Skip to main content
Home/Blog/Snapchat AR Try-On Ads 2026: Beauty Brands and the COPPA Crossover
Back to Intelligence Hub
kids-teensGlobalRisk Level: critical

Snapchat AR Try-On Ads 2026: Beauty Brands and the COPPA Crossover

Snapchat AR Try-On for beauty brands collides with COPPA where Snap's audience skews young. The biometric and age-gating obligations advertisers regularly miss.

May 22, 202610 min readAuditSocials Research
TweetShare
Quick Answer

Snapchat AR Try-On ads for beauty brands trigger COPPA-adjacent obligations when audience composition skews under-13 despite Snap's official 13+ stance. Biometric data collection by AR Lenses creates parallel exposure under state biometric privacy laws (BIPA, CUBI), requiring age-gating verification beyond signup attestation.

Snapchat AR Try-On Ads 2026: Beauty Brands and the COPPA Crossover

Where Beauty AR Collides with COPPA

Beauty brands have invested heavily in Snapchat AR Try-On through 2020-2026 because the format produces measurable conversion uplift, supports product discovery for shade-dependent categories, and aligns with Snap's audience demographic position. The investment produces a compliance crossover that beauty brands frequently underestimate — the format processes face data, the platform's audience skews young, and the underlying campaign mechanics produce COPPA, state biometric, and EU GDPR exposure that requires structured compliance posture beyond what the platform's own framework provides.

The crossover is consequential because each of the underlying frameworks operates with significant enforcement infrastructure. COPPA produces FTC and state AG enforcement against advertisers that meet the directed-to-children or actual-knowledge tests. State biometric privacy laws (BIPA most prominently) produce class action litigation with statutory damages frameworks. EU GDPR produces fines up to 4% of global turnover for biometric processing failures. The cumulative regulatory exposure is material for beauty brands at scale, and the structured compliance posture is non-optional rather than discretionary.

Under COPPA, operators can carry compliance obligations whether the service is directed to children under 13 or the operator has actual knowledge of collecting their data, and practitioners read the actual-knowledge analysis to extend to constructive knowledge from campaign signals.
— Practitioner reading of the COPPA actual-knowledge standard, not a verbatim FTC quote

This guide covers how Snapchat AR Try-On actually processes face data, the COPPA framework applied to AR beauty, state biometric laws and AR face processing, age-gating mechanics and their limits, and the structured beauty brand compliance workflow. For broader kids-and-teens framework see the Healthcare Compliance guide and the Policy Change Tracker.

Why the Crossover Matters Now

The crossover has become acute through 2024-2026 because three regulatory currents have intensified simultaneously. The FTC's biometric data enforcement focus, formalised in the 2023 Policy Statement on Biometric Information and operationalised through 2024-2026 enforcement, treats face processing as a priority concern regardless of processing location. State biometric privacy laws have proliferated beyond BIPA's Illinois baseline into Texas CUBI, Washington H.B. 1493, and sensitive-category provisions within the newer comprehensive state privacy laws in Colorado, Virginia, Connecticut, Utah, Oregon, Tennessee, and others. EU GDPR Article 9 special category data enforcement has tightened around biometric processing through the European Data Protection Board's 2024 guidance on AI and biometric identification. The three currents combine to produce a compliance landscape in which beauty brand AR Try-On campaigns face structured exposure across multiple frameworks with cumulative enforcement risk.

The Practitioner's Framing

The practitioner's framing of beauty AR Try-On compliance should treat each campaign as operating within a defined risk envelope rather than within an undifferentiated compliance baseline. The envelope is defined by the campaign's targeting parameters, the creative's audience appeal signals, the AR processing characteristics, the consent infrastructure quality, the retention and destruction posture, the disclosure adequacy, and the documentation completeness. Each dimension contributes to the overall risk envelope, and the compliance practice should address each dimension explicitly rather than relying on a single global posture. The dimensions interact in ways that are not always intuitive — a creative that produces directed-to-children signals can elevate the COPPA risk for a campaign with otherwise conservative targeting, and a consent infrastructure gap can elevate the BIPA risk even when the platform's own posture is compliant. The compliance practice must address the dimensions in combination rather than in isolation.

How Snapchat AR Try-On Actually Processes

Snapchat AR Try-On processing runs through Snap's Lens infrastructure with specific mechanics that produce the format's compliance profile. The processing has on-device and platform-side components.

Processing Components

ComponentProcessing LocationData Implication
Face detection and landmarksOn-device through Snap Lens SDKFace geometry data; biometric within state law definitions
Expression and movement trackingOn-deviceBehavioural data; supports interactivity
AR effect renderingOn-deviceCreative output; the rendered try-on visual
Engagement and interaction telemetryPlatform-sideAggregated metrics; supports ad measurement
Content sharing if user shares modified contentPlatform-side and user-initiatedModified content uploaded to platform if shared

Compliance Profile

  • On-device processing reduces some data transmission risk but does not eliminate biometric processing legal characterization.
  • Engagement telemetry reaches platform infrastructure and connects to broader Snap data systems.
  • Modified content sharing creates additional data flow when users share AR-modified content.
  • Conservative legal interpretation treats AR face processing as biometric for state law purposes regardless of processing location.

