limitation: images should not be retained beyond the session unless there is a clear, communicated reason to do so.
  • Transparency: the privacy notice must explain, in plain language, what is collected, for how long, and whether any processing occurs on a third-party server.

When Article 9 is genuinely engaged

The Article 9 threshold is crossed when the virtual try-on system moves from rendering to identification. Concretely, this happens in two scenarios:

Face template enrollment and matching. If the system extracts a facial embedding — a mathematical representation of the user's face — and stores it for later matching (for example, to allow a returning user to retrieve their saved avatar), the processing is directed at unique identification. Article 9 applies. The only available exception for a commercial context is explicit consent under Article 9(2)(a), which must be freely given, specific, informed and unambiguous — and must be separable from consent to the try-on feature itself.

Body template enrollment for persistent identification. A system that builds a persistent body model linked to an account, and uses that model to re-identify the user across sessions or devices, is similarly within Article 9's scope. The distinguishing factor is always purpose: is the template being used to render clothing, or to identify the person?

If your implementation does either of these things, you need an Article 9(2) exception, an explicit consent flow that meets the higher standard, and a DPIA that addresses the specific risks of biometric template storage — including the risk of a data breach that exposes templates that cannot be changed the way a password can.

The DPIA question: when is one required?

A data protection impact assessment is required under Article 35 of the GDPR when processing is "likely to result in a high risk" to individuals. Virtual try-on involving body imagery almost certainly meets this threshold, even where Article 9 does not apply, for two reasons.

First, the processing involves systematic collection of images of natural persons — a category that most national DPA lists of high-risk processing include explicitly. Second, the processing is carried out at scale, typically by an automated system with no meaningful human review.

The DPIA should address:

  • The nature of the data collected and whether it could, in combination with other data held by the controller, enable identification or profiling beyond the stated purpose
  • The third-party processors involved (the virtual try-on vendor, any cloud infrastructure provider) and the contractual safeguards in place
  • Data flows outside the EEA, if the vendor processes images on servers located in third countries
  • The technical measures in place to delete images after the session
  • The residual risks and whether they are acceptable

On-device processing — where the image is analysed locally on the user's device and no image is transmitted to a server — materially reduces the risk profile and simplifies the DPIA. It is the architecture that regulators are most likely to view favourably.

What regulators have actually said about virtual try-on

Here a note of candour is warranted. As of the time of writing, no EDPB guideline and no published decision from an EU national data protection authority addresses virtual try-on directly. The EDPB's Guidelines 3/2019 on video devices are the closest authoritative text, and they address CCTV and facial recognition rather than garment visualisation.

The most directly relevant regulatory material is a practical guide published by France's Direction générale des Entreprises (DGE) under the France Num programme. That guide on AI-powered size assistance and virtual try-on notes that certain virtual try-on solutions rely on analysis of images or video of the user's body, that such processing may involve biometric data within the meaning of the GDPR, and that particular vigilance is required. It recommends preferring solutions that perform analysis directly on the user's device, without retaining images.

The DGE guide is not a binding DPA decision and it does not resolve the Article 9 question definitively. It does, however, signal the direction of regulatory thinking: on-device processing, no retention, and careful attention to whether the processing crosses into identification.

For teams operating in the United States, the legal picture is different again. Several US states have biometric privacy statutes — Illinois's BIPA being the most litigated — and virtual try-on tools have attracted class action suits under those laws. The EU and US frameworks are not equivalent, and this article addresses only the GDPR.

Practical implications for vendors and retailers

Platforms such as Aiuta — which enables shoppers to upload their own image or use an AI-generated model to visualise garments — and Veesual — which automates the conversion of static product visuals into video — operate in this regulatory space. Both serve fashion retailers as processors or sub-processors, which means the retailer remains the data controller and bears primary responsibility for the lawful basis, the privacy notice, and the DPIA.

For a retailer deploying either type of tool, the practical checklist is:

  1. Determine whether the tool performs identification. Ask the vendor explicitly: does the system extract a face or body template? Is any template stored beyond the session? If yes, Article 9 applies and you need explicit consent.
  2. Establish your Article 6 lawful basis for the underlying image processing. Consent is the safest choice for body imagery; document the basis in your records of processing activities.
  3. Review the data processing agreement with the vendor. Confirm that the vendor acts only on your instructions, that sub-processors are listed, and that images are deleted within a defined period.
  4. Conduct a DPIA before go-live. Do not wait for a DPA to ask for one.
  5. Update your privacy notice to describe the try-on feature specifically — what is collected, where it is processed, and how long it is retained.
  6. Prefer on-device processing where the vendor offers it. This is both the architecturally safer choice and the one that regulators have signalled they favour.

For retailers operating across the EU, it is also worth monitoring the intersection of virtual try-on with the EU AI Act. A Taylor Wessing analysis of the AI Act's impact on fashion notes that most fashion AI systems are likely to fall into the limited-risk or minimal-risk categories, but that transparency obligations will apply to systems that interact with users in ways that are not immediately apparent.

The bottom line

The GDPR's Article 9 is a targeted prohibition, not a general rule that any processing of body data is special-category processing. For most virtual try-on deployments — those that render a garment overlay and do not enroll or match a biometric template — the correct framework is Article 6, data minimisation, purpose limitation, and a DPIA. Article 9 becomes relevant only when the system moves from visualisation to identification.

The absence of direct DPA guidance on virtual try-on is not a reason for complacency. It is a reason to document your analysis carefully, so that when guidance does arrive — or when a DPA inquiry does — you can demonstrate that you engaged with the question seriously and reached a reasoned conclusion.


FAQ

Is a photograph uploaded for virtual try-on automatically biometric data under GDPR? No. A photograph becomes biometric data within Article 9's scope only when it is subjected to specific technical processing directed at uniquely identifying the person. A photograph used solely to render a garment overlay does not meet that threshold.

What lawful basis should a retailer use for virtual try-on image processing? For most deployments, consent under Article 6(1)(a) is the most defensible basis. Performance of contract under Article 6(1)(b) may apply where the try-on is the core service requested, but body imagery makes legitimate interests harder to sustain.

When does virtual try-on trigger Article 9 of the GDPR? Article 9 is triggered when the system extracts and stores a biometric template — a facial embedding or persistent body model — used to identify the person across sessions. Rendering a garment overlay without storing a template does not trigger it.

Is a DPIA required for virtual try-on even if Article 9 does not apply? Almost certainly yes. Systematic automated processing of body images at scale is likely to meet the Article 35 high-risk threshold regardless of whether Article 9 applies. Conduct the DPIA before go-live.

Has any EU data protection authority issued guidance specifically on virtual try-on? Not as of the time of writing. The closest regulatory material is a practical guide from France's Direction générale des Entreprises, which recommends on-device processing and no image retention. The EDPB's Guidelines 3/2019 on video devices are the most relevant authoritative text, though they address CCTV and facial recognition rather than garment visualisation directly.


Further reading

Share this article:

Virtual Try-On GDPR Article 9: Is Body Data Biometric?