If you sell glasses online, you almost certainly have a virtual try-on tool. It is one of the few genuinely useful pieces of eyewear e-commerce technology: the customer points a camera at their face, the software maps the geometry of it, and the frames sit where they would actually sit.
That mapping step is the problem. Under Illinois law, a scan of face geometry is a biometric identifier, and collecting one without written consent is actionable — by the customer, individually, with statutory damages attached.
Eyewear used to have an unusually good defence against this, and the reason was flattering: glasses are medical devices, so a tool that helps you buy them is helping you get health care. That argument has now been rejected twice, by two different courts, and the second rejection came from the Seventh Circuit on 10 July 2026.
The important part is not that the defence failed. It is where the courts drew the line, because the line runs straight through the middle of a typical eyewear catalogue.
What the court actually decided
The case is Clements v. Gunnar Optiks, LLC, No. 25-1890 in the Seventh Circuit, argued 24 February 2026 and decided 10 July 2026. Judge Easterbrook wrote for a panel that also included Chief Judge Brennan and Judge Taibleson. Gunnar sells eyewear marketed as reducing digital eye strain, and it ran a virtual try-on tool that scanned facial geometry. The plaintiff alleged it did so without the notice, written consent and published retention schedule that Illinois's Biometric Information Privacy Act requires.
Gunnar's defence was BIPA's health care exemption, which takes out of the statute information collected, used or stored for health care treatment, payment or operations under HIPAA. The district court accepted it and dismissed. The Seventh Circuit vacated the judgment and remanded — it did not decide that the exemption is unavailable, it decided that the district court could not get there on the pleadings.
The reasoning is what matters. The relevant question is not whether the product has some health-related quality — it is whether the biometric data itself was collected for health care. On that, the court was direct: the “virtual try on” service Gunnar offered “seems to be aesthetic, not medical, even if the glasses themselves serve a health-related function”, and “better-appearing glasses are not medical treatment”.
The court also noted that the exemption covers treatment under HIPAA, which implies that the entity collecting the information has to comply with HIPAA's consent and confidentiality rules — and that whether Gunnar does could not be determined from the complaint. That is not a finding that an online eyewear store must become a HIPAA-covered entity. It is a warning that the exemption comes with conditions nobody had been checking.
The line is the prescription
This is the part the privacy coverage skipped, and it is the part that matters commercially.
BIPA's exemption borrows HIPAA's definition of health care, at 45 C.F.R. § 160.103. That definition covers the sale or dispensing of a device “in accordance with a prescription”. The prescription is not incidental to the definition; it is written into it.
The court made the consequence concrete with an example: “$5 sunglasses purchased at the corner drug store to reduce eye strain at the beach when reading a novel” are not medical treatment, whatever the FDA calls them.
So the dividing line that has emerged is not eyewear versus cosmetics. It runs inside eyewear:
- Non-prescription product — readers, fashion sunglasses, blue-light and computer glasses, plano frames. The health care argument is now very weak.
- Prescription product dispensed against an actual prescription — a stronger argument, but it is an argument about the transaction, not the catalogue, and it still has to clear the HIPAA-compliance condition the Seventh Circuit flagged.
If your try-on widget runs across your whole catalogue — and almost every one of them does — then it runs across a great deal of product for which no version of this defence works.
This started in 2024, not 2026
The story usually told is that eyewear was safe from February 2023 until this summer. That is wrong by about two years, and the error matters, because it means the exposure is older than most merchants think.
In Warmack-Stillwell v. Christian Dior, Inc., decided in the Northern District of Illinois on 10 February 2023, Judge Bucklo dismissed a near-identical claim over a sunglasses try-on tool, reasoning that sunglasses are FDA Class I medical devices and that the tool facilitated the provision of a device that protects vision. That decision was quoted approvingly in eyewear circles for years, and it is the reason try-on vendors could tell optical clients their legal risk was lower than a cosmetics brand's.
It did not survive long. On 30 August 2024, in Marino v. Gunnar Optiks, LLC, No. 1-23-1826, the Illinois Appellate Court for the First District answered a certified question: is an individual who tries on non-prescription sunglasses using a virtual try-on tool that captures biometric information a patient in a health care setting? The answer was no. The court expressly disagreed with the Dior reasoning, pointing out that FDA Class I devices include bandages and toothbrushes, so treating that classification as the test would make the exemption absurdly broad.
