If your brand lets a customer upload a selfie to see how a lip color or a pair of frames will look on their own face, pay attention to what just happened to MAC Cosmetics. A federal court has allowed a proposed class action against the brand to proceed, rejecting the idea that scanning a customer's face to power a virtual try-on tool is just harmless fun with a filter. It is not. It is biometric data collection, and in Illinois, that comes with a statute and real money attached.

The claim

The case is Javid v. M.A.C. Cosmetics, brought by plaintiff Fiza Javid, who encountered the brand's virtual try-on feature at a suburban Chicago store. Her complaint alleges that MAC's in-store and online tools scan a user's facial features to build a digital makeup simulation, and that the company did this without the written disclosures, informed consent, and public retention policy required under the Illinois Biometric Information Privacy Act. A federal court has now allowed that proposed class action to proceed, with the retailer accused of collecting consumers' facial geometry data through its virtual makeup try-on technology without obtaining the consent required under Illinois biometric privacy law. Specifically, she alleges her facial geometry was scanned without written consent and without being informed of how her data would be collected, used, or retained, requirements spelled out under BIPA. The suit seeks to represent a class of Illinois residents whose biometric data was allegedly collected through the tool without proper notice or consent.

Why it matters

BIPA is not a statute you want to meet for the first time in a demand letter. Violations can run $1,000 per negligent infraction or $5,000 per reckless or intentional one, plus attorneys' fees, and Illinois courts have made clear that a technical violation is enough to sue, no proof of actual harm required. For an independent designer or small beauty brand, the instinct to bolt an AI try-on widget onto your site feels like a low-risk way to compete with the big houses. It is not automatically low-risk. If that widget touches a customer's face, even for a second, even through a third-party vendor's code, you may be collecting biometric identifiers under Illinois law, and under a growing number of state analogs modeled on it. This lawsuit adds to a growing wave of BIPA litigation targeting beauty and retail brands that use virtual try-on technology, and it lands squarely on a corporate parent, Estée Lauder, that has already been through this fight once and only partially prevailed. Charlotte Tilbury settled a similar claim for $2.925 million in February 2025, with payments issued earlier this year. That is the going rate for getting this wrong.

What to watch

Watch what the court does next, not just that it let the case proceed. A motion to dismiss denial is not a verdict, and MAC will have the chance to argue the specifics of its consent flow and vendor relationships as the case moves toward class certification. Watch, too, for whether other states beyond Illinois start enforcing their own biometric statutes against fashion and beauty try-on tools with the same appetite. If you run a small label and you are shopping for an AI fitting-room vendor, ask the vendor directly whether their tool creates or stores a facial or body scan, get that answer in writing, and build a real consent flow before you launch, not after a demand letter arrives. The lesson from MAC is simple and it is not new: convenience for the customer does not excuse a business from getting consent right.

Sources