
1 July 2026 • 19 minute read
Deepfakes and the law: perspectives from the EU and China
Deepfakes (AI-generated synthetic media capable of producing highly realistic images, audio, and video of real individuals) have graduated from a mere novelty to a genuine legal concern. Using neural networks trained on visual and audio data, deepfake systems can replicate a person’s appearance and voice with remarkable fidelity, producing content that is often indistinguishable from genuine footage. While the technology has legitimate applications, it has also been deployed for harmful purposes, such as non-consensual intimate imagery, fraud, identity theft, defamation, and misinformation.
This article examines how several key jurisdictions - Spain, Germany, Italy (as well as the EU more broadly) and China - are responding to these challenges. Common themes can be observed: all of these territories recognise the need to protect individuals against unauthorised use of their image and voice, all grapple with data protection implications, and all are imposing transparency obligations on creators of synthetic media. However, there are also significant divergences. European jurisdictions frame regulation through individual rights, whereas China’s approach focuses on public order.
Deepfakes and personality rights
Personality rights (legal protections afforded to an individual’s image, likeness, voice, and identity) have a key role to play in deepfake regulation. Across the jurisdictions examined, these rights provide the primary mechanism for challenging unauthorised synthetic representations of real persons.
The European approach
In the EU, personality rights are not harmonised at the supranational level, leaving protection largely to domestic law. However, the civil law traditions of Spain, Germany and Italy contain personality and image rights protections which have proven adaptable to the deepfake context.
Spain enshrines the rights to image and honour in its Constitution, and Organic Law 1/1982 provides a comprehensive framework for their protection. Unlawful interference with these rights (including the creation or dissemination of deepfakes without consent) entitles the affected person to seek immediate cessation of the infringement, damages (including for moral harm), and publication of any judgment as a form of reparation. Importantly, an unlawful interference may exist even without public dissemination; the mere unauthorised recording or manipulation of images can suffice.
The Spanish Government is also considering legislative reform (Preliminary Draft of the Organic Law on Civil Protection of the Right to Honour) that would expressly classify the creation or use of deepfakes as an unlawful interference with the right to one’s own image and voice. This proposed reform would close a key legal gap exposed by AI-driven image and voice manipulation, strengthening protection against non-consensual synthetic media. For the first time, the published draft classifies, as an illegitimate infringement, the use, without consent, of a person’s image or voice that has been created, simulated, or manipulated through AI or similar technologies, particularly where this occurs for advertising, commercial, or comparable purposes. The draft also makes clear that the voluntary sharing of one’s image on social media does not authorise third parties to reuse that image in different channels or contexts, thereby closing a key legal gap exposed by AI-driven image and voice manipulation and strengthening protection against non-consensual synthetic media.
From a criminal law perspective, the Spanish Government is also considering the approval of a Preliminary Draft of the Organic Law for the protection of minors in digital environments, which, once passed, would modify the Spanish Criminal Code. The proposal would introduce a new criminal offence covering the use of physical images or voice recordings that have been generated, modified, or recreated using automated systems, software, algorithms, artificial intelligence, or any other technology, where these appear real and are intended to undermine an individual’s moral integrity, simulating situations involving sexual content; or situations that are severely humiliating. Such conduct would be punishable by a prison sentence of between one and two years.
Germany addresses deepfakes through a combination of civil and criminal law. Under civil law, Section 22 of the German Artistic Copyright Act (the Kunsturhebergesetz, or KUG) protects the right to one’s own image and stipulates that images may only be distributed or publicly displayed with the consent of the person depicted. This also applies to images generated by artificial intelligence, provided they resemble a real person to such an extent that this is recognisable to a viewer, meaning the provision is likely always applicable to deepfakes. The exceptions under Section 23 KUG, such as for artistic purposes, are likely to be rarely applicable to deepfakes. In addition, there is the right to one’s own voice, which is relevant when a voice is artificially imitated or altered to create recordings that appear authentic. In cases involving other notable characteristics relevant to personality rights, the general right of personality may apply. This is also the case, for example, when deepfakes attribute statements or behaviours to a person or a company that they never actually made or engaged in, thereby damaging their reputation. The general right of personality also protects against defamatory depictions and the dissemination of false or manipulatively altered content. On this basis, individuals or, in the event of reputational damage, even companies affected by deepfakes are entitled to injunctive relief. In cases of commercial use, or in the case of particularly serious violations, damages may also be considered.
