Synthesia

Risk Level: Low Risk
Updated: May 13, 2025
Provider Overview

The provider exhibits a high overall compliance risk (score 0.86), primarily due to gaps in consent granularity, insufficient documentation of legitimate interest assessments, and weaknesses in cookie consent logging. Key risks include potential violations of GDPR's lawful basis requirements (Articles 6-7), ePrivacy Directive's cookie rules, and EU AI Act's transparency obligations for automated decision-making. While the provider demonstrates strong adherence to data subject rights (DSAR fulfillment) and technical security measures, critical improvements are needed in consent management frameworks, automated decision disclosures, and third-party accountability mechanisms.

Tracked Documents
Terms of Service
May 13, 2025
Privacy Policy
May 13, 2025
Cookie Policy
May 13, 2025
Data Processing Addendum
May 13, 2025
Data Processing Agreement
May 13, 2025
User Terms of Service
May 13, 2025
Customer-Specific Supplement
May 13, 2025
AI Governance Practices
May 13, 2025
Acceptable Use Policy
May 13, 2025
Subprocessors
May 13, 2025
Modern Slavery Statement
May 13, 2025
Data Request Policy
May 13, 2025
Content Integrity Policy
May 13, 2025
Security Practices
May 13, 2025
Ethics
May 13, 2025