Cybersecurity Policy Report, Polish Privacy Office Explains Legal Consequences of Deepfake Data Processing, (Jun 26, 2026)
By Tony Foley
In a letter sent to the Krakow police, the Polish data protection authority, Urzad Ochrony Danych Osobowych (UODO), explained the legal implications of deepfake technology and the risks it poses.
The letter was prompted by reports of a 17-year-old girl who used artificial intelligence (AI) to alter a photo of a younger friend and create material that could be characterized as pornographic. In a Wednesday news release, UODO President Mirosław Wróblewski pointed out that, while Polish law does not define the term, under article 3, section 60 of the European Union’s Artificial Intelligence Act, the term “deepfake” refers to “images, audio content, or video content generated by artificial intelligence or manipulated by AI that resemble real persons, objects, places, entities, or events that the recipient could wrongly believe to be authentic or true."
President Wróblewski emphasized in the letter that while AI itself was neutral, the ability to create realistic but false images and sounds poses a threat for individuals and social groups, used for purposes like violations of images rights, identity theft, blackmail, and fraud. In addition, the letter points out that AI can be used for behavioral manipulation, to fabricate evidence for legal proceedings, and pose threats to national security.
Many of the threats outlined above already are covered by Polish law, but the letter points out that the creation of deepfakes also can be prosecuted under article 107 of the Poland’s Personal Data Protection Act (PDPA), which criminalizes the use of other people’s personal data without a legal basis. President Wróblewski clarified that an alteration of an individual’s image to create pornographic material or a nude photograph constitutes personal data processing under the law, and that the EU General Data Protection Regulation (GDPR) requires that legal grounds for the processing must be established.
The letter adds that the difficulty in distinguishing an artificially generated photo from an authentic image makes the phenomenon particularly harmful. For purposes of fulfilling the characteristic of a crime under PDPA article 107, it is irrelevant whether the altered image originated from a publicly available source; instead, the crime is defined by the processing of personal data without a legal basis.
Maintaining that minors and their personal data should be afforded special protection, the letter concludes by recommending a decisive response from law enforcement authorities in these situations, which it said would build awareness that the use of such deepfakes is a prohibited act and demonstrate that these activities will not go unpunished.
The letter may be downloaded from the news release but is available only in Polish.
News: InternationalLegislation DataPrivacy GDPR AINews