Authors
Introduction
Privacy regulation poses unique challenges for AI in the entertainment and media sector. Organizations developing AI systems, using AI-powered tools for content recommendations, targeted advertising, interactive content, or brand engagement, must navigate complex requirements around data minimization, transparency, lawful processing, and individual rights. In the EU, the General Data Protection Regulation (GDPR) remains the primary framework governing personal data used in AI, while the EU AI Act (Regulation (EU) 2024/1689), which entered into force on August 1, 2024, introduces a complementary risk-based regulatory layer. Both frameworks interact and must be considered together. In the United States, existing federal and state data privacy frameworks coupled with consumer protection laws continue to be leveraged to regulate the emerging technology. The UK still does not have a single, standalone AI law. Instead, AI is regulated through existing rules on data protection, online safety, consumer protection, and sector-specific regulation. That is consistent with the UK’s broader pro-innovation approach to AI regulation, which relies heavily on existing regulators and legal frameworks. Since the last edition of this guide, however, the UK privacy landscape has moved on, particularly through the Data (Use and Access) Act 2025 (DUAA) and the work of the Information Commissioner’s Office (ICO) on generative AI, automated decision-making, and children’s data.
The U.S. framework: Notable privacy developments
The Colorado AI Act, generally touted as the first comprehensive AI law in the United States, was repealed and re-enacted when Governor Polis signed Senate Bill 26-189 on May 14, 2026, with the new framework taking effect on January 1, 2027. The Act previously focused on regulating “high-risk artificial intelligence systems,” generally requiring developers of covered AI systems to use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination in high-risk systems. “High-risk artificial intelligence systems” generally encompassed AI systems that made, or were substantial factors in making, consequential decisions, regardless of whether the AI systems processed personal data.
The revised Act changes this framework fundamentally. It replaces the concept of high-risk AI systems with “automated decision-making technology” or ADMT that is used to materially influence a consequential decision (covered ADMT). ADMT is generally defined as technology that processes personal data and generates outputs to make a decision or assist in decision-making concerning an individual. The groundbreaking law now hinges, in part, on whether ADMTs are processing personal data, effectively fusing data privacy and AI regulation.
Beginning January 1, 2027, developers of covered ADMT must provide deployers with technical documentation addressing matters such as intended uses, categories of training data, known limitations, and appropriate human review, and must notify deployers of material updates or modifications. Deployers must provide prior clear and conspicuous notice and, within 30 days following an adverse outcome, provide a plain-language description of the ADMT’s role. Consumers may request personal data used by the system, correction of factually inaccurate data, and meaningful human review and reconsideration following an adverse outcome where reasonable. Colorado’s allocation of responsibilities between developers and deployers has practical procurement implications. A company acquiring a third-party decision tool may itself have consumer-facing obligations that it cannot perform unless the vendor supplies sufficient information about the system. Contracts for covered technologies should therefore address access to required technical documentation, material system updates, data inputs and limitations, assistance responding to correction or review requests, and record-retention responsibilities. Developers and deployers are each required to retain records necessary to demonstrate compliance for at least three years.
Colorado is not the first state to focus its AI regulations around systems that process personal data. For example, for several years California has maintained privacy laws and regulations focusing on certain AI tools that process personal data. The amended California Consumer Privacy Act Regulations concerning automated decision-making technologies took effect on January 1, 2026. The regulations cover ADMTs that process personal data and use the computations to substantially replace human decision-making. Notably, the regulations require covered entities to provide pre-use notices, the ability for consumers to opt out, and access to the ADMT. Businesses that use covered ADMTs are required to comply with the amended regulations by January 1, 2027.
For entertainment and media companies, this limited scope may be beneficial. AI use that does not involve the processing of personal data, or that falls outside the defined categories of consequential or significant decisions – such as content creation via generative AI – is likely to fall beyond the purview of certain AI-privacy laws.
