Back to Blog

Deepfakes, privacy and the AI Act: are we asking too much of the GDPR?

Davide Carboni·Massimo Simbula··11 min read
Two side-by-side panels showing the same presenter: one marked authentic, the other marked AI-generated

The Mentana case raises a question: when is manipulating a person's image genuinely a data protection problem?

On 7 August 2026, the Italian Data Protection Authority announced that it had issued a formal warning to R.T.I. S.p.A., following an investigation opened on a complaint by the data subject himself, over certain segments of Striscia la Notizia in which the image and voice of journalist Enrico Mentana had been manipulated using artificial intelligence systems.

In the videos, statements he never made were attributed to the journalist, and his image was virtually inserted into the television studio of the broadcaster he works for.

According to the Authority, the realism of the images, the low perceptibility of the alteration and the plausibility of the statements could have led the public to believe the content was authentic. The notices regarding the artificial nature of the videos were likewise considered insufficiently clear.

The Authority therefore found a violation of Articles 5 and 25 of the GDPR: lawfulness, fairness, transparency and data protection by design. Pursuant to Article 58(2) of the Regulation, in addition to the warning, the Authority prohibited any further use of the journalist's data in the manner complained of, save for its retention for possible judicial purposes.

The decision is interesting. But it also raises a less immediate question:

Is a deepfake of a public figure first and foremost a privacy problem?

The answer is not so obvious.

Image and voice are personal data. But that does not settle the question

Let us start from a point that is hard to contest.

The definition of personal data in Article 4(1) of the GDPR is deliberately broad: any information relating to an identified or identifiable person may constitute personal data.

The image of a recognisable person normally falls within this definition. The same may apply to the voice, which however takes on a biometric nature only where it is processed through specific technical means aimed at the unique identification of the data subject (Article 4(14) GDPR).

The fact that the person is a public figure does not change this classification.

Enrico Mentana's image therefore remains personal data even though it appears daily on television, in newspapers and on social networks.

But a second conclusion does not necessarily follow from this premise:

Every misuse of a person's image is essentially a personal data protection problem.

And it is precisely here that a first paradox emerges.

The paradox: the personal data stays identical, but the problem appears only when we falsify reality

Let us imagine that Striscia la Notizia had used an ordinary authentic clip of Mentana, taken for instance from a public interview.

The face would have been exactly the same personal data.

The voice would have been exactly the same personal data.

And yet, given the ordinary journalistic, informational or satirical grounds, the use would hardly have produced a comparable decision.

Consider four situations:

ContentAre face and voice personal data?Problematic element
Authentic footage of Mentanayesnormally none
Authentic clip placed in a satirical contextyespossible limits of satire
Manifestly artificial caricatureyespossible personality rights
Realistic deepfake with statements never madeyesfalse appearance of authenticity

The personal data does not change.

What changes is the relationship between the representation and reality.

This is a conceptually important point.

If the property that makes the fourth case problematic were simply the presence of personal data, we should expect similar problems in the first three as well.

That does not happen.

The personal data is therefore certainly present, but it does not appear to be the property that explains why that specific representation becomes unlawful or otherwise problematic.

The distinguishing factor lies elsewhere.

A simple counterfactual test

We can frame the problem through a thought experiment.

Take the contested deepfake and replace it with authentic footage of Mentana containing the same image, the same face and the same voice.

The personal data remains.

But what disappears is the element that triggered the Authority's intervention: the person is no longer represented doing or saying something that never actually happened.

This suggests a conclusion:

It is not simply the processing of the image that generates the problem. It is the falsification of the relationship between that image and the reality represented.

In schematic terms:

Mentana's face + authentic representationnormally no particular problem
Mentana's face + manifestly satirical artificial representationpossible lawfulness
Mentana's face + apparently authentic artificial representationproblem

The determining variable is therefore not the data.

It is the deceptive authenticity of the representation.

And it is precisely on this variable that the AI Act builds its rules on deepfakes.

What legal interest is really harmed?

Imagine an extremely realistic video in which a person utters words they never said.

The problem can be described in different ways.

We could say:

personal data has been processed unfairly.

But we could also say:

a false representation of that person's identity has been constructed.

The second formulation seems to capture the phenomenon better.

The harm does not necessarily derive from the fact that someone gained access to information that should have remained private.

On the contrary, all the source material could be perfectly public.

The problem arises from the manipulation of the person's public identity and from the capacity of artificial content to appear authentic.

Different legal interests therefore come into play:

  • personal data protection;
  • image rights;
  • personal identity;
  • reputation;
  • freedom of expression and satire;
  • transparency towards the public.

Addressing all these problems through the GDPR alone risks expanding data protection until it gradually becomes a general right to control one's own digital representation.