Under the criminal code, existing provisions on insult, defamation, slander, false accusation, coercion, and extortion can all apply to deepfake scenarios, depending on the nature of the content and its intended use. In addition, Section 201a of the German Criminal Code (StGB) (violation of the highly personal sphere of life and of personal rights through the taking of photographs) may also apply in cases involving the taking of photographs. In the case of pornographic deepfakes, Sections 184b and 184c StGB (distribution of child pornography or pornography involving minors) may also apply.
Germany is also considering dedicated deepfake regulation that would criminalise the creation and distribution of realistic digital forgeries of a person’s appearance, behaviour, or speech without consent.
Italy protects the right to one's own image through Article 10 of the Civil Code and Article 96 of Law 633/1941 (the Copyright Act), both of which require the consent of the person depicted for any reproduction or dissemination of their likeness. Violations entitle the affected person to injunctive relief, content removal, and damages including for moral harm under Article 2059 of the Civil Code. Prior to dedicated legislation, deepfakes were addressed through existing criminal offences such as aggravated defamation, identity substitution (Article 494 of the Criminal Code), and – in sexually explicit cases – the non-consensual dissemination of intimate images under Article 612-ter.
In September 2025, Italy adopted Law 132/2025 on Artificial Intelligence, which introduced Article 612-quater of the Criminal Code. This provision establishes a criminal offence for the dissemination, without consent, of AI-generated or altered images, videos, or audio capable of deceiving as to their authenticity and causing unjust harm, punishable by imprisonment of between one and five years.
The Chinese approach
In China, the law addresses AI-generated depictions of individuals through both civil remedies and targeted regulations. Under Chinese civil law, individuals enjoy various personality rights, including the rights to name, likeness, reputation, honour, and privacy. Notably, the right of likeness expressly denotes the right to create, use, publish, or license one’s own likeness, and the right of voice has analogous protection. Remedies for violation can include injunctions, damages, and public apologies.
Chinese courts have been willing to enforce personality rights in respect of AI-generated content. Recent cases have established that using a person’s recorded voice as source material for AI processing without consent, using AI-synthesised celebrity voices to promote products, and creating AI companions using a celebrity’s name, likeness, and personality traits all constitute infringements of personality rights.
China has also enacted specific regulations targeting synthetic media and deepfake technology. These provisions define ‘deep synthesis technology’ broadly to include AI systems capable of generating or manipulating text, images, audio, video, or virtual scenes. Service providers must carry out comprehensive security assessments and obtain administrative licences before making deep synthesis technology available to users, and the use of deep synthesis to create or disseminate content that violates laws, infringes upon others’ rights, or disrupts public order is prohibited.
Violations of these provisions may result in administrative penalties, including warnings, fines, and suspension of services, or referral for criminal prosecution in serious cases. China’s regulatory authorities have been active in enforcement, with platforms removing substantial volumes of non-compliant content and penalising significant numbers of accounts in recent crackdowns.
Deepfakes and data protection
Beyond personality rights, deepfakes raise significant issues at the intersection of privacy and data protection law. An individual’s image, voice, and biometric features constitute personal data whenever the person is identifiable, and any operation involving that data, including its collection, storage, manipulation, or fabrication into synthetic content, can amount to ‘processing’ under applicable law.