The UK framework: The Data (Use and Access) Act 2025
The DUAA received Royal Assent on June 19, 2025, and makes targeted changes to the UK GDPR (the assimilated version of Regulation (EU) 2016/679), the Data Protection Act 2018, and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR). It does not replace the UK GDPR. Most of the remaining data protection provisions came into force on February 5, 2026. For AI projects in the entertainment and media sector, the changes most likely to matter in practice are:
- A more flexible approach to automated decision-making, moving away from the previous near-prohibition and toward a model that allows more automated decisions if appropriate safeguards are in place.
- Changes to the rules on cookies and other storage technologies, including new exceptions for low-risk uses, together with a substantial increase in PECR penalties from £500,000 to the UK GDPR maximum of £17.5 million or, if greater, 4% of total annual worldwide turnover. Both matter for AI projects because the cookies and similar technologies governed by PECR are commonly the source of the behavioral signals used to train and operate recommendation, personalization, and ad-targeting models.
Lawful basis for AI training: EDPB and ICO guidance on legitimate interests
Under both the EU and UK GDPR, organizations training AI systems or using AI to process personal data must establish a lawful basis for each processing activity. The development and deployment phases of an AI system must each be analysed separately. While consent may seem like a natural choice, the standard is prescriptive and consent can be withdrawn at any time, requiring deletion of that individual’s data. This is problematic for AI training, where personal data may become embedded in model parameters. Accordingly, many organizations look to legitimate interests as an alternative basis.
In December 2024, the European Data Protection Board (EDPB) issued Opinion 28/2024, confirming that legitimate interests may, in appropriate circumstances, justify processing personal data for AI model training – including publicly available data. However, this is not a default basis. Organizations must conduct a three-step assessment: (1) identify a legitimate interest that is lawful, clearly articulated, and real (not speculative); (2) demonstrate that the processing is necessary, with no less intrusive alternative; and (3) balance this against the data subjects’ interests and fundamental rights. The right to object under Article 21 of the EU GDPR must always be ensured.
On July 7, 2026, the EDPB adopted draft Guidelines 03/2026 on web scraping in the context of generative AI, which build on this Opinion and provide the first comprehensive GDPR framework for organizations scraping data to train generative AI. The Guidelines confirm that consent is generally not a viable basis for scraping at scale, leaving legitimate interests as the primary avenue, and recommend scraping only from reliable sources, respecting robots.txt and ai.txt signals, recording timestamps, validating data before use, and implementing measures to limit personal data collection. They also confirm that special category data requires an Article 9 condition for processing in addition to an Article 6 lawful basis, and address scenarios where personal data was unlawfully processed during an AI model’s development phase – guidance particularly relevant for organizations using third-party AI models where training data provenance is uncertain. A final version of the Guidelines is not expected before the end of 2026.
In the UK, the analysis is similar. Before training or deploying an AI system, an organization needs to work out what personal data is being used, why it is being used, and which lawful basis applies. It also helps to separate the development stage from the live-use stage. For example, training a recommendation model on historic viewing data is not the same privacy question as using that model to personalize what a viewer sees in real time.
Consent will often be a difficult basis to use for AI training, particularly where large datasets have already been collected or where it would be hard to apply a withdrawal later. In many cases, organizations will need to consider whether they can rely on legitimate interests as their lawful basis for processing. The ICO has indicated that legitimate interests may be the only realistic lawful basis for training generative AI on personal data, but only where an organization can show a genuine purpose, necessity, and a fair balance against individuals’ rights. The purpose cannot simply be “training AI”; it needs to be specific enough for individuals, regulators, and internal teams to understand what is happening with the data. Scraped data remains particularly sensitive from a risk perspective. The ICO’s enforcement action against Clearview AI is still the leading UK example on large-scale web scraping for facial recognition. In October 2025, the Upper Tribunal allowed the Commissioner’s appeal on the scope of the UK GDPR and remitted the case to the First-tier Tribunal, so the substantive appeal remains unresolved and Clearview has since been granted permission to appeal to the Court of Appeal.
