Synthesia · Synthesia Privacy Policy · View original document ↗

Data Subject Rights and Exercise Process

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for Synthesia Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Depending on where you live, you may have rights to see, correct, or delete your personal data held by Synthesia, and you exercise those rights by emailing privacy@synthesia.io.

This analysis describes what Synthesia's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

Knowing how to exercise your data rights is practically important, especially if you have uploaded personal likeness or voice data, since deletion of avatar data may require a specific request.

Consumer impact (what this means for users)

EU, UK, and California users have legally backed rights to access, correct, and delete their personal data including avatar likeness and voice recordings, and can initiate those requests directly by emailing privacy@synthesia.io.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Send an email to privacy@synthesia.io clearly identifying your account and stating which personal data you wish to access, correct, or delete. Include your name and email address associated with your Synthesia account.
  • Export Your Data
    Email privacy@synthesia.io to request a portable copy of your personal data under data portability rights (applicable to EU, UK, and California users). Specify the data categories you want exported.

Cross-platform context

See how other platforms handle Data Subject Rights and Exercise Process and similar clauses.

Compare across platforms →

Monitoring

Synthesia has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Depending on your location and subject to applicable law, you may have certain rights regarding your personal data, including the right to access, correct, delete, restrict processing, object to processing, and data portability. To exercise any of these rights, please contact us at privacy@synthesia.io.

— Excerpt from Synthesia's Synthesia Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

(1) REGULATORY LANDSCAPE: GDPR Chapter III and UK GDPR establish enforceable data subject rights including access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20), and objection (Article 21). CCPA and CPRA grant California residents rights to know, delete, correct, and opt out of sale or sharing. These rights must be fulfilled within specific statutory timeframes (30 days under GDPR with possible extension; 45 days under CCPA). Supervisory authorities including the ICO (UK), national DPAs within the EU, and the California Privacy Protection Agency have enforcement authority. (2) GOVERNANCE EXPOSURE: Medium. The policy routes all data subject requests through a single email address (privacy@synthesia.io), which is a common practice but may create bottlenecks if request volumes are high or if verification processes are insufficiently documented. Failure to respond within statutory deadlines is a documented area of regulatory enforcement action across EU data protection authorities. (3) JURISDICTION FLAGS: EU and UK users have the most comprehensive and enforceable rights under GDPR and UK GDPR. California residents have CPRA rights enforceable by the California Privacy Protection Agency. US users outside California have more limited statutory rights, though Synthesia may extend rights as a matter of policy. Organizations with employees in multiple jurisdictions should ensure their internal procedures for relaying data subject requests to Synthesia as processor are documented. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers whose employees or end users submit data subject requests directly to Synthesia should confirm in the DPA how Synthesia will route controller-directed requests back to the appropriate business customer, and within what timeframe. Failure to coordinate this process can result in missed statutory deadlines creating joint or several liability. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should test the data subject request process periodically, document response timelines, and confirm that Synthesia's identity verification process is proportionate and does not create unnecessary barriers. Records of data subject requests and responses should be maintained as evidence of compliance.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority to enforce against unfair or deceptive practices in data handling, including failure to honor stated privacy rights and commitments.
    File a complaint →
  • State AG
    State Attorneys General, particularly in California, can enforce CCPA and CPRA data subject rights including the right to delete and right to know.
    File a complaint →

Provision details

Document information
Document
Synthesia Privacy Policy
Entity
Synthesia
Document last updated
May 5, 2026
Tracking information
First tracked
April 30, 2026
Last verified
May 10, 2026
Record ID
CA-P-009278
Document ID
CA-D-00470
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
7648d9071447f69ed848238281e6ab982ee2d650c8e20eb74c961b356314a183
Analysis generated
April 30, 2026 07:49 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Synthesia
Document: Synthesia Privacy Policy
Record ID: CA-P-009278
Captured: 2026-04-30 07:49:32 UTC
SHA-256: 7648d9071447f69e…
URL: https://conductatlas.com/platform/synthesia/synthesia-privacy-policy/data-subject-rights-and-exercise-process/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Synthesia's Data Subject Rights and Exercise Process clause do?

Knowing how to exercise your data rights is practically important, especially if you have uploaded personal likeness or voice data, since deletion of avatar data may require a specific request.

How does this clause affect you?

EU, UK, and California users have legally backed rights to access, correct, and delete their personal data including avatar likeness and voice recordings, and can initiate those requests directly by emailing privacy@synthesia.io.

Is ConductAtlas affiliated with Synthesia?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Synthesia.