Skip to main content
WAIMAKERS
About UsCareersContact
|
Start a conversation
Back to overview

HeyGen

HeyGen

ConditionalEU: UnconfirmedPlan-dependentRetention by featureRegion unconfirmed

Assessment labels are editorial guidance, not GDPR certifications. Validate the exact plan, lawful basis, DPA, subprocessors, retention, residency and feature settings. EU storage and no-training terms alone do not establish GDPR compliance. ¹ No training applies under the reviewed plan’s terms.

Rolling out HeyGen safely?

We assess the actual plan, settings, data flows and governance controls, then turn the findings into a practical rollout decision.

Request an assessment

Pricing / Contract Route

Enterprise custom pricing; verify current order form

Enterprise Features

DPA, Enterprise no-training statement, biometric consent and deletion controls, SOC 2 Type II assurance

Last Updated

September 10, 2026

Reviewed on 10 September 2026 by WAIMAKERS B.V.

1 Purpose

HeyGen processes text, images, video, voice and avatar data. Its privacy impact depends on the feature, account type, consent process and people depicted. Enterprise use can be a conditional business route after contractual and biometric controls are in place; consumer plans should not be treated as a no-training workspace.

2 Comparison of HeyGen privacy controls (EU focus)

Issue Current vendor documentation Procurement implication
Training HeyGen's privacy policy says user input may be used to train and improve models and provides an email opt-out. Its Enterprise page says Enterprise content is not used for training. Put the no-training term in the Enterprise order form/DPA and do not rely on an informal plan label.
DPA HeyGen publishes a DPA for processing customer personal data under eligible service agreements. It covers special-category face biometric data and incorporates transfer terms. Execute it and confirm roles, subprocessors, SCC module and conflict order.
Residency The reviewed public documents do not promise that all customer content, backups, subprocessors and support access remain in the EU. Obtain a written location and transfer map for the chosen features.
Deletion The privacy policy gives general purpose-based retention and says backups can persist for 60 days after deletion. Define deletion separately for projects, account data, avatars, biometrics, backups and legal/security records.
Biometric data HeyGen can derive face geometry and, depending on the service, a voiceprint. It requests consent for relevant processing and publishes feature-specific deletion rules. Use documented consent/authority for every depicted person and conduct a DPIA where risk warrants it.

3 Is HeyGen GDPR-compliant?

The privacy policy, updated 11 August 2026, says user inputs can include text, voice, image and video and may be used for service improvement and AI-model training. It provides a training opt-out contact, explains controller/processor roles, refers enterprise customers to a DPA, and states that some deleted information can remain in backups for up to 60 days.[1]

HeyGen's Enterprise page says Enterprise content is not used to train its models and advertises SOC 2 Type II controls. Treat these as vendor claims whose scope must be verified in the current report and contract.[2]

4 Avatars, consent and biometric data

HeyGen's biometric notice, updated 5 May 2026, describes face geometry and possible voiceprints. For EEA identity verification, it says biometric verification data is deleted immediately after verification, usually within minutes. Geometry used to create an avatar is retained while the avatar remains active and is destroyed within 60 days after the avatar or account is deleted. Where a user consents to biometric training, withdrawal triggers deletion of identifiable biometric data within 60 days to the extent feasible.[3]

Those are different retention events; the older blanket claim that HeyGen keeps EU biometric data for three years is unsupported by the current notice. A face or voice recording is personal data. It is special-category biometric data under GDPR when technically processed for uniquely identifying a person; other likeness and voice processing can still create high privacy, personality-rights and employment risks.

HeyGen's DPA addresses customer personal data and identifies face biometric data as special-category data where applicable. Review the current security portal subprocessor list before use.[4]

5 AI Act transparency

EU AI Act Article 50 transparency duties have applied since 2 August 2026. Providers of systems that generate synthetic audio, image, video or text must support machine-readable marking, subject to the Regulation's conditions. Deployers have a separate duty to disclose deepfake content and, for certain public-interest text, to disclose artificial generation or manipulation. There is a transition until 2 December 2026 for the provider marking duty for systems placed on the market before 2 August 2026. Whether a particular avatar output is a “deepfake” depends on the legal definition and context; not every synthetic avatar should be labelled automatically on that ground.[5][6]

6 Recommendations and EU rollout checklist

  1. Use an eligible business agreement and execute the DPA.
  2. Contractually prohibit training and verify the setting for every workspace.
  3. Document the location of source media, generated video, avatar assets, backups and support access.
  4. Record the depicted person's consent or other valid authority and withdrawal/deletion route.
  5. Run a DPIA for scalable employee, customer, voice or identity use.
  6. Define notices and machine-readable marking for each output scenario.
  7. Test deletion of the avatar, account and backups.

Prices, credits and plan names change and are not evidence of a privacy guarantee. Verify the current order form and pricing page at purchase.[7]

7 Verdict summary

HeyGen merits a conditional business route for a contracted Enterprise deployment with no-training, consent, deletion and transfer controls. Public documentation does not establish blanket EU residency, and consumer-plan input may be used for model improvement unless the documented opt-out applies.

8 Disclaimer

This is an editorial procurement assessment, not a legal determination or legal advice.

Compare related tools

Hugging FacePerplexity AI

Need help navigating AI?

Start a conversation
WAIMAKERS

Learn. Lead. Make.

AI Transformation Boutique · Amsterdam

Make work exciting, make businesses unstoppable.

Who We Help

View all roles & industriesCEOs & Board MembersPE & Investment ManagersCFOs & Finance LeadersInnovation DirectorsCTOs & IT LeadersCommercial Directors

What We Do

View all servicesOur ApproachLearnTailored Training ProgrammesAI Champions ProgrammeAI Champions — Executive (London)Agentic Way of WorkingE-learningLeadMake

Company

About UsResourcesContactCareersPodcast ↗

© 2026 WAIMAKERS. All rights reserved.

Privacy PolicyCookie Policy