And it is debatable whether this is the role for which the GDPR was conceived.

Public does not mean "not personal"

The opposite mistake must nonetheless be avoided.

Arguing that a public figure's image is not personal data because it is publicly available would be legally difficult to defend.

The GDPR does not equate "public data" with "non-personal data".

A television journalist's face remains attributable to an identified person.

The correct distinction is another one:

Personal data does not mean data necessarily withdrawn from use.

The GDPR governs processing by taking into account the legal basis, the purpose, the context, the data subject's expectations and the balance with other fundamental rights, including freedom of expression.

In the Mentana case, therefore, the point is not to deny that processing of personal data exists.

The point is to ask how far that classification actually explains the conduct complained of.

Image rights were already something other than privacy

Italian law has known specific instruments for addressing the use of a person's image long before the GDPR.

Article 10 of the Civil Code protects a person's image, while Articles 96 and 97 of Law No. 633 of 22 April 1941 on copyright govern portraits and set out particular conditions and exceptions for their publication.

To these must be added the protection of personal identity developed by case law.

These bodies of law start from a different perspective than data protection.

The question is not necessarily:

"is someone processing information relating to this person?"

but:

"is this person represented in a manner compatible with their rights?"

Deepfakes take this second question to a technologically new level.

It is not merely a matter of publishing a photograph.

Nor is it simply a matter of altering a shot.

A behaviour of the person that never occurred is artificially produced.

This is exactly the kind of phenomenon for which the AI Act introduced specific rules.

The AI Act describes the problem directly

Since 2 August 2026, the transparency obligations under Article 50 of the AI Act (Regulation (EU) 2024/1689) have applied, according to the timetable set out in Article 113.

Among the cases expressly covered are deepfakes.

The logic of the provision is significantly different from that of the GDPR.

The GDPR starts from the question:

does this information relate to an identified or identifiable person?

The rules on deepfakes instead start from the question:

can this artificial content be perceived as authentic?

This is a decisive shift in perspective.

In the first case, the centre of the analysis is the person to whom the information relates.

In the second, it is the relationship between synthetic content, reality and the recipient's perception.

The Colosseum test

Another thought experiment makes the difference clear.

Consider two videos produced with artificial intelligence systems.

In the first, the President of the Republic announces something he never said.

In the second, an explosion that never took place is shown at the Colosseum.

In the first case, personal data is evidently present.

In the second, the Colosseum has no right to privacy.

But the informational problem is substantially identical:

Synthetic content is presented in such a way that it can be mistaken for an authentic representation of reality.

It is no coincidence that the definition of deepfake adopted in Article 3(60) of the AI Act is not limited to persons.

It may concern AI-generated or AI-manipulated images, audio or video resembling existing persons, objects, places, entities or events, which could falsely appear authentic.

This makes it possible to isolate the essential element of the case.

It is not the personal data.

It is the deceptive appearance of authenticity.

The GDPR and the AI Act are not alternatives

This does not, of course, mean that the GDPR becomes irrelevant.

Producing a deepfake may involve numerous processing operations on personal data:

  • collection of photographs;
  • audio recordings;
  • voice samples;
  • video;
  • storage of the material;
  • processing through models;
  • possible processing of biometric data, where the conditions are actually met.

All these operations may fall squarely within the GDPR.

But a logical leap must be avoided:

the image is personal data the deepfake contains that image therefore the deepfake problem is essentially a GDPR problem.

The conclusion does not follow automatically from the premises.

The same fact may simultaneously engage different bodies of law, each protecting different interests.

One possible map is the following:

PhenomenonPredominantly relevant body of law
Collection and processing of images and voiceGDPR
Use of the person's imageimage rights
Attribution of statements never madepersonal identity / reputation
Apparently authentic artificial contentAI Act
Disclosure of the artificial natureArt. 50 AI Act
Satire and freedom of expressionbalancing with personality rights

The modern problem therefore does not consist in choosing between the GDPR and the AI Act.

It consists in preventing the GDPR from becoming the universal container for any digital phenomenon in which an identifiable person appears.

A particularly interesting case: satire

The Striscia la Notizia case adds a further layer.

We are not dealing with a fraud designed to impersonate Mentana, nor with a video disseminated for purposes of political disinformation.

The context is satirical.

It is precisely for this reason that Article 50(4) of the AI Act provides a lighter regime for manifestly artistic, creative, satirical, fictional or analogous works: the transparency obligation does not disappear, but is reduced to a disclosure made in an appropriate manner, such as not to hamper the display or enjoyment of the work.

The European legislator chose neither to ban satirical deepfakes nor to treat them as automatically harmless.

It sought a balance: preserving creative freedom while still guaranteeing an appropriate level of transparency about the artificial nature of the content.