Biometric Characterisation Under State Law

The legal characterisation of AR face processing as biometric data is the threshold question that determines which state and federal frameworks apply to the campaign. The characterisation is contested across jurisdictions, but the conservative compliance posture treats AR face processing as biometric for state law purposes regardless of processing location. The Illinois BIPA definition of biometric identifier includes a scan of face geometry, and Illinois courts have interpreted the definition to include face geometry created through AR processing where the geometry is capable of identifying the individual. The Texas CUBI definition is similar in scope. The Washington H.B. 1493 definition is narrower in some respects but is generally interpreted to include face geometry processing. The newer comprehensive state privacy laws (CPA, CDPA, CTDPA, UCPA, others) define biometric data as a sensitive data category with consent and processing requirements. The cumulative effect is that AR face processing in beauty Try-On campaigns reaching residents of any of these states triggers state law obligations unless the processing falls within a defined exception.

The On-Device vs Platform-Side Distinction

The on-device versus platform-side processing distinction matters for some compliance dimensions but does not eliminate the biometric characterisation. On-device processing through the Snap Lens SDK keeps the raw face data on the user's device rather than transmitting it to platform infrastructure, which reduces some data transmission risk and addresses some retention questions. However, on-device processing does not eliminate the biometric identifier creation, does not exempt the processing from state law consent requirements, and does not affect the FTC's biometric data enforcement posture. The on-device characterisation is useful for the data minimisation argument and for the security posture but is not a compliance shortcut. The platform-side engagement and interaction telemetry reaches Snap's infrastructure regardless of where the face processing occurs, and the telemetry can constitute personal information under various frameworks even when it does not constitute biometric data specifically. The compliance practice should address both the on-device biometric processing and the platform-side telemetry as separate data flows with separate compliance considerations.

For format context see the Snapchat Advertising Guide.

COPPA Framework Applied to AR Beauty

COPPA applies to operators of online services directed to children under 13 or that have actual knowledge of collecting personal information from children under 13. The application to beauty AR campaigns requires deliberate analysis.

COPPA Application Tests

  • Directed-to-children test: Multi-factor analysis of subject matter, visual content, music, language, model age, child celebrities.
  • Actual-knowledge standard: Includes constructive knowledge from campaign signals indicating under-13 engagement.
  • Effective audience analysis: Considers delivered audience composition rather than stated targeting alone.
  • Joint responsibility: Advertiser and platform both face obligations under different aspects of the framework.

Compliance Implications for Beauty AR

  • Creative review must avoid producing directed-to-children signals.
  • Targeting review must exclude signals correlated with under-13 audiences.
  • Engagement monitoring must identify under-13 indicators.
  • Documentation must support compliance posture in regulator inquiry.
  • Verifiable parental consent required if processing children's personal information.

2024-2026 COPPA Rule Developments

The FTC finalised amendments to the COPPA Rule in 2024 that materially affected the actual-knowledge analysis for advertisers. The amendments added biometric identifiers to the categories of personal information covered by COPPA, which directly affects AR Try-On campaigns where face processing can constitute biometric identifier collection. The amendments tightened the verifiable parental consent requirements and clarified that operators cannot rely on age screens alone to disclaim actual knowledge of under-13 users when other campaign signals contradict the age screen. The amendments also expanded the retention and deletion requirements and added specific requirements covering data security, third-party processor diligence, and parental access rights. The compliance impact for beauty brands running AR Try-On campaigns includes elevated obligations on biometric processing, tighter actual-knowledge analysis, and specific procedural requirements that the campaign workflow must accommodate.

State-Level Youth Protection Frameworks

State-level enactments through 2022-2026 extended the youth protection framework beyond the federal COPPA baseline. The California Age-Appropriate Design Code Act (AB 2273) imposes obligations on operators that process data from users under 18, with specific requirements covering default privacy settings, dark pattern prohibitions, age estimation accuracy, data minimisation, and Data Protection Impact Assessments. Similar enactments in other states extended the framework into additional jurisdictions. The state-level frameworks expand the youth protection obligation from the COPPA under-13 baseline into the 13-17 audience segment, which is material for beauty brand AR Try-On campaigns where the 13-17 segment is frequently a significant portion of the platform audience. The compliance practice for beauty brands operating across multiple states should treat the broader youth protection framework as the operational baseline rather than the federal COPPA minimum.

For COPPA framework deep-dive see the Healthcare Compliance guide and the AI Compliance Audit.

State Biometric Laws and AR Face Processing

State biometric privacy laws form a multi-state framework that affects AR face processing in Snapchat Try-On ads. The framework's complexity stems from variation in state-level approaches.

