Synthesia · Synthesia Privacy Policy · View original document ↗

Controller and Processor Role Allocation

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Synthesia changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Synthesia recorded 4 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Synthesia Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy establishes that enterprise customers (employers or other purchasing entities) act as data controllers for Customer Data submitted to the platform, while Synthesia acts as data controller for Other Information it independently collects. Synthesia processes Customer Data only on customer instructions.

This analysis describes what Synthesia's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision allocates primary compliance responsibility for Customer Data governance to enterprise customers, establishing that those customers determine the purposes and conditions of processing for user-submitted content including avatar samples, scripts, and videos. Authorized users with questions about Customer Data handling are directed to their employer or the relevant enterprise customer rather than Synthesia.

Consumer impact (what this means for users)

Under this clause, individual users authorized by an enterprise customer have limited direct recourse against Synthesia regarding Customer Data processing, as the policy positions the enterprise customer as the data controller responsible for those processing decisions. Users seeking information about how their employer's Synthesia instance handles their data should contact the enterprise customer directly.

Cross-platform context

See how other platforms handle Controller and Processor Role Allocation and similar clauses.

Compare across platforms →

Monitoring

Synthesia has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Certain jurisdictions distinguish between a "controller" or "processor" of personal data. A controller is the decision-maker and exercises overall control over how and why personal data is collected and used. In general, the Customer is the controller of Customer Data. A processor acts on behalf of, and only on the instructions of, the relevant controller. In general, Synthesia is the processor of Customer Data and the controller of Other Information (which is described in the 'Personal data that we process' section below). Synthesia is the controller of Other Information and a processor of Customer Data.

Excerpt from Synthesia's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision engages GDPR Articles 4(7) and 4(8) defining controller and processor, and equivalent provisions under UK GDPR. GDPR requires that controller-processor relationships be governed by a Data Processing Agreement specifying the subject matter, duration, nature, and purpose of processing. The relevant enforcement authorities are EU supervisory authorities and the UK ICO. Where enterprise customers are themselves subject to GDPR or UK GDPR, they bear primary accountability for lawful processing of Customer Data. 2. GOVERNANCE EXPOSURE: Medium. The allocation of controller status to enterprise customers is a standard B2B SaaS structure, but it creates material obligations for those customers that may not be immediately apparent to authorized users. Enterprise customers must ensure they have a valid legal basis for processing Customer Data, including biometric data submitted by their employees, and must execute a compliant Data Processing Agreement with Synthesia. 3. JURISDICTION FLAGS: EU and UK enterprise customers are subject to GDPR and UK GDPR controller obligations including transparency requirements toward data subjects. US enterprise customers in Illinois should assess BIPA controller obligations for employee biometric data. In jurisdictions without a formal controller/processor distinction, this allocation may have different legal significance. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers procuring Synthesia should confirm that a Data Processing Addendum is in place and that it adequately addresses the scope of Customer Data, sub-processor obligations, and data subject rights procedures. The policy states that Synthesia processes Customer Data in accordance with customer instructions and the Agreement, but does not detail the DPA terms in this document. 5. COMPLIANCE CONSIDERATIONS: Procurement and legal teams at enterprise customers should audit whether their DPA with Synthesia reflects the controller responsibilities described in this policy, particularly for biometric data. HR and IT governance teams should assess whether employees providing avatar samples have received appropriate GDPR or BIPA-compliant disclosures from the enterprise customer as controller.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Professional · $99/mo Start with Monitor · $29/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive practices in consumer data handling, including transparency regarding controller responsibilities in commercial data relationships.
    File a complaint →

Provision details

Document information
Document
Synthesia Privacy Policy
Entity
Synthesia
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015744
Document ID
CA-D-00470
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
c48a575e2d96eda30f9d795d55b7e461edba6b3a934c98d2b8aa22e3fc6ec27f
Analysis generated
July 9, 2026 08:42 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Synthesia
Document: Synthesia Privacy Policy
Record ID: CA-P-015744
Captured: 2026-07-09 08:42:29 UTC
SHA-256: c48a575e2d96eda3…
URL: https://conductatlas.com/platform/synthesia/synthesia-privacy-policy/provision/CA-P-015744/controller-and-processor-role-allocation/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Professional · $99/mo Start with Monitor · $29/mo

Frequently Asked Questions

What does Synthesia's Controller and Processor Role Allocation clause do?

This provision allocates primary compliance responsibility for Customer Data governance to enterprise customers, establishing that those customers determine the purposes and conditions of processing for user-submitted content including avatar samples, scripts, and videos. Authorized users with questions about Customer Data handling are directed to their employer or the relevant enterprise customer rather than Synthesia.

How does this clause affect you?

Under this clause, individual users authorized by an enterprise customer have limited direct recourse against Synthesia regarding Customer Data processing, as the policy positions the enterprise customer as the data controller responsible for those processing decisions. Users seeking information about how their employer's Synthesia instance handles their data should contact the enterprise customer directly.

Is ConductAtlas affiliated with Synthesia?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Synthesia.