Synthesia · Synthesia Privacy Policy · View original document ↗

Biometric Data Collection and Processing

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Synthesia changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Synthesia recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Synthesia Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy discloses that creating an avatar on Synthesia requires processing biometric data including facial geometry and voiceprints, classified as special category data under GDPR and as biometric identifiers under the Illinois Biometric Information Privacy Act. Processing occurs for avatar generation, identity verification, fraud prevention, and AI model fine-tuning.

This analysis describes what Synthesia's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that avatar creation constitutes biometric data processing subject to heightened legal obligations under GDPR Article 9 and the Illinois Biometric Information Privacy Act, requiring explicit consent as a derogation and compliance with jurisdiction-specific retention, disclosure, and prohibition-on-sale requirements. Enterprise customers deploying Synthesia for employee avatar creation should assess their own obligations as data controllers under these frameworks.

Consumer impact (what this means for users)

Under this provision, users who proceed with avatar creation consent to processing of their facial geometry and voiceprint data, which the policy classifies as biometric data under applicable law. The agreement states that users who decline consent will not have biometric data extracted or processed, but will also be unable to generate an avatar using the automated process, though a manual Studio Avatar option is described as an alternative.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email support@synthesia.io to request erasure of your biometric data. The policy states biometric data is permanently destroyed after relevant processing is completed or when instructed by the customer.

Cross-platform context

See how other platforms handle Biometric Data Collection and Processing and similar clauses.

Compare across platforms →

Monitoring

Synthesia has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Avatar submissions and Biometric Data Sample and Verification Recording by their very nature include unique information relating to the physical characteristics of a natural person, such as facial images and voice data. Avatar creation features require processing of the facial geometry and/or voiceprint from each of the Sample and Verification Recording. Certain steps in creating an Avatar involve the processing of data considered "biometric data", "biometric information", "biometric identifier", "sensitive personal data", or "special category of personal data" under applicable data protection laws in certain jurisdictions (including but not limited to the Illinois Biometric Privacy Act and GDPR). We will refer to this information throughout this Privacy Policy as "Biometric Data" for consistency.

Excerpt from Synthesia's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision implicates GDPR Article 9 (special category data), the Illinois Biometric Information Privacy Act, and by extension other US state biometric laws. The UK Information Commissioner's Office and relevant EU supervisory authorities exercise oversight under GDPR and UK GDPR. BIPA's private right of action creates direct litigation exposure in Illinois for biometric collection without compliant written consent and retention schedules. The policy's simultaneous reliance on explicit consent and legitimate interest as legal bases for Verification Recording processing may require evaluation under GDPR Article 9, which generally limits permissible derogations to an enumerated list. 2. GOVERNANCE EXPOSURE: High. The collection of facial geometry and voiceprint data as part of a standard platform workflow creates material compliance obligations across multiple jurisdictions. The policy states that Customer Data including the avatar Sample is controlled by enterprise customers, meaning those customers must independently assess their controller obligations under BIPA and GDPR Article 9. Synthesia's processor role does not eliminate enterprise customer liability for consent adequacy. 3. JURISDICTION FLAGS: Illinois creates heightened exposure due to BIPA's private right of action and specific written consent requirements. EU and EEA users are subject to GDPR Article 9 special category processing rules. UK users are subject to UK GDPR equivalents. Washington State's My Health MY Data Act and Texas and Arkansas biometric laws may also apply depending on user location. The policy's reference to BIPA by name indicates awareness of these obligations but does not confirm jurisdiction-specific compliance mechanisms. 4. CONTRACT AND VENDOR IMPLICATIONS: The policy discloses use of Amazon Web Services EMEA SARL as a third-party verification vendor for biometric processing. Procurement teams should assess whether the Data Processing Addendum with Synthesia addresses biometric sub-processor obligations, including BIPA-compliant data handling by vendors. The policy states that Synthesia requires its vendors to delete or destroy biometric data consistently with its own retention obligations, but does not specify the contractual mechanism. 5. COMPLIANCE CONSIDERATIONS: Legal teams should review whether consent collection mechanisms at avatar creation meet BIPA's written consent requirements including disclosure of specific retention periods and the purpose of collection. GDPR compliance teams should assess whether legitimate interest is a valid co-basis alongside explicit consent for Verification Recording processing under Article 9. Data mapping updates should reflect biometric data flows to AWS EMEA SARL. Enterprise customers should confirm that their Data Processing Addendums with Synthesia allocate controller responsibilities for biometric data consistently with applicable law.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive practices related to biometric data collection and consent under Section 5 of the FTC Act.
    File a complaint →
  • State AG
    Illinois, Texas, Washington, and other state attorneys general have enforcement authority over state biometric privacy laws applicable to this provision.
    File a complaint →

Provision details

Document information
Document
Synthesia Privacy Policy
Entity
Synthesia
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015743
Document ID
CA-D-00470
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
c48a575e2d96eda30f9d795d55b7e461edba6b3a934c98d2b8aa22e3fc6ec27f
Analysis generated
July 9, 2026 08:42 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Synthesia
Document: Synthesia Privacy Policy
Record ID: CA-P-015743
Captured: 2026-07-09 08:42:29 UTC
SHA-256: c48a575e2d96eda3…
URL: https://conductatlas.com/platform/synthesia/synthesia-privacy-policy/provision/CA-P-015743/biometric-data-collection-and-processing/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Synthesia's Biometric Data Collection and Processing clause do?

This provision establishes that avatar creation constitutes biometric data processing subject to heightened legal obligations under GDPR Article 9 and the Illinois Biometric Information Privacy Act, requiring explicit consent as a derogation and compliance with jurisdiction-specific retention, disclosure, and prohibition-on-sale requirements. Enterprise customers deploying Synthesia for employee avatar creation should assess their own obligations as data controllers under these frameworks.

How does this clause affect you?

Under this provision, users who proceed with avatar creation consent to processing of their facial geometry and voiceprint data, which the policy classifies as biometric data under applicable law. The agreement states that users who decline consent will not have biometric data extracted or processed, but will also be unable to generate an avatar using the automated process, though a …

Is ConductAtlas affiliated with Synthesia?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Synthesia.