Key State Laws

LawStateKey RequirementsEnforcement
BIPAIllinoisWritten consent; retention schedule; security; no salePrivate right of action; statutory damages
CUBITexasConsent before captureTexas AG
H.B. 1493WashingtonConsent for collectionWashington AG
Various biometric provisionsNY, CO, VA, CT, UT, othersSensitive data treatment; consent; opt-outState AGs; varies by state
EU GDPREU member statesArticle 9 special category; explicit consent or legal basisData protection authorities; up to 4% global turnover

Conservative Compliance Posture

  • Treat AR face processing as biometric for state law purposes regardless of processing location.
  • Consent infrastructure capturing informed consent before AR processing begins.
  • Retention and destruction policies specifying handling of AR processing data.
  • Security measures appropriate to biometric data sensitivity.
  • Documentation supporting defense against claims and regulator inquiry.

BIPA Litigation Record

The BIPA litigation record through 2017-2026 produced several foundational decisions and material settlements that beauty brands should treat as canonical reference. The Rosenbach v. Six Flags decision (Illinois Supreme Court 2019) established that a BIPA violation alone supports a private right of action without proof of actual injury, elevating the litigation risk for any technical BIPA violation. The Cothron v. White Castle decision (Illinois Supreme Court 2023) established that BIPA violations accrue per scan rather than per first-of-kind, materially increasing potential damages exposure for repeated biometric processing. The Patel v. Facebook settlement (2021, $650 million) established at scale that platform-side face geometry processing through AR or photo-tag features can constitute biometric processing under BIPA. Snapchat-specific BIPA settlements resolved through 2022-2024 established that Snap's Lens infrastructure is within BIPA's scope when applied to Illinois residents. The cumulative decisional record means that beauty brand AR Try-On campaigns reaching Illinois residents operate within a litigation framework that treats AR face processing as biometric, accrues damages per scan, and supports private right of action without proof of injury.

EU GDPR Article 9 Treatment

The EU GDPR Article 9 framework treats biometric data used for the purpose of uniquely identifying a natural person as special category data requiring explicit consent or an alternative legal basis from Article 9(2). The European Data Protection Board's 2024 guidance on AI and biometric processing clarified that AR face processing creating face geometry capable of identification falls within Article 9's scope. Consent under GDPR must meet strict standards including freely given, specific, informed, unambiguous, and separately collectable from other consents. The advertiser obligations under GDPR include lawful basis identification, the Data Protection Impact Assessment for high-risk processing, the data subject rights infrastructure, and the cross-border transfer mechanism for any data flow outside the EEA. Beauty brands operating EU-targeted AR Try-On campaigns must coordinate with Snap's GDPR compliance posture but cannot rely solely on the platform's framework.

FTC Biometric Information Policy Statement

The FTC's 2023 Policy Statement on Biometric Information and the subsequent 2024-2026 enforcement docket established that the FTC treats biometric data as a priority concern under Section 5 of the FTC Act. The Policy Statement covers consumer harm from biometric processing, including discrimination risk, security risk, and consumer expectation harm. The enforcement docket produced consent orders against advertisers and platforms for biometric processing failures, with the orders typically requiring affirmative compliance practices, multi-year monitoring, and substantial civil penalties. Beauty brand AR Try-On campaigns should treat the FTC's biometric enforcement posture as material to the compliance practice.

For broader state privacy framework see the US state privacy laws guide and the EU DSA compliance reference.

Age-Gating Mechanics and Their Limits

Snapchat's age-gating system operates through layered mechanisms with documented limitations that beauty brands must close themselves through campaign design.

Platform Mechanisms

  • Self-reported age at signup — base layer with known evasion patterns.
  • Verification layer for specific sensitive content categories.
  • Targeting controls using platform age signals.
  • Content suitability controls for placement adjacency.

Known Gaps

GapMechanismClosing Practice
Under-13 signup leakageUsers falsely confirmed age above 13Conservative targeting (18+); creative review for child-appeal signals
13-15 exposurePermitted users but not appropriate audienceHigher minimum targeting; audience exclusion parameters
Targeting precisionOther parameters shift effective audience youngerAudience definition review; exclude correlated signals
Engagement-pattern feedbackOptimization toward younger engagersOptimization parameter review; engagement monitoring

Technical Age Verification Patterns

Technical age verification patterns vary across platforms and regulatory frameworks, but the patterns that beauty brands should understand for Snapchat AR Try-On compliance fall into several categories. The self-attestation pattern relies on the user confirming a birth date at signup, with known evasion rates and limited reliability for users near the platform's minimum age. The behavioural-signal pattern uses platform-observed behaviour (engagement patterns, content interaction, network connections) to infer probable age, with accuracy that improves over time but remains imperfect. The facial age estimation pattern uses computer vision to estimate age from face images, with accuracy that has improved through 2024-2026 but produces error rates particularly in the 13-17 range. The document-verification pattern uses government-issued identification to verify age, with high accuracy but significant user friction and privacy considerations. The cross-reference pattern uses third-party identity verification services to validate age claims against external databases. Each pattern produces different accuracy, friction, and privacy trade-offs, and the compliance practice should understand which patterns the platform applies in which contexts and how the patterns interact with the advertiser's own targeting controls.

