LOOKSMITH

Notes

AI photo app privacy law: BIPA, CUBI, GDPR and the EU AI Act

Last updated:

Illinois, Texas, Washington, the GDPR and the EU AI Act each set a different rule for an app that touches your face, with different stakes for breaking it.

Five laws govern an app that captures your face and paints something onto it. Illinois requires a written release before collection. Texas and Washington require notice but leave enforcement to the state. The GDPR treats a face template as a special category of data. The EU AI Act, since 2 August 2026, requires the finished image to carry a machine-readable mark.

None of them were written with a makeup app in mind, and all of them now apply to one.

Which law applies to you

The laws differ on what happens once something goes wrong: a fixed payment you can collect without proving harm, a payment you can collect only if you prove it, a case only a regulator can bring, or no personal claim at all.

LawWho it coversWhat it requires of the appWhat it gives the user
Illinois BIPA, 740 ILCS 14Private companies collecting a biometric identifier from an Illinois residentWritten notice, then a written release, before collection. A published retention and destruction schedule. No sale, lease, trade or profit from biometric dataA private right to sue. Liquidated damages of $1,000, or actual damages if greater, for a negligent violation, $5,000 for an intentional one, plus attorneys' fees, no proof of harm required for the minimum
Texas CUBI, Bus. & Com. Code ch. 503Persons capturing a biometric identifier for a commercial purpose from a Texas residentInform the person and get consent before capture. No sale, lease or disclosure outside narrow exceptions. Destruction within a reasonable time, no later than one year after the purpose endsNo private right to sue. The attorney general may seek a civil penalty of up to $25,000 per violation
Washington biometric law, RCW 19.375Persons enrolling a biometric identifier in a database for a commercial purposeNotice, then either consent or a way to opt out, before enrollment. No sale or disclosure outside narrow exceptions. Retention only as long as necessaryNo private right to sue. Enforcement sits solely with the state attorney general under the state's consumer protection act
GDPR, Article 9Any company processing the personal data of someone in the EU, wherever basedBiometric data used to uniquely identify a person is a special category. Processing it is prohibited by default. Explicit consent is the exception an app relies onA right to sue for compensation if you can show damage, plus the right to withdraw consent, erase your data and complain to a supervisory authority
EU AI Act, Article 50, applicable from 2 August 2026Providers of AI systems that generate synthetic image, audio, video or textMark the output in a machine-readable format, detectable as artificially generated or manipulatedNot a consent right and not a private claim. A technical signal that travels with the file, so a platform or a viewer can detect it later

Does Illinois' BIPA require a written release before a face app runs?

Yes, and the word is release, not consent. Section 15(b) requires a private entity to give written notice of what it is collecting and how long it will keep it, then obtain a written release, before it collects a biometric identifier or biometric information. A consent checkbox buried in a terms-of-service screen nobody reads is not what the statute describes. Section 10 defines a biometric identifier as a retina or iris scan, a fingerprint, a voiceprint, or a scan of hand or face geometry, and excludes a photograph on its own. A scan of face geometry extracted from that photograph is a different thing, and it is the thing the statute reaches.

Retention has its own rule. Section 15(a) requires a written, publicly available policy that destroys biometric data when the purpose for collecting it is satisfied, or within three years of the person's last interaction with the company, whichever comes first. Section 15(c) separately bars selling, leasing, trading or profiting from a person's biometric identifier, with no consent exception.

Illinois is also the one jurisdiction here where a person, not a regulator, can bring the claim, and the only one where the fixed figure does not depend on proving harm. Section 20 gives anyone aggrieved a right of action in state or federal court: liquidated damages of $1,000, or actual damages if greater, for a negligent violation, and $5,000, or actual damages if greater, for an intentional or reckless one, plus attorneys' fees. An amendment effective 2 August 2024 narrowed how those damages accrue: repeated collection or disclosure of the same biometric data to the same recipient now counts as one violation, not one per instance, closing off a per-scan reading that had produced damages far larger than the underlying harm.

How is Texas' CUBI different from BIPA, and why does the difference matter?

The consent requirement reads similarly. Section 503.001 requires a person to inform someone and obtain consent before capturing a biometric identifier for a commercial purpose, and it bars selling, leasing or disclosing that identifier outside four narrow exceptions: consent to identify someone missing or dead, completing a requested transaction, a legal requirement, or a law enforcement warrant. Captured identifiers must be destroyed within a reasonable time, no later than one year after the purpose for collecting them ends.

What Texas does not give you is a way to enforce it yourself. There is no private right of action in CUBI. Only the Texas attorney general can bring a case, and the penalty is a civil fine of up to $25,000 per violation, paid to the state, not the person whose face was captured. A company that violates BIPA answers to the people it violated; one that violates CUBI answers to the attorney general, if it chooses to look. That difference is why BIPA drives class-action filings and CUBI mostly does not.