So Illinois's own appellate court rejected the Class I argument in 2024, and the Seventh Circuit has now closed the federal route as well, with a regulatory citation attached. If you or your vendor are still relying on Dior, you are relying on a 2023 district court decision that the state appellate court disagreed with in 2024 and that a federal appeals court declined to follow in 2026.
The practical consequence is procedural, and it is expensive. The court was explicit that the exemption question depends on facts beyond the complaint and that discovery may be needed to sort it out. In plain terms: a BIPA claim against an eyewear try-on tool now survives a motion to dismiss and proceeds to discovery. Most of these cases settle at exactly that point, because discovery costs more than the settlement does.
What the exposure is worth
BIPA provides for damages of up to $1,000 per negligent violation and up to $5,000 per intentional or reckless one, plus attorney's fees and injunctive relief. Those are discretionary maximums available to a court, not mandatory floors.
Two pieces of good news, such as they are. Illinois amended BIPA in August 2024 to limit a plaintiff to a single recovery per person rather than one per scan, which had been the theory behind the headline-grabbing damages figures. And on 1 April 2026, in Clay v. Union Pacific Railroad Co., No. 25-2185, the Seventh Circuit held that the amendment applies retroactively to pending cases — reasoning that it changed the availability of damages rather than the conduct the statute prohibits.
So the tail risk is smaller than it was in 2023. The gate to discovery, however, just opened wider. A per-customer exposure of up to four figures across an Illinois customer base, plus fees, is not a rounding error for a store doing seven figures in revenue.
Illinois is not the only jurisdiction
Texas's Capture or Use of Biometric Identifier Act (CUBI) requires notice and consent before a biometric identifier is captured for a commercial purpose, and its definition expressly includes a record of face geometry. It requires reasonable care in storage and destruction within a reasonable time, and no later than one year after the purpose of collection expires. It is enforced exclusively by the Texas Attorney General, with civil penalties of up to $25,000 per violation. There is no private right of action, which means no plaintiff's-bar settlement machine — but also no settlement ceiling.
Worth saying plainly: the Texas AG's biometric enforcement so far has been aimed at large platform operators rather than at retailers running try-on widgets. There is no reported CUBI action against an eyewear seller. That is a statement about where enforcement has gone to date, not about what the statute covers.
Washington's My Health My Data Act is the one most often underrated here. It lists biometric data as an example of consumer health data, requires separate opt-in consent before collecting or sharing it, and reaches any entity that provides products or services targeted to consumers in Washington — so an out-of-state online store is in scope. A violation is treated as an unfair or deceptive act under the Washington Consumer Protection Act, which carries a private right of action. The significant limit is that the Act provides no statutory damages: a plaintiff has to prove actual damages, which is a far harder case to bring than a BIPA claim.
The fix is smaller than the problem
None of this means turning off virtual try-on. It converts, and removing it would cost more than compliance does. What it means is four specific things, in order of how much they matter:
1. Find out where the face data goes. There is an enormous difference between a widget that computes face geometry on the device and discards it, and one that uploads frames to a vendor's servers. Ask your try-on vendor, in writing, whether any biometric identifier or template leaves the customer's device, whether it is stored, and for how long. If the answer is vague, treat it as a yes.
2. Put real consent in front of the scan. Not a cookie banner. Not a line in the privacy policy. A clear notice stating that face geometry is being collected, the specific purpose, how long it is kept, and an affirmative action by the customer before the camera starts. This is a modal, and it is a day of work.
3. Publish a retention and destruction schedule. Illinois requires a publicly available written policy with a retention schedule and destruction guidelines. This is the requirement most often missed, because unlike consent it produces no visible UI, and it is the easiest one for a plaintiff to plead.
4. Read the indemnity in your vendor contract. You are the one with the customer relationship and the one who gets named. Find out now whether your try-on provider indemnifies you for biometric claims, or whether the contract quietly puts the compliance obligation on you.
One thing not to do: do not try to engineer your way into the exemption by pointing at the prescription products in your catalogue. The courts are looking at the transaction the scan happened in, not at your product mix, and a try-on tool that runs on plano sunglasses is doing so whatever else you stock.
The part that is about how you sell
There is a broader point here, and it is not a stretch to reach it.
The face scan is the flashiest part of an eyewear buying flow and the least load-bearing. It helps a customer decide between two frames they already like. What actually determines whether the order completes, what it is worth, and whether it ships once or twice, is the step after that: the prescription, the lens type, the coatings, the pupillary distance.
