Back to Blog
AI & Emerging Tech GovernanceEU Privacy LawUK GDPR LawEnforcement & Risk Management

Deepfakes, Digital Identity, and What the GDPR Actually Says

By Rob Healey · May 06, 2026

Deepfake fraud surged 58% across UK and EU financial services in the past twelve months. Worryingly, a convincing synthetic identity now takes only 27 seconds to generate.

Therefore, “verify your customer” is no longer a one-time onboarding task. Instead, it is a continuous data protection problem that the GDPR addresses head-on.

The Article 9 problem most teams miss

Many organisations assume deepfake defence is purely a security issue. However, biometric verification systems process special category data under Article 9 UK GDPR and EU GDPR.

Consequently, you need a specific Article 9 condition before deploying facial liveness, voice biometrics, or behavioural biometrics. Generic “legitimate interests” will not work.

Moreover, the EDPB confirmed in 2026 guidance that even short-lived biometric templates count as processing. Therefore, a DPIA is mandatory in almost every deployment.

Why deepfakes break traditional KYC

Older identity checks rely on document scans plus a selfie. Unfortunately, generative video models now defeat that flow in seconds.

As a result, regulators expect layered defences. The UK ICO and FCA jointly recommend liveness, device intelligence, and behavioural signals as a minimum.

A four-point privacy programme for deepfake defence

1. Run a focused DPIA on your verification stack

Begin with a DPIA scoped to the entire identity journey. Importantly, include the third-party vendors processing biometric templates on your behalf.

For a structured approach, see our DPIA service. Equally, the Privacy360 DPIA workflow standardises the analysis across regions.

2. Tighten vendor due diligence

Next, scrutinise every biometric vendor. Ask where templates are stored, how long they live, and whether the model was trained on lawfully obtained data.

Our AI vendor risk management service applies a deepfake-specific questionnaire. Similarly, the Privacy360 Vendor Assessment module tracks responses and flags renewal risks.

3. Strengthen transparency to data subjects

Under Articles 13 and 14, you must tell users that biometric data is processed and explain why. Furthermore, you need a clear route to object and to request human review.

In practice, that means updating privacy notices, in-app disclosures, and any consent capture screens. Otherwise, enforcement risk rises sharply.

4. Build a deepfake incident playbook

Finally, prepare for the breach you hope never happens. Specifically, document who triages a suspected deepfake intrusion within the 72-hour notification clock.

Our outsourced DPO service covers cross-border breach coordination. Likewise, Privacy360's incident workflows route notifications to the right authorities automatically.

The regulatory direction of travel

Crucially, the EU AI Act now classifies remote biometric identification as high-risk. Therefore, expect tighter conformity assessments and stronger transparency duties through 2026 and 2027.

Meanwhile, the UK government's AI Action Plan signals similar expectations even without an equivalent statute. In short, the regulatory floor is rising fast.

Where to go next

Deepfake defence is a privacy programme problem, not just a fraud problem. Therefore, treat it as a Board-level risk.

To benchmark your programme, explore Formiti's AI governance services or visit the Privacy360 platform to see how DPIAs, vendor assessments, and incident response sit inside one operating system.

Privacy-first website: We do not use tracking cookies, advertising pixels, or third-party analytics on this site. Read our Privacy Notice.