Does Washington let you sue over your face data?

No. RCW 19.375.020 requires a company to give notice before enrolling someone's biometric identifier in a database for a commercial purpose, and either get consent or provide a way to prevent later use of that data, a lower bar than BIPA's written release. It restricts sale and disclosure outside similar exceptions, and limits retention to what is necessary. But RCW 19.375.030 states that the chapter "may be enforced solely by the attorney general" under the state's consumer protection act. Washington sits closer to Texas than to Illinois on the axis that decides whether the law is a right you hold or a rule the state might someday enforce.

Is a selfie biometric data under the GDPR?

Sometimes, and the wording is specific. Article 4(14) defines biometric data as personal data resulting from specific technical processing of a physical characteristic that allows or confirms unique identification, naming a facial image as an example. A photograph sitting untouched in a camera roll is personal data under Article 4(1) either way, because it relates to an identifiable person. It becomes biometric data specifically when something processes it into a form that can identify that person, such as a face geometry template built to render a look onto the right face every time.

Article 9 treats biometric data used for unique identification as a special category. Processing it is prohibited unless an exception applies, and for a consumer app the exception that fits is explicit consent under Article 9(2)(a), a higher bar than the ordinary consent covering most other personal data under Article 6. The GDPR also does not stop at the EU's border: Article 3(2) applies it to any company, wherever based, that offers goods or services to people in the EU. A US company with no EU office is still covered the moment an EU resident uses the product.

The GDPR does let you sue, unlike Texas or Washington, but on different terms than BIPA. Article 82 gives a data subject a right to compensation for material or non-material damage from an infringement, brought through the courts under Article 79. There is no fixed figure like BIPA's $1,000 or $5,000: a claimant has to show the damage, not just the paperwork failure.

Will the EU AI Act require an AI photo to say it is AI?

From 2 August 2026, yes, for the providers running the model. Article 50(2) requires a provider of an AI system that generates synthetic audio, image, video or text to mark the output in a machine-readable format, detectable as artificially generated or manipulated. That duty sits on the model provider's output, separate from what a consumer app discloses in its own interface. The Act sets that date in Article 113, and the European Commission's own summary of the phased rollout confirms transparency obligations, including Article 50, became applicable on 2 August 2026, ahead of a separate deadline of 2 December 2027 for high-risk uses of biometric systems.

A related duty falls on whoever deploys the system rather than whoever builds it. Article 50(4) requires a deployer of an AI system that generates or manipulates image, audio or video content amounting to a deepfake to disclose that it was artificially generated or manipulated. Whether a specific rendered photograph meets the Act's definition of a deepfake is a question this page will not settle. What is settled is that the marking duty on the model provider is not optional, and 2 August 2026 is not a future date anymore.

What Looksmith says about itself

This page describes what five legal texts require of any app that captures a face, not a claim about whether Looksmith meets them. Looksmith is an iOS app from Mirable Labs, Inc., coming soon, not shipped. What Mirable Labs states about consent, retention, disclosure and training is written in the privacy policy, and the terms governing the account are at /terms. Read those documents directly rather than taking this page's summary of the law as a summary of the company. If something in either is unclear, /help is where to ask, and /about says who is behind Mirable Labs.

The pattern underneath five different laws

Every one of these texts answers the same question with a different amount of trust in the regulated company. Illinois hands the remedy straight to the person whose face was taken, priced at a fixed figure regardless of provable harm. Texas and Washington route that same remedy through a state office that has to choose to act. The GDPR demands more than ordinary consent, and lets a person sue only once they can show a real injury. The EU AI Act assumes the harm sits downstream, at the point someone looks at an image and cannot tell it was made, so it regulates the file, not the transaction that produced it.

Read for what an app must do and every one of these laws sounds similar: tell the person, get something from them, do not keep the data forever. Read for what happens when an app does not, and they stop sounding similar at all. That second reading is the one worth doing before you upload a photograph, not the first.

Which of these laws actually protects me if an app misuses my face?

Illinois' BIPA does the most, since it is the only law here that pays without proof of harm. The GDPR lets you sue too, through Article 79 and Article 82, but only once you can show damage. Texas and Washington hand enforcement entirely to a state attorney general, and an unenforced rule is a promise, not a protection. The EU AI Act protects something narrower: your ability to tell a synthetic image from a real one, not your data, and no private claim comes with it. A state with no biometric statute of its own gives you nothing, worth knowing if you live in one.

Looksmith renders a full makeup look onto your own face and lists the products it used. iOS, coming soon.

What Looksmith does