That step involves no biometric identifiers at all. A structured prescription form collects sphere, cylinder, axis, add and PD — clinical data the customer already has on a piece of paper, entered deliberately, with an obvious purpose. It carries its own privacy obligations, which are real and worth taking seriously, but prescription values are not biometric identifiers as the statutes discussed here define them, so it does not put you inside a regime with per-person statutory damages and an active plaintiff's bar.
It is also where the money is. Try-on lifts engagement. Lens configuration lifts average order value, and it does it on every single prescription order rather than on the fraction of visitors willing to turn on a camera.
This is the same pattern we found when we looked at the rules that landed this year on AI-generated models in eyewear advertising: every part of an eyewear store that involves a human face acquired a compliance obligation in 2026, and the step that actually converts has none of them.
If the Gunnar decision prompts an audit of what your product page collects and why, that is a good outcome regardless of the law. Most eyewear stores are scanning faces enthusiastically and capturing prescriptions by asking the customer to email a photo afterwards. That is exactly backwards, on privacy grounds and on commercial ones.
Frequently asked questions
Does BIPA apply to me if my business is not in Illinois?
It turns on where the customer is, not where you are. An out-of-state online seller with Illinois customers is the standard fact pattern in these cases.
Is virtual try-on illegal now?
No. Nothing in the decision prohibits face-scanning try-on. It removes an exemption defence, which means the ordinary requirements — notice, written consent, a published retention policy — have to actually be met.
Did the Seventh Circuit rule that Gunnar violated BIPA?
No, and this is worth getting right. It vacated a dismissal and sent the case back for further proceedings. The exemption may still be litigated on a developed record. What changed is that this can no longer be resolved before discovery.
We only sell prescription eyewear. Are we safe?
Better positioned, not safe. The HIPAA definition the exemption borrows covers dispensing a device in accordance with a prescription, so the argument is available in a way it is not for plano product. But the Seventh Circuit also read the exemption as requiring the collecting entity to comply with HIPAA's rules, and most online eyewear retailers have never analysed whether they do. Take advice rather than assuming.
We use a third-party try-on app from the app store. Are we covered?
Not automatically. The obligation attaches to the party collecting the data, and plaintiffs routinely name the retailer whose site the tool ran on. Get the data-flow answer and the indemnity position in writing.
What about sunglasses specifically — aren't they medical devices?
They are FDA Class I devices, and that was the reasoning of the 2023 Dior dismissal. Both the Illinois Appellate Court in 2024 and the Seventh Circuit in 2026 declined to treat that classification as the test, the Illinois court noting that Class I also covers bandages and toothbrushes. Do not build a compliance posture on the older case without counsel.
Does a prescription upload form create the same problem?
It is a different category. Prescription values are not biometric identifiers as these statutes define them. They still deserve careful handling under general privacy and health-data law — and note that Washington's Act sweeps in a broad range of health-related data, not only biometrics — but they do not trigger the biometric consent regimes discussed here.
This article is general information about legal developments, not legal advice. Biometric privacy obligations depend on your product mix, your technology, your vendors and where your customers are; take advice on your own position before acting.
VisioncarePro adds structured prescription capture and lens selection to any Shopify product page, so the highest-value step in an eyewear order happens where the customer already is — no camera required. Free to install.
Install VisioncarePro free on the Shopify App Store →
New to selling prescription eyewear online? Start with our complete guide to selling prescription glasses on Shopify.
Sources: Clements v. Gunnar Optiks, LLC, No. 25-1890 (7th Cir. 10 July 2026) — slip opinion read directly, including the disposition, the “aesthetic, not medical” and “better-appearing glasses” passages, the “$5 sunglasses” example, the 45 C.F.R. § 160.103 “in accordance with a prescription” point and the HIPAA-compliance observation · Marino v. Gunnar Optiks, LLC, No. 1-23-1826 (Ill. App. 1st Dist. 30 Aug. 2024), certified question answered in the negative · Warmack-Stillwell v. Christian Dior, Inc. (N.D. Ill. 10 Feb. 2023) · Clay v. Union Pacific Railroad Co., No. 25-2185 (7th Cir. 1 Apr. 2026) · 740 ILCS 14 (BIPA), as amended August 2024 · Texas Attorney General guidance on the Capture or Use of Biometric Identifier Act · Washington My Health My Data Act, RCW 19.373, and Washington Consumer Protection Act · Quarles & Brady, DiCello Levitt and Sidley commentary on Clements and Clay.