When AI-generated media become a privacy violation

IT’S A RANDOM Tuesday night. You scroll through social media and see some AI-generated photos posted by your friends as part of one of those quintessential 2026 online trends. It’s cute, until it’s not.

The National Privacy Commission (NPC), the body statutorily mandated to administer and implement the provisions of the Data Privacy Act of 2012, has warned the public against using artificial intelligence (AI) tools in generating and/or posting images and/or videos depicting a real person’s face or likeness, particularly when it amounts to falsity, when it is unconsented, or when it lacks a legitimate purpose.

‘Personal information’

The Data Privacy Act defines “personal information” as “any information whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information would directly and certainly identify an individual.”

In its Advisory Opinion No. 2023-025, the NPC has made it clear that a photo of a person’s face is considered personal information under the data privacy law as it directly and certainly identifies a particular individual.

‘Processing’

Under the Data Privacy Act, “processing” is defined as “any operation or any set of operations performed upon personal information including, but not limited to, the collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure or destruction of data.”

Thus, generating images or videos from a real person’s face or likeness using an AI tool is considered data processing. Posting the AI-generated image or video online also counts as a separate act of data processing.

When AI lies

When the AI-generated media portrays a real person doing something they never did, saying something they never said, or being in a location they’ve never been to, such media is considered false personal data, as it ascribes false information to the person or data subject. When this happens, the person whose face or likeness was used to create such photo or video may exercise the rights granted under Section 16 of the Data Privacy Act, which include seeking the blocking, removal, or destruction of the personal information.

Moreover, the disclosure of false personal data – when attended by malice or bad faith – may amount to malicious disclosure under Section 31 of the Data Privacy Act, which is punishable by imprisonment and a fine ranging from Php 500,000.00 to Php 1,000,000.00.

When unconsented or lacks legitimate purpose

As discussed, generating and posting AI-generated media using a real person’s face or likeness are separate acts of data processing. For processing of personal information to be lawful, such act must be backed by at least one criterion enumerated under Section 12 of the Data Privacy Act.

The most common criterion is the data subject’s consent.

Absent consent, the person who generates or posts the AI-generated media must show that the processing is: (1) necessary and related to the fulfillment of a contract with the data subject or in order to take steps at the request of the data subject prior to entering into a contract; (2) necessary for compliance with a legal obligation to which the personal information controller is subject; (3) necessary to protect vitally important interests of the data subject, including life and health; (4) necessary in order to respond to national emergency, to comply with the requirements of public order and safety, or to fulfill functions of public authority which necessarily includes the processing of personal data for the fulfillment of its mandate; or (5) necessary for the purposes of the legitimate interests pursued by the personal information controller or by a third party or parties to whom the data is disclosed, except where such interests are overridden by fundamental rights and freedoms of the data subject which require protection under the Philippine Constitution.

The creation of AI media using a real person’s face or likeness, without lawful basis, may amount to unauthorized processing under Section 25 of the Data Privacy Act, which could lead to imprisonment and a fine ranging from Php 500,000.00 to Php 2,000,000.00.

Journalistic, artistic, or literary purposes

The data privacy law does not apply to processing of personal information for journalistic, artistic, or literary purposes, in deference to the constitutional right to freedom of speech, of expression, or of the press.

While this may be the case, using AI-generated media must still be done cautiously, as the protection that comes with journalistic, artistic, or literary purposes only attaches to the “minimum extent suitable and necessary to achieve them.” It would depend on the peculiar circumstances of each case, like whether the AI-generated media is presented as real or whether its use is necessary for the intended purpose.

While it may be entertaining to create AI-generated media using a friend’s face, or even that of a stranger, caution must still be exercised. Think twice before making that AI photo, as a person’s face is personal information protected by law.

***

Atty. Jonel P. Amio is an Ilonggo lawyer based in Makati City. You may reach him at jamio.blbalaw@gmail.com/PN

LEAVE A REPLY

Please enter your comment!
Please enter your name here