Legal Liability for Deepfake Porn Using Biometrics Without Consent
Published: 18.09.2026
Someone takes a photograph from a social media profile, extracts the facial geometry, and uses that biometric template to map a real person's face onto explicit imagery. The result—deepfake pornography—circulates within hours. The victim may never learn who created it. Even when the author is identifiable, the path to accountability is fragmented across privacy law, tort law, criminal statutes, and platform regulation, with no single jurisdiction offering a complete remedy. Understanding where liability falls, and what practical barriers obstruct it, is the first step toward choosing an effective legal strategy.
What constitutes unauthorized biometric use in deepfake pornography
Deepfake technology does not simply paste a two-dimensional image onto another body. It extracts biometric identifiers—measurable biological characteristics unique to an individual—and redeploys them. Facial landmark data, skin texture maps, and voiceprints all qualify as biometric information under most statutory definitions. The person whose data is harvested has not consented to this extraction, nor to its use in generating sexual content.
The unauthorised element operates at two distinct stages. First, the biometric data is collected or derived without the subject's knowledge or agreement. Second, that data is processed—trained into a model and used to synthesise new imagery—again without consent. Both stages matter, because different legal regimes attach liability to collection versus processing, and the evidentiary burden differs at each point.
Legal frameworks governing biometric data and deepfakes
No single body of law was designed for this problem. Instead, several overlapping regimes apply, each with different thresholds, remedies, and enforcement mechanisms.
Biometric information privacy statutes
The Illinois Biometric Information Privacy Act (BIPA) remains the most litigated statute of its kind. BIPA requires private entities to publish a written policy before collecting biometric identifiers, to inform the subject in writing, and to obtain a written release. It prohibits selling or profiting from biometric data. Crucially, it provides a private right of action with statutory damages: liquidated damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation, alongside actual damages and injunctive relief. Other states—Texas, Washington, Arkansas—have enacted biometric privacy laws, but most lack a private right of action, leaving enforcement to state attorneys general and sharply limiting the individual's leverage.
General data protection regulation
Under the EU's GDPR, biometric data processed to identify a natural person is a special category of personal data (Article 9). Processing is prohibited unless one of ten narrow exceptions applies—explicit consent, substantial public interest, or vital interests, for instance. A deepfake porn creator who harvested facial data without consent would struggle to satisfy any exception. The GDPR grants data subjects the right to erasure, the right to restrict processing, and the right to compensation for material and non-material damage (Article 82). Supervisory authorities can impose administrative fines up to €20 million or 4% of global annual turnover. The regulation's strength is its breadth and its enforcement infrastructure; its weakness, for deepfake victims, is that the controller—the person who created the deepfake—is often unreachable, and the processor defence (the platform) may claim it lacked knowledge.
Tort and privacy common law
In jurisdictions without specific biometric statutes, victims rely on common-law privacy torts. The most relevant are appropriation (using someone's name or likeness for a commercial or exploitative purpose), public disclosure of private facts, and intentional infliction of emotional distress. Each carries evidentiary demands that biometric statutes sidestep. Appropriation claims, for instance, may falter if the deepfake was distributed without a direct profit motive—shared freely on a forum rather than sold. Emotional distress claims require proof of extreme and outrageous conduct, a threshold that some courts have met in revenge-porn contexts but that remains unevenly applied to synthetic imagery.
Criminal liability and enforcement challenges
A growing number of jurisdictions have enacted criminal offences targeting non-consensual deepfake pornography. The United Kingdom's Online Safety Act 2023 creates an offence of sharing intimate images, explicit or synthetic, without consent, carrying a maximum sentence of two years' imprisonment. Several US states—including Virginia, California, and Texas—have added deepfake-specific provisions to their revenge-porn statutes. South Korea has amended its sexual violence laws to penalise the creation and distribution of deepfake sexual content, with penalties that have been strengthened repeatedly in response to large-scale incidents.
Enforcement, however, faces persistent obstacles. Creators frequently operate under pseudonyms on platforms that require minimal identity verification. Cross-border distribution complicates extradition and mutual legal assistance. Even when a suspect is identified, proving authorship—demonstrating that a specific person ran the model rather than merely forwarded an existing file—requires digital forensic evidence that many police units lack the capacity to gather. The result is a body of criminal law that signals deterrence but delivers uneven prosecution.
Jurisdictional comparison: how different legal systems respond
Jurisdiction Primary legal basis Private right of action Statutory / liquidated damages Criminal offence for deepfake porn Illinois (US) BIPA; common-law torts Yes (BIPA) $1,000–$5,000 per violation Revenge-porn statute (non-consensual dissemination) EU member states GDPR; national criminal law Yes (Article 82 GDPR) Actual + non-material damages; regulatory fines Varies by member state United Kingdom Common-law torts; Online Safety Act 2023 Misuse of private information; GDPR-based claims Common-law damages only Yes (up to 2 years' imprisonment) South Korea National sexual violence statutes; PIPA Yes (PIPA) Up to 5x actual damages under PIPA Yes (creation and distribution)The comparison reveals a structural trade-off. Statutes with liquidated damages—BIPA, South Korea's Personal Information Protection Act (PIPA)—give victims a predictable, relatively low-cost path to compensation without proving the extent of harm. GDPR-based claims offer broad coverage but require the victim to quantify non-material damage, which courts across Europe have assessed inconsistently. Common-law systems without statutory damages leave the victim bearing the full evidentiary burden of proving emotional and reputational injury, a process that is both protracted and psychologically taxing.