Data minimization and anonymization
AI systems require vast amounts of training data, creating tension with the data minimization principles under applicable EU, UK, and U.S. laws. Where possible, organizations should use anonymized, pseudonymized, de-identified, or synthetic data. The EDPB draft Guidelines 02/2026 on Anonymisation provide a practical framework: data qualifies as anonymous if it meets three criteria – no record isolation, no linkage across datasets, and no inference about individuals. If all three are satisfied, the data falls outside the scope of the GDPR entirely. Following the Court of Justice of the European Union’s (CJEU) judgment in Case C-413/23 P (EDPS v. SRB), the Guidelines also confirm that anonymity is assessed from the perspective of each relevant entity, and that AI models trained on personal data are not automatically anonymous; organizations must document and demonstrate anonymity through appropriate technical safeguards.
In the United States, there is no single federal data minimization principle equivalent to the GDPR, but state privacy laws generally maintain similar data minimization principles. For instance, California requires covered processing to be reasonably necessary and proportionate to disclosed purposes and limits retention, while Colorado restricts unnecessary collection and incompatible secondary uses, unless an exception applies. The California law expressly acknowledges that personal data may exist in various formats, including compressed or encrypted files, metadata, or AI systems that are capable of outputting personal data. AI operators should therefore assess whether personal data is in scope, including whether AI tools have the potential to output personal data for the purposes of California compliance, to help comply with the various data minimization requirements in the United States.
Many state omnibus privacy laws also carve out “publicly available” information from the definition of personal data, meaning these privacy frameworks may not apply to publicly available personal data. What constitutes “publicly available” data may vary across states; however, AI tools that scrape publicly accessible personal data (such as social media posts) may not necessarily be subject to the comprehensive data privacy regime in the United States.
The UK position is comparable, although the ICO frames the test differently. Where possible, AI projects should use less identifiable data, including anonymized, pseudonymized, or synthetic data. This is not always straightforward. The ICO’s March 2025 anonymization and pseudonymization guidance treats identifiability as a spectrum rather than a binary state, so the practical question is whether someone could reasonably be re-identified, taking account of the data itself and other information that may be available.
Transparency and explainability
Transparency is a fundamental requirement under both the EU and UK GDPR: individuals must know when their personal data is being processed and for what purposes. For AI systems, this extends to providing meaningful information about the logic involved in automated decisions. The EU AI Act’s Article 50 Guidelines add a further disclosure requirement for chatbots and other systems that interact directly with people (see above). Entertainment and media companies face a particular challenge: explaining how recommendation algorithms, personalization engines, or content moderation systems work in terms understandable to users – without overwhelming them. Information must also be timely, for example at the start of a game or when an AI-supported interaction begins.
U.S. transparency obligations are more fragmented, but state privacy laws generally require covered businesses to disclose what personal information they collect, the purpose for processing, and the potential recipients. For example, California requires notice at or before collection of personal information, and most states require disclosures concerning sharing, targeted advertising, and certain profiling. These obligations apply even where AI operates behind the scenes, so entertainment and media companies should ensure that disclosures are timely and understandable, and that they accurately reflect the purposes for which they use consumers’ personal information, especially where there may be secondary uses for AI development or deployment.
UK organizations should likewise explain recommendation engines, targeted advertising, personalization, and content moderation in language users can understand and at the point when the explanation is most useful. The ICO’s final guidance on storage and access technologies, published in April 2026, is relevant here: it covers cookies, tracking pixels, link decoration, and device fingerprinting, and reflects the DUAA’s new low-risk exceptions. A weakness in consent at the collection layer will carry through to the models that later consume those signals, so the two cannot sensibly be assessed in isolation.
Automated decision-making and profiling
In the entertainment and media sector, AI is regularly used for profiling – analyzing viewing habits to recommend content, targeting advertising, or using facial recognition at events. Article 22 of the EU GDPR gives individuals the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. The CJEU’s judgment in Case C-634/21 (SCHUFA Holding), handed down in December 2023, clarifies that even AI-generated scores may trigger Article 22 where downstream systems rely on them almost automatically. For entertainment and media companies, this means that content recommendation scores, personalized pricing algorithms, ad-targeting systems, and automated content moderation tools may all fall within scope if outputs are relied upon without meaningful human intervention.
