When you upload a photo to a virtual try-on tool or answer a sizing quiz, you are not just finding a better-fitting pair of jeans — you are handing a retailer a detailed profile of your body, your preferences, and your behaviour. AI fashion tools are built on personal data, and understanding exactly what is collected, how it flows, and what protections apply is now a practical concern for every shopper and every brand team deploying these technologies.
Key takeaways
- AI fashion tools collect at least three distinct categories of sensitive personal data: body measurements, purchase and browsing history, and image captures.
- Body measurement data can qualify as biometric data under GDPR, triggering stricter processing rules and explicit consent requirements.
- The EU AI Act introduces additional obligations for retailers deploying certain AI systems, including transparency duties and, in some cases, conformity assessments.
- Virtual try-on technology is attracting legal scrutiny in multiple jurisdictions, with biometric privacy litigation already under way in the United States.
- Shoppers have meaningful rights — access, deletion, portability — but exercising them requires knowing where to look.
What data does an AI fashion app actually collect?
The answer is more layered than most privacy policies make obvious. There are three core categories to understand.
Body measurements and biometric signals
Fit and sizing tools are the most data-intensive category. A platform like 3DLOOK — which ships FitXpress, an AI-powered body scanning product — extracts more than 80 body measurements from two smartphone photographs. That includes circumferences, lengths, and weight and BMI predictions, all derived from images of you.
Under GDPR, data derived from the specific technical processing of physical characteristics that allows unique identification of a person can qualify as biometric data — a special category that requires explicit consent and a lawful basis beyond the standard legitimate interest. Retailers deploying these tools are responsible for ensuring that consent is genuinely informed, not buried in a terms-of-service scroll.
Bold Metrics takes a different approach: its AI body data platform builds a digital twin from 50-plus body measurements, powering products like Smart Size Chart™ and Virtual Tailor™ for apparel brands. The data here is used to predict size and fit, reduce returns, and — increasingly — inform design and distribution decisions at the brand level. That last use is worth noting: your body data may influence what sizes a brand produces, not just what it recommends to you.
Image captures and visual data
Virtual try-on tools ask you to upload a photograph or activate a live camera feed. The image itself is personal data. Depending on how the tool processes it — whether it extracts facial geometry, body shape, or skin tone — it may also generate biometric data as a by-product, even if that was not the stated purpose.
Legal scrutiny of this category is growing. Bloomberg Law has reported that biometric privacy lawsuits against retailers offering virtual try-on for glasses and makeup are posing novel legal questions, with plaintiffs arguing that image-based tools capture biometric identifiers without adequate disclosure. The legal theory is straightforward: if the software extracts a facial geometry map to overlay a product, that map is a biometric identifier under laws like the Illinois Biometric Information Privacy Act.
Purchase history, browsing behaviour, and preference signals
This is the least visible category and arguably the most commercially valuable. Every item you view, save, abandon in a cart, or return feeds a recommendation model. Zalando, which connects 62 million active customers with more than 7,000 brands across 29 markets, is among the European platforms that use AI to personalise the shopping experience at scale. The data points involved — dwell time on a product page, return reasons, price sensitivity — build a behavioural profile that is both granular and persistent.
When this data is combined with body measurement data, the resulting profile is unusually rich: a retailer knows not just what you like but what fits you, what you can afford, and how your body has changed over time.
How is this data used for AI model training?
This is the question most privacy policies answer least clearly. There are three common uses:
Personalisation in real time. Your data is used to rank products, adjust recommendations, and predict your next purchase within the same session or across sessions.
Model improvement. Aggregated and — in theory — anonymised data from many users is used to retrain the underlying AI models. The risk here is re-identification: body measurement profiles are distinctive enough that anonymisation is harder than it sounds, particularly when combined with purchase history.
Brand-level analytics. As noted above, aggregated fit and preference data is sold or licensed back to brands as market intelligence. A brand may learn that a particular size runs large based on return data, or that a specific body shape is underserved in its range. This use is often disclosed only in the fine print.
The JD Supra analysis of AI-driven beauty and fashion tech tools notes that these digital solutions introduce meaningful data privacy and litigation risks precisely because the line between personalisation and surveillance is thin, and because the secondary uses of data are rarely foregrounded in consumer-facing interfaces.
What does GDPR actually require here?
For shoppers in the EU (and for any retailer serving EU customers), GDPR sets the floor. The key obligations are:
- Lawful basis. Processing body measurements or images requires a clear lawful basis. Consent is the most common, but it must be freely given, specific, informed, and unambiguous. Pre-ticked boxes and bundled consent do not qualify.
- Special category data. If the tool processes biometric data — and many do — explicit consent is required, or the processing must fall within a narrow set of exceptions. Retailers cannot rely on legitimate interest for special category data.
- Data minimisation. Only data that is necessary for the stated purpose should be collected. A size recommendation tool that also captures facial geometry for no stated reason is likely in breach.
