Midjourney · Midjourney Privacy Policy · View original document ↗

GDPR and UK GDPR User Rights

Low severity High confidence Explicitdocumentlanguage Rare · 1 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Midjourney recorded 6 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Midjourney Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Users in the EEA, Switzerland, and UK have the right to access, correct, delete, port, restrict, or object to processing of their personal data, and may withdraw consent at any time or lodge a complaint with a data protection authority.

This analysis describes what Midjourney's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The policy explicitly enumerates GDPR and UK GDPR data subject rights and provides a mechanism for exercising them through account settings, giving EEA and UK users enforceable controls over their personal data.

Recent Activity

This document changed recently

High Apr 21, 2026

The updated privacy policy removed language describing how Midjourney shares personal data, the security measures protecting that data, children's privacy safeguards, procedures for notifying users o…

Consumer impact (what this means for users)

EEA, Switzerland, and UK users can request access to, correction of, deletion of, or portability of their personal data, and can object to or restrict processing, by visiting www.midjourney.com/account; consent withdrawal does not affect prior lawful processing.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Visit www.midjourney.com/account and follow the instructions at the bottom of the page to request access, correction, deletion, or portability of your personal data as an EEA, UK, or Swiss user.

How other platforms handle this

Grammarly Medium

If you are located in the EEA, UK, or Switzerland, you have certain rights with respect to your personal information, including the right to access your personal data, to correct or delete your personal data, to restrict processing of your personal data, to data portability, and to object to process...

Waze Medium

If you are located in the European Economic Area or the United Kingdom, you have certain rights under applicable data protection laws, including the right to access, correct, or delete your personal data, the right to object to or restrict processing, and the right to data portability. You may also ...

Smartsheet Medium

If you are located in the EEA or UK, you may have the following rights under applicable data protection law: the right to access your personal data; the right to rectify inaccurate personal data; the right to erasure of your personal data; the right to restrict processing of your personal data; the ...

See all platforms with this clause type →

Monitoring

Midjourney has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Additionally You have the following data protection rights: You can request access, correction, updates or deletion of your Personal Data. You can object to our processing of your Personal Data, ask us to restrict processing of your Personal Data or request portability of your Personal Data. If we have collected and processed your Personal Data with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your Personal Data conducted in reliance on lawful processing grounds other than consent. You have the right to complain to a data protection authority about our collection and use of your Personal Data.

— Excerpt from Midjourney's Midjourney Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

1) REGULATORY LANDSCAPE: This provision directly implements GDPR Articles 15 through 21 (access, rectification, erasure, restriction, portability, and objection rights) and UK GDPR equivalents. The right to lodge a complaint engages EU national data protection authorities and the UK ICO as relevant enforcement bodies. The policy's note that consent withdrawal does not affect prior processing is consistent with GDPR Article 7(3). The Swiss Federal Act on Data Protection provides equivalent rights for Swiss users. 2) GOVERNANCE EXPOSURE: Medium. The operational capacity to fulfill access, deletion, portability, and objection requests within GDPR's statutory timeframes (generally one month, extendable to three months for complex requests) creates ongoing operational obligations. The policy directs users to www.midjourney.com/account for rights requests, and compliance teams should confirm this mechanism is functional, documented, and capable of meeting response timeframes across all request types. 3) JURISDICTION FLAGS: EEA member states, the UK, and Switzerland are specifically addressed. Rights fulfillment obligations differ in detail between GDPR, UK GDPR, and Swiss FADP, and compliance processes should account for these variations. Users in other jurisdictions are not covered by this section of the policy. 4) COMPLIANCE CONSIDERATIONS: Legal and compliance teams should verify that the rights request mechanism at www.midjourney.com/account is operationally capable of handling all enumerated rights (access, rectification, erasure, restriction, portability, objection), that identity verification procedures are in place, that response timeframes are tracked and met, and that data subject request logs are maintained. The ability to fulfill deletion requests for data used in ML training should be specifically assessed. 5) CONTRACT AND VENDOR IMPLICATIONS: Where Midjourney processes personal data on behalf of enterprise customers, the rights fulfillment process should be coordinated with those customers' own data subject request workflows to ensure end-to-end compliance.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    While EU/UK DPAs are the primary enforcers of GDPR rights, the FTC may evaluate whether Midjourney's US-facing rights fulfillment practices are consistent with stated policy commitments.
    File a complaint →

Applicable regulations

EU AI Act
European Union
BIPA
Illinois, USA
CCPA/CPRA
California, USA
Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
EU AI Act - High Risk Provisions
EU
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
UK GDPR
United Kingdom
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Midjourney Privacy Policy
Entity
Midjourney
Document last updated
May 5, 2026
Tracking information
First tracked
May 12, 2026
Last verified
May 12, 2026
Record ID
CA-P-010982
Document ID
CA-D-00094
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
4f973ca215c40ca11dfb698adf7f5dbf2114ba1559811ad1a732eca9efa6c06f
Analysis generated
May 12, 2026 04:55 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Midjourney
Document: Midjourney Privacy Policy
Record ID: CA-P-010982
Captured: 2026-05-12 04:55:54 UTC
SHA-256: 4f973ca215c40ca1…
URL: https://conductatlas.com/platform/midjourney/midjourney-privacy-policy/gdpr-and-uk-gdpr-user-rights/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Midjourney's GDPR and UK GDPR User Rights clause do?

The policy explicitly enumerates GDPR and UK GDPR data subject rights and provides a mechanism for exercising them through account settings, giving EEA and UK users enforceable controls over their personal data.

How does this clause affect you?

EEA, Switzerland, and UK users can request access to, correction of, deletion of, or portability of their personal data, and can object to or restrict processing, by visiting www.midjourney.com/account; consent withdrawal does not affect prior lawful processing.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 1 platforms. See the full comparison.

Is ConductAtlas affiliated with Midjourney?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Midjourney.