Audience Composition Monitoring

Audience composition monitoring is the practical mechanism for verifying that the campaign's delivered audience matches the brand's intended targeting. The monitoring should aggregate platform-reported demographics, engagement-pattern signals indicating audience age skew, organic audience feedback indicating youth exposure, and any external signals indicating audience composition issues. The monitoring should produce regular review cadence (typically weekly during active campaigns) and should trigger defined response workflows when the composition diverges from the intended targeting. The response workflows may include creative adjustment, targeting parameter adjustment, or campaign pause depending on the severity of the divergence. The monitoring infrastructure should be documented as part of the compliance practice rather than treated as ad-hoc per campaign.

For compliance practice see the Healthcare Compliance guide and the Keyword Risk Checker.

Beauty Brand Compliance Workflow

The structured compliance workflow operates as a documented end-to-end practice covering six phases. The workflow should be applied consistently across all Snap AR Try-On campaigns.

Workflow Phases

  • Campaign concept: Identify applicable frameworks (COPPA, state biometric, GDPR, FTC, Snap policy); document compliance baseline.
  • Creative production: Disclosure of AR modification; claim substantiation; age-appeal review; brand safety review.
  • Audience definition: Minimum age above platform baseline; exclusion parameters; documentation.
  • Technical implementation: Consent capture; retention schedules; destruction mechanics; security measures.
  • Monitoring: Audience composition; engagement patterns; compliance signals; response triggers.
  • Audit: Post-campaign review; pattern analysis; structural improvements; documentation maintenance.

Workflow Support

  • Tooling automating routine compliance checks.
  • Documentation capturing compliance posture per campaign.
  • Training ensuring consistent application across organization and agency partners.
  • Governance tying compliance outcomes to marketing accountability.

Cross-Functional Coordination

The compliance workflow requires cross-functional coordination across the brand's marketing, legal, privacy, and agency partner functions. The coordination should establish defined roles, responsibilities, and decision rights for each workflow phase. The marketing function typically owns the campaign concept and audience definition phases, with input from legal and privacy on the regulatory considerations. The legal function typically owns the regulatory framework identification and the compliance baseline documentation, with input from privacy on the biometric processing specifics. The privacy function typically owns the consent infrastructure, retention mechanics, and data subject rights implementation. The agency partners typically own the creative production execution, with compliance integrated into the production process through brand-supplied guidelines and review checkpoints. The cross-functional coordination should be governed through documented processes rather than relying on ad-hoc collaboration, and the documentation should be maintained as the workflow evolves.

Compliance Telemetry and Reporting

Compliance telemetry and reporting produces the visibility into the compliance posture that the brand's governance function requires. The telemetry should aggregate campaign-level compliance signals (targeting compliance, creative compliance, disclosure adequacy, consent capture, retention compliance) into brand-level reporting that supports governance review. The reporting cadence should align with the brand's broader compliance governance cycle (typically monthly operational review and quarterly executive review). The reporting should identify systemic issues that require structural workflow improvement rather than treating each issue as a one-off. The telemetry infrastructure should be designed to support both ongoing operational monitoring and post-campaign audit, with the audit producing learnings that feed back into the workflow design.

For workflow tooling and aggregate practice see the AI Compliance Audit, the Disclosure Checker, and the Legal Compliance Scan.

Beauty AR Compliance Checklist

  • [ ] Applicable frameworks identified — COPPA, state biometric, GDPR, FTC, Snap policy
  • [ ] Creative reviewed against directed-to-children signals
  • [ ] Disclosure of AR or AI modification in creative
  • [ ] Claim substantiation supports AR-rendered effect
  • [ ] Audience targeting set at 18+ minimum for beauty AR campaigns
  • [ ] Audience exclusion parameters for under-target signals
  • [ ] Lookalike and interest-based parameters reviewed for younger-skew
  • [ ] Consent infrastructure captures informed consent before AR processing
  • [ ] Retention schedule documented with destruction mechanics
  • [ ] Security measures appropriate to biometric data
  • [ ] Audience composition monitored against intended targeting
  • [ ] Engagement patterns monitored for under-target indicators
  • [ ] Post-campaign compliance audit completed

For comprehensive beauty brand compliance audit run the AI Compliance Audit and reference the Kids and Teens Compliance guide.

Frequently Asked Questions

For ongoing tracking of biometric privacy law, COPPA, and platform policy updates, see the Policy Change Tracker.