Where Article 22 applies, individuals must be able to obtain human intervention, express their view, and contest decisions. The EU AI Act reinforces this: high-risk AI systems used for profiling require transparency, risk management, and robust documentation. Companies should implement clear escalation processes allowing for meaningful human review – not mere procedural sign-off.
Automated decision-making is one of the clearest areas where the UK is moving away from the EU GDPR. Section 80 of the DUAA replaced Article 22 of the UK GDPR with new Articles 22A to 22D, which came into force on February 5, 2026. In simple terms, the question is whether a decision is made solely by automated means, without meaningful human involvement, and whether it has a legal or similarly significant effect on the individual. In an entertainment and media context, that could be relevant to age-gating, account restrictions, creator monetization decisions, access to services, or other decisions that materially affect a user.
The DUAA creates a more permissive framework for solely automated decisions involving ordinary personal data, provided safeguards are in place. Those safeguards include giving people information about the decision, allowing them to make representations, enabling human intervention, and giving them a right to contest the outcome. Decisions involving special category data remain more restricted. The ICO consulted on draft automated decision-making and profiling guidance between March 31 and May 29, 2026, and final guidance is awaited.
Biometric data and AI-powered consumer experiences
AI-powered tools such as virtual try-ons, skin analysis, shade matching, and personalized recommendations may involve the processing of biometric identifiers.
In the United States, biometric identifiers remain a significant enforcement risk, in particular under Illinois’ Biometric Information Privacy Act (BIPA), which requires notice and written consent before collecting biometric data. Retailers’ virtual try-on programs have been a particular target: national brands have faced BIPA class actions alleging that their tools scanned and stored consumers’ facial geometry without the required written notice and consent. Outcomes have varied, with some claims dismissed. For example, in one case involving a national cosmetics brand, an Illinois federal court denied the brand’s motion to dismiss in June 2026, allowing BIPA claims over its virtual try-on tool to proceed to discovery. Other fashion and beauty brands offering virtual try-on tools have settled.
Importantly, in August 2024, Illinois amended BIPA so that repeated collection or disclosure of the same biometric identifier from the same person by the same method gives rise to a single violation and at most one recovery, rather than a separate violation for each scan. That reduces potential damages exposure, although the risk of large-scale class actions remains significant given BIPA’s private right of action, and the distinction matters for AI-powered consumer tools, which typically capture a scan on each session rather than once per user. Beyond Illinois, brands should also monitor other state biometric regimes, in particular Texas’ Capture or Use of Biometric Identifier Act (CUBI), which requires notice and consent and significantly restricts the disclosure of covered biometrics – the law authorizes civil penalties of up to $25,000 per violation, enforced exclusively by the state Attorney General. Washington’s My Health My Data Act also regulates “consumer health data,” which includes biometric information, and creates a private right of action, potentially reaching AI-enabled tools that process biometrics in the health or health-adjacent space, such as wellness and beauty.
Children’s privacy and enforcement
In the UK, children’s data has become one of the ICO’s most active enforcement areas, and AI sits at the center of it: recommender systems, age estimation models, and profiling tools together shape what children see, what is suggested to them next, and how long they stay. This matters for games, social platforms, streaming services, apps, and other services that children are likely to access, even if children are not the intended audience. The ICO’s recent enforcement has focused on whether the service has a proper lawful basis for processing children’s data, whether age assurance is robust enough, and whether the business has carried out a suitable data protection impact assessment (DPIA).
The practical message is that self-declared age is unlikely to be enough for higher-risk services. Age assurance, recommender systems, default settings, profiling, and DPIAs need to be considered together, rather than as separate compliance workstreams.
Age verification and AI
AI-powered age verification tools, such as facial recognition and age estimation systems, raise significant data protection concerns. These systems may produce inaccurate outputs, and facial recognition has documented higher error rates for certain ethnic minorities and transgender individuals. Where such systems process biometric data for the purpose of uniquely identifying an individual, this constitutes special category data under Article 9 of the EU GDPR and the UK GDPR, requiring a separate condition for processing in addition to a lawful basis. Similarly, such data types constitute sensitive personal information, which is generally subject to heightened compliance obligations and enforcement in the United States. Transparency is also challenging: explaining AI verification systems in child-friendly language, without encouraging users to misrepresent their age, requires careful design.