- Retention limits. Data should not be kept longer than necessary. Body scan data from a one-time purchase should not persist indefinitely.
- Your rights. You have the right to access the data held about you, to request deletion, and to receive a portable copy. Exercising these rights against a fashion retailer is your legal entitlement, not a favour they grant.
What does the EU AI Act add?
The EU AI Act layers additional obligations on top of GDPR, specifically for AI systems. For fashion retail, the most relevant provisions concern transparency and, for higher-risk applications, conformity assessments.
Most AI fashion tools — recommendation engines, size predictors, trend forecasters — are likely to sit in the minimal or limited risk categories under the Act's classification framework. That still triggers transparency obligations: users must be informed when they are interacting with an AI system, and AI-generated content must be labelled as such.
The more significant obligations apply if a system is used to make decisions that materially affect consumers — for example, if an AI system determines creditworthiness for a buy-now-pay-later offer bundled into a fashion checkout. In those cases, the Act requires documentation, human oversight mechanisms, and in some cases a conformity assessment before deployment.
For brand teams, the practical implication is that deploying a third-party AI tool does not transfer liability. If the tool is embedded in your checkout, you are the deployer, and the Act's obligations fall on you.
What can you do as a shopper?
You have more leverage than the default experience suggests.
- Read the data section of the privacy policy before uploading an image. Look specifically for whether image data is retained after the session, and whether it is used for model training.
- Exercise your right of access. Under GDPR, you can ask any retailer to tell you exactly what data they hold about you. Many retailers have a self-service portal; if not, a written request triggers a 30-day response obligation.
- Request deletion. If you no longer use a platform, request deletion of your body measurement and image data specifically — not just your account.
- Check for biometric-specific disclosures. If a tool uses a camera or asks for a full-body photo, look for a biometric data notice. Its absence is a signal worth noting.
- Opt out of model training where possible. Some platforms offer this as a toggle in account settings; others require a written request under the right to object.
What should brand teams be doing?
If your brand deploys AI fitting, recommendation, or try-on tools — whether built in-house or via a third-party vendor — a few obligations are non-negotiable:
- Map the data. Know exactly what each tool collects, where it is stored, how long it is retained, and whether it leaves your infrastructure for model training purposes.
- Audit consent flows. Ensure that consent for biometric or special category data is collected separately from general terms of service, and that it is genuinely granular.
- Classify your AI systems under the EU AI Act. The Act's risk tiers determine your documentation and oversight obligations. Do not assume a tool is low-risk without checking.
- Review vendor contracts. Your data processing agreements with AI tool vendors must specify the purposes for which data can be used, including whether vendor model training is permitted.
- Prepare for subject access requests. Shoppers are increasingly aware of their rights. Having a clear process for access, deletion, and portability requests is both a legal requirement and a trust signal.
The data gap that still exists
For all the regulatory progress, one gap remains largely unresolved: secondary market use of aggregated fit and preference data. When a vendor sells anonymised insights derived from your body measurements to a third-party brand or data broker, the chain of consent becomes opaque. GDPR's anonymisation standard is high in theory but inconsistently applied in practice, and the EU AI Act does not directly address data brokerage.
This is the frontier where consumer advocacy and regulatory enforcement are still catching up with commercial practice. Shoppers who care about this issue can signal it through the brands they choose — and through the subject access requests they file.
FAQ
Does uploading a photo to a virtual try-on tool mean the retailer keeps my image? It depends on the platform's privacy policy. Some tools process the image in-session and discard it; others retain it for model training. Check the privacy policy for retention terms, and if it is unclear, submit a subject access request to find out what is stored.
Is body measurement data the same as biometric data under GDPR? Not automatically, but it can be. If measurements are derived from the specific technical processing of physical characteristics in a way that allows unique identification — as is the case with many AI body scanning tools — they qualify as biometric data and attract GDPR's special category protections.
Can I ask a fashion retailer to delete my body scan data? Yes. Under GDPR, you have the right to erasure. Submit a written request specifying the data you want deleted. The retailer has one month to respond, with a possible two-month extension for complex requests.
What does the EU AI Act require of fashion retailers specifically? At minimum, transparency: users must be told when they are interacting with an AI system. Higher-risk applications — such as AI used in credit or eligibility decisions bundled into fashion checkout — face additional documentation, human oversight, and conformity assessment requirements.
Is my purchase history considered personal data? Yes. Under GDPR, any information that relates to an identified or identifiable person is personal data. Your purchase history, browsing behaviour, and return patterns all qualify, and you have the right to access, correct, and delete them.
Further reading
- As Virtual Try-On Fashion Technology Grows, So Do Legal Risks
- Beauty & Fashion Tech Tools: AI-Driven Hyper-Personalization and Data Privacy
- EU AI Act — Full Text and Resources