Frequently Asked Questions

Why does COPPA apply to Snapchat AR Try-On ads when the campaigns are not directed at children?
COPPA's application to Snapchat AR Try-On campaigns is non-obvious because the Children's Online Privacy Protection Act applies to operators of websites or online services directed to children under 13 or that have actual knowledge of collecting personal information from children under 13. Snapchat's official platform position is that the service is for users 13 and older, and Snap requires age confirmation at signup. The position would seem to exempt Snapchat-based campaigns from COPPA obligations. The exemption is incomplete for three structural reasons that affect Beauty AR Try-On specifically. The first reason is the actual-knowledge standard. COPPA imposes obligations when an operator has actual knowledge of collecting personal information from children under 13, regardless of the operator's stated audience policy. Beauty brands running AR Try-On campaigns on Snapchat with high-engagement creator partnerships, broad targeting that reaches younger Snapchat audiences, or campaign signals that indicate substantial under-13 engagement may produce actual-knowledge situations. The actual-knowledge analysis considers the campaign's targeting parameters, the creative's audience appeal, the engagement patterns observed, and any direct signals indicating under-13 users. Brands that close their eyes to these signals do not avoid COPPA obligations; the actual-knowledge standard is interpreted to include constructive knowledge in some enforcement contexts. The second reason is the directed-to-children analysis. COPPA's directed-to-children test applies a multi-factor analysis covering the campaign's subject matter, visual content, music, language, age of models or characters, presence of child celebrities, and other relevant factors. Beauty campaigns can be directed to children even when the brand's stated target audience is adults if the campaign's content uses child-appealing aesthetics, features young models, includes child-oriented music or language, or otherwise produces directed-to-children signals. AR Try-On campaigns specifically often use playful, gamified, or fantasy aesthetics that can produce directed-to-children signals even when the underlying product is positioned for adults. The third reason is the platform-side responsibility chain. COPPA imposes obligations on operators of online services including platforms, and Snapchat's compliance with COPPA affects the advertiser's compliance posture through the platform-side chain. When Snapchat is operating as a COPPA-compliant service for users 13 and older but the advertiser's campaign produces effective targeting of under-13 users through campaign design or actual-knowledge signals, the advertiser inherits compliance obligations even though the platform operates with its own COPPA framework. The cumulative effect is that beauty brands running AR Try-On campaigns on Snapchat should treat COPPA as a baseline compliance consideration rather than assuming the platform's age policy exempts the brand. The structured compliance posture includes campaign targeting that excludes signals indicating under-13 users, creative that does not produce directed-to-children signals, monitoring of campaign engagement patterns for under-13 indicators, and documentation of the compliance review process. The compliance posture protects against both direct FTC enforcement (the FTC has authority to enforce COPPA against advertisers as well as platforms) and against parallel state attorneys general enforcement. The 2024-2026 enforcement window produced specific COPPA developments that beauty brands should treat as material to the actual-knowledge analysis. The 2024 COPPA Rule amendments tightened the verifiable parental consent requirements, added new categories of personal information including biometric identifiers, and clarified that operators cannot rely on age screens alone to disclaim knowledge of under-13 users when other campaign signals contradict the age screen. The amendments produced compliance impact across the advertising industry and elevated the actual-knowledge standard for advertisers whose campaigns produce engagement signals from younger users. State-level COPPA-adjacent enactments through 2024-2026 (California AB 2273 Age-Appropriate Design Code, similar enactments in other states) extended the youth protection framework beyond the federal COPPA baseline. The state enactments impose obligations on operators that process data from users under 18, with specific requirements covering default privacy settings, dark pattern prohibitions, age estimation accuracy, and data minimisation. Beauty brands running AR Try-On campaigns in states with the broader youth protection enactments face compliance obligations that extend beyond COPPA's under-13 scope into the 13-17 audience segment. The compliance practice for beauty brands operating across multiple states should treat the broader youth protection framework as the operational baseline rather than the federal COPPA minimum. The directed-to-children analysis for beauty AR specifically should consider several creative pattern signals that 2024-2026 enforcement has surfaced as problematic. Playful or fantasy AR effects (princess crowns, animal features, sparkle overlays) carry directed-to-children risk even when the underlying product is positioned for adults. Music selection from genres associated with younger audiences carries similar risk. Creator partnerships with influencers whose follower demographics skew young produce directed-to-children signals through the partnership rather than through the brand's own creative. Featured user-generated content from younger creators produces directed-to-children signals through the curated content selection. The cumulative effect of these signals across a campaign produces a directed-to-children determination even when no single signal would be decisive in isolation. For comprehensive COPPA compliance framework see the Healthcare Compliance guide, the AI Compliance Audit, and the FTC influencer compliance guide.
What state biometric privacy laws apply to AR face processing in Snapchat Try-On ads, and what specific obligations do they impose?
