Out-Law / Your Daily Need-To-Know

OUT-LAW ANALYSIS

Digital replicas: the data protection questions for businesses

Hugh Bonneville

Actor Hugh Bonneville wants new UK protections against using AI to recreate someone’s voice but the concept of digital replicas also raises data protection questions for businesses. Jack Taylor/Getty Images for SXSW London.


Businesses in the UK hoping to use AI to generate ‘digital replicas’ of people’s voices or appearance, such as for cyber training purposes or to offer a more personalised or immersive experience to customers, must navigate data protection law to do so.

In the UK, recent debate around digital replicas has been focused on whether there is a need to enhance UK intellectual property (IP) rights to account for their proliferation. That debate has been reopened by prominent celebrities, like Hugh Bonneville and Matt Lucas, raising concerns over AI imitations of their voices. However, as we explore below, the process of creating and then using digital replicas raise data protection questions that companies at the forefront of AI use also need to consider.

UK reviewing options on digital replicas law

The UK government is currently considering making updates to UK law around digital replicas – a concept it has defined as “images, videos and audio recordings created by digital technology to realistically replicate an individual’s voice or appearance”.

According to the government, digital replicas can cause a range of harms – for people whose likeness is mimicked, and for those who consume the content. Examples it has cited include: unauthorised commercial imitation, leading to lost commercial opportunities for those imitated; reputational harm derived from false depictions; fraud, radicalisation or the spread of misinformation stemming from digital replicas being used to deceive or manipulate people; technology facilitated sexual abuse; and production of criminal material.

In March 2026, the government pledged to consult on options to address those risks, which it acknowledged cannot fully be addressed under existing legal protections spread across a variety of frameworks – whether under the UK’s IP, data protection and privacy, defamation, or online safety regimes.

At the time, the then UK technology secretary Liz Kendall said the consultation would take place during the summer. There has been a subsequent change of UK prime minister and Cabinet restructure, with Kendall losing her job in government and her role being scrapped under a departmental reorganisation. A spokesperson for the government was unable to confirm when the consultation will now take place in response to a query raised by Out-Law.

The relevance of data protection law

Working with businesses at the forefront of AI innovation, Pinsent Masons is seeing how companies are increasingly interested in exploring what they can do with AI using someone’s voice or appearance, to enhance service offerings or their content output, or for training purposes.

For example, in the cybersecurity context, businesses might want to use a copy of a senior executive’s voice to generate an AI replica, with a view to testing employees’ willingness to take action – such as process a suspicious transaction – based on an instruction given via the AI imitation.

Some businesses may also feel that creating digital avatars of people can help them deliver a more personalised service or experience to customers or staff. This could involve creating AI replicas of a person’s voice or appearance.

These activities can engage obligations owed under data protection law. This is because if data relates to a specific person, it will constitute personal data, the processing of which will often be subject to data protection law. Both input data and AI output will constitute personal data in many circumstances. Where this is the case, it will trigger a raft of obligations.

Finding a reliable lawful basis for processing

Under UK data protection law, businesses need a lawful basis to process personal data.

Arguably, the most recognisable and discussed of the six lawful bases is consent. However, the need for consent to be ‘specific’ to the purpose of processing, together with the ability of individuals to withdraw their consent at any time, means it is impractical for businesses to rely on consent, either to input a recording of the person’s voice or picture of their appearance into an AI model or to generate AI output resembling the data that was input.

Of the remaining lawful bases, two will be most relevant to businesses seeking to recreate someone’s voice or appearance using AI.

Contracts

The most straightforward of the two is the lawful basis that applies if the processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.

A contractual right to control how their voices are used is what the likes of Hugh Bonneville and Matt Lucas are calling for in the UK. In one sense, the fact there are already provisions in data protection law might spur questions as to whether a new personality right really needs to be written into UK law. However, owing to the caveats on when a voice might constitute personal data, whether its processing would be governed by data protection law at all, and the lack of inherent commercial value that can be derived, on its own, from a person insisting that a contract governs the processing of their data, this does not provide a full solution to what those performers are seeking.

