Is Virtual Try-On GDPR Compliant? What EU Merchants Need to Know

By Raheel Gul7 min read
Editorial illustration for Is Virtual Try-On GDPR Compliant? What EU Merchants Need to Know

Quick answer

A photo a shopper uploads to try on a garment is personal data under GDPR, full stop. Whether it also counts as special category biometric data is an unsettled question: it depends on whether the tool extracts facial geometry to identify the person, not just on the fact that a face appears in the picture. Either way, an EU merchant needs a signed Data Processing Agreement with its try-on vendor, a clear privacy notice, and a vendor that can state exactly what happens to the photo and for how long.

Virtual try-on is one of the few ecommerce features that asks a shopper for a photo of themselves. For a merchant selling into the EU or UK, that single fact pulls GDPR into the conversation before the feature even launches. Most of the compliance question comes down to two things: what the tool actually does with the photo, and whether the paperwork between the merchant and the vendor reflects that honestly.

Is a virtual try-on photo personal data under GDPR?

Yes, without much debate. GDPR defines personal data broadly: any information relating to an identified or identifiable natural person. A photo showing a shopper's face or body qualifies the moment it could be linked back to that shopper, even if the underlying company processes it once and discards it a second later. Short retention reduces risk. It does not remove the photo from GDPR's scope.

That matters because merchants sometimes assume that a feature which "doesn't store anything" is automatically compliant. It still triggers GDPR's core obligations: a lawful basis for processing, a clear notice to the shopper, and, since the actual processing is usually outsourced to a vendor, a proper agreement covering that vendor's role.

Does virtual try-on count as biometric data?

This is where the legal nuance actually sits, and getting it right matters more than glossing over it. GDPR Article 9 singles out biometric data as a special category, defined in Article 4(14) as data from specific technical processing relating to physical characteristics that allows or confirms the unique identification of a natural person. Processing special category data needs a stronger legal basis than ordinary personal data, usually explicit consent.

  • Tools that map facial geometry to place glasses or lipstick precisely (common in eyewear and makeup try-on) are extracting measurements used to identify facial features, which is the exact activity Article 9 is written for.
  • Tools that render a garment onto a body in a photo without extracting facial landmarks are doing something structurally different: matching pose and proportions, not identifying who the face belongs to.
  • Regulatory guidance on this distinction is not fully settled. UK ICO commentary and several EU law firms have advised treating shopper photos as special category data out of caution, even for clothing try-on, while others read the Article 4(14) unique-identification test more narrowly.
Editorial illustration for Is Virtual Try-On GDPR Compliant? What EU Merchants Need to Know
An editorial illustration for this article

The practical takeaway for a merchant is not to bet on the narrower reading. Whichever side of that debate a regulator eventually settles on, asking for explicit, specific consent before a photo upload and picking a vendor that avoids facial analysis by design both hold up under either interpretation.

Who is the controller and who is the processor?

Under GDPR, the merchant running the store is almost always the data controller: the store decides why a try-on feature exists, offers it to shoppers, and owns the customer relationship. The vendor supplying the try-on technology, including Corlen, is the data processor, acting strictly on the merchant's documented instructions rather than for its own purposes.

Article 28 of GDPR requires a written contract between controller and processor covering the subject matter of processing, its duration, the nature and purpose, the categories of personal data and data subjects involved, and the obligations and rights of the controller. That contract is the Data Processing Agreement, and a merchant should not enable a try-on feature without one signed and on file.

What do EU merchants actually need to have in place?

  1. A signed DPA with the vendor, naming every sub-processor involved (cloud hosting, the AI model provider, email delivery, and so on), not just a generic reference to "third parties."
  2. A clear, specific consent step before the photo upload, separate from the general terms of service, stating what the photo is used for and how long it is kept.
  3. A stated retention window, in plain numbers: "as needed" is not a retention policy a regulator or a shopper can evaluate.
  4. A documented process for data subject rights requests, since a shopper can ask any point in the chain, merchant or vendor, to delete their photo or explain what happened to it.
  5. International transfer safeguards (typically standard contractual clauses) if any sub-processor operates infrastructure outside the EU or UK, which is common for AI-based tools running on major cloud providers.

How Corlen approaches GDPR for virtual try-on

Corlen's Data Processing Agreement states this directly rather than leaving it to inference: Corlen does not process special category or biometric data, and never runs face recognition or facial analysis on any photo it handles. On a Shopify storefront, a photo submitted to the Try It On button is processed in memory for the single request that generates a preview and is never written to a database or file storage. On an in-store kiosk, photos are deleted automatically within 2 hours, or immediately if the shopper asks for deletion.

The DPA also names every sub-processor involved (Google Cloud for the AI generation itself, Supabase for storage, Resend for email, Stripe for billing, Vercel for hosting), commits to standard contractual clauses for any international transfer, and gives merchants a direct contact for data subject rights requests. A merchant evaluating any try-on vendor, not just Corlen, should expect the same level of specificity before signing up. See how the same privacy approach reads from a shopper's side in is virtual try-on safe, or try Corlen on your own photo to see the whole flow firsthand.

Frequently asked questions

Is a photo uploaded to a virtual try-on tool personal data under GDPR?

Yes. A photo that shows a shopper's face or body is personal data under GDPR the moment it can be linked back to that person, regardless of how briefly it is kept or what happens to it afterward.

Does virtual try-on count as biometric data under GDPR?

It depends on what the tool does with the photo. GDPR defines biometric data as data resulting from specific technical processing used to uniquely identify a person, such as facial geometry mapping. A tool that only renders a garment onto a body in a photo, without extracting or storing facial measurements, has a defensible argument that it falls outside that definition. Several EU regulators and law firms still advise treating shopper photos as special category data out of caution, since guidance on this point remains mixed.

Who is the data controller and who is the processor when a store uses a virtual try-on app?

The merchant is almost always the controller, since the store decides why the try-on feature exists and controls the customer relationship. The virtual try-on vendor, including Corlen, is the processor, acting only on the merchant's instructions. GDPR Article 28 requires a written Data Processing Agreement between the two.

What should a Data Processing Agreement with a virtual try-on vendor cover?

At minimum: the subject matter and duration of processing, what categories of data and data subjects are involved, the sub-processors used, the security measures in place, how data subject rights requests are handled, safeguards for any international data transfer, and breach notification terms. Corlen publishes its own DPA covering all of this.

How does Corlen handle GDPR for virtual try-on?

Corlen's Data Processing Agreement states plainly that it does not process special category or biometric data and never runs face recognition or facial analysis on any photo. On a Shopify storefront, the photo is processed in memory for a single request and is never written to storage. On an in-store kiosk, photos are deleted automatically within 2 hours, or immediately on request.

Ready to add real try-on to your store?

Install Corlen on Shopify in minutes, or build it into your own platform with the developer API.

Similar posts

See it on your own photo

Corlen shows your customers how any garment looks on their own body, in seconds. Try it free, no account needed.

Try Corlen free