State biometric privacy laws have proliferated through 2018-2026 and now form a complex multi-state framework that affects AR face processing in Snapchat Try-On ads. The framework's complexity stems from the absence of a federal biometric privacy law and the variation in state-level approaches. The most consequential state laws include Illinois BIPA, Texas CUBI, Washington H.B. 1493, and more recent enactments in New York, Colorado, Virginia, Connecticut, and other states. Illinois BIPA (Biometric Information Privacy Act) is the most consequential state biometric law for several reasons. BIPA imposes broad obligations including written informed consent before collection or use of biometric identifiers or information, publicly available retention and destruction schedules, prohibition on selling or trading biometric data, reasonable care standards for biometric data security, and a private right of action with statutory damages ($1,000 per negligent violation, $5,000 per intentional violation). The private right of action has produced extensive class action litigation through 2017-2026 with material damages awards. BIPA applies to biometric processing of Illinois residents regardless of where the processing occurs, and AR face processing on Snapchat that includes Illinois-resident users triggers BIPA obligations. Texas CUBI (Capture or Use of Biometric Identifiers) imposes consent requirements before capturing biometric identifiers and is enforced by the Texas Attorney General. CUBI does not include a private right of action, which produces lower litigation risk than BIPA but does not reduce regulatory exposure. Washington H.B. 1493 imposes consent requirements for biometric identifier collection and is enforced by the Washington Attorney General. New York biometric provisions in various state acts impose obligations on biometric collection by certain operators. The newer comprehensive state privacy laws (Colorado CPA, Virginia CDPA, Connecticut CTDPA, Utah UCPA, and others enacted through 2021-2026) include biometric data as sensitive category data with specific consent and processing requirements. The AR face processing in Snapchat Try-On ads can produce biometric data within each of these frameworks' definitions, with the specific question being whether the processing creates a biometric identifier or biometric information as the state law defines those terms. The legal interpretation of whether AR face processing creates biometric identifiers is contested and varies across jurisdictions, but the conservative compliance posture treats AR face processing as biometric and applies the state law requirements. The advertiser obligations include consent infrastructure that captures informed consent before AR processing begins (notice of the processing, the purpose, the retention, the data subject rights), retention and destruction policies that specify how AR processing data is handled, security measures appropriate to biometric data, and documentation that supports defense against claims. The platform-side compliance through Snapchat does not exempt the advertiser; the advertiser inherits joint obligations through the campaign relationship. The compliance practice should be coordinated with the platform's own framework but should not depend solely on the platform's compliance. The BIPA litigation record through 2017-2026 produced several decisions that beauty brands should treat as foundational to the compliance posture. The Rosenbach v. Six Flags decision (Illinois Supreme Court 2019) established that a BIPA violation alone, without proof of actual injury, supports a private right of action; the decision elevated the litigation risk profile for any BIPA violation. The Cothron v. White Castle decision (Illinois Supreme Court 2023) established that BIPA violations accrue per scan rather than per first-of-kind, materially increasing potential damages exposure for repeated biometric processing. The Patel v. Facebook settlement (2021, $650 million) and the Snapchat-specific BIPA settlements through 2022-2024 established that platform-side processing of face geometry through AR features can constitute biometric processing under BIPA regardless of the platform's own legal characterisation. The cumulative decisional record means that beauty brand AR Try-On campaigns reaching Illinois residents through Snapchat operate within a litigation framework that treats AR face processing as biometric, accrues damages per scan, and supports private right of action without proof of injury. The compliance practice must include BIPA-specific consent capture before AR processing begins, retention schedules consistent with BIPA's three-year baseline, destruction mechanics documented and verifiable, and contractual allocation of liability with the platform and any creators participating in the campaign. The EU GDPR Article 9 framework treats biometric data used for the purpose of uniquely identifying a natural person as special category data requiring explicit consent or an alternative legal basis from Article 9(2). The European Data Protection Board's 2024 guidance on AI and biometric processing clarified that AR face processing creating face geometry capable of identification falls within Article 9's scope, and that consent must meet GDPR's strict standards (freely given, specific, informed, unambiguous, separately collectable from other consents). The advertiser obligations under GDPR include the lawful basis identification, the data protection impact assessment for high-risk processing, the data subject rights infrastructure (access, rectification, erasure, portability, objection), and the cross-border transfer mechanism for any data flow outside the EEA. Beauty brands operating EU-targeted AR Try-On campaigns must coordinate with Snap's GDPR compliance posture but cannot rely solely on the platform's framework. For broader state privacy law framework see the US state privacy laws guide, the EU DSA compliance reference, and the US compliance reference.
How does Snapchat's age-gating system actually work, and where are the gaps that beauty brands must close themselves?
Snapchat's age-gating system operates through layered mechanisms with documented limitations that affect beauty brand compliance posture. The base layer is age confirmation at signup. Users entering Snapchat for the first time confirm a birth date through the signup flow, and Snapchat applies the confirmed age to the user's account properties. Users under 13 are not permitted to use Snapchat per the platform's terms of service, and the platform applies enforcement against accounts identified as under-13. The age confirmation is self-reported and has documented evasion patterns. The verification layer for sensitive content uses additional age verification mechanisms in specific contexts. The mechanisms include facial age estimation, document-based verification (where applicable), and behavioural signals that indicate age. The verification layer applies primarily to age-restricted content categories (alcohol, gambling-adjacent, certain mature content) rather than to general advertising. Beauty AR Try-On is typically not subject to the verification layer's full requirements. The platform-side targeting controls allow advertisers to set minimum age targeting parameters and exclude users below specified ages. The targeting controls are based on the platform's age signal which derives from confirmed age and behavioural validation. The controls are useful for excluding users below the minimum age the advertiser is comfortable with, but the underlying