Illinois Federal Court Rules that BIPA Health Care Exemption Applies to Sunglasses Virtual Try-On Tool
Time 2 Minute Read

On February 10, 2023, an Illinois federal district court ordered the dismissal of a putative class action lawsuit alleging that an online tool that allowed users to virtually try on sunglasses violated the Illinois Biometric Privacy Act (“BIPA”).

In Delma Warmack-Stillwell v. Christian Dior Inc., the plaintiff sued French luxury brand Dior, and alleged that it violated (1) Section 15(b) of BIPA by failing to provide notice and to obtain consent when collecting her biometric information; (2) Section 15(a) of BIPA by failing to institute, maintain and adhere to a publicly available biometric information retention and destruction policy; and (3) Section 15(d) of BIPA by disclosing or otherwise disseminating her biometric information to third parties without consent.

Dior moved to dismiss the case based on the “health care” exemption in the statute. BIPA excludes “information captured from a patient in a health care setting” from the statute’s definition of “biometric identifier.” 740 ILCS 14/10. Dior argued that, because sunglasses—including the non-prescription sunglasses at issue in the plaintiff’s complaint—are Class I medical devices under the Food & Drug Administration’s regulations, the facial geometry information collected from the patient was captured “in a health care setting” and thus was exempt from BIPA’s application.

U.S. District Judge Elaine E. Bucklo agreed, finding that Dior’s virtual try-on tool “facilitates the provision of a medical device that protects vision.” Judge Bucklo concluded that the health care exemption applied because the virtual tool “facilitates the purchase of sunglasses to wear on one’s face—which is exactly the use that fulfills that product’s medical purpose.”

Because BIPA does not define what constitutes a “health care setting,” this case provides significant guidance on the scope of the health care exemption.

You May Also Be Interested In

Time 2 Minute Read

On April 1, 2026, the U.S. Court of Appeals for the Seventh Circuit held that the 2024 amendment to Illinois’ Biometric Information Privacy Act, limiting damages, applies retroactively to pending cases.

Time 5 Minute Read

Connecticut enacted SB 1295 in June, which added another round of amendments to the Connecticut Data Privacy Act. While most of the changes will take effect on July 1, 2026, impact assessment requirements will apply to processing activities created or generated on or after August 1, 2026.

Time 4 Minute Read

On May 30, 2025, the Texas legislature passed the Texas Responsible Artificial Intelligence Act, which regulates the development and deployment of AI systems.

Time 2 Minute Read

On May 9, 2025, Texas Attorney General Ken Paxton announced a $1.375 billion agreement in principle to settle cases it filed against Google in 2022 alleging that Google unlawfully collected, stored and used certain personal data of Texans without consent, including location information, biometric identifiers and web browsing activity.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page