What the MAC Cosmetics biometric privacy lawsuit is about
The MAC Cosmetics lawsuit over virtual try-on technology is a proposed class action claiming that the brand’s facial-scanning makeup tools collected consumers’ biometric identifiers, such as facial geometry data, without the informed written consent and disclosures required under Illinois’ Biometric Information Privacy Act (BIPA), raising questions about whether beauty-focused augmented reality violates biometric privacy law. At the center of the case is MAC’s in-store and online virtual try-on feature, which scans a user’s face to superimpose digital makeup in real time. The plaintiff, Illinois resident Fiza Javid, says she used these tools in a store and on MAC’s website and was never told her facial geometry would be captured, stored, or used. She alleges the company did not obtain a written release or publish a biometric data retention and destruction policy, core elements of BIPA compliance. A federal court has now allowed her class action to move forward.
Court ruling: Motion to dismiss denied and why it matters
A judge in the US District Court for the Northern District of Illinois has dismissed MAC Cosmetics’ motion to throw out the case, meaning the proposed class action will proceed into litigation. According to Global Cosmetics News, the court found that the plaintiff had plausibly alleged that MAC’s virtual try-on tools collected biometric data by scanning facial features to create digital makeup simulations. This early ruling does not decide whether MAC is liable, but it signals that courts are taking biometric privacy violation claims tied to virtual try-on technology seriously. It also opens the door for other Illinois consumers who used MAC’s in-store devices or online try-on feature to join the lawsuit. As the case advances, it could clarify how much detail brands must provide about facial recognition data collection and how strictly judges will enforce BIPA compliance in consumer-facing beauty tech.
How virtual try-on tools collect facial recognition data
Virtual try-on technology in beauty typically works by scanning a user’s face to detect eyes, nose, lips, and overall facial geometry, then layering digital cosmetics on top of that map. In the MAC Cosmetics lawsuit, the complaint says the company’s in-store devices and website feature allegedly “capture, collect, otherwise obtain, store and use” facial geometry through these mechanisms. While brands often market such tools as fun, instant makeovers, the underlying systems may generate detailed facial recognition data that can uniquely identify a person. Under laws like BIPA, that kind of biometric information is treated as highly sensitive, similar to fingerprints. The lawsuit argues MAC did not provide written notice explaining what biometric data would be collected, how long it would be kept, or for what purposes it would be used. Nor, the complaint says, did MAC obtain written consent or a signed release before scanning faces.
What BIPA compliance requires from beauty brands
The Illinois Biometric Information Privacy Act is one of the strictest biometric laws, and it is central to the MAC Cosmetics lawsuit. BIPA requires private companies to give written notice before collecting biometric identifiers, explain the specific purpose and length of time for collection, and obtain written consent or a release from the individual. It also obliges companies to publish a publicly available policy on data retention and destruction. The complaint against MAC claims the brand failed on each of these points when using virtual try-on technology that allegedly scanned facial geometry. If courts agree, the case could set a precedent for how beauty and retail brands must design AR and facial recognition tools to achieve BIPA compliance. This may include clearer opt-in prompts, separate consent forms for biometric data, and transparent policies about how long facial recognition data is stored and when it is deleted.
What consumers should know and do about beauty tech privacy
For consumers, the MAC Cosmetics lawsuit is a reminder to treat virtual try-on technology as more than a harmless filter. When a tool asks to scan your face or use your camera, it may be generating facial recognition data that falls under biometric privacy laws. Before using such features, look for clear notices explaining what data is collected, whether it is stored, and how long it will be kept. If a brand does not provide written disclosures or ask for consent beyond a general terms-of-use agreement, that can be a red flag. In states with biometric laws similar to BIPA, you may have rights to sue if your biometric privacy is violated. Even where such laws do not exist, you can choose not to opt in, contact the brand to request deletion of your data, or use non-biometric product discovery tools instead.