Practical obstacles to accountability
Even where the law provides a cause of action, several practical barriers reduce its effectiveness.
- Anonymity and attribution. Many deepfake images are produced and shared on anonymous or pseudonymous platforms. Identifying the creator requires cooperation from the platform, which may be headquartered in a jurisdiction that does not compel disclosure to foreign civil litigants.
- Platform immunity and intermediary liability. Section 230 of the US Communications Decency Act shields platforms from liability for user-generated content, pre-empting many negligence claims against hosts. The EU's Digital Services Act and the UK's Online Safety Act impose duties of care on platforms but allocate enforcement primarily to regulators, not to private litigants.
- Cost and duration of civil litigation. Biometric privacy claims can take years to resolve. Victims who need rapid removal of content may find that takedown notices under copyright or platform terms of service are faster than court orders, even though they address only distribution, not the underlying biometric violation.
- Jurisdictional fragmentation. A victim in Germany, a creator in Russia, and a hosting platform in the United States create a three-jurisdiction problem. No bilateral treaty streamlines civil biometric privacy claims across borders in the way that, say, trademark enforcement benefits from established international frameworks.
Evaluating legal and technical remedies
Choosing a response involves matching the available tool to the specific objective—removal, compensation, deterrence, or attribution—and weighing speed, cost, and probability of success.
Civil biometric privacy claims
Best suited when the creator is identifiable and resides in a jurisdiction with a private right of action and statutory damages. The claim is comparatively straightforward: the plaintiff must show that the defendant collected or used a biometric identifier without the required notice and consent. There is no need to prove that the deepfake caused specific emotional harm, although actual damages may be pleaded in addition. The limitation is geographic; BIPA-style statutes exist in only a handful of US states, and even there, courts have split on whether a plaintiff must allege a concrete injury beyond the statutory violation itself to satisfy standing requirements.
GDPR complaints and civil claims
Effective for removal and restriction of processing, and for triggering regulatory action against platforms. A data subject can lodge a complaint with the supervisory authority, which may order erasure and impose fines. The parallel civil claim for compensation requires proof of non-material damage, which the Court of Justice of the EU has held need not be serious but must be more than minimal. This route is strongest when the data controller is a corporate platform within the EU; it is weakest when the controller is an unidentifiable individual outside the EEA.
Criminal complaints
Appropriate when the goal is deterrence and the evidence supports a realistic prospect of prosecution. Criminal complaints shift the investigative burden to the state, which has resources the individual lacks. The trade-off is control: the victim cannot direct the investigation, and prosecutorial discretion may deprioritise a single deepfake case in favour of larger operations. Sentences in most jurisdictions remain modest, limiting deterrence for actors who are already insulated by anonymity.
Technical and platform-based measures
Content fingerprinting (embedding detectable signals in source imagery), reverse-image search tools, and platform content-moderation systems offer the fastest path to removal. They do not, however, establish liability against the creator or compensate the victim. Their proper role is as a first-response measure that limits circulation while legal processes run their course.
Selection criteria for an effective response
Faced with unauthorised biometric use in deepfake pornography, a victim or adviser should evaluate the available strategies against four criteria:
- Identifiability of the creator. If the creator is unknown and the platform is uncooperative, civil and criminal paths are largely blocked. Technical takedown and regulatory complaints against the platform become the primary options.
- Jurisdictional alignment. The victim, the creator, and the platform must be assessed separately. A cause of action that is strong in one jurisdiction may be unavailable in another. The optimal strategy may combine claims—biometric privacy against the creator, GDPR-based erasure against the platform.
- Speed versus completeness. Takedown requests resolve the immediate harm quickly but leave the underlying biometric violation unremedied. Litigation addresses the violation but may take years. In practice, most effective responses run both tracks in parallel.
- Evidentiary burden. Statutory claims with liquidated damages require less proof of harm than common-law torts or GDPR compensation claims. Where available, they should be preferred—not because they are more just, but because they are more likely to succeed within the victim's resources.
What changes, and what does not
Legislatures are moving. More US states are considering biometric privacy laws with private rights of action. The EU's AI Act will classify certain manipulative AI systems as prohibited or high-risk, potentially adding a regulatory layer above the GDPR. Criminal penalties for deepfake sexual content are trending upward in several jurisdictions. What does not change is the fundamental asymmetry: the technology to create deepfake pornography is cheap, accessible, and distributed, while the legal infrastructure to respond is expensive, jurisdiction-bound, and slow. Closing that gap requires not just stronger statutes but mechanisms for rapid cross-border identification, streamlined civil procedure for biometric privacy claims, and platform obligations that attach at the point of upload rather than the point of complaint. Until those structures exist, liability for the unauthorised use of biometrics in deepfake pornography will remain easier to articulate in principle than to enforce in practice.