In response to these challenges, and to meet requirements under the GDPR and Digital Services Act to protect minors online, the Commission has developed a privacy-preserving alternative to AI-based age estimation. The EU age verification app (the mini wallet), built on the same technical specifications as the European Digital Identity Wallet (EUDI Wallet) framework, uses zero-knowledge proof cryptography to confirm a user meets an age threshold (such as over 18) without revealing any other personal information – and without relying on AI-based biometric processing. Users cannot be tracked across platforms. The solution became feature-ready on April 15, 2026, and is being customized and piloted by Member States; the Commission has urged Member States to make it available to citizens by the end of 2026, with EUDI Wallets due to be rolled out across all Member States by the same date. The practical significance here is that a cryptographic route to age assurance may remove the need to deploy facial age estimation models at all, together with the special category data risks these models can attract.
The United States has taken a less prescriptive approach, relying in part on industry to provide practical technological solutions that comply with existing consumer protection and privacy requirements.
In the UK, age assurance is now a central privacy issue for services likely to be accessed by children. Under the Online Safety Act 2023, Ofcom expects highly effective age assurance in relevant cases, particularly where services need to prevent children from accessing certain content or features. Plans to ban social media for under-16s and to impose overnight curfews for 16- and 17-year-olds would extend that expectation further still, with the measures expected to come into force in spring 2027. These are online safety rather than privacy measures, but they have a direct data protection consequence: enforcing an age-based restriction requires the service to establish the age of its whole user base, which in practice tends to drive reliance on identity documents, facial age estimation, and other inference models. Stronger age checks may reduce child safety risks, but they also mean collecting more data about every user.
The data protection implications are therefore significant. Services need to consider whether the chosen age assurance method is proportionate, what data is collected, whether biometric data is involved, how long the information is retained, and whether the process can be explained clearly to users. The scope of future requirements is still developing, so businesses should avoid building age assurance processes around assumptions that may change. Services likely to be accessed by children should review their approach now, including the DPIAs that support it, and keep enough flexibility to adapt as the rules and technical standards develop.
The EU framework: The AI Act
The EU AI Act establishes a risk-based framework that classifies AI systems into prohibited, high-risk, limited-risk, and minimal-risk categories. AI systems falling within the Annex III areas – which include biometrics, education, employment, and access to essential private and public services such as credit scoring – are classified as high-risk and subject to extensive requirements, including risk management, technical documentation, human oversight, and conformity assessment. Importantly, an Annex III system that performs profiling of natural persons cannot benefit from the Article 6(3) derogation for systems that do not pose a significant risk of harm, and so will always be treated as high-risk.
The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on July 27, 2026, simplifying and streamlining implementation of the EU AI Act without altering its core architecture. The package postpones application of the high-risk requirements for standalone systems under Annex III to December 2, 2027, and for high-risk AI systems embedded in regulated products under Annex I to August 2, 2028. The AI Omnibus also introduces new prohibitions on AI systems that generate or manipulate non-consensual intimate imagery or child sexual abuse material, taking effect from December 2, 2026. Article 50 transparency obligations, including requirements to disclose AI interactions and label AI-generated content, were not postponed and have applied since August 2, 2026. The single concession is a transitional period until December 2, 2026, for the machine-readable marking requirement in Article 50(2), and only for systems placed on the market before August 2, 2026.
The European Commission (the Commission) is required under Articles 6(5) and 96 to issue guidelines on the practical implementation of the high-risk classification rules, with practical examples to help organizations assess the Annex III categories. Separately, on July 20, 2026, the Commission published its final Guidelines on Article 50 transparency obligations, which apply from August 2, 2026. These require chatbots and other systems that interact directly with people to disclose their AI nature upfront, which matters here because those systems typically process user inputs as personal data and the disclosure sits alongside the privacy information the GDPR already requires. The Guidelines also address the labeling and machine-readable marking of AI-generated content and deepfakes, which is covered elsewhere in this guide. Non-compliance may result in fines of up to €15 million or 3% of total worldwide annual turnover.
Authors