The EU and GDPR framework
Under the General Data Protection Regulation (GDPR), applicable across the EU and the European Economic Area, processing of personal data must have a valid legal basis. In most deepfake scenarios, the only tenable basis is the data subject’s explicit consent, which must be freely given, specific, informed, and unambiguous, and can be withdrawn at any time. Deepfakes created without such consent will typically amount to unlawful processing. However, depending on the context, other legal bases may also apply, such as legitimate interests under Article 6(1)(f) of the GDPR, where such interests are overridden by the interests or fundamental rights and freedoms of the individual, or processing for journalistic, scientific, artistic, or satirical purposes. Certain data used to generate deepfakes, such as biometric data, may also fall within the category of “special category data”, which is subject to stricter processing requirements under the GDPR. This includes a general prohibition on processing unless an Article 9 GDPR condition is met, such as obtaining explicit consent. In the absence of a valid legal basis, the creation or dissemination of a deepfake generally constitutes a violation of data protection law. In addition, any processing of personal data must comply with the broader GDPR requirements, including transparency, data minimisation, accuracy and purpose limitation - principles that are difficult to meet in the context of deepfake creation.
Given that deepfakes constitute deliberately manipulated and potentially misleading content, data subjects may invoke corrective rights such as rectification or, more suitably in this context, erasure under the ‘right to be forgotten’. The creator of a deepfake will typically be regarded as a data controller; hosting or dissemination platforms may act as processors depending on their factual role.
National data protection authorities have consistently reaffirmed that publishing or exploiting a person’s image without consent violates data protection principles. In Spain and Germany, for example, the data protection authorities take a robust approach to enforcement, treating lack of consent as inherently unlawful. In Germany, for example, the creation and/or dissemination of deepfakes may give rise to claims by affected individuals or regulatory intervention by authorities, including the imposition of significant fines. In Italy, the Italian data protection authority has taken an increasingly interventionist approach to deepfakes. For example, in October 2025 it issued an urgent provisional order restricting the processing of Italian users' data by an AI platform used to generate non-consensual synthetic nude images.
The Chinese approach
The primary focus of China's model is not only on the protection of individual rights, but also the need to preserve social trust and order. In addition to consent, transparency, erasure, and accountability, Chinese law imposes compliance through provider obligations and regulatory supervision. Under its Deep Synthesis Regulations, service providers must remind users that they should obtain the informed and express consent of the individuals concerned before using deep learning technologies to generate or alter biometric identifiers such as facial or vocal data. Service providers must also establish convenient channels for data subjects to raise concerns.
Deepfakes and post-mortem protection
A particular challenge is how the law addresses (or fails to address) the use of deepfakes involving deceased individuals. The ‘digital resurrection’ of the dead, whether for entertainment, commercial exploitation, or malicious purposes, raises thorny ethical and legal issues. As deepfake technology advances, the adequacy of existing post-mortem protections is likely to come under increasing scrutiny.
Germany
German law provides the most developed framework for post-mortem protection of personality rights, which is shaped by the KUG, case law and criminal law. Section 22 KUG requires consent for the public dissemination of a person’s image. After death, the right to one’s own image continues for a period of ten years (Section 22(3) KUG), enforceable by the deceased’s next closest relatives. When synthetic technologies recreate a deceased individual’s likeness or voice (such as through AI-generated ‘resurrections’ or sexualised deepfakes), the consent requirement makes such acts prima facie unlawful unless justified on one of the exceptions listed in Section 23 KUG. Beyond the statutory ten-year limit, the doctrine of postmortales Persönlichkeitsrecht (post-mortem personality rights), rooted in the constitutional protection of human dignity, provides additional protection against grave distortions of personal legacy. Case law distinguishes here between non-pecuniary and pecuniary aspects. The latter are inheritable and protect the value created during a person’s lifetime of their likeness, name, or other characteristics, and are also limited to ten years after death (Section 22(3) KUG).
In cases of violations of the non-property aspects of post-mortem personality rights, injunctive relief (cease and desist, removal) is available; in cases of violation of the pecuniary aspects, claims for damages may also be applicable.
Complementing these provisions, criminal law penalises insults to the memory of the deceased, allowing prosecution where a deepfake degrades or ridicules a deceased person’s honour (Section 189 StGB). These provisions adapt traditional protections to the digital environment: a deepfake may be treated as the contemporary equivalent of a defamatory montage or forged portrait and may be subject to injunctive relief and damages.