Organisations seeking to rely on the basis that processing is necessary for the performance of a contract may need a separate agreement to govern the processing involved in recreating someone’s voice or appearance using AI and then for using that output. This is certainly likely in an employment context where an employer might struggle to demonstrate that the activity is ‘necessary’ for performing an existing employment contract.

Legitimate interests

There are, however, circumstances in which an organisation would neither need a person’s consent nor their written agreement to recreate their voice or appearance using AI: if they, or a third party, have ‘legitimate interests’ in such processing.

Courts in Europe have confirmed that commercial interests can constitute legitimate interests. However, the ‘legitimate interests’ ground can only be relied upon for processing personal data if the interests cited are not “overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data […]”. A balancing exercise therefore needs to be undertaken by any organisation seeking to undertake legitimate interests processing – the UK’s Information Commissioner’s Office (ICO) has issued a template legitimate interests assessment (LIA) to support with that.

Factors relevant to whether an organisation could satisfy the balancing test in its favour might include the specific purposes for which it intends to recreate someone’s voice or appearance using AI and use that output, and whether the person whose likeness is being imitated is likely to be harmed by that activity. In the context of celebrities and other performers concerned over losing control over use of their voice in the AI age and possible loss of earnings in future, those factors would likely weigh heavily against businesses seeking to rely on legitimate interests processing of those voices.

Aside from identifying a lawful basis for processing, other data protection requirements will also significantly restrict how a digital replica can be used. For example, the principle of purpose limitation means that whatever legal basis is chosen, the replica can only be used for the clearly defined purpose identified at the outset. In addition, the requirement for fair processing means that the replica could not be used in a manner which is unduly prejudicial to the data subject.

What constitutes processing?

It seems clear cut that inputting a recording of a person’s voice or picture of their appearance into an AI model would constitute processing of personal data for data protection law purposes in many circumstances.

In relation to AI output, if an AI voice or appearance so closely resembles that of an individual to the extent that it can be said to relate to a specific person then the subsequent use of that output will often be subject to data protection law too.

However, there are unresolved questions of law concerning whether the technical wizardry involved in generating AI output from user prompts would itself constitute processing for data protection law purposes. Recent rulings in Germany and UK offer some clues as to how this question might be answered very differently by different judges in different jurisdictions.

In the context of copyright claims raised against AI music generator Suno, a Munich court considered that the content that the company’s system was trained on was effectively memorised within the system itself, enabling users to generate AI content closely resembling the input data in a way it found to be copyright infringing. Applying the court’s findings to a data protection context, it seems at least possible if not likely that the Munich court would consider an AI developer to be processing personal data subsisting within input materials it would consider to be stored within its AI system when acting on user prompts to generate related output.

However, there are suggestions from the ruling in the Getty Images v Stability AI copyright litigation that English courts might take a different view. The judge in that case considered that no infringing copies of Getty’s works were stored in Stability AI’s system, serving a fatal blow to the media company’s claims of secondary copyright infringement in that case. Read across to the data protection sphere, if no copies of the personal data could be said to be stored in an AI system, it seems likely the same judge would consider no processing of that data would take place in calling up AI output based on a user’s prompts.

UK policy uncertainty

The UK government has promised to consult on whether intervention is necessary in relation to digital replicas amidst the ease with which AI content replicating someone’s likeness can be generated and disseminated at scale.

For celebrity performers, they see a case for enhanced IP rights, but the UK government’s March 2026 AI and copyright consultation response makes clear that the growing proliferation of digital replicas triggers a wider range of legal questions. The government is right to consider these questions in the round. However, it should avoid unnecessary delay in shaping future policy on digital replicas given the importance of giving legal certainty to two sectors – the creative industries and the AI sector – so central to its plans to stimulate economic growth.

In the meantime, organisations exploring how they benefit from creating and using digital replicas must keep data protection compliance firmly in mind, to realise the commercial benefits that come from being trusted on matters of privacy.

We are processing your request. \n Thank you for your patience. An error occurred. This could be due to inactivity on the page - please try again.