Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy enumerates GDPR-aligned data subject rights including access, portability, restriction, withdrawal of consent, rectification, erasure, objection, and the right not to be subject to solely automated decision-making. Users may exercise these rights by emailing support@synthesia.io, and may lodge complaints with the UK ICO or local EU supervisory authority.
This analysis describes what Synthesia's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the procedural mechanism for users to exercise GDPR and UK GDPR data subject rights directly with Synthesia, and identifies the UK ICO as the primary supervisory authority for complaint escalation. The policy notes that erasure or processing restriction may result in loss of access to some services.
Under this provision, users may request access to, portability of, rectification of, restriction of, or erasure of their personal data by emailing support@synthesia.io, with the first copy provided free of charge and additional copies potentially subject to an administration fee. The agreement states that exercising erasure or restriction rights may result in inability to use certain services, and users will be notified if this occurs.
Cross-platform context
See how other platforms handle User Data Rights and Supervisory Authority Complaint and similar clauses.
Compare across platforms →Monitoring
Synthesia has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"You may exercise these rights by contacting us at support@synthesia.io. Where we are required to provide a copy of your personal data, this will be free of charge; however, any further copies requested may be subject to a reasonable fee based on administration costs. Where we stop processing personal data or delete your personal data, it will possibly mean that you are unable to continue using or contributing to the provision of some of our Services, and you will be notified accordingly. You have the right to lodge a complaint with the Information Commissioner's Office at 0303 123 1113 or via live chat at ico.org.uk/livechat or with your local supervisory authority.Excerpt from Synthesia's Privacy Policy
1. REGULATORY LANDSCAPE: This provision engages GDPR Articles 15 through 22, covering data subject rights including access, portability, rectification, erasure, restriction, objection, and rights regarding automated decision-making. The UK ICO is identified as the primary supervisory authority. EU users may also file complaints with their national supervisory authority. GDPR generally requires responses to data subject requests within one month, extendable to three months for complex requests. 2. GOVERNANCE EXPOSURE: Low. The enumeration of GDPR rights and provision of a contact mechanism is standard compliance practice. The fee disclosure for additional data copies is consistent with GDPR Article 15(3). The notification obligation regarding service impact from erasure or restriction is also a standard disclosure. 3. JURISDICTION FLAGS: EU and UK users have the most defined rights framework under GDPR and UK GDPR. California users may have additional rights under the CCPA including the right to know, delete, and opt out of sale. Illinois users may have rights under BIPA regarding biometric data specifically. Response timelines and procedures may vary by jurisdiction. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers whose employees submit data subject rights requests should assess the operational workflow for routing requests to Synthesia as processor versus to the enterprise customer as controller. The policy directs authorized users to contact the enterprise customer for Customer Data questions, which may require enterprise customers to maintain their own data subject rights procedures. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should confirm that Synthesia's data subject rights response procedures meet the one-month GDPR response timeline. DPO teams should assess whether the fee policy for additional data copies is consistent with GDPR Article 15(3) requirements. Enterprise customers should ensure their own procedures for handling employee data subject rights requests that involve Customer Data on the Synthesia platform are documented.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes the procedural mechanism for users to exercise GDPR and UK GDPR data subject rights directly with Synthesia, and identifies the UK ICO as the primary supervisory authority for complaint escalation. The policy notes that erasure or processing restriction may result in loss of access to some services.
Under this provision, users may request access to, portability of, rectification of, restriction of, or erasure of their personal data by emailing support@synthesia.io, with the first copy provided free of charge and additional copies potentially subject to an administration fee. The agreement states that exercising erasure or restriction rights may result in inability to use certain services, and users will …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Synthesia.