age signal has known accuracy limitations particularly for users in the 13-17 range. The platform-side content suitability controls allow advertisers to set content suitability parameters that affect ad placement near specific content categories. The controls reduce adjacency to sensitive content but do not directly address user-side age verification. The gaps in the system include several specific patterns that beauty brands should address through their own compliance practice. The first gap is the under-13 leakage from accounts where the user falsely confirmed age above 13 at signup. The leakage is estimated to be material based on regulatory enforcement findings against various platforms, and Snapchat-specific estimates suggest that under-13 users represent a small but non-trivial portion of accounts. Brands cannot rely on the platform's age policy to exclude all under-13 users. The second gap is the 13-15 age range exposure where users are technically permitted on the platform but may not be appropriate audience for certain beauty content. The minimum-age targeting controls help here but rely on the platform's age signal. The third gap is the targeting parameter precision where age-based targeting interacts with other parameters in ways that can produce younger audiences than the advertiser intends. Lookalike audiences, interest-based targeting, and engagement-based optimization can shift the effective audience below the stated age target. The fourth gap is the engagement-pattern feedback where ads that produce strong engagement among younger users may be optimized for further delivery to similar audiences through Snap's algorithmic systems. The optimization can produce younger effective audiences than the campaign's stated targeting. The compliance practice to close the gaps includes targeting parameters set conservatively above the platform's minimum (typically 18+ for beauty AR campaigns), audience definitions that exclude signals correlated with younger users, creative that does not produce age-appeal signals to younger users, engagement monitoring for under-target indicators, and documentation of the compliance posture. The practice should be documented and applied consistently rather than ad-hoc per campaign. The cumulative effect of the practice is that the advertiser closes the gaps in the platform's age-gating system through the advertiser's own campaign design, producing a compliance posture that does not depend solely on the platform's framework. For broader teen-advertising framework see the Kids and Teens Compliance guide.
What specific beauty brand AR Try-On compliance failures have surfaced through enforcement or litigation, and what do they signal about regulatory priorities?
Beauty brand AR Try-On compliance failures have surfaced through several channels including FTC enforcement, state attorney general action, BIPA class action litigation, EU regulatory action, and platform-side investigation findings through 2020-2026. The cumulative record signals regulatory priorities that beauty brands should treat as predictive of future enforcement. The FTC enforcement record includes actions against beauty and adjacent brands for inadequate disclosure of AI-generated or AR-modified imagery, claim substantiation failures where AR effects produced results not achievable with the actual product, and targeting violations where campaigns reached audiences below the brand's stated targeting. The actions have produced consent orders requiring affirmative compliance practices, civil penalties for repeated violations, and ongoing FTC monitoring. The state attorney general record includes parallel actions to FTC enforcement and state-specific actions on biometric processing, age-targeting violations, and consumer protection concerns. State AGs have produced settlements requiring affirmative practices and material monetary outcomes. The BIPA class action record includes multiple actions against beauty brands and platforms for biometric processing without informed consent, retention failures, and security inadequacies. The actions have produced material damages awards through settlement and verdict, with the scale reflecting BIPA's statutory damages framework. The EU regulatory record includes data protection authority action under GDPR on biometric processing without adequate legal basis, consent failures, and data subject rights violations. The actions have produced GDPR fines (up to 4% of global turnover) and ongoing supervisory action. The platform-side investigation record includes Snap-specific and broader platform investigations on age-targeting failures, targeting violations affecting minors, and content moderation issues affecting young audiences. The investigations have produced platform-side enforcement against advertisers including campaign restrictions, account holds, and partnership tagging restrictions. The cumulative record signals several regulatory priorities. The first priority is biometric processing with strong attention to consent infrastructure, retention practices, and security measures. The priority has been consistent across enforcement bodies through 2018-2026 and shows continuing strength. The second priority is age-targeting and youth-audience exposure with strong attention to actual-knowledge analysis, directed-to-children determinations, and effective audience composition. The priority has elevated through 2022-2026 as multiple state and federal frameworks have expanded youth protection. The third priority is disclosure of AI-modified or AR-modified imagery with strong attention to consumer perception, claim substantiation, and material connection. The priority has emerged through 2023-2026 as AI and AR techniques have expanded in advertising. The fourth priority is consumer protection in advertising claims with strong attention to AR effect representation, product claim substantiation, and consumer expectation. The priority has been consistent and shows continuing strength. Beauty brands should treat the priorities as predictive of future enforcement attention. The structured compliance posture includes biometric processing compliance through state and federal frameworks, age-targeting compliance through COPPA and platform mechanisms, disclosure compliance through FTC and platform requirements, and consumer protection compliance through claim substantiation and presentation. The compliance practice should be documented and tested against the established failure patterns. The specific litigation and enforcement events that beauty brands should treat as canonical reference include several recurring fact patterns. The Patel v. Facebook settlement (2021, $650 million) established that platform-side face geometry processing through AR or photo-tag features can constitute biometric processing under BIPA at scale. The Snapchat-specific BIPA class actions resolved through 2022-2024 produced material settlements