Spain
Spanish law also provides robust post-mortem protection. Organic Law 1/1982 grants an 80-year post-mortem protection for personality rights, including image, honour, and privacy. This extended period significantly exceeds the German ten-year statutory limit. Although GDPR protections lapse upon death, Spain’s domestic data protection legislation confers limited post-mortem control on relatives or authorised representatives (to request access to such data, as well as its correction or deletion, subject, where applicable, to the deceased’s instructions), unless the deceased had expressly precluded it.
The Preliminary Draft of the Organic Law on Civil Protection of the Right to Honour expressly states that the right to bring civil actions to protect the honour, privacy, or public image of a deceased person rests with the person designated by the deceased for that purpose in his or her will.
As a very relevant change, the Preliminary Draft of the Organic Law on Civil Protection of the Right to Honour confers a reinforced post-mortem protection, covering the faculty to prohibit in the future the use of one’s own image or voice (whether original or modified, simulated, or manipulated) for advertising, commercial, or similar purposes upon death. It also states that the testator may designate one or more persons to authorise or deny such uses.
Italy
Italian law offers a degree of post-mortem protection, though it is less systematically developed than the German or Spanish frameworks. Under Article 93 of Law 633/1941 (the Copyright Act), upon the death of the rights-holder, the consent required for the use of a person's image passes to close relatives – specifically the spouse, children, or, in their absence, parents and siblings. An AI-generated ‘resurrection’ of a deceased individual's likeness would therefore require the consent of these relatives, and an unauthorised deepfake could give rise to civil liability and injunctive relief on their behalf.
On the data protection side, Legislative Decree 101/2018 extended post-mortem data protection to Italy's Privacy Code, allowing the rights under Articles 15–22 of the GDPR to be exercised by designated individuals or heirs after the data subject's death.
China
In China, the Civil Code explicitly provides that where the name, likeness, reputation, honour, privacy, or remains of a deceased person are harmed, qualified close relatives have the right to take civil action. Chinese law treats post-mortem protection not as an inherited property right but as a right of close relatives to defend the deceased’s personality interests.
However, courts have recognised that the economic interests tied to a deceased person’s name and likeness can be inheritable, giving qualified close relatives the right to license usage and prevent unauthorised commercial exploitation.
Deepfakes and labelling obligations
As deepfakes have proliferated, regulators have increasingly turned to transparency as a tool for combating their harms. Labelling obligations (requirements that AI-generated or manipulated content be clearly disclosed) have emerged in many territories as a common regulatory response.
The European approach
The EU was among the first major jurisdictions to enact comprehensive labelling obligations for deepfakes. New labelling rules under Article 50 of the AI Act (which apply from 2 August 2026) require ‘deployers’ (any natural or legal person, public authority, agency or other body using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity) to disclose clearly that the resulting material has been artificially produced or altered. Importantly, these obligations are balanced against fundamental rights, particularly freedom of expression and artistic freedom. Exemptions exist where deepfakes serve legitimate public purposes, such as detecting or prosecuting criminal offences, or fall within evidently artistic, satirical, or fictional works. In the latter context, transparency is adapted rather than suppressed: creators must still acknowledge the artificial nature of the content, but in a manner that does not hamper the display or enjoyment of the work. AI-generated or AI-manipulated texts that are published to inform the public about matters of public interest are also subject to a disclosure requirement, unless the content has undergone a process of human review or editorial oversight and a natural or legal person bears editorial responsibility.
