On 18 December 2025, the Guarantor for the Protection of Personal Data (GPDP) issued a warning to users of artificial intelligence services regarding the generation of content using third-party voices or images via artificial intelligence technologies (deepfakes). The GPDP noted that such content potentially qualifies as personal data under Article 4(1) of Regulation (EU) 2016/679 (GDPR) and may constitute biometric data where processed for unique identification. The GPDP found that such processing, when lacking a valid legal basis and transparent information, may infringe Articles 5(1)(a), 6 and 9 of the GDPR. Consequently, the GPDP issued a formal warning under Article 58(2)(a) of the GDPR that such processing activities can constitute infringements of data protection rules.
Original source