This further confirms how far the AI Act's rules are built directly on the technological phenomenon that the Mentana case represents.

The time factor

There is however a circumstance that is fundamental to assessing the decision correctly.

Authority's decision
23 July 2026
Article 50 AI Act applies from
2 August 2026

The Authority adopted its decision on 23 July 2026.

Article 50 of the AI Act became applicable on 2 August 2026.

The case therefore cannot be read as if the Authority had chosen to use the GDPR while ignoring specific rules that were already fully applicable.

At the time of the decision, those rules were not yet operative.

The case rather captures an interesting historical transition.

Until 2 August 2026, a phenomenon such as the deepfake necessarily had to be addressed through pre-existing regulatory instruments: data protection, personality rights, audiovisual law, civil liability and other general principles.

Now there is a European provision built expressly around the artificial and apparently authentic nature of the content.

From GDPR overreach to regulatory specialisation

The GDPR has a feature that has determined much of its effectiveness: it uses principles general enough to adapt to technologies that the 2016 legislator could not have foreseen in detail.

Lawfulness.Fairness.Transparency.Accountability.Data protection by design.

This elasticity has been essential.

But that same elasticity can become problematic when more specific rules appear.

If any digital representation of a person is personal data, and any improper use of that representation is traced back to Article 5 GDPR, data protection risks gradually expanding into territory belonging to other legal institutions.

We might call this phenomenon GDPR overreach.

It does not mean arguing that the GDPR does not apply.

It means distinguishing two profoundly different statements:

"the GDPR is applicable to the case"

and

"the GDPR describes the core of the problem better than other bodies of law"

In the case of deepfakes, the two statements do not necessarily coincide.

The property that explains the wrong

We can therefore return to the initial paradox.

Mentana's face is personal data in the authentic footage.

It is personal data in the photograph.

It is personal data in the caricature.

It is personal data in the deepfake.

This characteristic remains constant.

But the legal problem changes radically when technology constructs a credible representation of something that never happened.

The quality of being "personal data" is therefore a condition present in the Mentana case, but it does not appear to be the property that explains why the case is problematic.

That property is another one:

The capacity of an artificial representation to be mistaken for reality.

This is the quid pluris introduced by the deepfake.

And this is exactly the phenomenon that Article 50 of the AI Act now seeks to govern.

Since 2 August 2026, a multi-layered reading is needed

For a deepfake produced today, the analysis should therefore develop on at least three levels.

1

First level: AI Act.

Does the content constitute a deepfake? Have the transparency obligations under Article 50 been met? Is the recipient placed in a position to understand that what they are watching is not authentic? Has the system provider ensured that outputs are marked in a machine-readable format and detectable as artificial (Article 50(2))? Has the deployer complied with its obligation to disclose the artificial nature of the content (Article 50(4))?

2

Second level: personality rights.

Is the use of the person's image, voice and identity legitimate? Are the right to report news, satire or artistic freedom involved? Are reputation and personal identity compromised? In pathological cases, the criminal safeguard of Article 612-quater of the Criminal Code also comes into play, introduced by Law No. 132 of 23 September 2025, which penalises the unlawful dissemination of content generated or altered with artificial intelligence systems.

3

Third level: GDPR.

Which personal data has actually been processed? For what purposes? On what legal basis? With what safeguards?

The distinction is not academic.

Identifying the correct body of law means identifying different obligations, different responsible parties, different competent authorities and different sanctioning regimes.

Privacy does not mean universal control of digital identity

The Mentana case therefore offers a more general lesson.

The fact that something can be classified as personal data does not mean that data protection is necessarily the best vantage point from which to understand the phenomenon.

The image and voice of a public figure remain personal data.

But if those same images can be used without particular problems when they represent something that actually happened, while becoming problematic when they are used to construct an event that never occurred, then it is hard to argue that it is the personal nature of the data that truly explains the difference.

The problem lies in the falsification.

In the artificially attributed identity.

In the relationship between representation and reality.

And in the public's capacity to tell them apart.

The GDPR continues to play an important role.

But since 2 August 2026 it is no longer alone.

The AI Act offers specific rules precisely for that property which makes a deepfake something other than the mere use of a person's image.

Perhaps it is also an opportunity to bring data protection back within more precise conceptual boundaries:

Protecting personal data without turning privacy into a general body of law covering everything that digitally concerns a person.

On the transparency obligations introduced by Article 50 and what they mean in practice for companies, see AI Act: Mandatory AI Transparency from 2 August 2026.

Sources

Do you produce or publish AI-generated content?

Tomato Blue helps you work out which rules actually govern your synthetic content — AI Act, personality rights or GDPR — and get your disclosure and marking in order before an authority does it for you.

Talk to us →