The EU Digital Services Act (DSA) is also relevant. Under Article 34, very large online platforms (VLOPs) and very large online search engines (VLOSEs) must assess systemic risks arising from the design, functioning, or use of their services, including risks from the dissemination of generated or manipulated content that could affect civic discourse and electoral processes. Article 35 requires these platforms to put in place reasonable, proportionate, and effective mitigation measures to address such risks. Unlike the AI Act, the DSA does not impose a direct statutory labelling obligation for AI-generated content. However, the European Commission’s Guidelines for VLOPs and VLOSEs on the mitigation of systemic risks for electoral processes (published on 26 April 2024) recommend, on a non-binding basis, that platforms implement labelling of AI-generated or manipulated content, invest in provenance and watermarking technologies, and provide user-facing disclosures as appropriate mitigation measures, particularly in the context of elections. The Guidelines also recommend that platforms offer user-friendly tools allowing recipients to flag content that appears to be artificially generated or altered.
The Chinese approach
China has established what is arguably the most comprehensive labelling regime in the world. The Deep Synthesis Provisions and the Measures for Labelling of AI-Generated Synthetic Content establish a detailed framework requiring online platforms and service providers to clearly identify synthetic or manipulated content across all formats, including text, images, audio, video, virtual characters, and digital environments.
Providers must apply both visible labels (such as on-screen text, audio cues, or graphic indicators) and invisible watermarking or embedded metadata to ensure persistent traceability, even after content is downloaded or shared. The rules mandate standardised labelling methods, consistent placement, and durability of marks, while also requiring platforms to implement internal review mechanisms, prevent removal or alteration of labels, and put in place contractual terms requiring downstream distributors to maintain them.
The rules prohibit the use of deep synthesis technology for illegal purposes, producing or distributing fake news, manipulating biometric data without consent, or altering or removing mandatory labels. Providers must verify user identities and file algorithm information with regulators. Violations may result in administrative penalties or, in serious cases, criminal prosecution.
Practical tips
Deepfakes represent one of the most significant legal challenges posed by artificial intelligence, striking at the heart of identity, privacy, and trust. As this article has shown, legal systems around the world are responding, albeit with different approaches and emphases. For organisations operating across borders, understanding these similarities and differences is essential as the regulatory landscape continues to evolve. Despite the complexity, a number of practical recommendations can be made:
- Understand the jurisdictional landscape. If your organisation creates, deploys, or hosts AI-generated content involving real individuals, ensure you understand the legal requirements in each jurisdiction where that content may be accessed or disseminated. A strategy that is compliant in one market may expose you to liability in another.
- Obtain informed consent. In virtually all jurisdictions, consent is the safest legal basis for using a person’s image or voice in AI-generated content. Ensure that consent is freely given, specific, informed, and documented. Be particularly careful where the intended use differs from the original context in which the image or voice was captured.
- Implement robust labelling and transparency measures. Labelling obligations are expanding. Proactively implement both visible and invisible labelling mechanisms for synthetic content, and ensure that downstream users and distributors are contractually obliged to maintain those labels.
- Establish clear AI policies and governance frameworks. Develop internal policies governing the creation, use, and dissemination of deepfakes and other AI-generated content. Assign clear accountability for compliance and ensure that staff are trained on the legal and reputational risks.
- Monitor for misuse. If your organisation is a potential target of deepfake misuse (whether through impersonation, fraud, or reputational harm), implement monitoring systems to detect and respond to synthetic media involving your executives, brand, or products.
- Prepare for rapid response. Have legal and communications protocols in place to respond swiftly if deepfakes affecting your organisation or personnel are identified. This may include takedown notices, injunctive relief, and proactive stakeholder communication.
- Consider post-mortem implications. If you are using AI to recreate deceased individuals (whether for entertainment, memorial, or commercial purposes), be aware that different jurisdictions provide very different levels of protection for the deceased. Seek legal advice before proceeding.
- Stay ahead of regulatory change. The legal landscape for deepfakes is evolving rapidly, with new legislation proposed or under consideration in multiple jurisdictions. Build relationships with legal advisers who can help you stay ahead of these developments and adapt your compliance programmes accordingly.
DLA Piper’s global team is well-placed to assist with your needs regarding AI, deepfakes, personality rights, data protection, and much more besides. If you have questions about anything raised in this article, please get in touch with the authors or your regular DLA Piper contact.











