Midjourney · Midjourney Data Retention & Privacy FAQ · View original document ↗

GDPR and UK GDPR Data Subject Rights

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Midjourney recorded 6 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Midjourney Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

If you are in the EU or UK, you have rights to see, correct, delete, or transfer your data, and to object to how it is processed; you can exercise these by emailing privacy@midjourney.com.

This analysis describes what Midjourney's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The policy explicitly grants EU and UK users a defined set of GDPR data subject rights, including the right to erasure and the right to object to processing, which are enforceable under GDPR against Midjourney as a data controller.

Consumer impact (what this means for users)

EU and UK users can contact Midjourney at privacy@midjourney.com to access, correct, delete, or obtain a copy of their personal data, or to object to specific processing activities such as AI training use.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    EU or UK users should email privacy@midjourney.com stating the specific right they wish to exercise (access, erasure, portability, or objection) and include sufficient information to verify their identity; Midjourney is required to respond within one month under GDPR.
  • Export Your Data
    Email privacy@midjourney.com requesting a copy of your personal data in a portable format, citing your right to data portability under GDPR Article 20.

Cross-platform context

See how other platforms handle GDPR and UK GDPR Data Subject Rights and similar clauses.

Compare across platforms →

Monitoring

Midjourney has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If you are located in the European Economic Area or the United Kingdom, you have certain rights regarding your personal information, including the right to access, correct, or delete your personal information, the right to restrict or object to processing, and the right to data portability. To exercise these rights, please contact us at privacy@midjourney.com.

— Excerpt from Midjourney's Midjourney Data Retention & Privacy FAQ

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: This provision directly engages GDPR Articles 15 through 22, covering access, rectification, erasure, restriction, portability, and objection rights. UK GDPR imposes equivalent obligations. Midjourney's compliance with response timelines (one month under GDPR Article 12, with extension in complex cases) is an enforceable obligation. EU/EEA data protection authorities, including the lead supervisory authority under GDPR's one-stop-shop mechanism, have jurisdiction over complaints. GOVERNANCE EXPOSURE: Medium. The provision is facially compliant with GDPR disclosure requirements, but governance exposure arises from the operational complexity of fulfilling rights requests for AI training data, prompt content, and generated images. Erasure requests for content already used in AI model training present particular technical and legal challenges that the policy does not address. JURISDICTION FLAGS: EU/EEA and UK users have enforceable rights under GDPR and UK GDPR respectively. The Irish Data Protection Commission may serve as lead supervisory authority depending on Midjourney's EU establishment. Failure to respond to rights requests within statutory timelines creates direct regulatory exposure. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers contracting for EU user data processing should verify that Midjourney's data processing agreement addresses sub-processor obligations and data subject rights fulfillment in relation to AI training data. Rights request handling procedures should be confirmed through due diligence. COMPLIANCE CONSIDERATIONS: Legal teams should assess whether Midjourney's process for handling erasure requests adequately addresses the technical challenge of removing personal data from AI training datasets. Objection to processing rights, if invoked regarding AI training use, require documented assessment of compelling legitimate grounds under GDPR Article 21. Response SLA monitoring and escalation procedures should be in place.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • State AG
    EU/EEA data protection authorities and the UK Information Commissioner's Office have enforcement authority over GDPR and UK GDPR rights; State_AG is the closest available category for regional regulatory authority.
    File a complaint →

Provision details

Document information
Document
Midjourney Data Retention & Privacy FAQ
Entity
Midjourney
Document last updated
May 12, 2026
Tracking information
First tracked
May 12, 2026
Last verified
May 12, 2026
Record ID
CA-P-011986
Document ID
CA-D-00828
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
dc64a31f31e3763fff77bbf3fcb645d925ef20a453b61c9779b90767e2a4b4bc
Analysis generated
May 12, 2026 16:49 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Midjourney
Document: Midjourney Data Retention & Privacy FAQ
Record ID: CA-P-011986
Captured: 2026-05-12 16:49:44 UTC
SHA-256: dc64a31f31e3763f…
URL: https://conductatlas.com/platform/midjourney/midjourney-data-retention-privacy-faq/gdpr-and-uk-gdpr-data-subject-rights/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Midjourney's GDPR and UK GDPR Data Subject Rights clause do?

The policy explicitly grants EU and UK users a defined set of GDPR data subject rights, including the right to erasure and the right to object to processing, which are enforceable under GDPR against Midjourney as a data controller.

How does this clause affect you?

EU and UK users can contact Midjourney at privacy@midjourney.com to access, correct, delete, or obtain a copy of their personal data, or to object to specific processing activities such as AI training use.

Is ConductAtlas affiliated with Midjourney?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Midjourney.