and established that Snap's Lens infrastructure is within BIPA's scope when applied to Illinois residents. The FTC's 2024-2026 enforcement docket against beauty and personal care brands produced consent orders covering AI-modified imagery disclosure, AR effect substantiation, and influencer disclosure adequacy; the consent orders typically require multi-year compliance monitoring, affirmative consumer notification, and substantial civil penalties. The state attorney general actions in California, New York, Texas, Washington, and Illinois through 2023-2026 produced settlements covering biometric processing, youth-audience exposure, and consumer protection in advertising. The EU Data Protection Authority docket through 2023-2026 produced GDPR enforcement on biometric processing failures with fines reaching the higher tiers of the Article 83 framework. The cumulative record across these channels establishes that beauty brand AR Try-On compliance is being actively scrutinised by multiple regulatory and litigation bodies with material enforcement outcomes. Beauty brands should also recognise that the enforcement priorities are reinforcing one another rather than operating in silos. The FTC's COPPA priority and biometric data priority intersect at AR Try-On campaigns that produce face processing and reach younger audiences. The state BIPA priority and the federal FTC consumer protection priority intersect at AR effects that constitute biometric processing and produce substantiation issues. The EU GDPR priority and the state biometric priorities intersect at cross-border processing where face data flows between EU and US infrastructure. The cumulative intersection produces a compliance landscape in which a single AR Try-On campaign failure can trigger parallel enforcement across multiple frameworks with cumulative material exposure. The compliance posture must address the intersection rather than treat each framework in isolation. The structured compliance practice should integrate biometric processing, youth-audience exposure, disclosure adequacy, and consumer protection into a unified posture that meets the strictest applicable standard rather than the weakest. For consumer protection framework see the Healthcare and Personal Care Compliance guide, the Disclosure Checker, and the Policy Change Tracker.
What does a structured beauty brand compliance workflow look like for Snapchat AR Try-On campaigns?
The structured compliance workflow operates as a documented end-to-end practice covering campaign concept, creative production, audience definition, technical implementation, monitoring, and audit. The workflow should be applied consistently across all Snap AR Try-On campaigns rather than treated as ad-hoc per campaign. The campaign concept phase establishes the campaign's product positioning, target audience, regulatory considerations, and compliance baseline. The phase identifies the applicable frameworks (COPPA, state biometric laws, EU GDPR, FTC consumer protection, Snap platform policy), the specific obligations under each, and the compliance baseline the campaign will meet. The phase documents the compliance approach before creative production begins. The creative production phase produces the AR Try-On creative with compliance integrated into the design. The phase includes disclosure design for AI-modified or AR-modified imagery (clear disclosure that the effect is computer-generated and not achievable with the actual product), claim substantiation for product claims made in conjunction with the AR effect (the AR effect should support rather than misrepresent the actual product), age-appeal review (the creative should not produce directed-to-children signals), and brand safety review (the creative should meet the brand's safety standards for the platform audience). The phase produces creative that supports compliance rather than retrofitting compliance to finished creative. The audience definition phase produces the targeting parameters with compliance posture built in. The phase includes minimum age targeting above the platform's baseline (typically 18+ for beauty AR), exclusion parameters for under-target signals, audience definitions that exclude lookalike or interest-based targeting correlated with younger users, and platform-supplied content suitability controls. The phase documents the audience approach. The technical implementation phase covers the consent infrastructure, retention mechanics, and security measures for biometric processing. The phase includes consent capture before AR processing begins (notice of processing, purpose, retention, data subject rights), retention schedule documentation (how long data is retained, why, when it is destroyed), destruction mechanics (technical implementation of data destruction at retention end), and security measures (appropriate to biometric data sensitivity). The phase coordinates with platform-side compliance through Snap's infrastructure but does not depend solely on platform compliance. The monitoring phase tracks campaign delivery and compliance signals. The phase includes audience composition monitoring (verifying delivered audience matches targeting), engagement pattern review (identifying under-target signals), compliance signal monitoring (any platform notices, regulatory developments, audience feedback indicating compliance concerns), and response triggers (defined thresholds that initiate remediation workflow). The phase produces ongoing visibility into compliance posture. The audit phase aggregates campaign outcomes and compliance learnings. The phase includes post-campaign compliance review (verification that the campaign met the documented compliance posture), pattern analysis (identification of systemic issues across multiple campaigns), structural improvements (changes to the workflow based on audit findings), and documentation maintenance (updated processes, templates, and training materials). The phase produces ongoing improvement to the workflow. The workflow should be supported by tooling that automates routine compliance checks, documentation that captures the compliance posture per campaign, training that ensures consistent application across the brand's marketing organization and agency partners, and governance that ties compliance outcomes back to broader marketing accountability. For workflow tooling and aggregate practice see the AI Compliance Audit and the Kids and Teens Compliance guide.

Don't miss the next policy change.

Create a free account — track every policy change across 8 platforms, get instant alerts, and access every free compliance tool. Or try our Snapchat Ads Audit first.

Create Free Account

Report Keywords — Run AI Compliance Audit

#Snapchat Ads#AR Try-On#Beauty#COPPA#Biometric Data#Age Gating#Ad Compliance#Kids and Teens#Brand Safety#Advertisers#2026 Policy#Compliance Guide 2026

Share This Report

TweetShare

Related Posts

Related Resources