Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy discloses that creating an avatar on Synthesia requires processing biometric data including facial geometry and voiceprints, classified as special category data under GDPR and as biometric identifiers under the Illinois Biometric Information Privacy Act. Processing occurs for avatar generation, identity verification, fraud prevention, and AI model fine-tuning.
This analysis describes what Synthesia's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that avatar creation constitutes biometric data processing subject to heightened legal obligations under GDPR Article 9 and the Illinois Biometric Information Privacy Act, requiring explicit consent as a derogation and compliance with jurisdiction-specific retention, disclosure, and prohibition-on-sale requirements. Enterprise customers deploying Synthesia for employee avatar creation should assess their own obligations as data controllers under these frameworks.
Under this provision, users who proceed with avatar creation consent to processing of their facial geometry and voiceprint data, which the policy classifies as biometric data under applicable law. The agreement states that users who decline consent will not have biometric data extracted or processed, but will also be unable to generate an avatar using the automated process, though a manual Studio Avatar option is described as an alternative.
Cross-platform context
See how other platforms handle Biometric Data Collection and Processing and similar clauses.
Compare across platforms →Monitoring
Synthesia has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Avatar submissions and Biometric Data Sample and Verification Recording by their very nature include unique information relating to the physical characteristics of a natural person, such as facial images and voice data. Avatar creation features require processing of the facial geometry and/or voiceprint from each of the Sample and Verification Recording. Certain steps in creating an Avatar involve the processing of data considered "biometric data", "biometric information", "biometric identifier", "sensitive personal data", or "special category of personal data" under applicable data protection laws in certain jurisdictions (including but not limited to the Illinois Biometric Privacy Act and GDPR). We will refer to this information throughout this Privacy Policy as "Biometric Data" for consistency.Excerpt from Synthesia's Privacy Policy
1. REGULATORY LANDSCAPE: This provision implicates GDPR Article 9 (special category data), the Illinois Biometric Information Privacy Act, and by extension other US state biometric laws. The UK Information Commissioner's Office and relevant EU supervisory authorities exercise oversight under GDPR and UK GDPR. BIPA's private right of action creates direct litigation exposure in Illinois for biometric collection without compliant written consent and retention schedules. The policy's simultaneous reliance on explicit consent and legitimate interest as legal bases for Verification Recording processing may require evaluation under GDPR Article 9, which generally limits permissible derogations to an enumerated list. 2. GOVERNANCE EXPOSURE: High. The collection of facial geometry and voiceprint data as part of a standard platform workflow creates material compliance obligations across multiple jurisdictions. The policy states that Customer Data including the avatar Sample is controlled by enterprise customers, meaning those customers must independently assess their controller obligations under BIPA and GDPR Article 9. Synthesia's processor role does not eliminate enterprise customer liability for consent adequacy. 3. JURISDICTION FLAGS: Illinois creates heightened exposure due to BIPA's private right of action and specific written consent requirements. EU and EEA users are subject to GDPR Article 9 special category processing rules. UK users are subject to UK GDPR equivalents. Washington State's My Health MY Data Act and Texas and Arkansas biometric laws may also apply depending on user location. The policy's reference to BIPA by name indicates awareness of these obligations but does not confirm jurisdiction-specific compliance mechanisms. 4. CONTRACT AND VENDOR IMPLICATIONS: The policy discloses use of Amazon Web Services EMEA SARL as a third-party verification vendor for biometric processing. Procurement teams should assess whether the Data Processing Addendum with Synthesia addresses biometric sub-processor obligations, including BIPA-compliant data handling by vendors. The policy states that Synthesia requires its vendors to delete or destroy biometric data consistently with its own retention obligations, but does not specify the contractual mechanism. 5. COMPLIANCE CONSIDERATIONS: Legal teams should review whether consent collection mechanisms at avatar creation meet BIPA's written consent requirements including disclosure of specific retention periods and the purpose of collection. GDPR compliance teams should assess whether legitimate interest is a valid co-basis alongside explicit consent for Verification Recording processing under Article 9. Data mapping updates should reflect biometric data flows to AWS EMEA SARL. Enterprise customers should confirm that their Data Processing Addendums with Synthesia allocate controller responsibilities for biometric data consistently with applicable law.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that avatar creation constitutes biometric data processing subject to heightened legal obligations under GDPR Article 9 and the Illinois Biometric Information Privacy Act, requiring explicit consent as a derogation and compliance with jurisdiction-specific retention, disclosure, and prohibition-on-sale requirements. Enterprise customers deploying Synthesia for employee avatar creation should assess their own obligations as data controllers under these frameworks.
Under this provision, users who proceed with avatar creation consent to processing of their facial geometry and voiceprint data, which the policy classifies as biometric data under applicable law. The agreement states that users who decline consent will not have biometric data extracted or processed, but will also be unable to generate an avatar using the automated process, though a …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Synthesia.