Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy establishes that enterprise customers (employers or other purchasing entities) act as data controllers for Customer Data submitted to the platform, while Synthesia acts as data controller for Other Information it independently collects. Synthesia processes Customer Data only on customer instructions.
This analysis describes what Synthesia's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision allocates primary compliance responsibility for Customer Data governance to enterprise customers, establishing that those customers determine the purposes and conditions of processing for user-submitted content including avatar samples, scripts, and videos. Authorized users with questions about Customer Data handling are directed to their employer or the relevant enterprise customer rather than Synthesia.
Under this clause, individual users authorized by an enterprise customer have limited direct recourse against Synthesia regarding Customer Data processing, as the policy positions the enterprise customer as the data controller responsible for those processing decisions. Users seeking information about how their employer's Synthesia instance handles their data should contact the enterprise customer directly.
Cross-platform context
See how other platforms handle Controller and Processor Role Allocation and similar clauses.
Compare across platforms →Monitoring
Synthesia has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Certain jurisdictions distinguish between a "controller" or "processor" of personal data. A controller is the decision-maker and exercises overall control over how and why personal data is collected and used. In general, the Customer is the controller of Customer Data. A processor acts on behalf of, and only on the instructions of, the relevant controller. In general, Synthesia is the processor of Customer Data and the controller of Other Information (which is described in the 'Personal data that we process' section below). Synthesia is the controller of Other Information and a processor of Customer Data.Excerpt from Synthesia's Privacy Policy
1. REGULATORY LANDSCAPE: This provision engages GDPR Articles 4(7) and 4(8) defining controller and processor, and equivalent provisions under UK GDPR. GDPR requires that controller-processor relationships be governed by a Data Processing Agreement specifying the subject matter, duration, nature, and purpose of processing. The relevant enforcement authorities are EU supervisory authorities and the UK ICO. Where enterprise customers are themselves subject to GDPR or UK GDPR, they bear primary accountability for lawful processing of Customer Data. 2. GOVERNANCE EXPOSURE: Medium. The allocation of controller status to enterprise customers is a standard B2B SaaS structure, but it creates material obligations for those customers that may not be immediately apparent to authorized users. Enterprise customers must ensure they have a valid legal basis for processing Customer Data, including biometric data submitted by their employees, and must execute a compliant Data Processing Agreement with Synthesia. 3. JURISDICTION FLAGS: EU and UK enterprise customers are subject to GDPR and UK GDPR controller obligations including transparency requirements toward data subjects. US enterprise customers in Illinois should assess BIPA controller obligations for employee biometric data. In jurisdictions without a formal controller/processor distinction, this allocation may have different legal significance. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers procuring Synthesia should confirm that a Data Processing Addendum is in place and that it adequately addresses the scope of Customer Data, sub-processor obligations, and data subject rights procedures. The policy states that Synthesia processes Customer Data in accordance with customer instructions and the Agreement, but does not detail the DPA terms in this document. 5. COMPLIANCE CONSIDERATIONS: Procurement and legal teams at enterprise customers should audit whether their DPA with Synthesia reflects the controller responsibilities described in this policy, particularly for biometric data. HR and IT governance teams should assess whether employees providing avatar samples have received appropriate GDPR or BIPA-compliant disclosures from the enterprise customer as controller.
This provision allocates primary compliance responsibility for Customer Data governance to enterprise customers, establishing that those customers determine the purposes and conditions of processing for user-submitted content including avatar samples, scripts, and videos. Authorized users with questions about Customer Data handling are directed to their employer or the relevant enterprise customer rather than Synthesia.
Under this clause, individual users authorized by an enterprise customer have limited direct recourse against Synthesia regarding Customer Data processing, as the policy positions the enterprise customer as the data controller responsible for those processing decisions. Users seeking information about how their employer's Synthesia instance handles their data should contact the enterprise customer directly.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Synthesia.